Bitcoin promised money that doesn't ask anyone's permission. That promise only works if you hold your own keys.
Two of the most common ways users lose funds: their own mistake, a seed written down wrong, a password forgotten. Or a flaw in the design of the tools they trusted, which they had no way to see. Either way, it is always the user who suffers the consequences.
Discipline cannot fix a flawed design. And good design removes the mistake instead of demanding a lifetime of perfect discipline. Making the setup more complex, or pushing more responsibility onto the user, is not security. It is security theatre. And this matters beyond any product. Holding your own keys is digital private property: owning something without anyone's permission. A right only experts can exercise is a right most people don't have. So safe and easy have to coexist. Digital private property cannot stay a niche.
Our industry has to build security design that scales to ordinary people. And no one's design should be taken on their word, ours included. Open what can be open, so anyone can check it. What must stay closed for security, hand to independent experts to test. And the proof is time: still standing years later, with real money inside.
Total safety does not exist. Anyone who promises it is selling something. Security is a direction: safer every year, easier every year, tested by people who try to break it. And the destination has never changed since the first nine pages: a billion people holding their own keys, and actually using them. Send, sign, transact, live with it. Money, and soon your identity too.
The only security is security by design. So here is the bar, for every wallet, ours included: no compromise. Not on security, to make it easy. Not on ease, to make it secure. Not on sovereignty, to make it safe. The moment we ask users to compromise, we have failed at the design. That is the bar. That is the whole fight, true to the original promise of those nine pages.
I love that the context in which I said this (on Bloomberg Crypto on Tuesday) was, "I said this on stage October 2025 and no one reacted."
Only reaction then was, "OK, security company guy, we know, you're paranoid."
We're all paying attention now.
Trust Wallet had essentially the same flaw of Coldcard - errors that led to insufficient entropy.
Fortunately for Trust Wallet, the Donjon, Ledger's in-house security team found it in 2022 and not a hacker.
With the @Ledger Wallet CLI you can put your agent to work with the peace of mind that no funds move unless you sign on your Ledger signer.
Let your agent play with Ledger Wallet CLI v2, out now.
v1: Give your agent balances, history, send, receive, swap via CEX providers.
v2? 🧵👇
Ledger Flex is here.
Alongside Ledger Stax, Ledger Flex is the latest addition to our new category of secure touchscreen devices.
Ledger's CEO @_pgauthier, CXO @iancr, CTO @P3b7_ and other members of the team sat down to tell us the story behind Ledger Flex and Ledger's new standard!
Ledger Flex is available now at: https://t.co/3poYXBYkJy
The era of secure touchscreens has arrived.
Today, I’m excited to announce our new device, Ledger Flex, now available for purchase on https://t.co/4t8sX3zewX and with immediate shipping. Zero wait. You can now also pre-order from the next batch of Ledger Stax on https://t.co/4t8sX3zewX.
🧵
Introducing Ledger Flex.
Ledger Flex marks the new standard for Ledger devices, featuring a secure E Ink touchscreen, NFC, and our new Security Key app that will allow you to go from painful logins to passwordless ease, all from your secure Ledger device.
Shipping NOW at: https://t.co/3poYXBYkJy
🚨 Attention Ledger users
Our Support section will be down for a short maintenance period as we migrate to a new and improved version for better service.
🔗 The URL (https://t.co/fNDRGKhf5d) remains unchanged.
✅ Other sections of our Ledger website are not impacted.
We are 100% focused on following up to last week’s security incident, making sure incidents like this are prevented in the future, and that the ecosystem remains safe.
We are aware of approximately $600k in assets impacted, stolen from users blind signing on EVM DApps.
Ledger will make sure victims affected will be made whole, and are committing to work with the DApp ecosystem to allow Clear Signing, and no longer allow Blind Signing with Ledger devices by June 2024.
