Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Tech

Ledger Recover Service Sparks Community Backlash Over Seed Phrase Security Model

Ledger announced the Ledger Recover service on May 16, 2023, dividing the security community over whether splitting seed phrases violated the core security principle.

By MiningPool Staff··2 min read
Ledger Recover Service Sparks Community Backlash Over Seed Phrase Security Model

Key Points

  • Ledger announced the Ledger Recover service on May 16, 2023, dividing the security community over whether splitting seed phrases violated the core security principle.

Ledger announced Ledger Recover on May 16, 2023, a paid optional service that splits hardware wallet seed phrases into encrypted shards distributed across three custodians, triggering fierce backlash from the security community over abandonment of the fundamental principle that seed phrases never leave the device.

The service operated as a $9.99-per-month subscription available to Ledger Nano X and Ledger Stax users. The recovery mechanism split the user's seed phrase into three encrypted shards held by Ledger, Coincover (a recovery service provider), and EscrowTech. Recovery required authentication through a biometric unlock on the device and two of the three shards. The architecture aimed to balance recovery options against key custody concentration.

Advertisement

728×90

CEO Pascal Gauthier defended Recover as an optional feature for users who had experienced seed phrase loss. He argued the service provided an alternative to the practical reality that many users stored recovery seeds insecurely. Gauthier positioned the feature as harm reduction rather than a fundamental security downgrade, maintaining that users could continue using traditional offline seed backups if they preferred.

The community perceived the announcement differently. Hardware wallet users had selected Ledger because the device never exposed seed phrases to internet-connected systems. Recover violated that core assurance by requiring the device to export its seed phrase, even in encrypted form, to the Ledger infrastructure. Multiple security researchers highlighted that any exposure mechanism introduced attack surface. Competitors immediately capitalized on the backlash.

Trezor, the primary alternative hardware wallet, released marketing materials emphasizing that its devices would never support such recovery mechanisms. GridPlus highlighted its commitment to offline-only key management. The competitive positioning effectively positioned Ledger as having compromised on the security principle that had driven hardware wallet adoption in the first place.

A firmware update released during the announcement period revealed technical details of Recover's implementation. Security researchers examining the code discovered that the device could technically export seed phrases to Ledger infrastructure. The device lacked hardware-level restrictions preventing seed phrase extraction. This discovery amplified concerns that Ledger's commitment to never exporting keys was a policy choice rather than an architectural constraint, potentially subject to change.

Ledger delayed full rollout of Recover following community pressure. The service remained opt-in and underwent extended security audits before broader availability. The company conducted bug bounty campaigns to identify vulnerabilities in the shard recovery mechanism. The extended timeline signaled acknowledgment that the feature required careful implementation to maintain user confidence.

The episode demonstrated the durability of the original hardware wallet value proposition: absolute exclusion of seed phrase exposure. Users had selected Ledger to eliminate the compromise inherent in self-custody. Recover reintroduced that compromise in encrypted form. Whether the encryption and multi-custodian distribution model actually reduced risk relative to offline storage remained contested territory. The market's immediate shift toward competitors suggested that users valued absolute commitment to the no-export principle over options for seed recovery.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

NEAR Intents Says an Omni Bridge Bug Cost It About $3.8 Million
Markets

The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.

·MiningPool Staff
SEC's Crypto Custody Rule Is Public and Self-Custody Is a Last Resort
Policy

An adviser could hold client crypto itself only after determining in writing, and again every quarter, that no permitted custodian is available for that asset. Transactions would need two people to authorize them, and the comment period runs 60 days from Federal Register publication.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff
Bitget Says Its Own Approval Process Released $351.6 Million
Tech

The exchange's security notice declined to name an attack vector, and hours later its chief executive said the attacker spoofed transaction data through a compromised backend system, ruling out private key theft. Withdrawals remain suspended, and the loss is close to 76 percent of the User Protection Fund Bitget says covers it.

·MiningPool Staff
Only Agave Can Run Alpenglow as Solana Starts the Testnet Phase
Tech

Anza is targeting about 150 milliseconds to finality, down from the roughly 12.8 seconds it attributes to TowerBFT, but Firedancer and Frankendancer cannot run the code yet. No mainnet date has been announced, and September 28 is a feature-gate processing date rather than a confirmed Alpenglow launch.

·MiningPool Staff
Solana's Slots Are 250ms Now and Still Run About 16ms Long
Tech

Network-reported block times put the new slots at about 267 milliseconds on average, the same roughly 16-millisecond overhead that sat on top of the 400, 350 and 300 millisecond targets before it. Block limits fell in proportion, so throughput stays at 150 million compute units a second.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.