Security
Phishing · PIN · Physical security {pboot:if('YueQianBao — independent Ledger English service hub (not official). Focused on three things: verifying the official portal, comparing models, and following usage guides; with seed/PIN safety and phishing awareness.'!='')}YueQianBao — independent Ledger English service hub (not official). Focused on three things: verifying the official portal, comparing models, and following usage guides; with seed/PIN safety and phishing awareness.
{/pboot:if}You Lost the Recovery Phrase but Still Have the Device — What Now?
Overview: What should you know about the scenario: You Lost the Recovery Phrase but Still Have the Device — What Now?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Make sure the device is still unlockable and immediately move assets.
- Reinitialise a new device with a fresh recovery phrase.
- Transfer assets to the new address.
- Reset and decommission the old device.
- Record the new backup locations and tighten physical protection.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Why You Must Never Photograph or Upload Your Recovery Phrase to the Cloud
Overview: What should you know about the scenario: Why You Must Never Photograph or Upload Your Recovery Phrase to the Cloud?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Stop any photo or screenshot activity right now.
- Thoroughly delete any digital copy and empty the recycle bin.
- Check cloud sync and photo albums and delete any backups there.
- Rewrite the recovery phrase onto paper or a metal plate.
- From now on, only view the phrase offline.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Why You Should Never Enter PIN or Recovery Phrase on a Computer or Phone
Overview: What should you know about the scenario: Why You Should Never Enter PIN or Recovery Phrase on a Computer or Phone?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Identify the scenario and disconnect the network and device immediately.
- Confirm you're on the genuine domain and the authentic app.
- Check device prompts and Ledger Live security warnings.
- Work through the official documentation step by step, recording what you find.
- Contact official support if needed — never reveal your recovery phrase or PIN.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Fake Ledger Support Identification — Social Media Anti-Scam
Ledger support does not DM first, does not ask for your recovery phrase, and does not ask you to run unusual commands or install new firmware via external tools. If an account does any of these, it's fake.
Safety reminder: Never share your recovery phrase, PIN, or verification codes with anyone. Always verify using the device screen. Use only official channels to download apps and install updates.
Do You Need a Metal Plate for Your Recovery Phrase?
Overview: What should you know about the scenario: Do You Need a Metal Plate for Your Recovery Phrase?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Choose a stainless-steel plate that resists fire and water.
- Engrave the recovery phrase offline, with nobody else present.
- Verify each word after engraving.
- Store the plate somewhere secure, dry, and theft-resistant.
- Keep a paper backup as a secondary fallback.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
What Are the Risks of an 'Update Patch' Sent by Email?
Overview: What should you know about the scenario: What Are the Risks of an 'Update Patch' Sent by Email?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Never open executable attachments from email.
- Download updates manually from the official site, not from email links.
- Check the sender's domain and the SPF/DKIM status.
- Delete suspicious emails and empty the trash.
- Change account passwords and scan for malware if needed.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Collect Evidence and Report After Confirming Funds Were Stolen
Overview: What should you know about the scenario: How to Collect Evidence and Report After Confirming Funds Were Stolen?
Key takeaway: Isolate the network first, then migrate remaining assets under a fresh recovery phrase, preserve evidence, and notify Ledger and the relevant platforms.
Action steps:
- Disconnect the network and unplug the device immediately.
- On a trusted device, initialise a new wallet with a fresh recovery phrase.
- Move remaining assets to the new address.
- Collect logs, transaction hashes, and chat records as evidence.
- Report to official support and any affected platform, and strengthen your security habits.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Do You Need to Rotate Your PIN Periodically?
Overview: What should you know about the scenario: Do You Need to Rotate Your PIN Periodically?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Confirm you remember the current recovery phrase first to avoid accidental wipe.
- Go to the device settings and choose Change PIN.
- Enter the old PIN, then set and confirm the new one.
- Reconnect Ledger Live to verify it works.
- Log the change date in a safe place — don't write the full PIN anywhere.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Set a PIN That Is Both Safe and Memorable
Overview: What should you know about the scenario: How to Set a PIN That Is Both Safe and Memorable?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Identify the scenario and disconnect the network and device immediately.
- Confirm you're on the genuine domain and the authentic app.
- Check device prompts and Ledger Live security warnings.
- Work through the official documentation step by step, recording what you find.
- Contact official support if needed — never reveal your recovery phrase or PIN.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Double-Check a Signing Prompt to Prevent Address Replacement
Overview: What should you know about the scenario: How to Double-Check a Signing Prompt to Prevent Address Replacement?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Verify the recipient address and amount field by field on the device screen.
- Confirm the app display matches the device before signing.
- If an unfamiliar address appears, reject and exit.
- Check the computer for clipboard-hijacker malware.
- Restart the device and the app before retrying.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Ledger Lost — What to Do
Your assets are safe as long as (a) your recovery phrase is safe and (b) your PIN was unknown to the thief (PIN retries are limited; the device wipes after repeated wrong PINs). Buy a new Ledger and restore from your recovery phrase.
Safety reminder: Never share your recovery phrase, PIN, or verification codes with anyone. Always verify using the device screen. Use only official channels to download apps and install updates.
What to Do When the Device Wipes Itself After Too Many Wrong PINs
Overview: What should you know about the scenario: What to Do When the Device Wipes Itself After Too Many Wrong PINs?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Check the remaining attempts left — don't keep entering wrong PINs.
- Keep the recovery phrase ready as your fallback.
- Let the device wipe itself, then restore from the recovery phrase.
- Set a new PIN and test unlocking.
- Log the incident for future audit.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Spot Fake Official Sites and Phishing Download Pages
Overview: What should you know about the scenario: How to Spot Fake Official Sites and Phishing Download Pages?
Key takeaway: Scam prevention comes down to one thing: verify the domain and the certificate. Any request for your recovery phrase or PIN is a scam.
Action steps:
- Type the domain ledger.com manually into the browser.
- Check the certificate issuer and the HTTPS padlock.
- Never download from search ads or community links.
- Verify the hash/signature of the installer.
- Close and report any fake site you spot.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How Should You Back Up the Recovery Phrase for Maximum Safety?
Overview: What should you know about the scenario: How Should You Back Up the Recovery Phrase for Maximum Safety?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Retrieve the recovery-phrase paper in an offline environment.
- Verify word order and spelling one by one.
- If you need to rewrite, use pen and paper — no photos or screenshots.
- Split backups across two fire- and moisture-proof locations.
- Log the inspection date and recheck periodically.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Security Boundary: PIN vs. Recovery Phrase
Overview: What should you know about the scenario: Security Boundary: PIN vs. Recovery Phrase?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Explain that the private key never leaves the device's secure element.
- No software interface ever needs the recovery phrase or PIN.
- When connecting to a computer, verify the official app and its certificate.
- Never disclose any key material through browser extensions or SMS.
- Keep device firmware and apps up to date.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.