XE for Ledger
Read it on the device. Then sign.
An app for Ledger devices that signs XE payments and messages. The key stays on the device, which shows each request in full before you approve it.
In testing. Not in Ledger Live. Run on Ledger's emulator only, never on a real device. Use a device that holds nothing of value.
01Install
Install version 0.1.0
About ten minutes of typed commands. Your recovery phrase is never needed.
Nano X: cannot be sideloaded. Ledger allows only apps from Ledger Live on it. Stax: no build in 0.1.0.
Nano S Plus on macOS
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In Terminal. Needs Python 3 from python.org.
python3 -m venv xe-ledger source xe-ledger/bin/activate pip install ledgerblueDownload the install file for the Nano S Plus.
curl -O https://ledger.xe.marketized.io/releases/0.1.0/nanosplus/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
shasum -a 256 app-xe.apdufbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274Install.
python -m ledgerblue.runScript --targetId 0x33100004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
32a965947298af77d66bd2ab137f5a3fad74389f2ee1ee4957aded821d5b6687Confirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Nano S Plus on Linux
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In a terminal. The first line lets your user reach the device and asks for your password; replug the device after it.
wget -q -O - https://raw.githubusercontent.com/LedgerHQ/udev-rules/master/add_udev_rules.sh | sudo bash python3 -m venv xe-ledger source xe-ledger/bin/activate pip install ledgerblueDownload the install file for the Nano S Plus.
curl -O https://ledger.xe.marketized.io/releases/0.1.0/nanosplus/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
sha256sum app-xe.apdufbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274Install.
python -m ledgerblue.runScript --targetId 0x33100004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
32a965947298af77d66bd2ab137f5a3fad74389f2ee1ee4957aded821d5b6687Confirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Nano S Plus on Windows
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In PowerShell. Needs Python 3 from python.org, installed with "Add python.exe to PATH" ticked.
py -m venv xe-ledger xe-ledger\Scripts\Activate.ps1 pip install ledgerblueDownload the install file for the Nano S Plus.
curl.exe -O https://ledger.xe.marketized.io/releases/0.1.0/nanosplus/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
certutil -hashfile app-xe.apdu SHA256fbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274Install.
python -m ledgerblue.runScript --targetId 0x33100004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
32a965947298af77d66bd2ab137f5a3fad74389f2ee1ee4957aded821d5b6687Confirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Flex on macOS
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In Terminal. Needs Python 3 from python.org.
python3 -m venv xe-ledger source xe-ledger/bin/activate pip install ledgerblueDownload the install file for the Flex.
curl -O https://ledger.xe.marketized.io/releases/0.1.0/flex/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
shasum -a 256 app-xe.apdue649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646cInstall.
python -m ledgerblue.runScript --targetId 0x33300004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
280d667db866b08275567afda60f4c92ca2aed92290af8e7aa30450ad9ae7eaeConfirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Flex on Linux
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In a terminal. The first line lets your user reach the device and asks for your password; replug the device after it.
wget -q -O - https://raw.githubusercontent.com/LedgerHQ/udev-rules/master/add_udev_rules.sh | sudo bash python3 -m venv xe-ledger source xe-ledger/bin/activate pip install ledgerblueDownload the install file for the Flex.
curl -O https://ledger.xe.marketized.io/releases/0.1.0/flex/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
sha256sum app-xe.apdue649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646cInstall.
python -m ledgerblue.runScript --targetId 0x33300004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
280d667db866b08275567afda60f4c92ca2aed92290af8e7aa30450ad9ae7eaeConfirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Flex on Windows
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In PowerShell. Needs Python 3 from python.org, installed with "Add python.exe to PATH" ticked.
py -m venv xe-ledger xe-ledger\Scripts\Activate.ps1 pip install ledgerblueDownload the install file for the Flex.
curl.exe -O https://ledger.xe.marketized.io/releases/0.1.0/flex/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
certutil -hashfile app-xe.apdu SHA256e649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646cInstall.
python -m ledgerblue.runScript --targetId 0x33300004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
280d667db866b08275567afda60f4c92ca2aed92290af8e7aa30450ad9ae7eaeConfirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Nano Gen5 on macOS
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In Terminal. Needs Python 3 from python.org.
python3 -m venv xe-ledger source xe-ledger/bin/activate pip install ledgerblueDownload the install file for the Nano Gen5.
curl -O https://ledger.xe.marketized.io/releases/0.1.0/apex_p/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
shasum -a 256 app-xe.apdu70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8Install.
python -m ledgerblue.runScript --targetId 0x33400004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
99e54d53c8b0e431f72941be689779b43d4ee1e9cb5e8d8b38527a9d98ea6a89Confirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Nano Gen5 on Linux
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In a terminal. The first line lets your user reach the device and asks for your password; replug the device after it.
wget -q -O - https://raw.githubusercontent.com/LedgerHQ/udev-rules/master/add_udev_rules.sh | sudo bash python3 -m venv xe-ledger source xe-ledger/bin/activate pip install ledgerblueDownload the install file for the Nano Gen5.
curl -O https://ledger.xe.marketized.io/releases/0.1.0/apex_p/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
sha256sum app-xe.apdu70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8Install.
python -m ledgerblue.runScript --targetId 0x33400004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
99e54d53c8b0e431f72941be689779b43d4ee1e9cb5e8d8b38527a9d98ea6a89Confirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
Nano Gen5 on Windows
Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.
