Passphrase: Ledger’s Advanced Security Feature

| KEY TAKEAWAYS: |
| — The Ledger Passphrase is an advanced feature that adds a 25th word of your choosing of max 100 characters to your Secret Recovery Phrase. — Using a Ledger Passphrase creates an entirely different set of accounts on your Ledger™ signer , which cannot be accessed via the standard 24-word Secret Recovery Phrase alone. Store it offline, character for character. — Besides extra security, a passphrase can create decoy accounts, giving you a measure of plausible deniability if you are ever pressured to unlock your signer. — There are two options to set up your passphrase in Ledger: set it and attach it to a new pin or set a temporary passphrase. |
Ledger signers keep your private keys offline and require physical confirmation for every transaction, which reduces your exposure to remote attacks. But what if someone learns about your portfolio or confronts you in person?
This is where Ledger Passphrase comes in. The passphrase is an advanced security feature that takes security on your Ledger signer to a new level.
In essence, it adds extra security to your digital asset by adding a word of your own choosing to your already existing recovery phrase that unlocks a separate set of accounts. Let’s take a closer look at how passphrases work, what they do, and some best practices for using one.
Introducing Ledger Passphrase
Your 24-word Secret Recovery Phrase is the backup to all of your crypto assets. It is necessary that you store it securely and never expose it over a smartphone, computer or other device that can connect to the internet.
If someone manages to get a hold of your set of 24 words, they can steal your digital assets associated with that Secret Recovery Phrase. The Ledger Passphrase feature lets you covertly unlock a separate set of unconnected accounts.
This is an advanced feature that allows you to add an additional word to your recovery phrase. For this reason, it’s also commonly referred to as the 25th word.
Unlike the regular Secret Recovery Phrase generated during initial device setup, you get to choose the 25th word. There are no limits on which password you pick. The only limitation is using a maximum of 100 characters. The passphrase is case-sensitive and can include numbers and symbols. The longer and more complex the passphrase, the more secure it is, but be extra careful in making the offline record.
Setting a passphrase does not move your existing crypto. It opens a separate set of accounts with brand-new addresses, and those accounts start empty. Your original funds stay in your standard accounts, which anyone with your 24-word Secret Recovery Phrase and primary PIN can still reach. To place assets behind your passphrase, you have to send them to the addresses associated with the newly created accounts. Even an account with the same name, such as Ethereum, has a completely different address once a passphrase is active.
Using a Ledger Passphrase: Key Advantages
Firstly, setting a passphrase adds an additional security layer, which means that even if someone has your 24-word Secret Recovery Phrase they would not be aware of the separate accounts protected by the 25th word.
Someone would need both your 24 words and your Ledger Passphrase, the 25th word, to reach those segregated crypto assets.. Think of it like creating a decoy account. If they only have your 24 words, they can only access your regular accounts. This is why the accounts managed with a Ledger Passphrase are often called hidden accounts.
Not only does it create another layer, it also adds more randomness to your backup. Now, the standard 24-word Secret Recovery Phrase is already extremely random and highly secure because there are 115,792,089,237,316,195,423,570,985,008,687,907,853,269,984,665,640,564,039,457,584,007,913,129,639,936 (that’s 115.79 quattuquindecillion) possible combinations; that’s more than the number of stars in the observable universe!
This number is so big that it’s nearly impossible for two people to ever have the same recovery phrase by chance.
These words are, however, from a set list known as the BIP39 word list.
Now, with a 25th word, you push that already huge number of combinations even higher.
Also this introduces a human element to the mix as well. Rather than relying on a set of 24 words, you are adding a random word of your choice.
Although, only using a recovery phrase created by a Ledger signer is highly secure as well. Ledger signers generate your recovery phrase using a certified True Random Number Generator (TRNG) inside the Secure Element chip. A passphrase adds plausible deniability on top. Let us look at why that matters.
Plausible Deniability
Much like with anything of value, there will always be people trying to steal it by any means possible. Unfortunately in the world of crypto, we have seen rare occasions where individuals known to possess wealth in crypto to be the target of physical robbery, kidnapping, and threats.
