February 23, 2026

Capitalizations Index – B ∞/21M

Ledger Nano X & Bluetooth – Security Model of a Wireless Hardware Wallet

Ledger nano x & bluetooth – security model of a wireless hardware wallet

Ledger Nano X & Bluetooth – Security Model of a Wireless Hardware Wallet

Ledger nano x & bluetooth – security model of a wireless hardware wallet

Ledger recently announced the launch of the IOTA compatible Ledger Nano X. This new product is built around a new hardware architecture, while taking advantage of our versatile security Operating System BOLOS.

The Ledger Nano X features Bluetooth Low Energy (BLE) connectivity enabling it to be used with Android or iOS devices without the need of a cable. While this feature greatly improves the user experience, it raised some concerns about the security of the wireless connection. We would like to address these.

In short:

  • Only public data is transported by Bluetooth; critical data (such as private keys and seed) never leave the device.
  • Even if the Bluetooth connection would be hacked, the security of the Ledger Nano X relies on the Secure Element (SE) which will request your consent for any action.
  • The Ledger Nano X Bluetooth implementation uses a state-of-the-art Bluetooth protocol. This Bluetooth protocol ensures authentication by using pairing. This is numeric comparison based and confidentiality is ensured using AES-based encryption.
  • If ever, you’re not comfortable using your Nano X with a wireless connection, you can disable the Bluetooth and use the USB type-C cable.

Let’s discuss in more detail how it works and why it does not impact the security model of this hardware wallet.

The new architecture is a bit different from the Ledger Nano S one while staying quite similar at the same time.

It features 2 chips:

  • A new state-of-the-art Secure Element (ST33J2M0)
  • A dual-core MCUs with wireless support (STM32WB55)

The STM32 MCU is in charge of the connection between the smartphone/desktop and the Secure Element and simply acts as a proxy.

The Secure Element is in charge of getting user inputs and driving the screen where critical information is displayed. Of course, it is also in charge of the security of the product. It stores the seed and the private keys and implements all cryptographic operations to manage your cryptocurrencies.

Impact on our security model

Bluetooth connection is only used as a transport layer for public information. The secret keys or seed are never exposed to the BLE stack and never, ever leave the Secure Element.

For instance, when you make a transaction, the transaction is prepared on the smartphone or desktop Ledger Live application and then sent using Bluetooth or USB to the MCU (STM32) which directly relays it to the Secure Element. You are then prompted to verify the amount and the address of the recipient, which are displayed on the screen. If everything is correct you can approve the transaction by pressing both buttons.

If ever your smartphone/computer were compromised, if ever the Bluetooth link was compromised, if ever the STM32 MCU was compromised, the Secure Element ultimately prompts you to verify the transaction information. The screen will show you the true transaction details. No transaction signature is issued without your explicit consent.

Our use of BLE

Nevertheless, the Bluetooth stack may transport your public keys or addresses and this could raise privacy concerns. That is why we implemented a state-of-the-art Bluetooth protocol.

A BLE connection is a 2-phase protocol.

  • Key Exchange
  • Use of the BLE channel

First of all, both parties (Ledger Nano X and smartphone) generate their own key pairs using a Random Generator.

After this, there is a pairing phase where, after user approval, the Ledger Nano X and the smartphone go through an Elliptic Curve Diffie Hellman key exchange. This phase is critical since it is the phase where the Ledger Nano X trusts the smartphone to which it pairs and vice versa. In order to avoid Man-In-the-Middle attacks (MiTM), which are the common attacks on BLE, the Bluetooth protocol has specific configurations.

We implemented the state-of-the-art security configuration to avoid MiTM attacks: Numeric Comparison. When the common secret is generated, both the Ledger Nano X and smartphone display a numeric code and the user verifies if they are the same. This numeric code is computed using AES-CMAC from public keys of both parties and random nonces. This avoids collision attacks and downgrade attacks, while enforcing the authentication of public keys. If this is the case, both parties consider each other as legitimate and can then communicate, guaranteeing authentication and confidentiality.

Once this key exchange protocol is completed, a secure channel can be established between the smartphone and the Ledger Nano X, featuring an AES-based encryption scheme.

