Ledger hardware wallets in 2026: every model compared, and what the price actually buys
If you own cryptocurrency and it sits on an exchange, you do not really own it. You own an entry in someone else's database, and a promise. That distinction has cost people everything more than once — Mt. Gox, QuadrigaCX, Celsius, FTX. Every one of those collapses ended the same way: users who held coins on the platform discovered that "your balance" and "your coins" were never the same thing.
A hardware wallet is the answer to that problem. It is a small physical device that holds the private keys to your crypto and never lets them leave. When you want to send funds, the transaction is built on your computer or phone, passed to the device, signed inside it, and passed back. The key itself never touches an internet-connected machine. Malware on your laptop can watch you type, read your clipboard and screenshot your screen, and still walk away with nothing.
Ledger is the most widely used maker of these devices. The company is French, founded in 2014, and has shipped several million units. This guide covers its full 2026 line-up — five devices at five price points — explains what actually differs between them, and is honest about the two episodes in the company's history that a buyer deserves to know about before spending money.
What a hardware wallet actually protects you from
It is worth being precise here, because hardware wallets are often sold with vague promises of "security" that do not tell you where the boundary lies.
A hardware wallet protects you from: malware on your computer that steals wallet files or keystrokes; a compromised browser extension that swaps a destination address; a phishing site that convinces you to paste a recovery phrase into a web form (assuming you refuse, which the device is designed to make easy); and physical theft of your laptop or phone.
A hardware wallet does not protect you from: approving a malicious transaction because you did not read the screen; losing your recovery phrase; writing that phrase into a photo, a password manager, or a cloud note; a scam that persuades you to send funds voluntarily; or someone with physical access to both the device and its PIN.
That last group matters more than the first, because in practice most people who lose crypto while owning a hardware wallet lose it to the second list. The device removes one very specific class of attack — remote key extraction — and leaves your judgement responsible for everything else. Any review that tells you a hardware wallet makes you safe, full stop, is selling something.
How a Ledger device works
Every Ledger contains a Secure Element — the same category of tamper-resistant chip used in passports and bank cards. It is built to resist physical attacks: probing the silicon, glitching the power supply, reading the chip under a microscope. Your private keys are generated inside it and are designed never to come out.
Alongside the Secure Element runs Ledger's own operating system, BOLOS, which keeps each cryptocurrency app isolated from the others. An app for one chain cannot read the keys used by another. This is why a single device can hold Bitcoin, Ethereum, Solana and a long list of others without those apps being able to interfere with each other.
When you first set the device up, it generates a 24-word recovery phrase. This follows the BIP39 standard, which means it is not Ledger-specific: those 24 words are the actual master key to your funds, and they would restore your wallet on a competing device from another manufacturer. This is the single most important object you will handle. Everything else — the device, the PIN, the app — is replaceable. The phrase is not.
Day-to-day you interact through Ledger Live, the desktop and mobile app that shows balances, builds transactions, and handles buying, swapping and staking through integrated third-party providers. Ledger Live never sees your keys. It prepares a transaction and asks the device to sign it; you verify the details on the device's own screen and physically confirm.
That last step is the heart of the design and the reason screen size matters more than it first appears. The device screen is the only display in the chain that malware cannot alter. If your computer is compromised and shows you one destination address while sending another, the device screen is where the discrepancy becomes visible — but only if you actually read it, and only if the screen is large enough to show the whole address and the full context of what you are approving.
The 2026 Ledger line-up at a glance
Five devices, from $59 to $399. The jump in price does not buy you more security — every model uses a Secure Element and the same underlying key handling. What it buys is screen, connectivity, and how pleasant the thing is to actually use.
| Model | Price | Screen | Connection | Best for |
|---|---|---|---|---|
| Nano S Plus | $59 | Small monochrome, buttons | USB-C | First device, long-term storage |
| Nano X | $99 | Small monochrome, buttons | USB-C + Bluetooth | Signing from a phone |
| Nano Gen5 | $179 | Larger, colour | USB-C + Bluetooth | The current mainstream Nano |
| Flex | $249 | 2.8″ E Ink touchscreen, Gorilla Glass | USB-C + Bluetooth | Frequent use, NFT and DeFi signing |
| Stax | $399 | Curved E Ink touchscreen | USB-C + Bluetooth | Those who want the flagship |
Prices are Ledger's own listed prices at the time of writing and exclude shipping and local taxes. Colour and special editions vary by a few dollars — the Flex Bonk Edition, for instance, lists at $259 rather than $249.
