Ledger hacked what to do

Was Ledger Hacked—or Was Your Data, Device, Signature or Recovery Phrase Exposed?

“Ledger was hacked” is not a complete diagnosis. A breach of customer contact data, malicious code loaded by a dApp, a stolen device, a signed token approval and an exposed 24-word Secret Recovery Phrase create very different risks. Do not reset or move everything because of a headline alone, but do not keep using the same accounts after the recovery phrase has been exposed. First identify the highest layer the attacker reached.

Most faucet rewards are tiny. FaucetPay can help you collect small payouts from supported faucets, PTC sites and reward platforms in one microwallet before withdrawing later.

Set up FaucetPay to collect small rewards →

Start with the affected layer, not the headline

Use the strongest confirmed fact. A marketing-database leak can expose identity and contact details without exposing wallet keys. A malicious dApp can request a dangerous signature while the hardware device itself remains genuine. A stolen device creates a physical-access problem. A recovery phrase entered into a website creates full account compromise.

  • Customer-data layer — email, name, phone number, postal address or order details
  • Application layer — fake Ledger software, malicious update prompt or compromised dApp code
  • Signing layer — message, permit, token approval or transaction confirmed on the device
  • Device layer — lost, stolen, preconfigured, tampered or failing authenticity checks
  • Recovery layer — Secret Recovery Phrase or private key seen, copied, typed or photographed by someone else

Choose one of three response outcomes

The classification should end in one operational decision.

  • Watch — no wallet authority was exposed; harden communications and monitor for targeted phishing
  • Contain — the recovery phrase remains trusted, but a connection, signature, approval or transaction needs inspection and possibly revocation
  • Migrate now — the recovery phrase, private key or trusted signing environment may be compromised; move surviving assets to accounts derived from a new recovery phrase

The 2020 Ledger breach and 2026 Global-e incident belong in the Watch branch

Ledger reported that an unauthorized party accessed its e-commerce and marketing database in 2020. In January 2026, Ledger also published guidance about unauthorized access to order data held by Global-e, a payment processor used for some purchases. The incidents involved contact or order information, while Ledger stated that wallet addresses, recovery phrases, devices and Ledger systems were not exposed by the Global-e incident. Both events can make phishing more convincing without automatically giving an attacker blockchain authority.

Respond to customer-data exposure without inventing key compromise

Treat unexpected Ledger emails, calls, text messages and mailed devices as hostile until independently verified. Do not click an urgent update link. Open the official support site by typing the address yourself. Consider changing the email address used for crypto services, strengthen the email account with phishing-resistant authentication and remove public links between your identity and wallet addresses where practical. A new recovery phrase is not required merely because an email address leaked.

The 2023 Connect Kit exploit belongs in the Signing branch

Ledger’s December 2023 report described malicious versions of Ledger Connect Kit loaded by some third-party dApps. The attack attempted to trick users into signing transactions that drained assets. Ledger stated that the exploit did not compromise Ledger hardware, Ledger Wallet or Ledger infrastructure. The decisive question is therefore whether the user interacted with an affected dApp and approved a malicious request—not whether the person owned a Ledger device.

A hardware wallet cannot make a bad approval harmless

A hardware device protects private keys from leaving the secure environment, but it still executes a transaction or approval that the owner confirms. If the secure screen showed an unfamiliar recipient, unlimited allowance, permit, contract call or unreadable data and the request was approved, classify the incident by what was signed. Do not assume that offline key storage reverses authority voluntarily granted on-chain.

Connection only is different from a signed permission

If the wallet merely connected and no message, approval or transaction was confirmed, disconnect the session and inspect the account history. If a readable login message was signed, preserve the text, domain and timestamp. If a permit, token approval or contract transaction was signed, inspect the spender, asset, amount, network and transaction hash. Disconnecting a site does not remove an on-chain allowance.

