Ledger Recover ou Tangem Seedless : quelle solution protège le mieux vos
Ledger divise la phrase de récupération en fragments détenus par des tiers. Tangem supprime la phrase de récupération. Quelle
- Points essentiels
- TL ; DR
- What is Ledger Recover, and how does it work? When a user chooses to subscribe
- The seed phrase extraction problem The core controversy is about what the service’s existence reveals about the device’s capabilities. Before Ledger Recover was announced, users operated under the assumption that the Secure Element was a one-way vault: keys go in, signatures come out, nothing else leaves. Ledger’s own marketing reinforced this understanding. A Ledger post on X had previously mentioned that firmware updates cannot extract the seed from the Secure Element. Ledger Recover proved this was incomplete. The firmware does have the capability to extract seed phrase data from the Secure Element and transmit it to external parties. Ledger’s former CEO and co-founder, Éric Larchevêque, later acknowledged that the previous statement was missing the caveat “as long as you are trusting Ledger.” The service launch revealed that Ledger firmware has the technical ability to extract and transmit seed phrase material if the user opts in. Tangem’s default setup never generates a seed phrase. Private keys are stored only in the Secure Element chips of your physical cards. There is no way of extracting keys from the card. This isn’t a policy choice that could be reversed; Tangem cannot update firmware on existing devices.
- The government subpoena admission In a podcast interview following the announcement, Ledger CEO Pascal Gauthier was asked directly whether governments could access users’ seed phrases through the Ledger Recover service. His response was unambiguous: the “only concern” is if the company is subpoenaed by a government, in which case the three custodians could be compelled to hand over the shards. Ledger is based in France (EU), headquartered in Paris. Coincover is registered in the United Kingdom, regulated by the FCA. EscrowTech is headquartered in Utah, US The encrypted seed phrase shards are now subject to three independent legal systems, each with its own surveillance and compulsion powers, and a subpoena in any one of them can compromise a shard. France operates under EU data protection (GDPR) but also has broad national security powers. The UK, post-Brexit, operates under its own data regime and the Investigatory Powers Act, which grants extensive government access to data held by UK companies. The US has the broadest toolkit: FBI National Security Letters, FISA court orders, and standard federal subpoenas, all of which can compel Utah-based EscrowTech to hand over materials, often with gag orders preventing disclosure to the user. The critical problem with Shamir Secret Sharing in a 2-of-3 scheme is that compromising any two of the three custodians reconstructs the full seed. So, a coordinated request between just two of these jurisdictions, say a US-UK mutual legal assistance treaty (MLAT) request, or a Five Eyes intelligence-sharing arrangement (the UK and US are both members), could theoretically reconstruct a user's keys without the user ever knowing. Even without coordination, the sheer surface area could be a problem. Three different governments, three different legal standards for compulsion, and three different breach notification regimes.
- Le problème du KYC
- Le problème de la confiance dans le code propriétaire
- Payer pour sa propre sécurité
- Un historique d’incidents de sécurité
- Comment Tangem évite ces risques
Points essentiels
Ledger Recover ajoute de la confiance, des risques et une exposition légale. Tangem supprime ces trois facteurs.
TL ; DR
Ledger Recover pourrait remettre en cause la promesse initiale du hardware wallet : les clés ne quittent jamais l’appareil.
It introduces remote seed extraction, cloud custody, identity verification, and legal exposure across multiple jurisdictions.
Tangem takes the opposite approach. No seed phrase is ever created. Keys never leave the Secure Element. Backup is purely physical via multiple cards held by the user—no servers, no custodians, no KYC, no subscriptions.
En mai 2023, Ledger a annoncé Ledger Recover, un service optionnel par abonnement (9,99 $/mois) permettant de créer une sauvegarde cloud de la phrase de récupération. Cette annonce a déclenché l’une des plus grandes polémiques de l’histoire des hardware wallets, des experts en sécurité mettant publiquement en doute les implications du service.
Ledger a depuis lancé le service et continue de le promouvoir. Comprendre ce que Ledger Recover fait réellement, et ce que cela implique pour la sécurité, est essentiel pour tout utilisateur comparant les hardware wallets.
What is Ledger Recover, and how does it work? When a user chooses to subscribe
Lorsque l’utilisateur souscrit à Ledger Recover, le firmware chiffre l’entropie de la phrase de récupération, la découpe en trois fragments chiffrés (shards) via le Shamir Secret Sharing, puis envoie chaque fragment à un tiers : Ledger, Coincover et EscrowTech.