Ledger Nano S Plus — $59
The Nano S Plus is the entry point and, for a large share of buyers, the correct answer. It has a small monochrome display and two physical buttons. You scroll with the buttons, confirm by pressing both. There is no Bluetooth: it connects by USB-C to a computer or, with the right cable, to a phone.
What matters is what it does not compromise on. The Secure Element is there. The 24-word phrase is generated the same way. The signing model is identical to the $399 device. A transaction signed on a Nano S Plus is exactly as valid and exactly as protected as one signed on a Stax.
The trade-off is the experience. Reading a long Ethereum contract interaction on a screen that shows a handful of characters at a time is genuinely tedious, and tedium is a security problem: people who find verification annoying start skipping it. If you are going to interact with DeFi protocols weekly, that friction will eventually cost you attention at the wrong moment.
Buy it if: you are buying Bitcoin or a few major assets and intend to hold them, moving funds rarely. For that use, spending more is spending on convenience you will not use.
Ledger Nano X — $99
The Nano X is the Nano S Plus with Bluetooth and a larger battery. That sounds minor and is not: it changes where you can use the device. With Bluetooth you can sign from Ledger Live on a phone without carrying a cable and without an adapter, which is the difference between a device you use and a device that lives in a drawer.
Bluetooth raises an obvious question, and the answer is reassuring: the pairing carries only the transaction to be signed and the signature that comes back. Private keys are never transmitted over it, by design — the wireless link is treated as untrusted in the same way the USB link is. An attacker in Bluetooth range gains the ability to be annoying, not the ability to steal.
Buy it if: you manage crypto mostly from your phone, or you travel and want to check and move funds without carrying accessories.
Ledger Nano Gen5 — $179
The Gen5 is the current generation of the Nano line and sits at $179, between the Nano X and the Flex. The headline change is the display: substantially larger and in colour, which addresses the single biggest complaint about the older Nanos. It keeps Bluetooth and USB-C, and it accepts the Magnet Folio and Badges accessories Ledger sells alongside it.
Where it lands for a buyer is straightforward. If the small Nano screen is what has put you off, but $249 for a Flex is more than you want to spend, this is the device that exists to fill that gap. If you were content with a Nano X, the Gen5 is a comfort upgrade rather than a security one.
Ledger Flex — $249
The Flex is where the line-up changes character. It has a 2.8-inch E Ink touchscreen behind Gorilla Glass, and you operate it by touch rather than by clicking through with buttons. Ledger includes a Recovery Key with it.
E Ink is an unusual choice for a device like this and a deliberate one. It holds an image without drawing power, so the screen can display an address indefinitely while you check it against another source. It stays readable in direct sunlight. And it draws so little power that battery life is measured in a way that makes the device practical to keep in a bag rather than on a charger.
The practical gain is verification. On a Nano, checking a long address means scrolling through it in fragments and holding the pieces in your head. On the Flex the whole thing is on screen at once, next to the amount and the contract you are interacting with. If you sign transactions regularly — and especially if you touch DeFi, where what you are approving is often a permission rather than a payment — this is the difference between actually reading the screen and developing the habit of pressing confirm.
Touch input also makes entering a passphrase bearable. On a two-button device, typing a long alphanumeric string means clicking through the alphabet one character at a time. Anyone who has done it once understands why passphrase adoption is low among Nano owners.
Buy it if: you sign transactions more than occasionally, hold NFTs, or use DeFi protocols where reading exactly what you are approving is the whole game.
Ledger Stax — $399
The Stax is the flagship, designed with Tony Fadell — the engineer behind the iPod and Nest. Its distinguishing feature is a curved E Ink display that wraps around the edge of the device, so a name or image remains visible along the spine when it is set down or stacked. The devices are magnetic and designed to stack, which is where the name comes from.
Functionally it does what the Flex does. Same signing model, same Secure Element, same Ledger Live, a comparable touchscreen experience. The $150 over a Flex buys industrial design, the curved display and the stacking magnets — not additional protection for your keys.
