Passphrase: Ledger’ın İleri Seviye Güvenlik Özelliği

| Özetle: |
| — The Ledger Passphrase is an advanced feature that adds a 25th word of your choosing of max 100 characters to your Secret Recovery Phrase. — Using a Ledger Passphrase creates an entirely different set of accounts on your Ledger™ signer , which cannot be accessed via the standard 24-word Secret Recovery Phrase alone. Store it offline, character for character. — Besides extra security, a passphrase can create decoy accounts, giving you a measure of plausible deniability if you are ever pressured to unlock your signer. — There are two options to set up your passphrase in Ledger: set it and attach it to a new pin or set a temporary passphrase.The Ledger Passphrase is an advanced feature that adds a 25th word of your choosing of max 100 characters to your secret recovery phrase. |
Ledger signers keep your private keys offline and require physical confirmation for every transaction, which reduces your exposure to remote attacks. But what if someone learns about your portfolio or confronts you in person?
This is where Ledger Passphrase comes in. The passphrase is an advanced security feature that takes security on your Ledger signer to a new level.
In essence, it adds an extra word of your own choosing to your already existing recovery phrase to unlock a separate set of accounts. Let’s take a closer look at how passphrases work, what they do, and some best practices for using one.
İşte Karşınızda Ledger Passphrase
Your 24-word Secret Recovery Phrase is the backup to all of your crypto assets. It is necessary that you store it securely and never expose it over a smartphone, computer or other device that can connect to the internet.
If someone manages to get a hold of your set of 24 words, they can steal your digital assets associated with that Secret Recovery Phrase. The Ledger Passphrase feature lets you covertly unlock a separate set of unconnected accounts.
This is an advanced feature that allows you to add an additional word to your recovery phrase. For this reason, it’s also commonly referred to as the 25th word.
Unlike the regular Secret Recovery Phrase generated during initial device setup, you get to choose the 25th word. There are no limits on which password you pick. . The only limitation is using a maximum of 100 characters. The passphrase is case-sensitive and can include numbers and symbols.
Setting a passphrase does not move your existing crypto. It opens a separate set of accounts with brand-new addresses, and those accounts start empty. Your original funds stay in your standard accounts, which anyone with your 24-word Secret Recovery Phrase and primary PIN can still reach. To place assets behind your passphrase, you have to send them to the addresses associated with the newly created accounts. Even an account with the same name, such as Ethereum, has a completely different address once a passphrase is active.
Ledger Passphrase Kullanımı: Temel Avantajlar
Firstly, setting a passphrase adds an additional security layer, which means that even if someone has your 24-word Secret Recovery Phrase they would not be aware of the separate accounts protected by the 25th word.
Someone would need both your 24 words and your Ledger Passphrase, the 25th word, to reach those segregated crypto assets.. Think of it like creating a decoy account. If they only have your 24 words, they can only access your regular accounts. This is why the accounts managed with a Ledger Passphrase are often called hidden accounts.
Not only does it create another layer, it also adds more randomness to your backup. Now, the standard 24-word Secret Recovery Phrase is already extremely random and highly secure because there are 115,792,089,237,316,195,423,570,985,008,687,907,853,269,984,665,640,564,039,457,584,007,913,129,639,936 (that’s 115.79 quattuquindecillion) possible combinations; that’s more than the number of stars in the observable universe!
This number is so big that it’s nearly impossible for two people to ever have the same recovery phrase by chance.
These words are, however, from a set list known as the BIP39 word list.
Now, with a 25th word, you push that already huge number of combinations even higher.
Bu, kombinasyonlara aynı zamanda bir insan ögesi de katar. 24 kelimelik bir diziye güvenmek yerine istediğiniz rastgele bir kelimeyi de bu diziye eklemiş olursunuz.
Although, only using a recovery phrase created by a Ledger signer is highly secure as well. Ledger signers generate your recovery phrase using a certified True Random Number Generator (TRNG) inside the Secure Element chip. A passphrase adds plausible deniability on top. Let us look at why that matters.
Makul reddedilebilirlik
Değerli olan herhangi bir şeyi, bir şekilde çalmaya çalışan insanlar her zaman olacaktır. Ne yazık ki kripto dünyasında bir miktar kripto sahibi olduğu bilinen kişilerin fiziksel soygun, adam kaçırma ve tehditlere maruz kaldığı nadiren de olsa görülüyor.
Ledger Passphrase, böyle bir durumda kripto paralarınız için sınırlı bir koruma sağlayabilir.
Plausible deniability is the ability to convincingly deny something, even when it is not the whole truth. With a passphrase tied to your device, you keep a way to stay in control if a situation turns tense.
With a passphrase, you can make someone believe they have full access to your crypto assets.
For example, someone could pressure you to hand over your recovery phrase or unlock your Ledger signer. With its usual setup, that only reveals your regular accounts. If you keep a small balance on your regular accounts while most of your crypto sits on hidden accounts, this can be convincing in a difficult moment.
