Crypto wallet startup Ledger faces criticism after unveiling an optional seed phrase recovery subscription service that some security experts say is insecure
Many members of the crypto community believe Ledger's latest seed phrase recovery feature is a bad idea. — 362 Total views
CointelegraphJudith Bannermanquist
Context & Ripple Effects
Ledger built its hardware-wallet business around storing private keys, scaling from early wallet sales to a $380M Series C for its Nano wallet business. The recovery-service backlash puts that security-centered positioning under sharper scrutiny.
The debate also lands after a leak of Ledger customer contact and address data, making trust in how the company handles sensitive security-related information especially consequential to its user base.
First-order effects
Ledger must defend the security model and optional nature of its seed-phrase recovery subscription to users and security researchers.
Customers who prioritize self-custody face a more explicit choice between recoverability and minimizing exposure around their recovery credentials.
Second-order effects
Rival hardware-wallet providers can differentiate on simpler, strictly self-managed recovery approaches, while Ledger’s recovery design becomes a comparison point in purchase decisions.
Wallet buyers may place greater weight on a provider’s operational-security record, not only the device’s technical protections; Ledger had already faced a publicly disclosed hardware-wallet vulnerability.
Third-order effects
If recovery becomes a standard wallet feature, crypto wallets will increasingly compete on governance, disclosure, and trust models as much as on key storage hardware.
The episode highlights a durable self-custody trade-off: products that reduce the risk of permanent loss can introduce new parties, processes, or perceived attack surfaces that users must evaluate.
The trend: Crypto wallet makers are trying to make self-custody recoverable for mainstream users without weakening the trust assumptions that make self-custody valuable.
Exciting update, Ledger has a new product, Ledger Recover, that's launching soon: https://www.ledger.com/recover 🧵Here's what Ledger Recover is and what it isn't, explained by @P3b7_ & in the thread below. [video]
Ledger, the company that has experienced multiple security breaches that exposed the personal information of hundreds of thousands of its customers Now wants you to export your private keys from your hardware wallet and give fragments to them, Coincover, and an unnamed third... h…
Ledger Recover is an optional subscription for users who want a backup of their Secret Recovery Phrase. You don't have to use it, and can continue managing your recovery phrase yourself if that's why you bought a Ledger.
First they exposed mailing address, phone numbers, and email addresses of their customers... And now they've put a back door into seed phrases. It's time to say goodbye to @Ledger ✌️ https://twitter.com/...
Sure, you *could* use Ledger's new ‘Recover’ service and give them the your private keys controlling your assets as well as a copy of your ID and other personal information... ... but why then bother with a hardware wallet in the first place? [image]
So yesterday @Ledger published an update for a service that sends your seed phrases to different companies Which can be “opted out” but i feel like trust is now 100% broken because whether a person subscribes to the service the backdoor was always there to begin with [image]
The problem here is not splitting the key in 3 parts. That's actually good! I may or may not be doing that personally as well :) The problem here is that the encrypted keys parts are sent to 3 corporations and they can reconstruct your keys.
The entire point of a hardware wallet is that it's a digital iron vault.. if you lose your keys, it's gone. Ledger may have just compromised that by creating a backdoor to access your keys. If anyone can provide additional clarity pls do. https://twitter.com/...
Shamir Secret Sharing saved my life more than once. Nice move from @ledger with an elegant way to provide opt-in banking services to users who cannot manage Shamir secrets. Would be awesome to provide a list of safes that users can pick and choose instead of 3 services https://tw…
Oh but it is secured by ID verification! You know what else is secured by ID verification? Mobile number porting. Do you know how many high profile sim jacking cases happen every day? Too many. Anything secured by “ID verification” is inherently insecure. Too easy to fake.
Did @ledger just suicide itself? Words like identity verification is what crypto was designed to avoid. Never buying ledger ever again. https://twitter.com/...
Recover by @ledger has been released today. Quite a cool idea for people who are scared of loosing their seed phrases, but not for everyone. 🔌⚡️ #crypto #ledger #hardwarewallet #Ethereum #Bitcoin #Binance #TrustWallet #TrezorWallet #ETH https://twitter.com/...
You know in crypto, every two weeks or so, someone gets cancelled? And then afterwards, once one week or so passes, everyone forgets? Well, this week is Ledger. It does not look very good. @Ledger friends, if I bought a Ledger device, I clearly want the private key to be... https…
1/5 Ledger offers new private key backup service that requires KYC documents. Bold move for a company that neglected to secure over 1 million customer records including full name, phone #, email, & physical address. https://twitter.com/...
It's really painful to see a market leader lose all its trust in a single day. I myself am a customer since 2017, but after this day I will never buy a new product from @Ledger again. #Bitcoin #Cardano #Ledger #boycottLedger https://twitter.com/...
reminder that several years ago, Ledger leaked the name and home addresses for all of their customers via a data breach the absolute last thing you want on their servers is your private key https://twitter.com/...
1/2 1) This required identity verification, with a company that has leaked personal data more than once. 2) SSS encryption is threshold based & be decrypted with enough shards 3) Companies can be compelled by law enforcement to surrender key shards. Don't do it. https://twitter.c…
ledger: it's impossible to extract the master key from the device also ledger: we backdoored the firmware to allow extracting the master key from the device. but don't worry, we will safeguard it as well as your physical addresses. https://twitter.com/...