CryptoReal
CASE FILE — May 16, 2023

Ledger's Opt-In Seed Recovery Feature Reignites Debate Over Closed-Source Hardware Wallets

A new firmware update from Ledger has set off a wave of concern across the crypto community.

The update introduces an optional, identity-verified Ledger Recover service, priced at $10 per month, and its existence has prompted renewed scrutiny of exactly what Ledger's closed-source devices are capable of.

Ledger has stated that the backup data required to restore a device through this service is never generated unless a user actively opts in. But the company's history with sensitive user data gives reason for skepticism.

Nearly three years ago, the names, home addresses, and phone numbers of roughly 250,000 users were exposed in a breach — despite Ledger initially estimating fewer than 10,000 accounts were affected. Six months later, that data was published online. At the time, this outlet noted:

The best case scenario is that Ledger has provided a target list for SIM swappers and phishing campaigns.

Identity theft is a comparatively minor threat next to the prospect of brute-forcing a private key directly — raising the question of how long it will take before a Ledger wallet is "recovered" by a SIM-swapping attacker, or before a government or law enforcement agency demands access to a user's holdings via the same mechanism.

01How Ledger Recover works

The subscription service operates on a principle resembling Shamir's Secret Sharing: a user's seed phrase is backed up and split into three encrypted fragments, each sent to a different "backup service provider." Recombining and restoring the seed requires passing an identity verification check with those providers.

Ledger maintains the seed is never backed up unless a user explicitly opts in — but simply knowing the capability exists at the firmware level has been enough to trigger backlash. With no way to independently audit the closed-source code, users are left relying entirely on Ledger's own assurances.

That tension is sharpened by a statement Ledger gave back in November 2022, responding to a user asking whether firmware updates could expose private keys:

Hi - your private keys never leave the Secure Element chip, which has never been hacked. The Secure Element is 3rd party certified, and is the same technology as used in passports and credit cards. A firmware update cannot extract the private keys from the Secure Element.

In light of the new Recover feature, it now appears that Ledger devices — Secure Element included — have always had upgradeable firmware capable of more than previously assumed.

Some argue the underlying trust assumptions haven't really changed. Even so, the realization that these devices were built with the technical capacity to transmit seed-phrase fragments to outside parties is unsettling on its own, regardless of whether that capacity is ever activated. Given Ledger's track record, it's an open question whether users will continue to extend that trust.

02Weighing the trade-offs

Hardware wallets exist largely because they make it extremely difficult for an attacker to reach a user's funds without physically possessing the device. Phishing remains a separate risk entirely — one Ledger itself contributed to via its 2020 data breach.

For users more concerned about state actors than criminals, the possibility of a built-in backdoor is a serious red line. But as Mudit Gupta has pointed out, identity-based recovery carries its own security weaknesses — identity theft enabling SIM-swap attacks is already widespread, particularly within this industry.

Recovering a lost seed phrase, or regaining access to funds on a lost device, are nonetheless genuinely useful features for mainstream users — the kind of people who might otherwise be deterred by the self-custody paranoia common among longtime crypto holders. Despite objections from purists, many casual users may well prefer this convenience over taking on full responsibility for their own keys.

At $10 a month, Ledger appears to be betting that a meaningful share of its customer base agrees. At least the recovery process isn't happening through a centralized exchange — or is it?

LedgerWallet
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.