To use Recover, the user has to pass an identity verification process using a government-issued ID and facial recognition. Two of the three custodians then send their shards back to the user’s Ledger device, where they are reassembled to reconstruct the seed phrase.
The service costs $9.99 monthly for other wallets. If the user ceases payments, access to the backup will eventually be revoked. To regain access after the subscription is suspended, the user must pay a 50 EUR administration fee along with any remaining balance.
The seed phrase extraction problem The core controversy is about what the service’s existence reveals about the device’s capabilities. Before Ledger Recover was announced, users operated under the assumption that the Secure Element was a one-way vault: keys go in, signatures come out, nothing else leaves. Ledger’s own marketing reinforced this understanding. A Ledger post on X had previously mentioned that firmware updates cannot extract the seed from the Secure Element. Ledger Recover proved this was incomplete. The firmware does have the capability to extract seed phrase data from the Secure Element and transmit it to external parties. Ledger’s former CEO and co-founder, Éric Larchevêque, later acknowledged that the previous statement was missing the caveat “as long as you are trusting Ledger.” The service launch revealed that Ledger firmware has the technical ability to extract and transmit seed phrase material if the user opts in. Tangem’s default setup never generates a seed phrase. Private keys are stored only in the Secure Element chips of your physical cards. There is no way of extracting keys from the card. This isn’t a policy choice that could be reversed; Tangem cannot update firmware on existing devices.
The government subpoena admission In a podcast interview following the announcement, Ledger CEO Pascal Gauthier was asked directly whether governments could access users’ seed phrases through the Ledger Recover service. His response was unambiguous: the “only concern” is if the company is subpoenaed by a government, in which case the three custodians could be compelled to hand over the shards. Ledger is based in France (EU), headquartered in Paris. Coincover is registered in the United Kingdom, regulated by the FCA. EscrowTech is headquartered in Utah, US The encrypted seed phrase shards are now subject to three independent legal systems, each with its own surveillance and compulsion powers, and a subpoena in any one of them can compromise a shard. France operates under EU data protection (GDPR) but also has broad national security powers. The UK, post-Brexit, operates under its own data regime and the Investigatory Powers Act, which grants extensive government access to data held by UK companies. The US has the broadest toolkit: FBI National Security Letters, FISA court orders, and standard federal subpoenas, all of which can compel Utah-based EscrowTech to hand over materials, often with gag orders preventing disclosure to the user. The critical problem with Shamir Secret Sharing in a 2-of-3 scheme is that compromising any two of the three custodians reconstructs the full seed. So, a coordinated request between just two of these jurisdictions, say a US-UK mutual legal assistance treaty (MLAT) request, or a Five Eyes intelligence-sharing arrangement (the UK and US are both members), could theoretically reconstruct a user's keys without the user ever knowing. Even without coordination, the sheer surface area could be a problem. Three different governments, three different legal standards for compulsion, and three different breach notification regimes.
« Criminals don’t use cryptos much. »
Gauthier a minimisé ce risque, affirmant que les gouvernements n’émettent ce type d’ordonnance que dans des affaires criminelles graves, et qu’à son avis, « criminals don’t use cryptos much ». Il reconnaît donc qu’un mécanisme légal existe pour permettre à des tiers d’accéder à la phrase de récupération des utilisateurs ayant opté pour Ledger Recover.
Lorsque l’animateur du podcast rappelle que l’IRS a déjà subpoenaed user information chez Coinbase (13 000 utilisateurs concernés), Gauthier répond que Ledger n’est pas une banque et ne serait donc pas soumise aux mêmes contraintes légales.
Il reste à voir si cette distinction tiendrait face à la pression de certaines agences gouvernementales.
Le problème du KYC
Ledger Recover impose une vérification d’identité avec pièce officielle et reconnaissance faciale. Ledger affirme qu’il s’agit d’une vérification d’identité, pas d’un KYC, mais la différence est ténue. En pratique, l’utilisateur relie son identité réelle à la sauvegarde de la phrase de récupération de son hardware wallet.
Le problème de la confiance dans le code propriétaire
Les utilisateurs ne peuvent pas vérifier indépendamment le code exécuté sur leur appareil. Impossible donc pour la communauté de s’assurer que l’extraction de la phrase de récupération ne peut être déclenchée que dans le cadre du service Recover et uniquement avec le consentement de l’utilisateur.
