The Ledger Nano X is the wireless flagship of the world's best-selling hardware-wallet line. It pairs an ST33 Secure Element with Bluetooth 5.2 and USB-C, driving a small 128x64 monochrome OLED, and it manages 500+ assets through the Ledger Live app. At around $149 it costs roughly double the USB-only Nano S Plus, and most of that premium buys you Bluetooth and a larger transaction memory rather than any extra security. As a piece of consumer hardware it is genuinely good: fast, sturdy, and about as friendly as cold storage gets.
The security model rests on that Secure Element, a bank-card-grade chip designed to resist physical extraction. The catch, which Ledger states openly, is that the SE's low-level firmware is closed source and locked behind an STMicroelectronics NDA. Ledger describes its stack as '95% open source'; the remaining 5% is exactly the part that governs the chip holding your keys. For many users that is an acceptable trade for certified hardware. For anyone who believes 'don't trust, verify,' it is the whole ballgame — you are trusting a company, not inspecting a design.
That trust has been tested. In 2020 a breach of Ledger's e-commerce and marketing database exposed roughly one million customer emails and, in the public dump that followed, 272,853 buyers' names, home addresses and phone numbers. No funds, passwords or seed data were touched — the private keys were never at risk — but for a product bought specifically by people holding wealth, leaking a list of who owns hardware wallets and where they live is a serious physical-security failure, and it drove a wave of phishing and extortion attempts.
The second dent came in May 2023 with 'Ledger Recover,' an optional paid service that splits an encrypted copy of your seed across three custodians so it can be restored with ID verification. The uproar was not really about the feature; it was Ledger's own explanation that firmware could facilitate key extraction. That single admission rewrote how many users understood the device, and Ledger postponed the launch, promising to open-source OS components first. It was a self-inflicted credibility wound more than a technical break.
On Bluetooth, Ledger's position is that only public data crosses the radio, keys never leave the SE, and pairing uses numeric comparison to resist man-in-the-middle attacks. Independent reviewers generally rate the practical BLE risk as low, but note the obvious: a radio you can turn on is attack surface a USB-only wallet does not have. If you want the Ledger experience without it, the Nano S Plus is the cheaper, wire-only sibling.
The verdict is nuanced. The Nano X is not insecure, and the millions of people using it without incident are not fools. But it is a device that repeatedly asks you to trust the maker on the parts you cannot check, and whose maker has twice given critics ammunition. If you value convenience, multi-coin support and a smooth app, it is a reasonable buy. If your priority is auditability and minimizing who you must trust, the open-source Bitcoin-only wallets in this roundup answer that need more directly for less money.