The Ledger Passphrase could offer a limited amount of protection for your cryptocurrencies in such an event.
Plausible deniability is the ability to convincingly deny something, even when it is not the whole truth. With a passphrase tied to your device, you keep a way to stay in control if a situation turns tense.
With a passphrase, you can make someone believe they have full access to your crypto assets.
For example, someone could pressure you to hand over your recovery phrase or unlock your Ledger signer. With its usual setup, that only reveals your regular accounts. If you keep a small balance on your regular accounts while most of your crypto sits on hidden accounts, this can be convincing in a difficult moment.
For extra protection, you can use multiple hidden accounts with different passphrases. This helps if an attacker knows about the Ledger Passphrase feature.
The value of passphrases was illustrated by the Coldcard vulnerability in July 2026 where a firmware bug had weakened how some devices generated seed phrases leading to significant user losses. In that scenario a strong user-generated 25th word might have mitigated the weakness of Secret Recovery Phrases. Read analysis of how the Coldcard incident happened from Ledger CTO, Charles Guillemet.
Using Passphrases on Ledger’s Next-Gen Devices
Compared to previous gen Ledger signers, using the passphrase feature on a Ledger Nano™ Gen 5, Ledger Flex™ or Ledger Stax™ offers distinct advantages due to their larger, more user-friendly Secure Touchscreens.
These bigger displays make it easier to navigate and manage passphrase entries, reducing the risk of mistakes when entering or setting up your passphrase.
Smaller screens can sometimes make entering complex passphrases a bit more cumbersome and prone to errors. The larger screens also enhance overall usability, allowing for clearer, more intuitive interactions and a smoother experience when managing multiple accounts or passphrases.
See this guide on How to set up a passphrase.
Setting Up A Passphrase on Your Ledger Device
Quite a few wallets allow for a passphrase, but some require you to enter it on your computer, which can expose it to online attacks.
With Ledger, you can enter your passphrase directly on your Ledger signer to enable a hidden account. This would prevent your passphrase from falling into the wrong hands.
How to Set Up Advanced Ledger Passphrase | Official Step-by-Step Guide
Option 1: Set A Temporary Passphrase
You have two options for setting up a Passphrase with Ledger.
One way is to enter it manually on your device every time you want to access your hidden accounts; this is called the temporary passphrase.
With this option, the passphrase only stays active while your Ledger is powered on. Once the device turns off, it’ll return to accessing your regular accounts. To use your hidden accounts again, you’ll need to re-enter the temporary passphrase.
Suppose you’re traveling or using your Ledger in a shared environment, this is a good option to manage your assets if you’re looking for extra security on a temporary basis.
However, it’s essential to remember or securely back up your temporary passphrase because Ledger does not store it anywhere. If you lose or forget it, your hidden accounts become inaccessible.
Option 2: Set A Passphrase Connected To A Secondary PIN Code
Another option is to link a passphrase of your choosing to a secondary PIN code.
When you choose this option, you first create a passphrase directly on your Ledger signer. Next, you select a secondary PIN code for your Ledger signer. After this, each time you turn on your device, you can choose between entering your normal PIN code or your secondary PIN code.
If you enter your secondary PIN code, you’ll gain access to your passphrase-protected accounts.
For example:
- Regular PIN code: 1653 → Normal accounts
- Secondary PIN code: 8530 → Hidden accounts
You can read more about using a Passphrase for your Ledger signer in this article as well.
Best Practices for Ledger Passphrase
A passphrase is considered an advanced feature for a few simple reasons. Firstly, you must remember your passphrase perfectly, and your secondary pin if you choose that setup. Mixing up just a single character would mean losing access to the separate set of accounts. Even changing one character from uppercase to lowercase will do this.
If you don’t remember your passphrase character for character, you cannot gain access to the crypto you managed with it. As such, it’s key that you enter it correctly the first time you set it up and remember it perfectly. And if you use a secondary pin, after three incorrect attempts your device will be reset, requiring you to recover your accounts from a backup of your Secret Recovery Phrase.

