Ledger has a customer-funds incident on record (2023-12), with Ledger committed to reimburse victims; it remains eligible under our rules. Other incidents on record: firmware vulnerability (2026-08); data breach (2020-07). Regulatory actions in the last 5 years on record: 0.
Data as of · Last updated · By VaultRubric Research · How we score · Not investment advice.
Ledger has a customer-funds incident on record (2023-12), with Ledger committed to reimburse victims; it remains eligible under our rules. Other incidents on record: firmware vulnerability (2026-08); data breach (2020-07). Regulatory actions in the last 5 years on record: 0.
This page answers “Is Ledger safe?” only from VaultRubric's sourced record (security incidents, regulatory actions, licensing and protections), as of 2026-10-11. It is not a guarantee: no platform is risk-free, and safety also depends on how you use it (2FA, phishing, backups).
Security: 5.5/10. base 7, +1.5 secure element, +0.5 partially open-source, 0 data breach (2020-07, >48 months, no customer funds lost), −3 customer funds loss (2023-12), −0.5 firmware vulnerability (2026-08)
Overall VaultRubric score across all hardware wallet options we track: 71.5% (data coverage 100%). How incidents are scored · hack cap.
| Date | Type | What happened | Sources |
|---|---|---|---|
| 2026-08 | firmware vulnerability | Ledger Security Bulletins 023 and 025: Secure SDK command-interleaving flaw (fixed SDK v26.6.1) and Ethereum app swap flow that could sign a token approval without display (fixed in app 1.22.3); device OS unaffected; no funds loss reported | donjon.ledger.com, donjon.ledger.com |
| 2023-12 | customer funds loss | Ledger Connect Kit supply-chain attack: malicious library version drained ~$600K from users blind-signing on EVM dApps; Ledger committed to make victims whole via a claims process (by Feb 2024) | www.ledger.com, support.ledger.com, www.theblock.co |
| 2020-07 | data breach | E-commerce DB breach: ~1M emails, ~272k detailed customer records leaked; devices/funds unaffected | www.ledger.com |
None in our sourced record.
Ledger has a customer-funds incident on record (2023-12), with Ledger committed to reimburse victims; it remains eligible under our rules. Other incidents on record: firmware vulnerability (2026-08); data breach (2020-07). Regulatory actions in the last 5 years on record: 0. No platform is risk-free; see the full record on this page.
Yes. 2023-12: Ledger Connect Kit supply-chain attack: malicious library version drained ~$600K from users blind-signing on EVM dApps; Ledger committed to make victims whole via a claims process (by Feb 2024)
Ledger scores 71.5% across all hardware wallet options we track, with 100% data coverage. See /methodology.