Ledger s’est engagé à ouvrir davantage son code, mais le firmware principal reste propriétaire. L’utilisateur doit donc faire confiance aux déclarations de Ledger sur ce que fait ou non son firmware.
Payer pour sa propre sécurité
Pour les utilisateurs de Nano X et Nano S Plus, Recover coûte 9,99 $ par mois. Si l’utilisateur arrête de payer, il perd l’accès à sa sauvegarde. Sur cinq ans, cela représente environ 600 $ de frais d’abonnement.
This is a recurring revenue model that takes the industry-standard seed phrase requirement shared by virtually every self-custody wallet and monetizes the anxiety around it.
Tangem’s backup model is physical (2–3 cards with the same private keys). When you set up a wallet, you can link two or three cards that securely generate and store the same private keys.
Chaque carte devient un accès indépendant au même wallet. Tant que vous gardez au moins une carte en sécurité, vous gardez le contrôle total de vos actifs. Il n’y a pas de phrase de récupération à écrire, pas de sauvegarde cloud, pas de récupération à distance.
Un historique d’incidents de sécurité
Évaluer la confiance à accorder à une entreprise qui propose l’extraction de phrase de récupération ou le stockage cloud nécessite d’examiner son historique de sécurité. Celui de Ledger révèle un schéma :
2020 : fuite de la base clients
En 2020, Ledger a subi une fuite de données qui a exposé les informations personnelles de plus de 270 000 clients (noms, adresses postales, e-mails, numéros de téléphone). Une base marketing d’environ un million d’e-mails a aussi été compromise.
La base a été publiée sur des forums de hacking et reste accessible publiquement, hantant encore aujourd’hui les victimes. Les conséquences sont graves et personnelles :
- campagnes de phishing ciblées se faisant passer pour Ledger
- menaces physiques et tentatives d’extorsion envers des utilisateurs dont l’adresse a fuité,
- et attaques SIM-swap utilisant les numéros divulgués.
Aucune clé privée n’a été compromise, mais l’incident montre que la sécurité opérationnelle de Ledger n’était pas suffisante pour les données clients.
2023 : attaque supply chain sur Connect Kit
En décembre 2023, des attaquants ont compromis le Connect Kit de Ledger, une bibliothèque JavaScript open source utilisée par de nombreuses applications décentralisées pour interagir avec les appareils Ledger.
L’attaquant a piégé un ancien employé de Ledger dont l’accès au gestionnaire npm n’avait pas été révoqué à son départ, puis a publié des versions malveillantes de la bibliothèque qui redirigeaient les fonds vers des wallets contrôlés par l’attaquant.
Le code malveillant est resté actif environ cinq heures et a entraîné le vol de plus de 600 000 $ sur plusieurs plateformes DeFi (Revoke.cash, SushiSwap, etc.). L’attaque a touché non seulement les utilisateurs Ledger mais aussi toute personne utilisant une DApp s’appuyant sur cette bibliothèque.
La cause principale : un échec opérationnel basique : les identifiants d’un ancien employé n’avaient pas été révoqués. Le post-mortem de Ledger reconnaît que la procédure de départ n’incluait pas l’accès npm.
2026 : fuite de données chez le prestataire Global-e
En janvier 2026, Ledger a confirmé que des données personnelles clients avaient été exposées via une faille chez son prestataire e-commerce Global-e, qui gère les commandes sur Ledger.com. Les données exposées incluaient noms, coordonnées, adresses de livraison et détails de commande, mais les wallets et clés privées sont restés sécurisés.
Comment Tangem évite ces risques
L’architecture de sécurité de Tangem a été conçue dès le départ pour minimiser la confiance nécessaire et éliminer les vecteurs d’attaque qui ont posé problème ailleurs.
La sauvegarde est tangible : elle vit dans les cartes que vous détenez, pas dans une infrastructure cloud répartie entre plusieurs sociétés. Ce modèle réduit les dépendances externes et garde le contrôle entre les mains du propriétaire du wallet.
En savoir plus sur la sauvegarde Tangem.
No customer database of seed phrases.
Tangem ne possède aucune base de fragments de clés liés à des identités, ni aucune relation de garde sur vos données cryptographiques. Il n’y a rien à saisir pour un gouvernement, rien à cibler pour un hacker.
Le modèle économique de Tangem repose sur la vente de matériel et les commissions sur les services intégrés comme Yield Mode, pas sur l’abonnement. Vous achetez les cartes, vous détenez les cartes, vous détenez vos clés.
Ledger asks you to trust.
Tangem removes the need for trust