Use Contain only while the recovery phrase remains trusted

When the keys and device are still trusted, revoke suspicious token or NFT permissions using a reputable network-specific tool, and move high-value assets if the incident scope is uncertain. Revocation costs network fees and cannot undo a completed transfer. If an unknown native-coin transfer leaves immediately whenever gas arrives, stop repeatedly funding the address; that pattern may indicate a compromised key and automated sweeper rather than a single approval.

A fake Ledger app moves the incident to the Recovery branch if 24 words were entered

Ledger warns that fraudulent Ledger applications and websites use urgent messages such as firmware updates, account protection or clear-signing activation to request the 24-word Secret Recovery Phrase. The genuine application should not ask for those words on a computer or phone. If the phrase was typed into software, deleting the application is not containment. Anyone with the phrase can recreate the accounts elsewhere.

Migrate in the correct order after recovery-phrase exposure

Use a clean, trusted environment and accounts you already control. Transfer surviving tokens first while enough native coin remains for fees, then move the remaining native assets. After the old accounts are empty, reset or replace the device, generate a new recovery phrase on the genuine device, add new accounts and return assets only after verifying receiving addresses on the secure screen. A new account created under the old phrase is not a clean destination.

A lost or stolen Ledger device is not automatically a lost wallet

Ledger devices are protected by a PIN and reset after repeated incorrect attempts. If the recovery phrase remains secret and a backup device is available, access can be restored. Ledger nevertheless recommends considering new accounts, especially when the PIN was weak or physical access risk is uncertain. If both the device and the only recovery copy are unavailable, recovery may be impossible unless another previously configured recovery method or backup exists.

Do not use a device that arrives preconfigured

A new Ledger device should generate its recovery phrase during setup. A box containing completed recovery words, a supplied PIN or a device that opens as already configured is unsafe. Do not transfer funds through it. Use the official application to perform the authenticity check, verify the device’s initial state and contact Ledger through the official support channel.

Treat the secure screen as the transaction source of truth

Malware can alter addresses and details shown on a computer or phone. Compare the full recipient, amount, network and fee with the information shown on the Ledger device itself. Cancel when the device and software disagree. Prefer clear, human-readable transaction details and reject blind or unexplained signing requests. For a new destination, verify the receiving address on the device and use a small test transfer before moving a larger balance.

Preserve an incident record before changing everything

Evidence helps distinguish phishing from on-chain compromise and gives support or law enforcement something concrete to examine.

  • Date, time and exact wording of the alert, email, call or popup
  • Sender address, website domain and download source
  • Device model, application version and whether Genuine Check passed
  • Network, affected account and public address
  • Transaction hashes, signed-message text, spender addresses and approval amounts
  • Screenshots that do not reveal the recovery phrase, private key, PIN or authentication secrets

Run the first fifteen minutes in a fixed order

Do not return to the suspicious page to look for a cancellation button.

  • Stop signing, unplug the device and close the suspicious application or browser tab
  • From a clean device, inspect the public account history and approval state without entering the recovery phrase
  • Classify the highest confirmed layer: data, application, signing, device or recovery
  • Choose Watch, Contain or Migrate now
  • Contact Ledger only through the support site you opened independently
  • Warn relevant exchanges or services only when an account, address or transaction under their control is involved

Avoid the second-wave recovery scam

Attackers often follow a breach headline or visible theft with fake support, wallet-validation pages and paid recovery offers. No legitimate helper needs the 24 words to inspect a public address or transaction hash. Do not send a “verification” payment, install remote-access software or sign a rescue transaction whose recipient and authority you cannot verify on the device.

Worked case — breach email, no wallet action

A user receives an urgent email claiming that Ledger accounts are being migrated. The user does not click, sign or enter recovery words. The incident remains at the customer-data or phishing layer. Outcome: Watch. Preserve the email, report it, secure the email account and use only independently opened official channels.

