# How to send and receive Grin with Ledger Live Desktop

**URL:** <https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021>\
**Category:** Uncategorized\
**Created:** [September 9, 2022, 11:19am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021 "2022-09-09T11:19:26Z")\
**Posts on this page:** 13\
**Page:** 2

<div class="post-metadata">

**Author:** ![NicolasFlamel](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/nicolasflamel/32/4912_2.png) [@NicolasFlamel](https://forum.grin.mw/u/NicolasFlamel)\
**Post date:** [May 20, 2023, 2:26am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/21 "2023-05-20T02:26:46Z")

</div>

There’s always some trust involved when using Ledger hardware wallets since their firmware is closed source, their hardware is closed source, the secure elements they use are closed source, etc.

Ledger’s new recovery service, [Ledger Recover](https://www.ledger.com/recover), involves exporting the seed from a hardware wallet and storing it in an encrypted, sharded form at several custodial companies. Ledger if facing criticism for this since they’ve previously stated that a firmware update couldn’t allow the seed to be exported from a hardware wallet.  
 ![Cannot Extract Private Keys](https://canada1.discourse-cdn.com/flex036/uploads/grin/original/2X/a/ae907b8ffa96866e1f36e13e7511dcaf5a36acc2.png)

I personally don’t recommend anyone use Ledger’s recovery service since it appears to use the same key to decrypt everyone’s seeds based on this comment.  
 ![Decryption Keys](https://canada1.discourse-cdn.com/flex036/uploads/grin/original/2X/f/ff64f6076112f9033a16cb941d876ac65598e63f.png)

---

<div class="post-metadata">

**Author:** ![tromp](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/tromp/32/22_2.png) [@tromp](https://forum.grin.mw/u/tromp)\
**Post date:** [May 20, 2023, 6:56am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/22 "2023-05-20T06:56:10Z")

</div>

It baffles me that a company like Ledger rolls out such a feature without even answering basic questions such as:

1. are the decryption keys unique to your ledger device? (I’ve seen reports elsewhere that the seed could be restored to _another_ Ledger device, which has completely different security implications).
2. are the decryption keys in my device known to Ledger?
3. can any firmware update leak those decryption keys (some reports suggest that the decryption keys are in the firmware update itself, which is the worst of all possible worlds) ?

I want to trust them, but they make it so hard…

---

<div class="post-metadata">

**Author:** ![Cobragrin](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@Cobragrin](https://forum.grin.mw/u/Cobragrin)\
**Post date:** [May 20, 2023, 2:25pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/23 "2023-05-20T14:25:49Z")

</div>

If it is a firm, subject to legal laws. Answer is simple. Always.

 ![FwkbdPgXoAEg1lj](https://canada1.discourse-cdn.com/flex036/uploads/grin/original/2X/3/39f6e71f8d2e3bb4f0b3b2a461090d63f0a75b86.jpeg)

---

<div class="post-metadata">

**Author:** ![AceKaplin](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/acekaplin/32/4958_2.png) [@AceKaplin](https://forum.grin.mw/u/AceKaplin)\
**Post date:** [May 20, 2023, 7:57pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/24 "2023-05-20T19:57:37Z")

</div>

Well there you have it @tromp . Shamir shares are not encrypted. An organization which can access the shares can access your funds.

Trying not to put on my tin foil hat, but the whole ledger thing feels like a law enforcement op to _at best_ catch tax evaders or criminals.

---

<div class="post-metadata">

**Author:** ![vegycslol](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/vegycslol/32/3340_2.png) [@vegycslol](https://forum.grin.mw/u/vegycslol)\
**Post date:** [May 20, 2023, 8:26pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/25 "2023-05-20T20:26:23Z")

</div>

> [@AceKaplin](#):
>
> Shamir shares are not encrypted

How do you know they’re not encrypted?

