Market Cap: $2.2274T 1.22%
Volume(24h): $43.1719B 13.79%
Fear & Greed Index:

39 - Fear

  • Market Cap: $2.2274T 1.22%
  • Volume(24h): $43.1719B 13.79%
  • Fear & Greed Index:
  • Market Cap: $2.2274T 1.22%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top Cryptospedia

Select Language

Select Language

Select Currency

Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos

How to set up a passphrase-protected hidden wallet on Ledger?

Ledger’s passphrase feature creates isolated wallets via BIP-39’s PBKDF2 derivation—identical seeds + different passphrases yield entirely distinct, non-overlapping address spaces.

May 30, 2026 at 03:40 pm

Passphrase Setup Mechanics

1. Power on your Ledger device and navigate to Settings > Security > Passphrase.

2. Select “Set up passphrase” at the far right of the screen.

3. You will be prompted to choose between two modes: “Attach to PIN” or “Separate from PIN”.

4. Choosing “Attach to PIN” stores the passphrase internally alongside a user-defined PIN; entering that PIN unlocks the attached wallet instantly.

5. Selecting “Separate from PIN” requires manual entry of the passphrase each time before accessing the hidden wallet—no PIN shortcut is involved.

Security Implications of Passphrase Modes

1. The “Attach to PIN” option does not increase cryptographic security — it merely adds convenience through PIN-triggered access.

2. A hidden wallet secured with “Separate from PIN” remains fully isolated unless the exact 25th word sequence is entered during boot.

3. Devices configured with “Attach to PIN” may expose metadata leakage if physically compromised, as the presence of an attached passphrase can be inferred.

4. No firmware-level encryption differentiates between standard and passphrase-protected wallets—the isolation relies entirely on derivation path obfuscation.

5. Ledger’s BIP-39 implementation treats the passphrase as an additional input to the PBKDF2 key-stretching function, meaning even identical 24-word seeds yield completely distinct master keys when combined with different passphrases.

Derivation Path Behavior

1. Standard wallets use m/44'/0'/0' for Bitcoin by default.

2. A passphrase-activated wallet derives addresses from m/44'/0'/0' but with the seed recalculated using SHA512(seed_bytes || passphrase).

3. This results in a mathematically unrelated address space—no overlap exists between addresses generated with and without the passphrase.

4. Each unique passphrase creates a new, independent wallet universe—even one character difference yields zero shared history or balance visibility.

5. Ledger Live does not auto-detect passphrase wallets; users must manually toggle “Show passphrase wallets” in Settings > Accounts to view them.

Recovery and Access Protocol

1. If the device is lost or damaged, recovery requires both the original 24-word recovery phrase and the exact passphrase used during setup.

2. Typing the wrong passphrase—even with correct capitalization and spacing—produces a valid but empty wallet with no transaction history.

3. Ledger devices do not store or cache passphrase attempts; brute-force resistance depends solely on passphrase entropy and human memory discipline.

4. During initialization, Ledger does not validate passphrase strength—users may enter “a”, “123”, or “password”, all of which generate functional wallets.

5. The device displays no visual indicator confirming whether a passphrase was entered correctly until the home screen appears with account balances.

Frequently Asked Questions

Q: Can I use the same passphrase across multiple Ledger devices?A: Yes—but doing so eliminates compartmentalization benefits. Identical seed + identical passphrase yields identical keys across devices.

Q: Does Ledger Live encrypt or transmit my passphrase when syncing accounts?A: No. Ledger Live never receives, stores, or transmits the passphrase. It only displays balances after the device itself performs on-device derivation and signs requests.

Q: What happens if I forget my passphrase but remember my 24 words?A: All assets in the passphrase-protected wallet become irretrievable. Ledger cannot reverse the PBKDF2 derivation or assist with passphrase recovery.

Q: Is there a maximum length for a Ledger passphrase?A: No hard limit exists, but firmware imposes a practical cap of 100 Unicode characters. Excess characters beyond that are truncated silently during hashing.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Related knowledge

See all articles

User not found or password invalid

Your input is correct