Mkt Cap$2.26T+3.05%
24h Vol$79.77B
BTC Dom56.3%
ETH Dom8.9%
F&G12Extreme Fear
BTC$63,414.00+3.30% ETH$1,674.13+3.56% USDT$0.999-0.01% BNB$602.77+3.11% USDC$0.99980.00% XRP$1.14+4.04% SOL$66.86+6.33% TRX$0.3138-2.31% FIGR_HELOC$1.03+0.29% DOGE$0.0863+4.74% HYPE$58.58+9.65% USDS$0.99970.00% LEO$9.49-0.98% RAIN$0.0133+1.92% ZEC$435.32+6.35% XMR$375.99+12.10% BTC$63,414.00+3.30% ETH$1,674.13+3.56% USDT$0.999-0.01% BNB$602.77+3.11% USDC$0.99980.00% XRP$1.14+4.04% SOL$66.86+6.33% TRX$0.3138-2.31% FIGR_HELOC$1.03+0.29% DOGE$0.0863+4.74% HYPE$58.58+9.65% USDS$0.99970.00% LEO$9.49-0.98% RAIN$0.0133+1.92% ZEC$435.32+6.35% XMR$375.99+12.10%
BTC+3.30% Crypto

“Horrendous Idea” to Back Up Keys Leads to User Backlash for Ledger

The optional subscription service to recover seed phrases is treading a fine line between convenience and controversy.

"Horrendous Idea" to Back Up Keys Leads to User Backlash for Ledger
Image courtesy of 123rf.
Editorial disclosureRead more

All reviews, research, news and assessments of any kind on The Tokenist are compiled using a strict editorial review process by our editorial team. Neither our writers nor our editors receive direct compensation of any kind to publish information on tokenist.com. Our company, Tokenist Media LLC, is community supported and may receive a small commission when you purchase products or services through links on our website. Click here for a full list of our partners and an in-depth explanation on how we get paid.

Neither the author, Tim Fries, nor this website, The Tokenist, provide financial advice. Please consult our website policy prior to making financial decisions.

On Tuesday, Ledger’s Chief Security Officer, Charles Guillemet, announced a new feature for the popular lineup of hardware wallets. For users who are not confident enough to safeguard their recovery phrase, Ledger will provide an alternative.

Specifically, an optional subscription called Ledger Recover. As the name suggests, it will enable users to recover their access to the blockchain network, i.e., their funds. The service is device-agnostic so that the recovery process can be accessed anytime. However, the firm came under fire from the community over the move.

Ledger’s New Feature is Optional

According to Guillemet, the subscription is not automatically enabled. If activated, the user would first have to go through a KYC-like procedure by verifying their identity via selfie recording. Then, the Ledger device, such as Ledger Nano X, would copy the user’s recovery phrase. 

This duplicate would be encrypted and linked to the verified identity. In addition to encryption, the recovery phrase backup would be fragmented into three shards. Ledger, Coincover, and an unnamed third party would secure each.

On their own, these three fragments are purportedly useless. When the user activates the Ledger Recover procedure, two parties return the fragments to the device. They are then recombined into a functioning recovery phrase following identity verification.

“Decryption can only happen on Ledger after identity verification.”

Third parties, Onfido and Electronic IDentifications will be in charge of verifying users’ identities. Thus made whole from fragments and multiple third parties, the backup is restored on the Ledger device. 

Ledger Faces Backlash from Users

A recovery phrase, typically 12 – 24 words, is the master key that unlocks blockchain access from any device. This is useful in some cases; for example, a user loses 100% of their belongings in a house fire, including the smartphone/computer with the installed wallet app. 

If those were regular digital files, such as videos, they would be permanently lost if no backup existed. But a crypto wallet is not a file container per se. The user would regenerate the wallet app (blockchain access) on a new device with a remembered recovery phrase or retrieved from another location. 

More precisely, the recovery phrase would generate the wallet’s private keys, also called a seed phrase. Therefore, private keys themselves are less important. Private keys authorize transactions while they are derived from the seed phrase.

In this light, Ledger Recover is controversial in several ways:

  • By tying multiple third parties to self-custody, Ledger could erode the very concept.
  • User ID becomes tied to the recovery phrase, i.e., the digital assets.
  • If the device has this firmware capability, is there a backdoor in the cards?

These are potential vulnerability vectors that could be exploited down the line. Preemptively, Guillemet assured Ledger customers that such potential exploits were not possible.

“Self-custody is at the core of our offering and your secret recovery phrase is created on your device. We have no access to it. This will never change.”

However, even Binance CEO expressed some doubts about the new Ledger feature.

Another notable cybersecurity figure, Mudit Gupta of Polygon Labs, called Ledger Recovery a “horrendous idea,” warning users not to enable the subscription service.

Join our Telegram group and never miss a breaking digital asset story.

Is Ledger’s Optional Convenience Worth It?

In the first decade of Bitcoin adoption, there was no shortage of headlines on thousands of bitcoins lost. For instance, Gabriel Abed lost 800 BTC in 2011 when his colleague formatted a laptop hard drive containing the wallet’s private keys. These funds are forever locked on the Bitcoin network without a recovery phrase.

It could also be said that the human brain is unreliable. What if someone suffers a concussion, and the seed phrase is scrambled? In this light, Ledger Recovery is an enticing option.

However, as software engineers know, complexity breeds points of failure. In 2020, Ledger’s customers received emails from fake Ledger support asking them to download the latest Ledger Live version. These classic phishing attacks exploit the erected bridges between users and third parties.

In that instance, an unauthorized third party accessed Ledger’s e-commerce database via the API key. This time, Ledger will use multiple third parties and fragment the seed phrase. Yet, all this bridging and connectivity signifies a departure from what users understand as a “self-custodial hardware wallet.”

<strong>Finance is changing.</strong>
Learn how, with Five Minute Finance.
A weekly newsletter that covers the big trends in FinTech and Decentralized Finance.

Do you think extra redundancy in wallet recovery is worth the risk? Let us know in the comments below.

Tim Fries

Tim Fries

Author · Tokenist

Tim Fries is the cofounder of The Tokenist. He has a B. Sc. in Mechanical Engineering from the University of Michigan, and an MBA from the University of Chicago Booth School of Business. Tim served as a Senior Associate on the investment team at RW Baird's US Private Equity division, and is also the co-founder of Protective Technologies Capital, an investment firm specializing in sensing, protection and control solutions.

Related Stories