For extra protection, you can use multiple hidden accounts with different passphrases. This helps if an attacker knows about the Ledger Passphrase feature.
The value of Passphrases was illustrated by the Coldcard vulnerability in July 2026 where a firmware bug had weakened how some devices generated seed phrases leading to significant user losses. In that scenario a user-generated 25th word could have mitigated the weakness of Secret Recovery Phrases. Read analysis of how the Coldcard incident happened from Ledger CTO, Charles Guillemet.
Ledger’ın Yeni Nesil Cihazlarında Passphrase Kullanımı
Compared to previous gen Ledger signers, using the passphrase feature on a Ledger Nano™ Gen 5, Ledger Flex™ or Ledger Stax™ offers distinct advantages due to their larger, more user-friendly Secure Touchscreens.
Bu büyük ekranlar sayesinde Passphrase girişleri arasında gezinmek ve bunları yönetmek daha kolaydır ve böylece Passphrase’inizi girerken veya belirlerken hata yapma riskiniz azalır.
Smaller screens can sometimes make entering complex passphrases a bit more cumbersome and prone to errors. The larger screens also enhance overall usability, allowing for clearer, more intuitive interactions and a smoother experience when managing multiple accounts or passphrases.
See this guide on How to set up a passphrase.
Ledger Cihazınızda Bir Passphrase Belirleme
Quite a few wallets allow for a passphrase, but some require you to enter it on your computer, which can expose it to online attacks.
Ledger ile, gizli bir hesabı etkinleştirmek için Passphrase’inizi doğrudan Ledger imzalayıcınızda girebilirsiniz. Bu da Passphrase’inizin yanlış kişilerin eline geçmesini engeller.
How to Set Up Advanced Ledger Passphrase | Official Step-by-Step Guide
Option 1: Set A Temporary Passphrase
You have two options for setting up a Passphrase with Ledger.
One way is to enter it manually on your device every time you want to access your hidden accounts; this is called the temporary passphrase.
With this option, the passphrase only stays active while your Ledger is powered on. Once the device turns off, it’ll return to accessing your regular accounts. To use your hidden accounts again, you’ll need to re-enter the temporary passphrase.
Suppose you’re traveling or using your Ledger in a shared environment, this is a good option to manage your assets if you’re looking for extra security on a temporary basis.
However, it’s essential to remember or securely back up your temporary passphrase because Ledger does not store it anywhere. If you lose or forget it, your hidden accounts become inaccessible.
Option 2: Set A Passphrase Connected To A Secondary PIN Code
Diğer seçenek ise seçtiğiniz bir passphrase’i ikincil bir PIN koduna bağlamaktır.
When you choose this option, you first create a passphrase directly on your Ledger signer. Next, you select a secondary PIN code for your Ledger signer. After this, each time you turn on your device, you can choose between entering your normal PIN code or your secondary PIN code.
If you enter your secondary PIN code, you’ll gain access to your passphrase-protected accounts.
Örneğin:
- Normal PIN kodu: 1653 → Standart hesaplar
- İkincil PIN kodu: 8530 → Gizli hesaplar
Ledger imzalayıcınızda Passphrase kullanımı hakkında daha fazla bilgi edinmek için bu makaleyi de okuyabilirsiniz.
Ledger Passphrase için En İyi Uygulamalar
A passphrase is considered an advanced feature for a few simple reasons. Firstly, you must remember your passphrase perfectly, and your secondary pin if you choose that setup. Mixing up just a single character would mean losing access to the separate set of accounts. Even changing one character from uppercase to lowercase will do this.
If you don’t remember your passphrase character for character, you cannot gain access to the crypto you managed with it. As such, it’s key that you enter it correctly the first time you set it up and remember it perfectly. And if you use a secondary pin, after three incorrect attempts your device will be reset, requiring you to recover your accounts from a backup of your Secret Recovery Phrase.

Passphrase Karmaşıklığı
Tüm Passphrase’lerin aynı derecede güvenli olmadığını unutmayın. Daha uzun ve daha karmaşık Passphrase’ler (ör. bir dizi rakam, harf veya sembolün kombinasyonu), hesaplarınız için daha güçlü bir koruma sağlar.
Ledger Passphrase’iniz 100 karaktere kadar dilediğiniz uzunlukta olabilir ve büyük harfle yazılmış karakterler, rakamlar ve/veya işaretler kullanabilirsiniz.
İdeal olarak Ledger Passphrase’e, mümkün olduğunca karmaşık bir hâle getirmeye çalıştığınız ve bir kelimeyi doğrudan kullanmadığınız bir parola gibi davranın.
Örneğin:
- Passphrase 1: password → Very insecure due to short length, no random characters or caps.
- Passphrase 2: IReallyLikeMyBitcoins → A bit more secure: longer and uses caps, but still uses common English words and no numbers or signs.
- Passphrase 3: H05!xp4e2i6dAnV?esRjfap953nxZprsi495nAASF5n,!f01.?d → Even more secure: lengthy, wide mix of caps, numbers and signs and does not use actual words.