---

<div class="post-metadata">

**Author:** ![AceKaplin](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/acekaplin/32/4958_2.png) [@AceKaplin](https://forum.grin.mw/u/AceKaplin)\
**Post date:** [May 20, 2023, 8:45pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/26 "2023-05-20T20:45:37Z")

</div>

If they were encrypted, then the funds would not be accessible if the shares were revealed, e.g. in subpoena. The Ledger cofounder cited above says that shares accessed via subpoena would allow access to the funds. This is only possible if the shares are not encrypted.

---

<div class="post-metadata">

**Author:** ![vegycslol](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/vegycslol/32/3340_2.png) [@vegycslol](https://forum.grin.mw/u/vegycslol)\
**Post date:** [May 20, 2023, 9:04pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/27 "2023-05-20T21:04:24Z")

</div>

Are you sure they’re not encrypted by the ledger team and they would decrypt them if government demanded it?

---

<div class="post-metadata">

**Author:** ![AceKaplin](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/acekaplin/32/4958_2.png) [@AceKaplin](https://forum.grin.mw/u/AceKaplin)\
**Post date:** [May 21, 2023, 3:00am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/28 "2023-05-21T03:00:06Z")

</div>

That’s not what the Ledger founder said, but even so would that be any better? If your keys are stored on 3rd party servers and accessible by 3rd parties, the rest doesn’t really matter. At that point you’ve lost the whole reason of using a hardware wallet.

I’ve always said people were foolish for trusting Ledger (or other similar companies), but anyone that continues to use ledger now is just willfully ignorant. They’ve lost the plot.

---

<div class="post-metadata">

**Author:** ![ardocrat](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/ardocrat/32/5164_2.png) [@ardocrat](https://forum.grin.mw/u/ardocrat)\
**Post date:** [May 21, 2023, 6:37am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/29 "2023-05-21T06:37:14Z")

</div>

> [@AceKaplin](#):
>
> At that point you’ve lost the whole reason of using a hardware wallet.

The only solution here is to build our own HW from open components, I am personally waiting for powerful Arduino GIGA R1 ([https://docs.arduino.cc/hardware/giga-r1-wifi](https://docs.arduino.cc/hardware/giga-r1-wifi)) to start experimenting at this field.

---

<div class="post-metadata">

**Author:** ![vegycslol](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/vegycslol/32/3340_2.png) [@vegycslol](https://forum.grin.mw/u/vegycslol)\
**Post date:** [May 21, 2023, 7:07am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/30 "2023-05-21T07:07:18Z")

</div>

It’s better, but yes it’s horrible. I agree that key extraction should be hardware limited otherwise you always need to trust each software update.

---

<div class="post-metadata">

**Author:** ![ardocrat](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/ardocrat/32/5164_2.png) [@ardocrat](https://forum.grin.mw/u/ardocrat)\
**Post date:** [May 21, 2023, 7:25am UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/31 "2023-05-21T07:25:33Z")

</div>

> [@vegycslol](#):
>
> you always need to trust

Every hardware has firmware still. Don’t trust → verify.

---

<div class="post-metadata">

**Author:** ![AceKaplin](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.grin.mw/acekaplin/32/4958_2.png) [@AceKaplin](https://forum.grin.mw/u/AceKaplin)\
**Post date:** [May 21, 2023, 12:24pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/32 "2023-05-21T12:24:47Z")

</div>

This. And only open source firmware can be verified. Thus, don’t use closed source wallets.

---

<div class="post-metadata">

**Author:** ![serge](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@serge](https://forum.grin.mw/u/serge)\
**Post date:** [September 2, 2024, 4:46pm UTC](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021/33 "2024-09-02T16:46:01Z")

</div>

Guys, has there been any further progress?

Is the way described above to get Ledger working with Grin safe?

What happens when Ledger FW gets updated? Is the app still compatible with the latest FW version?

Also I read that GRIN app was being reviewed by ledger. Any further progress on that?

[Previous page](https://forum.grin.mw/t/how-to-send-and-receive-grin-with-ledger-live-desktop/10021.md?page=1)
