Ledger crypto wallet

Ledger Wallet Review: Nano, Flex, and Stax Compared

Ledger is the biggest name in hardware wallets by unit volume, and also the one with the most complicated trust history of the three we’ve now covered. This review looks at the current five-model lineup, the real security incident timeline (there’s more here than with Tangem or Trezor), and why the Trustpilot numbers tell a genuinely different story than the other two reviews on this site.

At a glance: Non-custodial hardware wallet line from Ledger SAS, founded 2014 in Paris. Five current models from $59 to $399, all using a certified secure element. The longest and most eventful security history of the major hardware wallets – including a major 2020 data breach with long-running phishing fallout, a 2023 trust controversy over an optional recovery feature, and a supply-chain attack later that year. User sentiment is sharply polarized: 3.3/5 on Trustpilot with 45% five-star and 43% one-star.

Company History

Ledger was founded in 2014 in Paris by Eric Larchevêque, Nicolas Bacca, and Joel Pons, a team with backgrounds in embedded smart-card security at companies like Oberthur Technologies and Gemalto. The original Ledger Nano S launched in 2016, followed by the Bluetooth-enabled Nano X in 2019. The company raised a $7M Series A (2017), $75M Series B (2018), and a $380M+ Series C (2021) that valued Ledger at over $1.5 billion, making it one of the best-funded companies in this space by a wide margin. The current lineup – Stax, Flex, Nano Gen5, alongside the older Nano S Plus and Nano X – reflects that scale, spanning budget to premium price points. For a look at the wallet type that skips the seed phrase entirely, see our Tangem Wallet Review; for the open-source alternative, our Trezor Wallet Review.

Current Lineup

ModelPriceDisplaySecure ElementConnectivity
Nano S Plus$591.1″ monochrome OLEDEAL6+USB-C only
Nano X$991.1″ monochrome OLEDEAL5+USB-C + Bluetooth, battery
Nano Gen5$1792.8″ E Ink touchscreenEAL6+USB-C + Bluetooth + NFC
Flex$2492.8″ E Ink touchscreen, Gorilla GlassEAL6+USB-C + Bluetooth + NFC
Stax$3993.7″ curved E Ink touchscreen, wireless chargingEAL6+USB-C + Bluetooth + NFC

The Nano S Plus is the budget pick for pure cold storage with no wireless anything – arguably the most conservative choice from a security-surface standpoint. The Nano X trades a slightly older secure element certification for Bluetooth convenience. Flex and Stax are the modern flagships with full touchscreens, better transaction verification (you can actually read what you’re signing), and NFC. Stax adds a curved premium display and wireless charging on top.

Security Track Record

This is the part where Ledger’s story diverges meaningfully from Tangem and Trezor, and it deserves to be laid out plainly rather than softened:

  • 2018 – Independent researchers demonstrated pre-initialization tampering and physical/side-channel attacks against early Nano devices. Lab-grade, requiring physical access and specialized equipment – Ledger hardened firmware checks in response.
  • December 2020 – A major breach of Ledger’s e-commerce and marketing databases exposed email addresses for over 1 million customers, and for hundreds of thousands, names, phone numbers, and home addresses.
  • 2020-2021 – The leaked data fueled sustained phishing campaigns, and disturbingly, physical scams: fraudulent “replacement device” packages mailed to customers’ real home addresses, designed to trick people into entering their seed phrase into a compromised device.
  • May 2023 – The Ledger Recover controversy: announcing an optional identity-verified key-recovery service revealed that Ledger’s firmware technically had the capability to export key material under certain conditions. No funds were compromised and the feature is opt-in, but it damaged trust in the “your keys never leave the device, ever” promise that had been core to Ledger’s pitch.
  • December 2023 – The Ledger Connect Kit supply-chain attack: malicious code was injected into a code library used by numerous decentralized apps that integrate with Ledger, tricking connected users into approving fraudulent transactions. Ledger detected and patched it within hours, but real funds were stolen from users who interacted with affected dApps during that window.
  • January 2026 – A third-party payment/logistics provider (Global-e) breach exposed customer contact details – the same category of vendor breach Tangem and Trezor have also disclosed, with no funds or recovery phrases compromised.

The pattern: two genuinely serious incidents (the 2020 breach and its years-long phishing fallout, and the 2023 Connect Kit attack, which did cause real fund losses for affected users) plus a trust-model controversy, on top of vendor breaches similar to what competitors have also faced. That’s a longer and more serious list than either Tangem or Trezor’s.