Worked case — suspicious dApp approval

A user connects a Ledger account to a dApp and approves an unlimited token allowance. No recovery words were exposed and the device remains trusted. Outcome: Contain. Stop interaction, record the spender and transaction, revoke the relevant allowance and decide whether the remaining assets should be moved because the dApp or device environment is still uncertain.

Worked case — 24 words entered into a desktop form

A fake Ledger update asks for all 24 recovery words and the user submits them. Outcome: Migrate now. The old recovery phrase must be treated as permanently compromised even if no theft is visible yet. Move surviving assets from a clean environment to accounts generated from a new phrase, then retire the old accounts.

Close the incident only when the evidence matches the response

The Watch branch closes when communications are secured and no blockchain authority was exposed. The Contain branch closes when suspicious permissions are removed, affected assets are accounted for and the device and recovery phrase remain trusted. The Migrate branch closes only after surviving assets sit in verified accounts controlled by a new recovery phrase and the old accounts are no longer used.

Ledger incident references checked on July 31, 2026

These primary Ledger sources support the incident distinctions and response steps above. Product names, interfaces and support procedures can change, so verify the current official instructions before acting.

  • 2020 e-commerce and marketing data breach: https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach
  • January 2026 Global-e order-data incident guidance: https://support.ledger.com/article/Global-e-Incident-to-Order-Data---January-2026
  • December 2023 Ledger Connect Kit security incident report: https://www.ledger.com/blog/security-incident-report
  • Fraudulent Ledger applications and phishing response: https://support.ledger.com/article/fraudulent-ledger-live-applications
  • Lost or stolen Ledger device guidance: https://support.ledger.com/article/9729302536989-zd
  • Changing a compromised recovery phrase and creating new accounts: https://support.ledger.com/article/8460010791069-zd
  • Checking whether a Ledger device is genuine: https://support.ledger.com/article/13692454787613-zd
  • Revoking token approvals on Ethereum: https://support.ledger.com/article/8700644160925-zd
  • Verifying transaction details on the Ledger device: https://support.ledger.com/article/8397197967005-zd
  • Clear Signing explanation: https://www.ledger.com/academy/topics/ledgersolutions/what-is-clear-signing
Scam-aware reminder

Be careful with websites that promise unrealistic rewards, ask for deposits before withdrawal, or require suspicious wallet connections. Small reward sites should never need your seed phrase.

FAQ

Did the 2020 Ledger breach expose hardware-wallet recovery phrases?

Ledger described the 2020 incident as a breach of its e-commerce and marketing database. It said the breach involved customer contact or order data, not hardware-wallet keys or recovery phrases. The practical response is heightened phishing defense unless the user later disclosed a recovery secret.

Does a Ledger device prevent theft from every malicious dApp?

No. The device keeps private keys isolated, but it can still authorize a malicious approval or transaction that the owner confirms. Read the secure-screen details and reject requests that are unexpected, unreadable or broader than the intended action.

Should I generate a new recovery phrase after receiving a phishing email?

Not solely because an email arrived. Generate a new phrase when the existing phrase or private keys may have been exposed, the device environment cannot be trusted or the physical-device risk justifies migration. Otherwise secure communications and monitor the accounts.

What should I do if I entered my 24 words into a Ledger app or website?

Treat the phrase as compromised. From a clean environment, move surviving assets to accounts derived from a newly generated recovery phrase. Do not reuse the old phrase or create a “new” account under it as the safe destination.

Is disconnecting a suspicious dApp enough?

It is enough only when no higher-authority action occurred. Disconnecting does not revoke token allowances, cancel signed permits or reverse transactions. Inspect what was signed and remove relevant permissions while the keys remain trusted.

What if my Ledger device was stolen but the recovery phrase is safe?

Restore access with a trusted backup or replacement device. A strong PIN and automatic reset reduce physical-access risk, but consider migrating to new accounts when the PIN was weak, the device state is uncertain or the value at risk justifies the extra safety step.