Skip to content
Ledger Live Desktop Independent guide

Ledger Live Desktop security: the habits that actually protect you

A hardware wallet removes the biggest risk in crypto — keys sitting on an internet-connected computer. It cannot protect you from being persuaded to hand over your recovery phrase, and that is how the overwhelming majority of losses happen. Everything on this page is about closing that gap.

Reviewed 28 September 2026 · Independent, unofficial resource

Rule one

Your recovery phrase is the wallet

The 24 words generated during setup are not a password you can reset. They are the mathematical backup of every account tied to that wallet. Anyone who reads them can rebuild the wallet on their own device and move everything, wherever you are and whatever you do about it afterwards.

  • Write them by hand, in order, at setup — never copy and paste
  • Keep them offline: paper in a safe place, or a metal plate that survives fire and water
  • Never store them digitally: no photos, no notes app, no cloud drive, no password manager, no email to yourself
  • Never type them into anything except the device itself, and only during a restore you initiated
  • Never split or “safely share” them with a person who offers to help — including a supposed employee

If you only remember one sentence

Anyone who asks for your 24 words is trying to steal from you. There is no exception, no emergency and no technical reason that makes it necessary.

Rule two

Fake download sites are the number one trap

A convincing copy of a vendor’s website, ranking above the real one in a search advert, is the standard way people end up with a compromised installer. The page looks right, the artwork is right, and the download button gives you software that asks for your recovery phrase the first time it runs.

Type the address yourself

Do not rely on a search result, an advert, a QR code or a link in a message — including from a friend whose account may itself be compromised.

Read the domain character by character

Lookalikes swap letters, add words like “-download”, “-app”, “-support” or use a different ending. Legitimate vendor pages do not need those extras.

No installer ever needs your phrase

A genuine companion app shows a portfolio. If software asks you to enter 24 words before it will start, delete it and reinstall from the official site.

Rule three

Scam patterns worth memorising

These reappear in new clothes every year. The underlying move is always the same: get you to reveal the phrase or sign something you did not read.

Common approaches and the honest response.
What it looks like What to do
“Validate / sync / migrate your wallet” Nothing. Close the page. No legitimate process needs your phrase.
Support in a DM or on social media Assume it is fraudulent. Reach support only through the official site you typed yourself.
A firmware “update file” sent by email Ignore it. Updates come from inside the app, with the device connected.
A giveaway requiring you to connect your wallet Do not connect. Free money that asks for access is a drain, not a gift.
Someone offering remote access to your computer Refuse. Remote access plus an unlocked wallet is how funds leave.
A “beta app” or browser extension for your wallet Do not install. Use only the official desktop and mobile applications.

Rule four

Protections built into the setup

  • PIN on the wallet — four to eight digits, changed after three wrong attempts resets the device, not your funds
  • Optional passphrase — a second word that creates hidden accounts from the same phrase; powerful, but back it up as carefully as the phrase itself
  • Device-screen verification — the amount and the destination address appear on the wallet, out of reach of malware on the computer
  • App password lock — keeps the interface closed on a shared machine, and hides balances in discreet mode
  • Signed firmware — the device verifies what it installs and refuses anything it cannot authenticate

Keep the computer boring

  • Install operating-system updates promptly
  • Keep a reputable malware scanner running
  • Be sparing with browser extensions — they can read and rewrite anything on a page
  • Log out of remote-access tools when you are not using them
  • Do not transact on public or shared Wi-Fi without thinking about who else is on it

Check before you paste

Clipboard-hijacking malware silently replaces a copied address with the attacker’s. Compare the first and last few characters in the app against the address on the device screen — every single time.

If something goes wrong

You think your phrase or computer is compromised

  1. 1

    Stop using that machine and that wallet. Do not move funds from it while you are unsure — but do not leave them there indefinitely either.

  2. 2

    Create a new wallet — a fresh device or a factory reset of the same one — and write down its new recovery phrase properly.

  3. 3

    Move assets to the new accounts from a clean computer, starting with the largest holdings, verifying each destination on the device screen.

  4. 4

    Retire the old phrase for good. Never reuse it, and treat any funds left on it as already gone.

Report impersonation to the official support channel — found by typing the vendor’s address yourself — and to the search engine or host serving the fake page.

A quick security checklist

  • Recovery phrase written on paper or metal, stored off-site from the device
  • App installed from the official source, and updated from inside the app
  • Device PIN set, wallet locked when idle
  • Address verified on the device screen for every transfer
  • No one — however official they sound — has ever been given the 24 words
  • A plan for what happens to your wallet if you are no longer able to access it

New to the app? Start with the setup guide, then skim the FAQ for the situations people hit most often.

Download only from the official page

That one habit removes the most common way people lose crypto. The link below goes to the vendor’s own site — check the address before you use it, and again before you open the file.