Bunların arasında Passphrase 3 en güvenlisi olarak kabul edilse de hatırlaması çok zordur. En iyi uygulama olarak aynı düzeyde karmaşık ve hatırlayabileceğiniz bir Passphrase kullanmanız önerilir.
You could make it a form of cryptographic puzzle. For example: Iret3LSDtUBgm! concerns the first letters and special characters/numbers of the sentence “I really enjoy the 3 Ledger Stax Devices that Uncle Bob gave me!”.
Your Passphrase is sensitive information. As such, we recommend treating it with the same kind of care as you would treat your Recovery Phrase:
- Passphrase’inizi hiç kimseyle asla paylaşmayın; Ledger bunu yapmanızı hiçbir zaman istemeyecektir
- Passphrase’inizi asla bir bilgisayara, akıllı telefona veya internete bağlı başka bir cihaza girmeyin
- Take extreme care when writing it down, using clear non-cursive characters
Bu tür en iyi uygulamalar hakkında daha fazla bilgi edinmek için buraya bakabilirsiniz
Passphrase Hakkında Sıkça Sorulan Sorular
Parola ile Passphrase arasındaki fark nedir?
Parola kısadır ve çoğunlukla tek bir hesap için kullanılırken Passphrase ise daha uzun ve daha karmaşıktır; karakterler, rakamlar ve semboller içerdiği için ve uzunluğu sayesinde daha yüksek bir güvenlik sunar.
Ledger Passphrase’imi unutursam ne olur?
If you forget your passphrase, access to the associated hidden wallet is permanently lost, as Ledger does not store or back up passphrases. Store your passphrase securely and make sure you can recall it accurately.
Mevcut bir Ledger cihazına Passphrase ekleyebilir miyim?
Yes, you can add a passphrase to an already set-up Ledger signer. This will create a new set of accounts linked to the passphrase, separate from your original accounts. Store the new passphrase securely, as it cannot be recovered if lost.
Passphrase’im tahmin edilebilir veya kırılabilir mi?
A passphrase is much harder to crack than a regular password because of its length and complexity.
Dönüşüm: Donanım Cüzdandan İmzalayıcıya
Kripto cesur bir deney olarak başlamış olabilir, ancak teknolojinin ve kullanıcı deneyiminin hızla gelişmesiyle benimsenmesi arttı. Bununla birlikte, kriptoyu tanımlamak için kullanılan dil, hâlâ emekleme döneminde takılıp kalmış durumda.
Cihazlarımıza “donanım cüzdan” adını vererek, güvenli donanımın rolünü yanlış adlandırmış ve yazılımın (Ledger Live) rolünü belirsizleştirmiş olduk. Bu süreçte geride kalan kullanıcılar oldu.
İnsanlar şuna inanıyordu:
- Değerin cihazın içinde saklandığına (saklanmıyor).
- Cihazın kaybolması hâlinde varlıkların kaybedildiğine (kaybedilmiyor).
- Cihazın tek başına kullanıldığına (kullanılmıyor).
- 24 kelimenin yalnızca teknoloji tutkunu kullanıcıların kaldırabileceği bir yük olduğuna (artık doğru değil).
Bunlar yanlış anlamalardan daha fazlasıdır. Bunlar benimsenmeyi engelleyen unsurlardır. Dolayısıyla da Ledger olarak, şeffaf olmanın çok önemli olduğuna inanıyoruz. Bu, benimsenmenin bir sonraki aşamasıdır.
Ürünlerimiz hakkında konuşma şeklimizi değiştiriyoruz. Bu şekilde, insanların dijital mülkiyeti anlama biçimlerini değiştiriyoruz.
Donanım cüzdanlar → imzalayıcılar
Ledger cihazları değer depolamaz. İşlemleri imzalarlar. Niyeti ispat ederler. Kimliği doğrularlar. Bunlar birer kasa değil; kim olduğunuz ile çevrim içi yaptıklarınız arasında güvenli bir köprüdür. Ledger imzalayıcılar sadece anahtarlarınızı tutmaz. Sizi kendinize güvenmeye teşvik eder.
Onlara artık imzalayıcılar diyoruz, çünkü gerçekten de öyleler.
Yapay Zekanın her geçen gün daha da geliştiği bir dünyada, insan olduğunu kanıtlamak her zamankinden daha fazla önem taşır. Bir imzalayıcı, bir güvenlik cihazından fazlasıdır; o, sizin kriptografik kimlik kanıtınızdır. Başka kimseye bel bağlamadan dijital hayatınıza sahip olmak, onu yetkilendirmek ve korumak için güvenli bir temel oluşturur. Bir işlemin gönderilmesinden bir sözleşmenin imzalanmasına veya kimlik bilgilerinizin doğrulanmasına kadar, imzalayıcınız yalnızca sizin dijital onay verebilmenizi sağlar; bu sizin dijital kimlik ispatınızdır. İmzalayıcı ve Ledger Wallet birlikte, dijital mülkiyetin nasıl göründüğünü yeniden tanımlıyor: net, güvenli ve tavizsiz.