Ledger · Vulnerability Disclosure
Ledger Vulnerability Disclosure
Vulnerability disclosure
Ledger publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.
CryptocurrencyDigital AssetsHardware WalletSelf-Custodyinstitutional-custodyBlockchainPaymentsStakingSecurityAgent Skillsagent-native
Program:
Disclosure Policy
Security Contact
Contact
https://donjon.ledger.com/bounty/
Source
Vulnerability Disclosure
generated: '2026-08-25'
method: searched
probe: true
source: https://donjon.ledger.com/bounty/
program:
name: Ledger Donjon Bug Bounty Program
url: https://donjon.ledger.com/bounty/
platform: self-hosted
submission: >-
Vulnerability report form that opens in a Jira dialog; no Jira account required. Sensitive
exploit detail may be encrypted with Ledger's GPG key before attachment.
gpg_key: https://donjon.ledger.com/ledger-bounty.asc
rewards: true
hall_of_fame: https://donjon.ledger.com/hall-of-fame/
security_bulletins: https://donjon.ledger.com/lsb/
threat_model: https://donjon.ledger.com/threat-model/
policy:
- https://donjon.ledger.com/bounty/
contact:
- https://donjon.ledger.com/bounty/
scope:
devices:
in_scope:
- Hardware attacks on Ledger devices
- Software attacks on device firmware
- Bypass of the PIN
- Arbitrary code execution on the Secure Element
- Arbitrary code execution on the MCU without physical access
- Privilege escalation from an app
- Bypass of user confirmation to issue a transaction
- Sensitive memory leak
in_scope_apps:
- app-bitcoin
- app-bitcoin-new
- app-cardano
- app-stellar
- app-sui
- app-ethereum
- app-exchange
- app-monero
- app-openpgp
- app-recovery-check
- app-security-key
- app-solana
- app-tron
- app-xrp
- app-hyperliquid
out_of_scope:
- Wrong information displayed in Ledger Wallet when the device shows correct details or a warning
- Theoretical vulnerabilities with no working proof-of-concept on the device
poc_requirements: >-
Embedded-app findings must demonstrate exploitation through APDUs sent to the device,
reproducible on the Speculos emulator with the Ragger Python test framework or on real
hardware, against the latest Ledger-released version. Clear-signing findings must show
incorrect or misleading information rendered on the device screen with no warning.
web:
in_scope:
- Critical vulnerabilities in Ledger web infrastructure
out_of_scope:
- Presence or absence of SPF/DMARC records
- Lack of CSRF tokens
- Clickjacking and tabnabbing
- Missing security headers with no direct vulnerability
- Automated scanner output without a demonstrated vulnerability
evidence:
- source: https://donjon.ledger.com/bounty/
kind: bug bounty program page
http_status: 200
keywords:
- bug bounty
- vulnerability report form
- responsible disclosure policy
- reward
- hall of fame
- source: https://donjon.ledger.com/lsb/
kind: security bulletins index
http_status: 200
note: >-
Ledger publishes no RFC 9116 /.well-known/security.txt on any of its own hosts (see
well-known/ledger-well-known.yml). The disclosure program is real but web-page-only, so an agent
or scanner following the well-known convention will not find it. The 200 security.txt on
status.ledger.com belongs to Atlassian Statuspage, not to Ledger.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ledger-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.