Trading Education Platform SystemSubscribe for FreeSupport
Wallets / Ledger Flex
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Ledger Flex: what the sources say

Current 0 disclosed weaknesses 4 company incidents

Key facts

The questions, with sources

QuestionWhat the sources saySource
Status
Current — Listed on shop.ledger.com on 2026-10-11 with Add to cart. Launched 2024-07-26 per Cointelegraph. Store also lists Stax and Nano Gen5.
Company
Ledger
List price
n/v — Official store pages fetched on 2026-10-11 show price fields as 'Loading' (JavaScript-rendered), so no list price could be read. Launch price was $249 in the US (Cointelegraph, 2024-07-26; Nasdaq press release); not verified as the current list price.
Secure element
Yes: ST33K1M5; Common Criteria EAL6+
Firmware code
Partial; reproducible build: not verified. Ledger states OS is about 95% open source/reviewable; secure-element low-level code is closed.
Companion app
Yes. Ledger states Ledger Wallet app is MIT-licensed open source.
Connections
USB: yes. Bluetooth: yes. NFC: yes. QR: n/v. microSD: n/v.
Screen
2.8 in E Ink touchscreen, 480x600 px, 16 grayscale, Gorilla Glass; touch: True
Assets
500+ coins directly in the Ledger Wallet app; thousands more via third-party wallets
Multisig and PSBT
Yes. Ledger's Bitcoin app is described as supporting multisig, miniscript and PSBT; Flex page itself does not mention multisig. Ledger's app requirements cover Flex.
Passphrase
Yes. Ledger's article describes passphrase (up to 100 characters) with temporary or secondary-PIN modes on the Flex.
Shamir backup (SLIP-39)
Not verified. No statement on SLIP-39 found in pages read.
—
Recovery phrase standard
24-word recovery phrase
Optional recovery service
Optional. Ledger Recover (by Coincover): optional paid backup; three encrypted pieces held by three independent companies; ID verification; Flex listed as supported.
FIDO / passkeys
Yes. Cointelegraph reports NFC logins via Ledger Security Key with FIDO2 passkey standard; Ledger's developer docs state the Security Key app supports FIDO2/U2F.
Bug bounty
Yes

"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.

Summary

Five facts

  • Ledger lists the Flex with a ST33K1M5 secure element certified Common Criteria EAL6+, a 2.8 in E Ink touchscreen, USB-C, Bluetooth 5.2 and NFC [source 3].
  • The Flex launched on 2024-07-26 at a US price of $249 according to Cointelegraph [source 8].
  • Ledger describes its OS as about 95% open source or reviewable, with secure-element low-level code closed [source 9].
  • The Flex is listed as supported by the optional Ledger Recover paid backup service [source 21].
  • Ledger had a 2020 customer-data breach, a December 2023 Connect Kit supply-chain incident and a January 2026 Global-e third-party data breach [source 14][source 13][source 15].
Independent checks

Audits

  • 2023-09 Synacktiv. Scope: Penetration test of the Ledger Recover service (white-box, 80 man-days, Nano X samples; documentation and source access); findings led to architecture changes, per Ledger source
  • date n/v Unnamed external security labs (per Ledger). Scope: Ledger states a third-party security lab audits the entire OS before each release; auditor not named on the page read source
Device record

Publicly disclosed weaknesses

  • No publicly disclosed weakness found in our search. That is not proof there is none.

Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.

Company record

Incidents at the maker or its service providers

  • 2020-07 Ledger's e-commerce/marketing database was accessed by a third party in July 2020 and was dumped publicly in December 2020. Ledger's forensic review: about 1 million email addresses stolen; detailed personal data (name, postal address, phone) confirmed for 9,532 customers; the public dump held about 272,000 detailed records. Ledger states no link to hardware wallets, app or funds. (Older than 5 years.) Customer funds lost: no. Outcome: Ledger stated no funds were affected and no refund would be given; it named a new CISO, a bug bounty program and a public phishing-status page. Phishing campaigns against customers followed. source
  • 2023-05 Ledger announced the opt-in Ledger Recover seed-backup service (encrypted seed shards sent to three companies), which drew criticism from security commenters that the firmware could now export the seed. Ledger said the service is opt-in and that decryption happens only on the user's device. Customer funds lost: no. Outcome: On 2023-05-23 Ledger's CEO apologised for a communication mistake, held the release and committed to open-sourcing more of the OS and the Recover protocol. Ledger Recover is now listed on its store for Nano S Plus, Nano X and Flex. source
  • 2023-12-14 Malicious versions 1.1.5-1.1.7 of Ledger's Connect Kit npm library were published after a former employee's npm account was phished; malicious code (a wallet drainer) ran in dApps using the library and users signing transactions through those dApps lost funds. Ledger states it was not an attack on device firmware or Ledger infrastructure. Customer funds lost: yes. Outcome: Ledger says a fix was deployed within 40 minutes of learning of it (malicious file reachable about 5 hours due to CDN caching, active draining under 2 hours); it describes a 'low volume of users' signing malicious transactions and gives no total. source
  • 2026-01 Payment/checkout partner Global-e notified customers (from about 2026-01-05) that Ledger-store order data (names, contact details, order details) was accessed. Ledger and Global-e state that financial data, crypto assets, passwords and recovery phrases were not exposed. Customer funds lost: no. Outcome: Ledger confirmed the third-party breach and warned customers of phishing. source

These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.

Questions

Questions about Ledger Flex

Is Ledger Flex safe?

We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 0 publicly disclosed weaknesses and 4 company incidents in our search. Read the sources above before you buy.

Does Ledger Flex need an internet connection?

Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, Bluetooth, NFC. The companion app or software that builds the transaction is online.

Who found the weaknesses listed for Ledger Flex?

The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.

Sources

Where this comes from

Not verified: Not verified: official list price (store price fields not rendered); warranty terms; firmware licence and reproducible-build status (no repo page read); company country/registration (not read on an official page); QR/air-gapped and microSD (not stated on pages read); whether Shamir/SLIP-39 is supported (no statement found); whether the seed can be exported/imported on-device; independent third-party firmware audit report dates. Third-party review sites and the competitor-authored incident list (ryder.id) were not used as sources. Store price fields showed 'Loading'. No Flex-specific vulnerability disclosure was searched beyond one general query; none found.

See how we check. To report an error, use corrections and right of reply.