We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
#Ledger tutorial. How to Use Ledger as a Security Key for Crypto Exchanges
Your Ledger can do more than sign crypto transactions. You can install the dedicated Security Key app and use the device as a physical security key for accounts such as email, GitHub, password managers, and crypto exchanges.
In this guide, we’ll show you how to use Ledger as a security key for a crypto exchange, how the authentication process works, which Ledger models support USB and NFC, and when a dedicated FIDO2 security key may be the better choice.
Ledger Security Key: the essentials
What Ledger Security Key does on a crypto exchange
Once configured, Ledger is registered with the exchange as a physical authentication key. When you sign in or approve a sensitive action, the service may ask you to connect your Ledger, unlock it with your PIN, open the Security Key app, and approve the request on the device.
Even if someone gets hold of your account password, they will still need your physical Ledger whenever the service requires authentication with the registered security key.
One important limitation: support depends on the service. Ledger Security Key supports FIDO2/WebAuthn, but the app does not currently support discoverable credentials, also known as resident keys. As a result, some passkey workflows may not work when a website specifically requires that type of credential.
What Ledger Security Key is and what it protects
Security Key is installed on Ledger as a separate app through Ledger Wallet. It supports U2F and FIDO2/CTAP2, the standards used by browsers and online services through WebAuthn.
When you register Ledger with a website, the device creates cryptographic credentials. The private part stays protected inside the device’s Secure Element, while the service receives the public part. During authentication, the website sends a random challenge that your Ledger signs with the corresponding private key.
This has two important consequences.
1. A phishing site cannot use the correct credential
WebAuthn credentials are tied to a specific website. If you land on a phishing copy of an exchange hosted on a different domain, the authenticator cannot use the credential created for the legitimate domain.
This is one of the main advantages of FIDO2/WebAuthn over one-time codes. You can accidentally type a TOTP code into a phishing page, while cryptographic authentication also verifies the service domain.
2. Your Security Key credentials can be restored with Ledger
Security Key credentials are linked to your Secret Recovery Phrase. If you restore another compatible Ledger with the same 24 words and install the Security Key app, you can use the same credentials on websites where they were previously registered.
That makes recovery convenient, but it also creates an additional risk: the same seed phrase is effectively responsible for both your crypto keys and your Security Key credentials.
It is also important to understand what Security Key does not protect:
In other words, Security Key primarily protects access to your account and the actions a service secures with FIDO2/WebAuthn.
Ledger Security Key vs a dedicated FIDO2 key
Before setting anything up, it is worth deciding whether Ledger is actually the right tool for this job. A hardware wallet can work well as a Security Key, but a dedicated FIDO2 key has some advantages of its own.
Already own a Ledger? Security Key is a convenient way to add hardware-based authentication without buying another device.
Buying a device specifically for 2FA? A dedicated FIDO2 key is usually the more practical option. It is independent of your crypto seed, and you can choose a model based on the interfaces and protocols you actually need.
Want maximum separation between risks? A separate key also makes more sense. In that setup, compromising your Ledger Secret Recovery Phrase does not automatically compromise the second factor protecting your online accounts.
What to check before you start
Check these four things before setting up Security Key:
Update Ledger Wallet, Ledger OS, and Security Key. Use current software and firmware versions before starting the setup.
Check your browser and platform. Compatibility depends not only on the Ledger model, but also on the operating system, browser, and connection method.
Keep a backup sign-in method. Do not disable TOTP or another recovery method immediately after registering Ledger. First confirm that Security Key works on every device you normally use.
How to install Ledger Security Key
The Security Key app is installed through Ledger Wallet.
After installation, remember the key requirement: whenever you register or use the key, the Security Key app must be open on the Ledger itself.
If the device is sitting on the main menu or another app such as Bitcoin is open, the browser may not detect Ledger as a Security Key.
How to use Ledger as a security key on a crypto exchange
Menu names vary between exchanges, but the general Ledger Security Key setup process is almost always the same.
Now let’s look at the setup on specific exchanges.
Binance
On Binance, a physical key is added through the Passkeys section. Binance supports passkeys created with a USB security key and, on compatible mobile devices, over NFC.
On the web, go to Profile → Account → Security → Manage next to Passkeys → Add Passkey. Complete the existing security checks, choose the option for another phone, tablet, or security key, and then connect your Ledger.
There is another detail when removing keys. In the Binance web interface through Chrome, deleting a USB security key may require confirmation with that same key. In the Binance app, other existing 2FA methods may also be available for passkey removal.
Official guide: How to Create a Passkey for My Binance Account.