Passphrase Complexity
Remember, not all passphrases are equally secure. Longer, more complex passphrases (like those that mix strings of numbers, letters, or symbols) give you stronger protection for your accounts.
Your Ledger Passphrase can be as long as 100 characters and you can choose whether you want to use capitalized characters, numbers and/or signs. But remember, you should only keep an offline record, so noting every character of your Passphrase correctly is of the utmost importance.
Ideally, treat it like a password where you try to make it as complex as possible and not use words directly.
For example:
- Passphrase 1: password → Very insecure due to short length, no random characters or caps.
- Passphrase 2: IReallyLikeMyBitcoins → A bit more secure: longer and uses caps, but still uses common English words and no numbers or signs.
- Passphrase 3: H05!xp4e2i6dAnV?esRjfap953nxZprsi495nAASF5n,!f01.?d → Even more secure: lengthy, wide mix of caps, numbers and signs and does not use actual words.
While Passphrase 3 can be seen as the most secure of the bunch, it’s also extremely hard to remember. For best practice, it is recommended to use a passphrase that is equally complex and memorable to you.
You could make it a form of cryptographic puzzle. For example: Iret3LSDtUBgm! concerns the first letters and special characters/numbers of the sentence “I really enjoy the 3 Ledger Stax Devices that Uncle Bob gave me!”.
Your Passphrase is sensitive information. As such, we recommend treating it with the same kind of care as you would treat your Recovery Phrase:
- Never share your Passphrase with anyone, Ledger will never ask for this
- Never enter your Passphrase on a computer, smartphone, or other internet-connected device
- Take extreme care when writing it down, using clear non-cursive characters
You can read more on these best practices here.
Frequently Asked Questions About Passphrase
What’s the difference between a password and a passphrase?
A password is short and often used for single accounts, while a passphrase is longer and more complex, offering better security due to its length and variation of characters, numbers, and symbols.
What happens if I forget my Ledger Passphrase?
If you forget your passphrase, access to the associated hidden wallet is permanently lost, as Ledger does not store or back up passphrases. Store your passphrase securely and make sure you can recall it accurately.
Can I add a passphrase to an existing Ledger device?
Yes, you can add a passphrase to an already set-up Ledger signer. This will create a new set of accounts linked to the passphrase, separate from your original accounts. Store the new passphrase securely, as it cannot be recovered if lost.
Can my passphrase be guessed or cracked?
A passphrase is much harder to crack than a regular password because of its length and complexity.
The Shift: From Hardware Wallet to signer
Crypto may have begun as a bold experiment, but adoption has grown as the technology and user experience have rapidly evolved; the language used to describe it, has however, stayed stuck in its infancy.
We called our devices “hardware wallets,” mislabelling the role of secure hardware, and obfuscating the role of software (Ledger Live). Along the way, users were left behind.
People believed:
- That value was stored on the device (it isn’t).
- That if you lose the device, you lose your assets (you don’t).
- That the device itself was the endgame (it’s not).
- That those 24 words were a burden only tech-savvy users could manage (not true anymore).
These are more than misconceptions. They are adoption blockers. So at Ledger, we believe that clarity is essential for the next stage of adoption
We’re changing how we speak about our products. And by doing so, we’re changing how people understand digital ownership itself.
Hardware wallets → signers
Ledger devices don’t store value. They sign transactions. They prove intent. They verify identity. They’re not vaults, they’re the secure bridge between who you are and what you do online. They don’t just hold keys. They empower you to trust yourself.
We call them signers now, because that’s what they truly are.
In a world where AI grows more powerful every day, proof of humanity matters more than ever. A signer is more than a security device, it’s your cryptographic proof of you. It gives you a secure foundation to own, authorize, and protect your digital life without relying on anyone else. From sending a transaction to signing a contract or verifying your credentials, your signer ensures you, and only, can provide digital consent – proof of you.Together, signer and Ledger Wallet redefine what digital ownership looks like, clear, secure, and free from compromise.