Two secrets protect a Ledger device. The PIN, entered on the hardware itself, defends against someone picking the device up; a few wrong attempts and it wipes. The 24-word recovery phrase is the wallet itself, and anyone who reads it owns the funds in any compatible software, forever. Neither secret is ever typed into Ledger Live.
The signing screen is the second pillar. Because Ledger Live runs on a general-purpose computer that can be compromised, the design simply assumes the computer might be hostile and pushes the final check onto hardware you can trust. Verify the recipient and the amount on the device, every single time, even when it feels tedious.
Where the model stops is authorization you grant willingly. A device will happily sign a token approval that drains a wallet weeks later, if you approve it. Ledger Live cannot know that a contract is malicious, which is why newer firmware and app releases work hard to decode transactions into readable terms instead of an opaque blob, and to flag the risky ones. Read what is displayed before you confirm.
The most productive attack against Ledger Live users is not technical at all. Fake emails, fake support agents, counterfeit downloads and rogue browser extensions all converge on the same request: enter your 24 words to restore, migrate, validate or secure your wallet. Ledger Live will never ask for a recovery phrase, and no legitimate support process ever will. A 2020 breach of the company's e-commerce customer database handed scammers a long list of names and addresses to work from, so the phishing has been persistent and sometimes unnervingly well informed.
Supply chain risk deserves naming too. Buy hardware from the manufacturer or an authorized reseller, never second hand, and let the device generate its own recovery phrase. A device that arrives with a phrase already printed on the card is a trap. Ledger Live runs a genuine-hardware check during onboarding, which helps, but a clean purchase path is still the first line of defense.
Finally, the optional recovery subscription. It is an opt-in paid service that keeps an encrypted, split backup of the seed and restores it after identity verification. Some owners see reasonable insurance, others reject it on principle. The point for this page is that it is a deliberate choice made inside Ledger Live, not something that happens by default.