Getting started
Download, install, pair your device, add an account.
Open guide →Independent, unofficial guide. This site is not affiliated with, endorsed by or sponsored by Ledger SAS. Ledger Live is only ever published on ledger.com — download it there and nowhere else.
Security
A hardware wallet removes the biggest risk in crypto — keys on a computer — and replaces it with a much smaller, much more human set of risks: downloads, links, messages and the 24 words you wrote down.
Your 24-word recovery phrase is the wallet. Anybody who has those words can restore your wallet on their own device and spend everything in it, and they do not need your hardware wallet, your PIN or your computer to do it. Every serious scam aimed at Ledger owners is a variation on getting those words out of you.
That gives you one rule that covers almost everything:
Not to restore an app. Not to "validate" a wallet. Not to claim an airdrop. Not for a support agent, an exchange, a wallet update or a prize. The legitimate place for those words is the hardware wallet's own screen and buttons, and nowhere else — and Ledger Live Desktop never needs them to install, sync, update or recover anything.
The app runs on a computer that could be compromised. The hardware wallet does not. So the device screen is the one display in your setup that an attacker cannot rewrite, and it is where you check the things that matter: the receive address you are about to share, the destination and amount of a payment, and the details of anything you are asked to sign.
This is why the app nags you. Verifying the address on the device is not a formality; it is the mechanism that defeats malware designed to swap addresses in a computer's clipboard or in the app's own display.
The most direct attack on a desktop user is a fake build of Ledger Live. It looks right, it installs, it may even show a plausible app — and at some point it asks for your recovery phrase. Common delivery routes:
Defences are simple and take seconds: reach the site by typing ledger.com or through a bookmark you created yourself; read the domain rather than the logo; never install a wallet app you received as a link; and treat an emailed "update" as phishing by default.
Someone replies to your question on social media or in a chat group, offering to help and asking for your recovery phrase or a remote session. Real support never asks for either, and never opens a direct message to help you first.
Messages warning that your wallet needs to be "secured", "validated" or "reconnected", with a link to a page that asks for your words. Ledger emails and order data have been leaked before now, so brand-correct greetings prove nothing.
Pages that offer an airdrop, a migration or a "wallet check" and ask you to connect or enter a phrase. Connecting a web3 app only ever needs your public address; anything asking for a secret is stealing it.
Callers claiming to be from Ledger or the police, or someone who turns up at your door. No legitimate process requires you to hand over a device, a PIN or a recovery sheet under time pressure.
An optional passphrase, sometimes called BIP39, adds a word or phrase of your own on top of the recovery phrase and creates a separate hidden wallet. It is a genuine security upgrade against someone who finds your written seed — and a genuine way to lose everything if you forget it, because there is no reset and no recovery. If you use one, store it separately from the recovery phrase and understand that it is not the same thing as your device PIN.
Ledger Live Desktop is free and is distributed by Ledger at ledger.com. There are no mirrors, no “pro” versions, no paid unlocks and no need to enter your recovery phrase anywhere to install it.
Download, install, pair your device, add an account.
Open guide →Short answers to the questions people ask most.
Open guide →Device not detected, sync errors, stuck transactions.
Open guide →