WhiteBIT
WhiteBIT supports passkeys as a separate two-factor authentication method and recommends using physical security keys where possible.
In the web interface, go to Account Settings → Security → Two-Factor Authentication → Edit → Manage Passkeys → Continue. Then register a new passkey using the authentication method you want.
You can register up to 5 passkeys on one account. WhiteBIT also allows passkeys and TOTP to confirm changes to each other: a passkey can approve TOTP changes, while TOTP can be used to manage passkeys.
Official guide: What is Passkey and how to enable it?
Bybit
Bybit supports FIDO2 USB security keys. Go to Account and Security → Passkeys → Add Passkey, complete the existing security verification, and choose the method you want to use for the new key.
If you are using Ledger over USB, choose the physical security key option in the system dialog, connect your Ledger, open Security Key, and approve the request.
Bybit allows up to 10 passkeys per account.
Official guide: How to Set Up and Manage Passkey on Bybit.
Other exchanges at a glance
Backup: what happens if you lose your Ledger
Recovery is one of the biggest advantages of using Ledger as a Security Key.
Because Security Key credentials can be restored from the same Secret Recovery Phrase, you can take another compatible Ledger, restore it with your 24 words, and reinstall the Security Key app.
The restored Ledger can then use the same credentials on websites where Security Key was previously registered. You do not need to register the replacement device again with every service.
With a typical standalone security key, backup works differently: you normally need to register a second physical key separately with every service in advance.
That recovery advantage does not replace a few basic precautions:
Limitations and common problems
“The browser can’t see my Ledger”
Check the device first. Ledger needs to be unlocked and the Security Key app must be open. Then retry the request in your browser.
“Security Key doesn’t work on my iPhone with Nano X”
The issue is not that Nano X lacks Bluetooth. The problem is that the Security Key app itself does not use Bluetooth. For a convenient NFC-based iPhone setup, use Ledger Nano Gen5, Flex, or Stax.
“Will I lose my registered logins after updating the app?”
With the current non-resident credentials, an app update should not mean losing access: the credentials can be restored from the same Secret Recovery Phrase. Resident keys would require a separate backup mechanism, and support for them is currently disabled in Security Key.
“I disabled my old TOTP right away”
Do not remove your backup method too quickly. Test Ledger on every device you plan to use first. Also keep exchange-specific rules in mind: fully disabling 2FA on WhiteBIT can trigger a 72-hour restriction, while certain passkey changes on OKX may result in a 24-hour restriction on withdrawals and P2P.
“I lost my Ledger and Binance requires a passkey”
If Must verify using passkey for important scenarios is enabled on Binance and you no longer have access to any registered passkey, normal sign-in may be unavailable. In that case, you will need to use Binance’s account recovery process.
“I forgot my PIN and the Ledger reset”
After three incorrect PIN attempts, Ledger resets to factory settings. If you still have the correct Secret Recovery Phrase, you can restore the device, reinstall Security Key, and regain access to the derived credentials.
Until the Ledger has been restored, however, you cannot use it as the registered physical security key. That is exactly why a backup access method should be configured in advance.
Who should use Ledger Security Key?
What to read next
If you want to go deeper into wallet and seed phrase security, these guides are a good next step:
Related Posts
#Tutorial. Recovery phrase is invalid: why your wallet won’t accept your seed phrase
You enter your recovery words, reach the last one, and instead of restoring the wallet, the device shows an error such as “Recovery phrase is invalid.” This does not automatically mean your funds are lost. It means the wallet cannot validate the phrase in the format it expects. The cause may be simple: a typo, …
#Ledger tutorial. Battery problem: Charging stopped
Ledger Nano X is not charging: if you see “Battery problem” or “Charging stopped” on the screen, it does not mean your coins are gone. Your keys and funds remain safe; the issue is related to the battery or the charging conditions of the device. Nano X is a Ledger model with a built-in 100 …
How to update the firmware of the Ledger Nano X
This guide walks you through how to update Ledger Nano X firmware to the latest version safely. At the time of writing, that’s firmware 2.1.0. Before you start, check the following: Let’s get started. Connecting to a PC 1) Connect your Ledger Nano X to your computer and unlock the device. You can use a …
#Safepal tutorial. SafePal S1 not detecting upgrade.bin: causes and fixes
SafePal S1 not detecting upgrade.bin? You downloaded the firmware, copied the file to the device and selected “Upgrade,” but the S1 says that it cannot find the firmware file. Or the update simply does not start. In most cases, this does not mean that the device is faulty or that the file is corrupted. The …