Security
Phishing · PIN · Physical security {pboot:if('YueQianBao — independent Ledger English service hub (not official). Focused on three things: verifying the official portal, comparing models, and following usage guides; with seed/PIN safety and phishing awareness.'!='')}YueQianBao — independent Ledger English service hub (not official). Focused on three things: verifying the official portal, comparing models, and following usage guides; with seed/PIN safety and phishing awareness.
{/pboot:if}The Right Process for Moving Your Recovery-Phrase Storage
Overview: What should you know about the scenario: The Right Process for Moving Your Recovery-Phrase Storage?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Pick the new moisture- and fire-proof location in advance.
- Prepare a fresh secure container before the move.
- Ensure nobody else is watching during the transfer.
- After the move, check for and destroy any leftover copies.
- Update your custody list and inform your trusted contact.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Keeping the Recovery Phrase Fire- and Moisture-Proof at Home
Overview: What should you know about the scenario: Keeping the Recovery Phrase Fire- and Moisture-Proof at Home?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Use a fire- and moisture-proof physical container or a metal plate.
- Split the recovery-phrase copies across two locations to avoid single-point risk.
- Inspect the storage environment regularly for moisture.
- Keep the phrase away from ID documents — you don't want both stolen together.
- Record the custodian and the inspection date.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Emergency Steps When You Spot an Unauthorised Outbound Transaction
Overview: What should you know about the scenario: Emergency Steps When You Spot an Unauthorised Outbound Transaction?
Key takeaway: Isolate the network first, then migrate remaining assets under a fresh recovery phrase, preserve evidence, and notify Ledger and the relevant platforms.
Action steps:
- Disconnect the network and unplug the device immediately.
- On a trusted device, initialise a new wallet with a fresh recovery phrase.
- Move remaining assets to the new address.
- Collect logs, transaction hashes, and chat records as evidence.
- Report to official support and any affected platform, and strengthen your security habits.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Handle the Recovery Phrase in a Will or Custodial Handover
Overview: What should you know about the scenario: How to Handle the Recovery Phrase in a Will or Custodial Handover?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Seal the recovery phrase and the handover instructions separately.
- Assign a trusted witness or lawyer as custodian.
- Emphasise in the document that the phrase must not be photographed or copied.
- When updating, destroy the old version of the instructions too.
- Periodically confirm the seal is unbroken.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
A Safe Way to Verify You Wrote the Recovery Phrase Correctly
Overview: What should you know about the scenario: A Safe Way to Verify You Wrote the Recovery Phrase Correctly?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Use the on-device check-phrase feature.
- Verify word by word as prompted — never type into any software.
- On error, rewrite the backup and destroy the old paper.
- Store the paper afterwards and record the check date.
- Keep everything offline — no photos.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Do You Need Multiple Copies When Backing Up the Recovery Phrase?
Overview: What should you know about the scenario: Do You Need Multiple Copies When Backing Up the Recovery Phrase?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Ensure you have at least two offline backups kept in separate locations.
- Keep each copy legible and moisture-proof.
- Don't create so many copies that the exposure surface grows.
- When you update a backup, destroy the outdated version.
- Log the number of copies and their locations for audit purposes.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Avoid Leaking the Private Key When Connecting to an Unfamiliar Computer
Overview: What should you know about the scenario: How to Avoid Leaking the Private Key When Connecting to an Unfamiliar Computer?
Key takeaway: Isolate the network first, then migrate remaining assets under a fresh recovery phrase, preserve evidence, and notify Ledger and the relevant platforms.
Action steps:
- Disconnect the network and unplug the device immediately.
- On a trusted device, initialise a new wallet with a fresh recovery phrase.
- Move remaining assets to the new address.
- Collect logs, transaction hashes, and chat records as evidence.
- Report to official support and any affected platform, and strengthen your security habits.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
What to Do When You Encounter a Ledger Phishing Attempt
Overview: What should you know about the scenario: What to Do When You Encounter a Ledger Phishing Attempt?
Key takeaway: Follow the official guidance and start by making sure the environment and the information source are trustworthy.
Action steps:
- Refuse to share your PIN or recovery phrase with any support rep or web page.
- Spot phishing copies of the official site and close them immediately.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Common Mistakes When Writing Down the Recovery Phrase
Overview: What should you know about the scenario: Common Mistakes When Writing Down the Recovery Phrase?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Identify the scenario and disconnect the network and device immediately.
- Confirm you're on the genuine domain and the authentic app.
- Check device prompts and Ledger Live security warnings.
- Work through the official documentation step by step, recording what you find.
- Contact official support if needed — never reveal your recovery phrase or PIN.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How the Device's Secure Element Protects the Private Key from Exposure
Overview: What should you know about the scenario: How the Device's Secure Element Protects the Private Key from Exposure?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Explain that the private key never leaves the device's secure element.
- No software interface ever needs the recovery phrase or PIN.
- When connecting to a computer, verify the official app and its certificate.
- Never disclose any key material through browser extensions or SMS.
- Keep device firmware and apps up to date.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
After Clicking a Malicious Link — Remediation Steps
Overview: What should you know about the scenario: After Clicking a Malicious Link — Remediation Steps?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Close the page and clear the browser cache.
- Disconnect the network and check for malicious extensions.
- Run a full antivirus scan.
- Rotate the recovery phrase and migrate to a new address.
- Monitor the account for a period to confirm no new anomalies.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
How to Keep Your Ledger Recovery Phrase Safe
Overview: What should you know about the scenario: How to Keep Your Ledger Recovery Phrase Safe?
Key takeaway: Follow the official guidance and start by making sure the environment and the information source are trustworthy.
Action steps:
- Refuse to share your PIN or recovery phrase with any support rep or web page.
- Spot phishing copies of the official site and close them immediately.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Someone Claims to Be Official Support and Asks for Your Recovery Phrase — What to Do
Overview: What should you know about the scenario: Someone Claims to Be Official Support and Asks for Your Recovery Phrase — What to Do?
Key takeaway: Scam prevention comes down to one thing: verify the domain and the certificate. Any request for your recovery phrase or PIN is a scam.
Action steps:
- Refuse flat-out anyone asking for your recovery phrase or PIN.
- Confirm official support speaks only through the official ticket and verification channels.
- Refuse remote-control software on your device.
- Preserve the chat as evidence and report the phishing account.
- Rotate the recovery phrase and migrate assets if needed.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Does Forgetting the PIN Put Your Assets at Risk?
Overview: What should you know about the scenario: Does Forgetting the PIN Put Your Assets at Risk?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Don't keep retrying incorrect PINs — the device will wipe itself.
- Use the recovery phrase on the device to restore.
- Set a new PIN after recovery and record how you remember it.
- Reconnect Ledger Live to confirm accounts are normal.
- Destroy any old backup that records the previous PIN.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.
Are Airdrop Links in Telegram/Community Groups Trustworthy?
Overview: What should you know about the scenario: Are Airdrop Links in Telegram/Community Groups Trustworthy?
Key takeaway: Your recovery phrase and PIN must never leak. Do every operation on the official device and app, and if something is wrong, stop using the device at once and migrate the assets.
Action steps:
- Treat airdrop links as untrusted by default — verify the official source first.
- Don't connect to unknown sites or sign suspicious transactions.
- Use watch-only mode to view assets and disable write access.
- Check whether the URL is impersonating the real domain.
- If you clicked by mistake, disconnect and isolate cold storage.
Safety reminder: Anyone asking for your recovery phrase or PIN is a scammer. Never enter the recovery phrase into software or webpages, use only official channels for updates and downloads, and migrate assets and report the incident immediately if anything looks off.