Ledger Nano S Plus: what the sources say
Current 1 disclosed weakness 4 company incidents
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- Ledger lists the Nano S Plus on its store with a ST33K1M5 secure element certified Common Criteria EAL6+, a 1.1 in monochrome OLED and USB-C only [source 1].
- Ledger describes the OS as about 95% open source or reviewable, with the secure-element low-level code closed; the Ledger Wallet app is MIT-licensed [source 9].
- The device is listed as supported by the optional Ledger Recover paid backup service, which splits an encrypted seed copy among three companies [source 21].
- Ledger had a customer-data breach in 2020, a Connect Kit npm supply-chain incident in December 2023 (user funds drained via dApps) and a Global-e third-party data breach in January 2026 [source 14][source 13][source 15].
- Ledger runs a bug bounty program via Ledger Donjon [source 11].
Audits
- 2023-09 Synacktiv. Scope: Penetration test of the Ledger Recover service (white-box, 80 man-days, Nano X samples; documentation and source access); findings led to architecture changes, per Ledger source
- date n/v Unnamed external security labs (per Ledger). Scope: Ledger states a third-party security lab audits the entire OS before each release; auditor not named on the page read source
Publicly disclosed weaknesses
- 2019-08 OLED power-consumption side channel reported 2019-05-07 by researcher Christian Reitter through Ledger's bounty; partial recovery of on-screen PIN/recovery words possible via power-trace analysis with lab equipment. Ledger rated it non-critical, found no evidence of exploitation; countermeasures (randomised screen parameters, inverted-pixel boxes) were scheduled for Q4 2019 firmware. Ledger's write-up names the Nano S and Nano X (older than 5 years). Funds lost: no. Mitigated source
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- 2020-07 Ledger's e-commerce/marketing database was accessed by a third party in July 2020 and was dumped publicly in December 2020. Ledger's forensic review: about 1 million email addresses stolen; detailed personal data (name, postal address, phone) confirmed for 9,532 customers; the public dump held about 272,000 detailed records. Ledger states no link to hardware wallets, app or funds. (Older than 5 years.) Customer funds lost: no. Outcome: Ledger stated no funds were affected and no refund would be given; it named a new CISO, a bug bounty program and a public phishing-status page. Phishing campaigns against customers followed. source
- 2023-05 Ledger announced the opt-in Ledger Recover seed-backup service (encrypted seed shards sent to three companies), which drew criticism from security commenters that the firmware could now export the seed. Ledger said the service is opt-in and that decryption happens only on the user's device. Customer funds lost: no. Outcome: On 2023-05-23 Ledger's CEO apologised for a communication mistake, held the release and committed to open-sourcing more of the OS and the Recover protocol. Ledger Recover is now listed on its store for Nano S Plus, Nano X and Flex. source
- 2023-12-14 Malicious versions 1.1.5-1.1.7 of Ledger's Connect Kit npm library were published after a former employee's npm account was phished; malicious code (a wallet drainer) ran in dApps using the library and users signing transactions through those dApps lost funds. Ledger states it was not an attack on device firmware or Ledger infrastructure. Customer funds lost: yes. Outcome: Ledger says a fix was deployed within 40 minutes of learning of it (malicious file reachable about 5 hours due to CDN caching, active draining under 2 hours); it describes a 'low volume of users' signing malicious transactions and gives no total. source
- 2026-01 Payment/checkout partner Global-e notified customers (from about 2026-01-05) that Ledger-store order data (names, contact details, order details) was accessed. Ledger and Global-e state that financial data, crypto assets, passwords and recovery phrases were not exposed. Customer funds lost: no. Outcome: Ledger confirmed the third-party breach and warned customers of phishing. source
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about Ledger Nano S Plus
Is Ledger Nano S Plus safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 1 publicly disclosed weakness and 4 company incidents in our search. Read the sources above before you buy.
Does Ledger Nano S Plus need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for Ledger Nano S Plus?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [1] Ledger Nano S Plus product page (shop.ledger.com) accessed 2026-10-11
- [2] Ledger Nano X product page (shop.ledger.com) accessed 2026-10-11
- [3] Ledger Flex product page (shop.ledger.com) accessed 2026-10-11
- [4] Compare Ledger hardware wallets (shop.ledger.com) accessed 2026-10-11
- [5] Ledger Nano S Plus / Nano X 'classic' page (shop.ledger.com) accessed 2026-10-11
- [6] Ledger Flex page (shop.ledger.com) accessed 2026-10-11
- [7] Introducing Ledger Flex (Nasdaq / press release) accessed 2026-10-11
- [8] Ledger launches Ledger Flex wallet (Cointelegraph) accessed 2026-10-11
- [9] Is Ledger open source? (Ledger Academy) accessed 2026-10-11
- [10] Ledger is 95% open source, why not 100% (Ledger blog) accessed 2026-10-11
- [11] Ledger Bug Bounty Program (Ledger Donjon) accessed 2026-10-11
- [12] OLED side-channel vulnerability write-up (Ledger blog, 2019-08-07) accessed 2026-10-11
- [13] Ledger Connect Kit security incident report (Ledger, 2023-12-20) accessed 2026-10-11
- [14] Message from Ledger's CEO on the July data breach (Ledger, 2020-12-21) accessed 2026-10-11
- [15] Crypto wallet shop Ledger confirms customer data lifted in Global-e snafu (The Register, 2026-01-06) accessed 2026-10-11
- [16] Ledger defends crypto wallet recovery tool (The Block, 2023-05-16) accessed 2026-10-11
- [17] Ledger Recover: a message from Pascal Gauthier (Ledger, 2023-05-23) accessed 2026-10-11
- [18] Genesis of Ledger Recover, part 6: security analysis (Ledger, 2023-09) accessed 2026-10-11
- [19] Passphrase: Ledger's advanced security feature (Ledger Academy) accessed 2026-10-11
- [20] Let the MuSig Play (Ledger blog) accessed 2026-10-11
- [21] Ledger Recover page (shop.ledger.com) accessed 2026-10-11
- [22] Security Key app (developers.ledger.com) accessed 2026-10-11
- [23] Device app security audit (developers.ledger.com) accessed 2026-10-11
- [24] Ledger Nano S Plus listing (shop.ledger.com) accessed 2026-10-11
Not verified: Not verified: official list price (store price fields not rendered); warranty terms; firmware licence and reproducible-build status (no repo page read); company country/registration (not read on an official page); QR/air-gapped and microSD (not stated on pages read); whether Shamir/SLIP-39 is supported (no statement found); whether the seed can be exported/imported on-device; independent third-party firmware audit report dates. Third-party review sites and the competitor-authored incident list (ryder.id) were not used as sources. Store price fields showed 'Loading'.
See how we check. To report an error, use corrections and right of reply.