That is worth stating plainly, because the price ladder invites the assumption that the expensive device is the safe one. It is not. A Nano S Plus at $59 and a Stax at $399 defend your private keys identically. What differs is how much you enjoy the object and how easily you can read what you are signing.
Buy it if: you want the flagship and the design appeals to you. It is a legitimate reason to buy something. Just do not buy it believing it protects funds a cheaper Ledger would not.
Which one should you actually buy
Strip away the marketing and the decision comes down to how you will use it.
You are buying your first hardware wallet to hold Bitcoin or a handful of major coins long-term. Nano S Plus, $59. You will move funds a few times a year. The screen is small, and it will not matter, because you will barely look at it. Spend the difference on the coins.
You manage crypto from your phone. Nano X at $99, or Gen5 at $179 if the small screen bothers you. Bluetooth is the whole point; without it, phone signing means carrying a cable and an adapter, and you will stop doing it.
You use DeFi, hold NFTs, or sign several transactions a week. Flex, $249. This is the one recommendation in the list where the extra money buys something that genuinely bears on safety — not through better cryptography, but because a screen you can actually read is a screen you actually read.
You have a large portfolio and want the best device made. Stax, $399. Understand what you are paying for.
You are holding a genuinely significant amount. Buy two devices, from different sources, and treat one as a tested backup. The failure mode that ends people is not a broken chip, it is a lost recovery phrase with no second path to the funds.
Setting it up without making the common mistakes
The setup takes twenty minutes and almost all of the risk in owning a hardware wallet is concentrated in it. Get this right and the device does its job for years.
- Check the box before you open it. Ledger devices ship without a factory seal by design — the company relies on a cryptographic attestation instead, which Ledger Live performs when you first connect. A genuine device proves itself to Ledger's servers using a key burned into the Secure Element. Trust that check, not a sticker.
- Never accept a pre-filled recovery phrase. If a device arrives with a card carrying 24 words already written on it, you are holding a scam. The phrase is generated by the device, by you, at setup. Somebody sending you a phrase is sending you a wallet they can empty whenever they choose. This attack is common enough that it deserves to be the loudest sentence in this guide.
- Generate the phrase and write it on paper. The device shows 24 words in order. Write them down. Then let it quiz you on a few and confirm you copied them correctly.
- Never photograph it, type it, or store it digitally. Not a phone photo, not a password manager, not a cloud note, not an encrypted file, not a draft email to yourself. The moment those words exist in any device connected to a network, you have undone the reason you bought the wallet.
- Set a PIN you have not used elsewhere. Three wrong attempts wipes the device — which is the correct behaviour, and harmless, because the recovery phrase restores it.
- Send a small amount first. Then restore from your phrase and check it works. Most people skip this step. It is the only way to find out that your copy of the phrase is wrong while that discovery is still cheap.
Where to keep the phrase
Paper in a safe place is the baseline, and it is genuinely fine for most people. Its weakness is fire and water, which is why steel backup plates exist: you stamp the words into metal that survives a house fire. For meaningful holdings that is a sensible fifty dollars.
Splitting the phrase across two locations — twelve words each — sounds clever and usually is not. It halves the chance of theft and doubles the chance that you lose access permanently, and permanent loss is by far the more common outcome. Unless you have a specific reason and a tested plan, keep the phrase intact in one secure place, or hold two complete copies in two secure places.
The passphrase: the feature worth understanding
Every Ledger supports an optional passphrase — sometimes called a 25th word. It is a string you choose, and it creates an entirely separate wallet derived from your 24 words plus that string. Change one character and you get a different wallet, with different addresses, holding nothing.
The point is that your recovery phrase alone no longer opens the real wallet. Somebody who finds your paper, or coerces you into surrendering it, reaches a wallet that can hold a modest decoy balance while the actual holdings sit behind a passphrase that exists only in your memory.
The danger is symmetrical and severe: there is no recovery for a forgotten passphrase. None. It is not stored anywhere, Ledger cannot help, and the funds behind it are gone as completely as if you had burned the phrase. Use it if you genuinely understand this trade-off, and be certain you will remember the exact string — including capitalisation and spacing — years from now.
This is also where a touchscreen device earns part of its price. Entering a long passphrase by clicking through the alphabet with two buttons is unpleasant enough that people choose weak ones or abandon the feature entirely.
