Ledger · Vulnerability Disclosure

Ledger Vulnerability Disclosure

Vulnerability disclosure

Ledger publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CryptocurrencyDigital AssetsHardware WalletSelf-Custodyinstitutional-custodyBlockchainPaymentsStakingSecurityAgent Skillsagent-native
Program:

Disclosure Policy

Policy

Security Contact

Contact
https://donjon.ledger.com/bounty/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-25'
method: searched
probe: true
source: https://donjon.ledger.com/bounty/
program:
  name: Ledger Donjon Bug Bounty Program
  url: https://donjon.ledger.com/bounty/
  platform: self-hosted
  submission: >-
    Vulnerability report form that opens in a Jira dialog; no Jira account required. Sensitive
    exploit detail may be encrypted with Ledger's GPG key before attachment.
  gpg_key: https://donjon.ledger.com/ledger-bounty.asc
  rewards: true
  hall_of_fame: https://donjon.ledger.com/hall-of-fame/
  security_bulletins: https://donjon.ledger.com/lsb/
  threat_model: https://donjon.ledger.com/threat-model/
policy:
  - https://donjon.ledger.com/bounty/
contact:
  - https://donjon.ledger.com/bounty/
scope:
  devices:
    in_scope:
      - Hardware attacks on Ledger devices
      - Software attacks on device firmware
      - Bypass of the PIN
      - Arbitrary code execution on the Secure Element
      - Arbitrary code execution on the MCU without physical access
      - Privilege escalation from an app
      - Bypass of user confirmation to issue a transaction
      - Sensitive memory leak
    in_scope_apps:
      - app-bitcoin
      - app-bitcoin-new
      - app-cardano
      - app-stellar
      - app-sui
      - app-ethereum
      - app-exchange
      - app-monero
      - app-openpgp
      - app-recovery-check
      - app-security-key
      - app-solana
      - app-tron
      - app-xrp
      - app-hyperliquid
    out_of_scope:
      - Wrong information displayed in Ledger Wallet when the device shows correct details or a warning
      - Theoretical vulnerabilities with no working proof-of-concept on the device
    poc_requirements: >-
      Embedded-app findings must demonstrate exploitation through APDUs sent to the device,
      reproducible on the Speculos emulator with the Ragger Python test framework or on real
      hardware, against the latest Ledger-released version. Clear-signing findings must show
      incorrect or misleading information rendered on the device screen with no warning.
  web:
    in_scope:
      - Critical vulnerabilities in Ledger web infrastructure
    out_of_scope:
      - Presence or absence of SPF/DMARC records
      - Lack of CSRF tokens
      - Clickjacking and tabnabbing
      - Missing security headers with no direct vulnerability
      - Automated scanner output without a demonstrated vulnerability
evidence:
  - source: https://donjon.ledger.com/bounty/
    kind: bug bounty program page
    http_status: 200
    keywords:
      - bug bounty
      - vulnerability report form
      - responsible disclosure policy
      - reward
      - hall of fame
  - source: https://donjon.ledger.com/lsb/
    kind: security bulletins index
    http_status: 200
note: >-
  Ledger publishes no RFC 9116 /.well-known/security.txt on any of its own hosts (see
  well-known/ledger-well-known.yml). The disclosure program is real but web-page-only, so an agent
  or scanner following the well-known convention will not find it. The 200 security.txt on
  status.ledger.com belongs to Atlassian Statuspage, not to Ledger.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ledger-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.