Read more:
We affirm our CEO & Chairman @_pgauthier’s promise https://t.co/6ScBNshwvV to make sure victims who had their assets stolen on Dec 14th, 2023 by the attacker together with angel drainer are made whole, including users who are not Ledger customers.
We commit, by any way possible, including gestures of goodwill, to make sure this is done by the end of February, 2024. We are already in contact with many impacted users and are actively working through the specifics with them.
We remind users that if you signed a transaction on affected DApps Dec 14th, 2023, best security practices would recommend revoking any authorized transactions to further reduce impact from the malicious code.
We are announcing that by June 2024, users will no longer be able to Blind Sign with Ledger devices. Our commitment is to work with the community and DApp ecosystem to allow Clear Signing so users can verify all transactions on Ledger devices before signing. This will lead to a new standard to protect users and encourage Clear Signing across DApps.
Front-end attacks have happened many times before and will continue to plague our ecosystem. The only foolproof countermeasure for this type of attack is to always verify what you consent to on your device.
This is only possible with Clear Signing: meaning you can see and verify exactly what you sign on a secure display.
If the ecosystem continues to allow Blind Signing, users remain at risk.
We ask DApp developers to support the Clear Signing security brick. Please reach out to us through our Developer portal (https://t.co/KGfFIuQFAs) or Discord (https://t.co/wAsoun1Xlh) so we can work together to add Clear Signing to your DApp.
We have detailed the cause of this hack and our security team’s response to this in a Ledger Connect Kit Incident Report on our Ledger tech and security blog:
https://t.co/pqrhAxGl28
We remind you your Ledger devices and Ledger Live have always been secure to use, and were not made vulnerable by this exploit.
If you believe you may have been affected by the attack, please reach out via our Ledger Help Center to find out more:
https://t.co/g4YV2inCDL
Thank you again, stay safe and Happy Holidays.
An important message for #developers: I’m thrilled to announce that our new Developer Portal is now available!
What are its new features?
And why are developers at the core of everything we do at @Ledger?
Thread 🧵
https://t.co/lvb2lA5FBk
Ledger Recover, provided by Coincover, is launching today! This solution is a paid, *optional* subscription wallet recovery service for users who want a secure backup of their Secret Recovery Phrase.
🧵 Let’s recap why this solution is a great and secure option for Ledger users
Today is the day. I’m glad to announce that our secure wallet recovery solution Ledger Recover, provided by Coincover, is now available for Ledger Nano X users. You can subscribe to this paid and optional service here:
https://t.co/rHKDR3fS7N
Ledger Recover, provided by Coincover, is launching today!
https://t.co/JRl4cLn2tQ
What does this mean, how does the service work, and who is it for?
Scroll down to learn more and sign up👇
Today, I’m excited to announce we’re beginning the countdown for our launch of Ledger Recover, provided by Coincover. After months of listening, taking community feedback, and publishing the code for verification, I wanted to go back to our “why.”
A thread 🧵
@TrustyHogs @HelenBaBauer @CatherineBohart On a commuter train in Paris and people are looking at me funny as I keep snorting with laughter #corridor#international#internationalcorridor
I want to address the feedback over Ledger Recover, the way it was communicated, and share our path forward. Read my letter and join our town hall with our leadership team to learn more.
🧵👉 https://t.co/2hlPrMwzaN
Ledger’s mission is, and will always be, to provide our users with the right tools to own their digital value securely.
We have decided to accelerate our open-sourcing roadmap to bring more verifiability to everything we do.
A thread 🧵
Today, Ledger announced our new funding. I'm grateful for our long-term investors' support, and I welcome the new ones backing the undeniable revolution of value and hardware.
Unfurl for a thread 🧵
https://t.co/hlTEhZBzrW
Ledger is proud to announce our Series C extension fundraising round.
We continue our mission of bringing ease-of-use and uncompromised security to your digital value.
Read what our CEO @_pgauthier has to say:
https://t.co/JSHyi5jKIQ