Two things about Ledger a buyer deserves to know
No review is worth reading if it omits the parts the manufacturer would rather you skipped. There are two, and neither is a reason to avoid the product — but you should decide that yourself, with the facts.
The 2020 customer data breach
In July 2020 Ledger's e-commerce and marketing database was breached. The keys were never at risk — the breach touched the shop, not the devices — but the exposed data included customer names, email addresses, phone numbers and, for a subset, physical delivery addresses. That information was later published.
The consequences were serious and long-lived. Customers received phishing emails that were convincing precisely because the sender knew they owned a hardware wallet. Some received physical letters, and in a number of cases counterfeit devices in the post, packaged to look official and shipped with a pre-filled recovery phrase card. People lost real money to it.
What this means for you practically: treat every unsolicited message about your Ledger as hostile, without exception. Ledger will never email asking you to verify a recovery phrase. No legitimate device, service or support agent will ever need those 24 words. If a package arrives you did not order, do not connect it to anything.
Ledger Recover
In May 2023 Ledger announced Ledger Recover, an optional paid subscription that backs up your recovery phrase by encrypting it, splitting it into three fragments, and distributing those fragments among separate custodians. If you lose your phrase, an identity check reassembles it.
The reaction was severe. The objection was not the price but the premise: users had been told for years that the seed could never leave the Secure Element, and here was a firmware capability that could extract it, however encrypted and however opt-in. Critics argued that if the firmware can do this at all, the guarantee was always conditional on Ledger's cooperation and on nobody ever compelling that firmware to behave differently.
Ledger's response was that the service is entirely optional, that the extraction only occurs with explicit user consent on the device, and that the firmware has always been something users trusted. That last point is true, and it is also exactly why the announcement unsettled people — it made an implicit trust explicit.
Where this leaves a buyer: Recover is opt-in, it costs money, and you can simply not subscribe. The devices work fully without it. But it is a real datapoint about the trust model you are accepting, and it is the honest reason some users moved to fully open-source alternatives. If your threat model includes a manufacturer being compelled by a government, that concern is coherent and Ledger is not the right device for you. For the overwhelming majority of owners, whose realistic threats are malware and phishing, it changes very little.
The open-source question
Related and worth stating: Ledger's firmware is not fully open source. The Secure Element code is closed, which the company attributes to the licensing terms attached to that class of chip. Parts of the stack, and Ledger Live, are open. Competitors that are fully open source generally do not use a Secure Element, and instead accept a weaker physical-attack profile in exchange for auditability.
That is a genuine engineering trade-off with no universally correct answer: verifiable code you can inspect, or tamper-resistant silicon you must trust. Which matters more depends on whether you fear a malicious manufacturer or a thief with your device in their hands.
Living with it: what Ledger Live actually does
The device is half the product. The other half is Ledger Live, the app you will open far more often than you will touch the hardware.
Its core job is unglamorous and important: show you what you hold, across every chain, in one place, and build transactions for the device to sign. Add an account for a chain, and Ledger Live scans the blockchain for addresses derived from your keys and reports the balances. Nothing sensitive is stored — reinstall it on a new computer, reconnect the device, and everything reappears, because the data lives on public blockchains and the keys live on the device.
Around that sit optional services, and it is worth being clear that these are third parties operating inside Ledger's interface rather than Ledger itself:
- Buy — card and bank purchases through integrated providers, delivered straight to an address your device controls. Convenient, and typically more expensive in fees and spread than buying on an exchange and withdrawing. You are paying for the shortcut.
- Swap — exchanging one asset for another without an exchange account. Same trade-off: convenience against rate.
- Stake — earning yield on proof-of-stake assets while the keys stay on your device. This is the feature where self-custody genuinely competes with an exchange, because you are not surrendering the coins to earn on them.
None of these are obligatory and none change the security model: every one still ends with a transaction you approve on the device screen. If you want a wallet and nothing else, ignore the tabs.
One habit worth forming from day one: when the device asks you to confirm, read the screen rather than the app. The app is the thing an attacker can change. The device is the thing they cannot. That single discipline is most of what separates people who own hardware wallets from people who own hardware wallets and still lose funds.
Accessories, and which are worth it
Ledger sells a range of add-ons alongside the devices. Most are optional; two are worth considering.
- Magnet Folio — $39, for the Flex and the Nano Gen5. A magnetic cover that protects the screen. On a $249 device with a glass front that is carried around, this is reasonable insurance.
