Best Crypto Wallets
Top rated: Rabby 8.3
Software wallets for everyday use.
5rated →
The best-supported device in the category by asset coverage and app quality, and the one with the most damaging trust history around it. The 2020 customer-data breach put home addresses of owners online, the 2023 Recover announcement confirmed that signed firmware can export seed material, the December 2023 Connect Kit attack drained about $600,000 from users who blind-signed, and customer order data leaked again through payment processor Global-e in January 2026.
Best for: The widest asset coverage and the best mobile experience
7.7 is the weighted average of the five pillar findings below. Dependable, with trade-offs a reader should know about first.
Certified secure element with no key extraction on record. Firmware is closed source, and the Recover programme confirmed that signed firmware can export seed shards — opt-in, but a capability that exists whether or not a user enrols. The December 2023 Connect Kit supply-chain attack (malicious versions 1.1.5–1.1.7 on npm) drained about $600,000 from dapp users who blind-signed; Ledger pledged to repay victims, and we found no confirmation that payouts were completed.
Competitive pricing with no mandatory ongoing cost. Recover is an optional $9.99-a-month subscription.
Ledger SAS, Paris. The 2020 shop-database breach exposed customer data, and about 270,000 names and postal addresses were dumped publicly in December 2020 — a security failure with physical consequences. In January 2026 names, addresses and order details of some Ledger.com buyers leaked through its payment processor Global-e; the number affected has not been published.
The widest asset and app coverage available, with a mature and reliable mobile experience.
Excellent onboarding and the most polished software in the category.
Strengths
Against it
Nothing else in this category matches Ledger for asset coverage or app quality, and its certified secure element has no key extraction on record. On performance and access it is at or near the top of this table.
The record around the device pulls it down. The 2020 breach of the customer database put names and home addresses of known hardware-wallet owners online — a security failure with physical consequences, not merely a privacy one — and order data leaked again through payment processor Global-e in January 2026. The 2023 Recover announcement confirmed that signed firmware can export seed material, a capability many owners had assumed the architecture made impossible. And in December 2023 a compromised Connect Kit library, published to npm after a former employee was phished, drained about $600,000 from dapp users who blind-signed. No key was extracted from a Ledger device in any of these; the closed firmware is why owners cannot check that for themselves.
Only if you enrol in Recover, which encrypts the seed on the device and splits it among three custodians after you approve it with your PIN. The programme showed that signed firmware can export seed shards, so the capability exists whether or not you enable it. Because the firmware is closed, Ledger’s statement that nothing leaves without consent cannot be independently verified — which is the substance of the objection.
Not through an exploit of Ledger device firmware or a key extracted from its secure element. Users did lose about $600,000 on 14 December 2023, when three malicious versions of Ledger’s Connect Kit library, published to npm after a former employee was phished, served drainer transactions through dapps such as SushiSwap and Revoke.cash. Ledger pledged to repay victims by the end of February 2024; we found no public confirmation that the payouts were completed.
In 2020 an attacker pulled Ledger’s shop and marketing database; in December 2020 about 270,000 customers’ names, postal addresses and phone numbers were dumped publicly, and phishing, fake devices and extortion letters followed. In January 2026 names, addresses, phone numbers and order details of some Ledger.com buyers leaked through its payment processor Global-e. Neither touched devices or keys.
Assessed by
Blockchain Security Researcher · September 27, 2026
CoinRadar Daily is a non-commercial project. We have no commercial relationship with Ledger Nano X, earn nothing from any link on this page, and carry no advertising or sponsorship anywhere on the site. Findings rest on public sources; we did not open an account or transact.
Rubric v2.0How we score →
Independent, rubric-scored tables for the services behind this story.
Top rated: Rabby 8.3
Software wallets for everyday use.
5rated →
Top rated: Kraken 8.4
Centralised venues that hold your funds while you trade.
6rated →
Top rated: Kraken Staking 8.0
Services that stake on your behalf.
5rated →