Analysis reviewed on . The price is checked separately and carries its own date.
The Nano X is the best-selling hardware wallet in Europe and the one most people have sitting in a drawer. This page is not going to tell you whether it "feels nice to use": we have not used it. It is going to tell you what is inside it, what has happened to this company, and what it means in Spain to keep your coins there.
Inside the device there is an ST33J2M0 chip certified to CC EAL5+: the same family of components that goes into bank cards and electronic passports. Your private key lives in there and never leaves. When you move funds, the transaction goes in unsigned and comes out signed; the computer never sees the key, even if it is infected.
The Nano X adds Bluetooth (BLE 5.2), which is what sets it apart from the Nano S Plus. It is there so you can use it from a phone without a cable. It is worth understanding what travels over that link: already-signed transactions and requests to sign, not the key. The key has no way out over Bluetooth because it has no way out at all, full stop.
This is the uncomfortable part, and the one most often left unsaid. Ledger's firmware is closed: you cannot read the code that runs inside the secure element, nor compile it yourself. The EAL5+ certification was issued by an external laboratory and that counts for a great deal, but it is an audit you cannot repeat. With Ledger, in the end, you are trusting Ledger.
For plenty of people that is perfectly fine — you also trust whoever made your bank card — and for others it is precisely what they do not want. If you are in the second group, the alternative is on the Trezor Safe 5 page, which runs open firmware.
This is the part that hardly ever makes it into a round-up, and all of it was published by the company itself:
The pattern reads itself: the device has never been compromised. What gets compromised, over and over, is the data of the people who buy it. If it worries you that someone might know where you live and that you keep crypto there, that weighs on the decision more than any technical specification.
In 2023 Ledger launched Recover, an optional paid subscription — $9.99 a month — in which the device itself splits up and encrypts your recovery phrase and sends the fragments to three separate custodians: Coincover, Ledger and Escrowtech. To get it back you have to pass two identity checks with an identity document and a selfie. The manufacturer's explanation.
The service is optional and you have to sign up for it. That was not what upset people: it was finding out that the firmware can take fragments of the seed out of the device if it is asked to. A lot of people had understood that to be physically impossible. It was not: it was a software decision, and the software is closed. If your reason for owning a hardware wallet is not having to depend on anybody's goodwill, this is exactly the fact you need before you buy, not after.
Yes if you want the largest ecosystem — it supports more coins and more applications than anything else — if you are going to work from your phone, and if the backing of an external certification counts as guarantee enough for you.
No if your aim is not having to trust the manufacturer, if it makes you uneasy that your postal address has been going around in a leak, or if you hold less than €1,000 in crypto: in that case the device is not the best use of those euros, and we explain why on the page above.
Two things, both in your favour. Moving your coins off an exchange and onto this device is not taxed: it is not a disposal, so there is no gain to declare. And that balance stops counting towards Form 721, which only looks at what is custodied by entities outside Spain. When you sell, the gain will still be worked out from your original purchase price: moving resets nothing, and the calculator does it for you.
— We have not checked the price. You will see it in the shop.
Affiliate link. If you buy through it we earn a commission at no extra cost to you. That commission does not decide what appears on this page — our editorial policy explains it.
Not from the device itself. The three public Ledger incidents affected customer data (2020 and 2026) and a software library used by decentralised applications (December 2023). In none of them was the private key held inside the device compromised.
With the Ledger Recover service taken out, the device itself splits up and encrypts the seed and sends the fragments to three custodians. It is optional and paid for, but it shows that the firmware can do it if it is asked to. As the firmware is closed, that capability cannot be audited from outside.
What travels over Bluetooth is requests to sign and already-signed transactions, never the private key: there is no route by which the key leaves the secure element. If you would rather not have a radio in the device, the Nano S Plus is the same device without one.
No. Form 721 reports cryptocurrency custodied by entities outside Spain. What you keep on your own device is custodied by nobody but you, so it does not count towards it.