Ledger security model — defense in depth
Ledger devices use a secure element (SE) combined with Ledger's BOLOS operating system. The secure element stores private keys and executes signing operations inside the chip. BOLOS provides app isolation and enforces that only approved code interacts with the key material.
Key protections
- PIN code: Thwarts casual access if your device is lost or stolen.
- Recovery phrase: A 24-word mnemonic used to restore your accounts on any compatible wallet.
- Passphrase (optional): Adds an additional secret to create hidden wallets.
- Device attestation: Ledger Live verifies device authenticity and firmware integrity.