Ledger
Best for verifiable firmware openness
How it rates
- Firmware source published in a public repository
- Device security or specification page published
- Technical documentation reachable without an account
- Terms page not found at the conventional address at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetFirmware source published in a public repository
Vendor repository reachable at this check.
github.com/LedgerHQ - MetDevice security or specification page published
Security or specification page reachable at this check.
donjon.ledger.com/ - MetIndependent security research or audit programme published
Security research programme published by the vendor.
donjon.ledger.com/ - MetTechnical documentation reachable without an account
Documentation open at this check.
support.ledger.com/ - MetVendor organisation identifiable from the repository
Repository published under the vendor organisation (Ledger SAS).
github.com/LedgerHQ
- Met
- MetModel-specific product page public
Model page reachable at this check.
www.ledger.com/academy/security - Not metLegal or terms page public
Not found at the conventional address at this check.
- Met
- MetPurchase information viewable without an account
No account required to reach the shop at this check.
shop.ledger.com/
- Met
- Met
- Met
- MetDocumentation site separate from marketing
Dedicated documentation or support resource published.
support.ledger.com/ - Met
- Met
- Met
- Met
- Not metTerms or legal documentation published
Not found at the conventional address at this check.
- Met
- Met
- Met
- Met
- Met
- Not metLegal documentation reachable
Not found at the conventional address at this check.
A widely used secure-element wallet with public firmware repositories and a security research programme, built on a closed secure-element operating system.
Our assessment
Ledger publishes firmware repositories, a security research programme and reachable technical documentation — most of what our rubric asks for. The part it does not publish is the part its architecture depends on most: BOLOS, the operating system running inside the secure element, is closed source.
A different bet on where trust should sit
Ledger drives the device display directly from the secure element, so the screen showing what you are about to sign sits inside the protected boundary rather than outside it. That is a real security property, and it is the reason the company gives for keeping the operating system closed. Whether you accept the trade is the single decision that separates this device from Trezor.
What is published
Wallet applications and much of the surrounding firmware are in public repositories under the vendor organisation, and Ledger Donjon publishes security research including attacks on its own products and on competitors. Security documentation and specification pages are reachable without an account. On our openness indicators the only consistent failure is a legal page at a conventional address.
Reputation and the 2020 data breach
The 2020 customer database leak exposed names and physical addresses of buyers and produced years of targeted phishing and physical threats. It was a marketing-database failure rather than a device failure, and it remains the most consequential thing that has happened to a hardware wallet company's customers. Anyone buying should assume their purchase details may be handled by a third party.
Who it suits
Ledger fits buyers who prioritise broad asset support, a mature ecosystem and secure-element-driven display verification, and who accept a closed operating system in exchange. Buyers whose requirement is that every line of code be auditable should choose Trezor, BitBox or Foundation Passport.
How rivals compare
| Service | Score | Best for | |
|---|---|---|---|
| Trezor | 9.9 | verifiable firmware openness | Read → |
Frequently asked
Does this score mean Ledger is secure?
No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.
Why does firmware openness matter so much here?
It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.
What would raise this score?
Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.