I had the chance to meet Ismail a few years ago, and his dedication, generosity, and genuine spirit have always stood out. He is a one-of-a-kind artist and an even better human being. Couldn’t be happier to finally bring this one to life. So proud of you, brother @l4artiste
“Freedom from compromise is when the image stays the way I first felt it.”
@l4artiste doesn’t chase moments. He waits for them, lets them unfold and then captures them in the purest form.
"Security is not a cost. It's not an afterthought. It's the entire product."
That's the philosophy behind Ledger Enterprise, Ledger built for teams: financial institutions that need governance on top of the hardware wallet, not just a device. Ledger Enterprise is the trusted infrastructure for managing on-chain operations.
🌞 WIN the ultimate Ledger Summer Bundle 🔐
We're giving one winner the full kit, free from compromise:
3x Ledger Nano™ Gen5 touchscreen signers (you pick the colors)
3x Ledger Recovery Key™ PIN-protected backup card
1x Limited Edition Susan Kare clip-on Badge Pack
$80 Bitcoin voucher
To enter: Follow @Ledger + tag your summer buddies in the replies below 👇
💥One Check, One Laser, Every Card: The Tangem Immutability Trap.
The @DonjonLedger just published research worth stating plainly.
With a single laser pulse the Ledger Donjon team faults one conditional check in the firmware of a Tangem card and resets the password to a value of its choosing. No existing password, backup card, or recovery feature needed. Once reset, the attacker is able to sign anything and can potentially drain the user’s wallet.
To be precise about the threat model: this attack requires physical possession of the card, invasive chip opening, lab-grade fault-injection equipment, our own setup costs roughly $250,000, and genuine technical expertise. That puts it well beyond the reach of an opportunistic thief, but comfortably within the capabilities of a serious lab. Both things can be true at the same time.
Why one pulse is enough: the recovery path depends on a single yes/no check, “is this card in recovery state?”, and a pulse is simply a precisely timed electrical disturbance designed to make the chip misread that decision at the critical moment. Because there is no redundant check and no penalty for repeated SetPin attempts, one successful disturbance is enough. The chip’s countermeasures are formidable, but they cannot protect the one bit the firmware chose to trust.
The uncomfortable part: it cannot be patched. Tangem cards have no firmware update mechanism. The vulnerability was disclosed on February 10th, 2026. There is no fix coming, because there is no channel to deliver one.
Tangem presents immutable firmware as a security feature. Call it what it is: a trade-off. "We cannot change the firmware" is a strong story right up until the firmware is wrong. Then the same property that protected you guarantees you can never be protected again. This research did not create that reality. It made it visible.
What a user can do, since there is no patch: this attack requires physical possession of the card and invasive lab work, so it cannot be done covertly. The practical risk is a lost or stolen card in the hands of a capable attacker. If the card stays in your possession, there is no reason to assume compromise. If you have doubt, or if your threat model requires a higher level of assurance, treat the funds as compromised and move them to a new secure set up.
This was published in line with Ledger Donjon’s responsible disclosure process. When a vulnerability cannot be patched, the next responsibility is to inform users clearly and widely, so they can make their own informed decisions, especially here where the vulnerability can not be exploited remotely.
The bigger lesson is not about one product. Security is never static, and systems should be designed with human error and future failure in mind. You should not have to blindly trust that yesterday’s assumptions still hold. You should be able to verify, adapt, and recover when they do not. Design for the day you are wrong, because eventually, you will be.
Full write-up from Baptistin Boilot, Ledger Donjon.
Stay safe. Stay honest about your trust assumptions.
https://t.co/1FMn0fjGJd
New upgrades are officially rolling out for the Ledger Wallet™ app.
The ease of an exchange. The security of a Ledger touchscreen signer. Free from compromise.
→ Clarity: your whole portfolio, history, Profit & Loss all in one view
→ Choice: swap, earn, trade Perps and more across 50+ providers, 100+ chains
→ Control: verify every move on your secure signer. Keys stay offline.
Download Ledger Wallet today 👇
AI agents can search, plan, negotiate, and execute at a speed no human can match. But speed without a security boundary is just a faster way to lose control. This is the architectural problem the financial industry has already solved once before, and Ledger Agent Stack is how it gets solved again.
The internet economy needs a foundation you can verify.
When value moves, who holds it? With Ledger, you do - every transaction Clear Signed before you approve it.
Proud to be a launch partner for Open USD.
remote signal unlocked 👁️⃤
ledger's agent kit only talks to your device over usb-c
got it working over bluetooth — signed a real usdc transfer on base with the ledger sitting across the desk, no cable
here's how 🧵
Under MiCA, exchanges operating in Europe must now hold a licence.
But the exchange holds the private keys: you hold a claim.
Your Ledger signer secures your transactions, and Ledger Wallet™ handles the interface 🔐
We gave 50 students the Ledger Agent Stack and one week.
One rule across all of them: the agent proposes, the signer approves.
The key never lives in a .env.
Here's what they built:
Your Perps deserve better security
Stop juggling fragile browser extensions and risking your digital assets to blind signing just to hit your next trade.
Paired with your Ledger signer, you can now long or short through @yield_xyz in Ledger Wallet™ with 100% Clear Signing.
Lock in, verify on your device, and stay secure, even on the go.
Free from compromise 🔐
Perps trading involves significant risk. See below.
July 1, 2026 marked the end of the grace period under MiCA.
Whether an exchange is licensed or not, your assets are held by a third party on your behalf.
Set up a Ledger signer with Ledger Wallet™ and hold control over the asset directly 🔐