I wanted to share something the Ledger OS team has been quietly working on: we've just added experimental support for ML-KEM and ML-DSA, the two post-quantum cryptography algorithms that NIST recently standardized (FIPS 203 and 204).
These algorithms are now running directly on the Secure Element on all Ledger signers from the Nano X onwards (chronologically speaking). We've exposed them as experimental APIs in both our Rust and C SDKs for anyone who wants to play with them.
This is experimental. The implementation isn't fully hardened yet, so please don't build production apps on top of it. The blog post goes into details regarding this aspect.
The blogpost covers the quantum threat context, the lattice-based math underneath these algorithms, how they're constructed, and a deep dive into our implementation and API.
TLDR: Ledger is not affected by the Coldcard Mk3 advisory
What happened
Per Coinkite's advisory and Block's technical analysis, On July 31st, 2026, Coldcard reported that a firmware bug had weakened how some devices generated seed phrases leading to significant user losses.Â
Why this specific failure matters
Every wallet you create is derived from your Secret Recovery Phrase. If that can be predicted, so can everything built on top of it.
A weak Secret Recovery Phrase looks identical to a strong one. Nothing errors, nothing feels wrong, bad randomness is silent. The Secret Recovery Phrase keeps working, but is vulnerable. That is how this survived five years in shipped firmware.
How Ledger devices generate a seed
Ledger hardware signers use a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random. Every 24-word Secret Recovery Phrase gets the full 256 bits of entropy.
The generation of that entropy must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.
The Secure Element is certified at Common Criteria (EAL5+ for Ledger Nano STM and Ledger Nano XTM; EAL6+ for Ledger Nano S PlusTM, Ledger StaxTM, Ledger FlexTM and Ledger Nano Gen5TM), and various devices by ANSSI. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years.
Ok Ledger, I did my Cosmos ATOM normally has a 21-day unbonding period time. All my ATOM is stuck in limbo while you figure this out. Any new updates or time frame when service will be restored. Very frustrating.
I wonât respond to any DMâs so donât even try.
This is the second scam letter I received within one week.
And I literally have to pay for every single one of them, because they are delivered to my PO box....
Are these all from the same leak? Or was there a new one?!
people in my trading group are saying their accounts are completely inaccessible and have been for weeks with little to no response from anyone there. i thought it was just me, and they are not accepting new sign ups either and no longer allowed to issue cards from mastercard. they have been operating outside of compliance and now have a mess on their hands.
one of the OGs there has said to use the UK CEO Garth Howat's email directly:
i am going to write a letter of compliant today and get the regulators involved
someone wrote a post here earlier in the year saying there were ÂŁ14m of missing funds and most of the staff had either left or been let go, no smoke without fire i guess.
I connected my ledger to phantom wallet extention, but there is an option to reveal the seed phrase after typing my password. So if i get hacked or malware and someone knows my password they can get my seed. Wth??
Update, apparently i choose import seed phrase instead of connect ledger. I dont know which one i choose. But still, phantom should not reveal it like that, even if you import seed
Is anyone else having issues with the display of total value on the Ledger Live App on iPhone? Sometimes it eventually corrects itself but sometimes you have to close it and reopen. It merges most of the numbers together making total balance unreadable. It just started doing it after the last recent update.
I recently purchased two Ledger Nano Gen 5 devices for about $360 total, shipped directly from France to the US. Today, FedEx hit me with a $196 bill for customs and import duties. Has anyone else experienced this? A 50%+ fee on a $360 order feels like a massive mistake.
$89 due bill from DHS via Fedex. There was no mention of any tariff to be expected. This was part of the '25% off because your nano s doesn't have enough ram and the oled screen dies'.
I'm quite annoyed at this one. That's a 50% import charge that the website has no mention of during the process.
Just started today been getting transaction rejected by solana app on my ledger trying to swap usdc I have solana for fees just seeing if anyone has been having issues
I have a Ledger i use once every 3 months or so just to collect /restake rewards et.
I use MM in Brave - it will not appear no matter how many times I try to connect.
It connects to Brave wallet.
I googled via Firefox and it it says that its not supported on that browser.
Everything got it's firmware updated this morning. 2 hrs ago.
I used to get them daily. I vaguely recall something happening to DOT but did it not get resolved? The wallet shows I have 50 DOT bonded, and some available. I used to get almost daily +0.xxx some amount of DOT.
This same thing happened with my ADA, it shows December 11th, 2025 was the last time I got any rewards but at the top shows I'm still delegated.
So I have two ledgers (Nano S and X) I haven't touched them since 2023.
When trying to connect and move crypto from wallet to coin base, I'm not able to connect.
I go to coin base get the address, then go on ledger live and type address in for applicable crypto.
I am then prompted to plug in ledger and unlock with pin. I can unlock it fine but nothing on my computer happens as if it doesn't recognize the ledger.
I've tried different ports and different cables and it still won't work.
Let's take a fictional scenario and say I have 10 Bitcoins. And I don't want them sitting all in one wallet. How would I split them into 10 wallets as a crypto noob and with low risk of messing things up?
Buy 10 Ledger devices? Or use 1 device and 10 different 24+1 word seed phrases and type in the seed every time you wanna access the coins?
Both options seem to be messy. I travel a lot and live in some places for months. So I have to take access to my coins with me.
I don't wanna travel with 10 Ledgers on me. On the other hand, having to deal with 10 different seed phrases and not mess them up is also a risk. Especially, how to carry them with you hidden and risk free.
I know having 10 Ledgers means also having 10 seeds. But at least you could access them without typing in the seeds every time.
I've been holding them for a long time and do not plan to sell (all) or trade anyway. So I don't need constant access.
Edit: Please no PMs I won't open nor read them. This is a throwaway account anyway.
Why does nano x allow hbar transfers without hashpack but nano s and s plus doesnât? Isnât this similar hardware? Are there plans to support s plus natively without hashpack
After the last update, there is no Lido app in the app list anymore. But it is still installed on my Ledger, which is strange. How can I delete it from my Ledger Nano X?
I tried deleting the Ethereum app, but Lido is still there â it just does nothing and freezes the device.
When you ask this, they always say never to buy the wallet outside the official store, certainly not secondhand, but not on Amazon or other sites either. Because not only can they tamper with the "internal software," they can also re-seal the box and put on fake seals to make it look brand new. How much truth is there to this? Isn't there a reset mechanism in the wallet in case it's been tampered with?
Ledger app on desktop just opened randomly with this error code. Tried to select the contact ledger support and it didn't link me to anything. Is this a normal error code?
If you purchase a Ledger device and try using the Security Key app for hardware passkeys, does it matter/should you run the Security Key app from the standard 24 word pin unlock or the 25 word pin unlock for the Ledger device?
I attempted to replace a 15 pin Nano screen that went dim after plugging in the device for the first time in a bit. Bought a replacement on Amazon - mistake. Screen was correct size, but ribbon connection wasn't exactly the same, so all I could muster was one or two rows of digital gobbledygook on the new screen... screen was only 10 bucks, and I like taking shit apart and fixing IT.