What Real Users Say

Ledger holds a 3.3/5 rating on Trustpilot across 2,707 reviews – sharply polarized at 45% five-star and 43% one-star, a very different shape than Tangem’s or Trezor’s more consistently positive distributions.

Positive reviews still praise support quality: “the support team were excellent… responsive, knowledgeable and reassuring.”

Negative reviews split between hardware gripes (Nano X battery degrading within a year) and far more serious claims of stolen funds – one user reported over 38,000 XRP and 70,000 XLM stolen from their wallet. These are very likely victims of the phishing and social-engineering campaigns that followed the 2020 data breach rather than a device-level flaw, but from a buyer’s perspective, the practical risk is the same: your data being in criminals’ hands for years increases your personal attack surface regardless of what caused it.

Watch Out For

  • The most eventful security history of the three wallets we’ve reviewed. Not a reason to avoid Ledger outright, but a real factor – go in informed rather than assuming “biggest brand” means “cleanest record.”
  • The 2020 breach’s long tail. If you bought a Ledger device before December 2020, your contact information may still be circulating, and you remain a more likely phishing target than a newer customer. Never enter your seed phrase anywhere except your physical device, ever – no email, no “support” call, no replacement-device mailer.
  • The Ledger Recover controversy is worth understanding, even though it’s opt-in and no funds were compromised: it means the “keys physically cannot leave the device” claim has an asterisk if you ever enable that feature. Leave it off if that trust model matters to you.
  • The Connect Kit incident is a reminder that dApp connections are a real attack surface – your Ledger device itself wasn’t hacked, but the software layer connecting it to web3 apps was, and it caused real losses. Double-check what you’re signing every time, not just trusting the “Ledger says it’s fine” assumption.
  • Trustpilot sentiment here is meaningfully worse than Tangem or Trezor – 43% one-star is not noise. Some of it is understandable given the 2020 breach fallout, but it means the “everyone loves it” assumption a market leader might otherwise earn doesn’t fully hold.

Dan’s Verdict

Ledger’s hardware itself has held up reasonably well – the certified secure elements are solid, and outside the Connect Kit window, there’s no confirmed case of a Ledger device’s actual key storage being defeated remotely. But this is the wallet with the most to be honest about. The 2020 breach and its phishing fallout are a real, ongoing risk factor for anyone who’s been a Ledger customer for a while, and the Recover controversy is a legitimate reason some security-focused users have moved to Trezor’s fully open-source model instead. If you’re buying today: the Flex is the sweet spot for most people – full touchscreen for reading what you’re actually signing, at a reasonable price. Skip the Nano X unless Bluetooth convenience really matters to you, given its older secure element rating and the battery complaints. Whatever model you pick, treat any unsolicited email, call, or mailed “replacement device” as a scam by default – that’s the single most important habit given Ledger’s history specifically.

You can grab a Ledger wallet here.

For comparison, see our Tangem Wallet Review (seedless NFC) and Trezor Wallet Review (fully open source), or our review methodology for how we evaluate products like this.

Frequently Asked Questions

Yes, Ledger is a well-funded, established hardware wallet maker founded in 2014 in Paris, with a certified secure element in every current model. Its security history includes more disclosed incidents than some competitors, so it’s worth understanding that history before buying.

The Flex ($249) is the best fit for most people, offering a full touchscreen for verifying transactions at a reasonable price. Budget buyers can get the same core security with the Nano S Plus ($79), while the Stax ($399) is the premium flagship option.

Ledger’s device hardware has not been remotely compromised, but the company disclosed a major 2020 data breach exposing over a million customers’ contact information, and a December 2023 Ledger Connect Kit supply-chain attack that did cause real fund losses for users connected to affected apps during a several-hour window before it was patched.

In May 2023, Ledger announced an optional identity-verified key recovery service, which revealed that its firmware technically had the capability to export key material under certain conditions. No funds were compromised and the feature is opt-in, but it raised trust concerns among users who expected keys to never be exportable under any circumstance.

Ledger sits at 3.3/5 on Trustpilot, sharply split between 45% five-star and 43% one-star reviews. Much of the negative sentiment traces back to phishing and scam attempts that followed the 2020 data breach, along with some hardware reliability complaints, rather than the core wallet security failing.

Ledger’s current lineup ranges from $79 for the Nano S Plus up to $399 for the flagship Stax, with the Nano X, Nano Gen5, and Flex filling in between.

Similar Posts