Post
Topic
Board Hardware wallets
Merits 6 from 3 users
Re: Is a ledger nano x still a safe cold storage wallet to use
by
Meuserna
on 22/02/2025, 20:35:19 UTC
⭐ Merited by The Sceptical Chymist (4) ,Forsyth Jones (1) ,dkbit98 (1)
I've had a Ledger Nano X for years, but I've never used it except for testing purposes. I recently used it on Ledger Live on iOS for the first time. I think the Ledger Live app (both for desktop and mobile) is very cluttered. It should be simpler, highlighting the options: send, receive, and view transaction history...

Ledger Live sold you out though.  It has tons of trackers that send out data about you and everything you do.

Quote
Ledger Live is phoning out data on assets you hold in your hardware wallet the moment you access Ledger Live. It’s also sending out tons of other information about your computer and device.

The app apparently transmits data to an external endpoint at “https://api.segment.io/v1/t”, identified as an outsourced data collection service.

--BitcoinNews.com
https://bitcoinnews.com/ledger-live-app-accused-of-collecting-user-data/)

That's bad.

I know people who trust older Ledger models more, such as the Ledger Nano S (not the plus model) that doesn't have ledger recover, but support, updates, and newly developed features are no longer the company's focus on this device.

People make the mistake of thinking "doesn't support" means "doesn't contain any of the code or vulnerabilities."

The code is closed source.  Even though the original Nano S doesn't support Ledger Recover, it doesn't mean the firmware doesn't contain any of the code that enables at least some form of internet access even if it's not supported.

This is especially an issue if they're reusing any code across devices.  Any sloppy work could create unintended vulnerabilities.  And Ledger has proven their work can be very sloppy, which is why they leaked their entire customer database a while back, and why former employees still had access to their codebase (and got phished).

And with the Nano X, you have the issue of bluetooth which means potential access for online hackers to reach the device.

I'd never trust Ledger.  I'm embarrassed that I ever trusted them in the first place.