- Protective Case — $29 for the Flex, $39 for the Nano X. Same argument, lower price.
- Nano Gen5 Badges — $19. Cosmetic.
- Stax Magnet Shell — $39. Cosmetic and protective.
- Ledger Replace — from $8.99 for a Nano S Plus up to $49.99 for a Stax. A replacement programme for a lost or damaged device. Worth understanding clearly: this replaces hardware, it does not recover funds. Your recovery phrase does that. If you have the phrase you can restore to any device; if you do not, no replacement helps.
- Gift card — from $53, if you are buying for somebody else and would rather they picked the model.
The accessory nobody sells that matters most is a steel plate for your recovery phrase. Paper is adequate until the day it is not.
Where to buy — the part that gets people robbed
Buy from Ledger directly, or from a reseller Ledger lists as authorised. That is the entire rule, and the reason is the supply chain.
A hardware wallet is one of the few consumer products where a tampered unit is catastrophic rather than annoying. A second-hand device, a marketplace listing, an unfamiliar shop with a suspiciously good price — any of these can be a device whose recovery phrase somebody already knows. It will work perfectly. It will receive your funds. And it will be emptied at a moment of the seller's choosing, possibly months later.
This is not hypothetical. After the 2020 data leak, counterfeit Ledgers were mailed to real customers at their real addresses, in convincing packaging, with a card of pre-written words inside. Some people used them.
Never buy a hardware wallet second-hand. Never use a recovery phrase you did not generate yourself. There is no exception to either rule.
Frequently asked questions
What happens if my Ledger breaks or I lose it?
Nothing, provided you have your 24 words. The device holds no unique data — it derives your keys from that phrase. Buy another Ledger, or any BIP39-compatible wallet, restore from the phrase, and your funds are there. The device is replaceable; the phrase is not.
Does Ledger know how much crypto I own?
Ledger Live communicates with blockchain nodes to display balances, and that traffic reveals which addresses are being queried. The company publishes a privacy policy covering this, and you can point Ledger Live at your own node if that concerns you. Your keys remain private regardless; what is potentially observable is activity, not control.
Can I use one device for several cryptocurrencies?
Yes. A single device holds apps for many chains simultaneously, limited by storage rather than by design — the Nano S Plus and newer models hold a substantial number of apps at once, and apps can be removed and reinstalled without any effect on your funds, because the keys come from the phrase, not the app.
Can I use the same recovery phrase on two devices?
Yes, and it is a sound backup strategy. Restoring the same phrase onto a second device gives you two devices controlling the same wallet. Keep the second one somewhere separate.
Is Bluetooth on the Nano X, Gen5, Flex and Stax a risk?
Keys are never transmitted over it. The link carries an unsigned transaction in and a signature out, and is treated as untrusted in the same way a USB cable is. You can disable it if you prefer.
Do I need to keep the device charged?
Only the models with batteries, and only to use them. Your funds are on the blockchain, not on the device — a flat or dead Ledger loses nothing at all.
What if Ledger the company disappears?
Your 24 words follow the BIP39 standard and work with wallets from other manufacturers and with open-source software wallets. You are not locked in. This is worth internalising: you are buying a signing device, not a custodian.
The verdict
Ledger makes good hardware, and the security model is sound for the threats most owners actually face. The line-up is honestly differentiated once you see past the price ladder: the difference between $59 and $399 is screen and convenience, not the safety of your keys.
For most people buying a first device, the Nano S Plus at $59 is the right purchase and the extra money is better spent on the assets themselves. If you sign transactions often — DeFi, NFTs, anything where reading what you approve is the whole defence — the Flex at $249 is the one upgrade in the range that meaningfully affects your safety, because a screen you can read is a screen you will read.
The company's history has two blemishes worth knowing: a customer data breach in 2020 that still fuels targeted phishing, and the Ledger Recover announcement that made an implicit trust in the firmware explicit and unsettled people. Neither compromised anybody's keys. Both are legitimate inputs to your decision, and you should weigh them yourself rather than take a reviewer's word — including this one's.
Whatever you choose: buy it from the official shop, generate your own recovery phrase, write it on something that survives a fire, and never type those words into anything with a network connection. Do that, and the device does what you bought it for.