On older versions of Android, the Numeric Comparison may not be featured. In this case, the Secure Element warns the user with a message and a MiTM attack could be implemented. This attack would require an attacker, located nearby, to firstly pair a rogue device with the Ledger Nano X and also with the smartphone. Then he could intercept and forward every packet. This would allow spying on the communication between the Ledger Nano X and the smartphone or even sending commands to the Secure Element. However, the user would still be asked to verify and consent for any transaction.

Security Audit

Our BLE stack is implemented through the ST stack. The Ledger Donjon, our security team, has evaluated the security of this implementation regarding the latest attacks such as Invalid Point attacks.

Good old USB cable

Nonetheless, if you do not feel comfortable using a wireless connection on your Ledger Nano X, you can simply deactivate the Bluetooth connectivity and use the USB type-C connector with your computer to enjoy the remaining features of the Ledger Nano X.

Ledger Nano X IOTA

source: https://iota-news.com/ledger-nano-x-bluetooth-security-model-of-a-wireless-hardware-wallet/

Published at Wed, 16 Jan 2019 10:36:21 +0000

Previous Article

Bankrupt [BTC] Miner Giga Watt Forced to Cease Daily Operations

Next Article

REAL ESTATE INVESTMENT ON THE BLOCKCHAIN | SWINCA ICO REVIEW

You might be interested in …

The Bitcoin Game #47: Scaling Bitcoin with Paul Puey, Tone Vays, Ryan X. Charles, and Eric Lombrozo

Hello, welcome to episode 47 of The bitcoin Game, I’m Rob Mitchell. We recently had the State Of Digital Money, the first big bitcoin conference in Los Angeles since 2015. Actually, I’m unsure if I should call it a bitcoin conference, since the majority of the presentations were not directly related to bitcoin. Luckily for me, I got to moderate a panel on scaling bitcoin with notable Bitcoiners: Core developer Eric Lombrozo, longtime bitcoin developer Ryan X. Charles, vocal trader and personality Tone Vays, and Airbitz Wallet?’?s Paul Puey. You’ll hear the discussion in its entirety on this episode.


SHOW LINKS

State Of Digital Money

Paul Puey Twitter
Airbitz

Tone Vays Twitter
Liberty-Life-Trail

Ryan X. Charles Twitter
Yours

Eric Lombrozo Twitter
Ciphrex

Periscope live stream from audience member Vivek Kasarabada


STAY IN TOUCH

https://Twitter.com/TheBTCGame
http://TheBitcoinGame.com
Rob@TheBitcoinGame.com

Thanks so much for taking the time to listen to The bitcoin Game!

bitcoin tipping address:
1G8HDg5EsPQpamKYS2bDya9Riv9xv1nVo5


SPONSOR

While much of a Bitcoiner’s time is spent in the world of digital assets, sometimes it’s nice to own a physical representation of the virtual things you care about. For just the price of a cup of coffee or two (at Starbucks), you can own your own Bitcoin Keychain or the newer Bitcoin Fork Pen.

As Seen On
TechCrunch ?’ Engadget ?’ Ars Technica ?’ Popular Mechanics
Maxim ?’ Inc. ?’ Vice ?’ RT ?’ Bitcoin Magazine ?’ VentureBeat
CoinDesk ?’ Washington Post ?’ Forbes ?’ Fast Company

http://bkeychain.com
http://bitcoinforks.com


CREDITS

Episode photo courtesy of Valerian Bennett.

All music in this episode of The bitcoin Game was created by Rob Mitchell.

The bitcoin Game box art was created from an illustration by Rock Barcellos.

Social investing platform etoro expanding crypto trading to us

Social Investing Platform eToro Expanding Crypto Trading to US

Social Investing Platform eToro Expanding Crypto Trading to US eToro, the social investing platform, is launching a full-fledged cryptocurrency exchange and mobile wallet and expanding into the United States. Announced Tuesday, the Israel-based company has […]

Ljubljana Blockchain developer (hyperledger + ethereum) for business training | hyper ledger, erc20, smart contract (private+public) bitcoin [BTC] bitcoin [BTC] cryptocurrency token, coin development, solution architect, bitcoin [BTC] development tr

Ljubljana Blockchain developer (hyperledger + ethereum) for business training | hyper ledger, erc20, smart contract (private+public) bitcoin [BTC] bitcoin [BTC] cryptocurrency token, coin development, solution architect, bitcoin [BTC] development tr Programming Knowledge and JavaScript Knowledge […]