Ledger: first-time setup
Why the box seal proves nothing, what the genuine check actually verifies, the one optional service to think hard about, and the phishing every Ledger owner should expect.
Ledger has the largest installed base of any hardware wallet, which means two things for this guide. The setup is polished and hard to get wrong. And Ledger owners are the single most heavily targeted group of bitcoin holders for phishing, which is a section further down that matters more than any of the setup steps.
There are also two decisions worth making before you begin rather than partway through: whether to enable an optional backup service, and whether to drive the device with Ledger's own app or with Bitcoin-only software. Both are covered below.
A Ledger device and its box on a desk, with a laptop showing Ledger Live's genuine-check result beside it.
Image to come
Before you start
- A Ledger device bought from ledger.com or an authorised reseller — never a marketplace listing or second-hand.
- Ledger Live, downloaded from ledger.com typed by hand rather than reached from a search result or an email.
- The supplied recovery sheets and a pen, or a metal backup plate.
- An uninterrupted half hour somewhere private.
- No bitcoin. Move none until the checks at the end pass.
1The box seal is not the security check
Ledger deliberately does not rely on tamper-evident stickers, on the reasoning that seals are cheap to forge and give false confidence. Some boxes arrive looking casually opened. That is expected and is not, by itself, a problem.
The real check is cryptographic. Each device holds an attestation key issued during manufacturing, and Ledger Live challenges the device to prove it holds a genuine one. A cloned or substituted device cannot produce that proof.
- Connect the device and run the genuine check when Ledger Live offers it. Do not skip past it.
- Set the device up yourself from a blank state — you should be choosing a PIN and generating a phrase, not being shown one.
- Install any firmware update Ledger Live offers before creating the wallet.
- A device that arrives already initialised, already holding a PIN, or supplied with a printed recovery phrase is an attack. There is no legitimate version of this.
- Never buy Ledger hardware second-hand or through a marketplace, however sealed it appears.
2Set the PIN, on the device
You choose a PIN using the device's own buttons or touchscreen, so a keylogger on the computer never sees it. Three wrong attempts wipes the device — which is a feature, and also the reason your recovery phrase needs to exist before you rely on the PIN.
- Choose something you can recall under stress, longer than four digits if the device allows it.
- Record it somewhere durable, and separate from your recovery phrase.
- Remember that a wipe is recoverable from your phrase, and only from your phrase.
3Write down the recovery phrase
The device generates the phrase and shows it on its own screen, one word at a time. It never appears on your computer.
- Write the words in order, by hand, on the supplied sheets or a metal plate.
- Complete the confirmation step the device runs afterwards.
- Store the phrase away from the device, so one theft or one fire cannot take both.
- Never photograph the phrase, type it into any computer or phone, or enter it into a website for any reason whatsoever.
- Ledger will never ask for it. Any message, email, letter, or support agent asking for it is stealing from you.
4Ledger Recover: decide deliberately, then move on
Ledger offers an optional subscription service that backs up your recovery phrase by encrypting it, splitting it into shares, and storing those with third-party custodians, with identity verification required to restore. It is opt-in and drew considerable criticism when it launched.
The objection is not that the cryptography is weak. It is that a service which can reconstruct your key on request, tied to your verified identity, reintroduces exactly the dependency self-custody exists to remove — a third party who can be compelled, breached, or simply go out of business.
If you are here to self-custody, decline it and keep your own backup. The service can be ignored entirely and the device works as normal without it. If you are considering it for genuine reasons — no safe place for a written backup, or nobody who could help you recover — treat it as a considered trade rather than a default, and understand that you are choosing to have a recoverable identity-linked copy of your key exist.
5Install the Bitcoin app
Ledger devices are multi-asset by default and there is no Bitcoin-only firmware edition. Individual coin apps are installed through Ledger Live as you need them.
- Install only the Bitcoin app if bitcoin is all you hold. Every app you do not install is code that is not on the device.
- Ledger Live will show your account once the app is installed and the device is unlocked.
- Keep the firmware and the Bitcoin app updated through Ledger Live rather than any other source.
6Verify a receive address on the device
This is the step that defeats malware which swaps addresses on your screen. The computer is assumed to be lying; the device is the thing you trust.
- Generate a receive address and display it on the device.
- Compare the whole string, not just the first and last few characters — lookalike addresses are generated to match at both ends.
- Review the recipient and amount on the device before approving any send.
- Send a small test amount, confirm it arrives, and send it back out before committing real savings.
7Consider driving it with Bitcoin-only software
Ledger Live is capable and pleasant, but it is not the only option, and for a bitcoin holder it is often not the best one. The device works as a signer for third-party wallet software including Sparrow and Electrum.
Doing so gives you coin control, labelling, the ability to point at your own node, and a wallet whose scope matches what you actually own. Your keys stay on the Ledger either way — you are changing which software builds the transactions, not where the signing happens.
One structural limitation to know: Ledger devices connect over USB or Bluetooth and have no air-gapped signing path — no QR camera, no microSD workflow. If a fully air-gapped setup is what you want, that is a reason to look at a different device rather than a reason to use this one differently.
Expect targeted phishing, because it is aimed at you specifically
In 2020 a Ledger e-commerce database was breached, exposing customer contact details including names, postal addresses, phone numbers and email addresses. That data has circulated ever since, and the result is that Ledger owners receive unusually well-informed scam attempts.
These are not generic spam. They arrive addressed to you by name, sometimes referencing a real order, and occasionally by physical post.
- Fake security notices claiming a breach and urging you to verify or migrate your wallet.
- Fake Ledger Live updates linking to a lookalike site that asks for your recovery phrase.
- Physical letters or replacement devices arriving unrequested, sometimes with a tampered device or a QR code to scan.
- Phone calls from people who already know your name, address, and that you own a Ledger.
One rule handles every version of this
Your recovery phrase is never typed into anything except a hardware wallet you are deliberately restoring. Not a website, not Ledger Live, not an app, not a form, not a support agent, no matter what has gone wrong or how urgent it sounds. Any request for it is theft, full stop — and a device arriving in the post that you did not order goes in the bin, not into a USB port.
What you are trusting
Every hardware wallet asks you to trust something. Being specific about what makes the choice an informed one.
- The secure element operating system is closed source. The individual coin apps are open, but the underlying layer cannot be independently reviewed — you are trusting Ledger's certification rather than auditing the design yourself.
- The certification is real but narrow. EAL ratings describe resistance to specific evaluated attacks, not a general guarantee.
- There is no air-gapped path. The device is always connected to something when signing.
- Updates flow through Ledger Live. Convenient, and a channel you depend on.
None of that makes the device unsuitable — it is certified hardware with a large user base and a mature app. It does mean the trade is different from a fully open, air-gapped design, and it is worth knowing which one you picked.
Before you fund it properly
Run the drill in test your recovery. Ledger includes a recovery check that lets you re-enter your phrase and confirms it matches the device without overwriting anything — use it, then do a full restore onto spare hardware before the amount gets serious.
Lineups, app names, and setup wording change between releases. Confirm the current flow against Ledger's own documentation — reached by typing the address yourself — and trust the device screen over any page, including this one.