Install Ledger's tool. In PowerShell. Needs Python 3 from python.org, installed with "Add python.exe to PATH" ticked.
py -m venv xe-ledger xe-ledger\Scripts\Activate.ps1 pip install ledgerblueDownload the install file for the Nano Gen5.
curl.exe -O https://ledger.xe.marketized.io/releases/0.1.0/apex_p/app-xe.apduCheck it. This command must print the hash below it. If it does not, delete the file.
certutil -hashfile app-xe.apdu SHA25670f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8Install.
python -m ledgerblue.runScript --targetId 0x33400004 --fileName app-xe.apdu --apdu --scpThe device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.
Then it shows the app's identifier. It must be this, or reject:
99e54d53c8b0e431f72941be689779b43d4ee1e9cb5e8d8b38527a9d98ea6a89Confirm and enter your PIN.
Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.
02Reference
Reference
What you see when signingFour reviews, word for word from the app's tests.
A review is a title, one page per value, then the question. On a Nano you page with the right button and approve with both. On a touchscreen you swipe, then hold to sign. Addresses are shown in full, in eight groups.
Review transaction to send XETest network: XE here has no value
- From
- Account #0
- Amount
- 2.5 XE
- To
- 894d59e0 c55aea5a 5c6535b1 9b29a21a f0c4d3f7 67e827ec 102b6eb0 ebb29f39
- Memo
- "x402:ca04a86ee2cb3785"
- Pays
- x402 invoice ca04a86ee2cb3785
- Fees
- None
- Balance after
- 7.5 XE
- Network
- XE Sim - xe-sim-0001
Sign transaction to send XE?
Review transaction to receive XETest network: XE here has no value
- From
- de0d6432 c89794f3 e9532e1e dc0afcca 3b3a6dce 9d679a27 0fe05c76 ad2b611e
- Amount
- 2.5 XE
- Account
- Account #0
- Claims payment
- 264a6a60 a8c6c079 ce6309e1 7c4f441b a300b6bc 9e470bd2 e6bd2603 9ce3040f
- Balance after
- 12.5 XE
- Network
- XE Sim - xe-sim-0001
Sign transaction to receive XE?
Review message
- Account
- Account #0
- Address
- 9a9c3f26 644be432 4ac28a5f 72f19657 1ab039b5 1f9ca69c 8e1c1e52 3df0a4dd
- Message
- hello world
Sign message?
A sign-in to a site is titled "Review message to sign in" and adds two lines: Site, taken from the signed text, and Purpose, "Sign in to" that site, "Not a payment."
Warning, shown first
You would not control this account alone
After this change, other keys could change who controls this shared account, or you could not change it without them.
Continue or Reject
Review transaction to change signersTest network: XE here has no value
- Shared account
- a97dcf46 da33b022 97e83215 5107279f 76d8053c 21ec21d1 19ba24ed 9da26af4
- Signed with
- Your key (account #0)
- Signers after
- payments need weight 2 of 6, key changes 5
- Your keys
- 1 key, weight 1 of 6
- You alone can
- nothing
- Other keys together can
- pay and change keys
- Balance after
- 3 XE
- Network
- XE Sim - xe-sim-0001
Sign transaction to change signers?
- Memos are public. One with characters outside plain ASCII is shown as hexadecimal, labelled "Memo (hex)".
- "Balance after" comes from the wallet. If it is wrong the network rejects the block; the amount paid cannot differ from the one shown.
- A receive shows "From" and "Amount" only when the wallet hands over the payment for the device to check.
- A request that breaks the app's rules is refused before any screen appears.
What it cannot do yetTest networks and XE only, and a few cases it refuses.
- No main network: XE Sim and the XE testnet only. XE on them has no value.
- XE only. It refuses XUSD, leases and burns.
- It will not sign as another account's delegated key. It can grant such a key limits on your account, on XE Sim only, and revoke it.
- It will not change your representative, the account your voting weight follows.
- A passphrase attached to a PIN on the Ledger gives different XE accounts from the plain recovery phrase.
- A 24-word phrase from the XE command-line wallet gives different accounts when restored on a Ledger.
- A block longer than 4,096 bytes, such as a very large shared account's, is refused.
If something goes wrongThe install's error numbers and what to do about each.
| What you see | What to do |
|---|---|
| No device found | Unlock the device, close Ledger Live and any wallet page using it, and try a cable that carries data. |
Error 5515 | The device is locked. Enter your PIN. |
Error 6d00 or 6e00 | An app is open. Go back to the device's home screen. |
Error 511f | The build does not match the device's software. Update the device in Ledger Live. If it is up to date, this build is too old for it. |
Error 5120 | This model only takes apps from Ledger Live. That is the Nano X. |
Error 6a84 or 6a85 | The device is full. Remove an app. |
Error 6985 | You rejected it on the device. Run the command again. |
python or pip not found | In a new terminal window, run the "activate" line of step 2 again. |
| ledgerblue fails to install on Linux | sudo apt install libudev-dev libusb-1.0-0-dev python3-dev python3-venv, then repeat step 2. |
| The wallet cannot find the device | Use Chrome or Edge on a computer, and open the XE app on the device first. |
The numbers are the ones Ledger's own installer names. They come at the end of the terminal output.
Remove itOne command. Your keys are not affected.
With the device unlocked on its home screen, in the terminal from step 2. Installing again brings the same accounts back.
Nano S Plus
python -m ledgerblue.deleteApp --targetId 0x33100004 --appName XEFlex
python -m ledgerblue.deleteApp --targetId 0x33300004 --appName XENano Gen5
python -m ledgerblue.deleteApp --targetId 0x33400004 --appName XEEvery file and its hashEach version's files with their SHA-256.
The same list for scripts: /releases/manifest.json.
Version 0.1.0. Built 2026-10-10 from the 0.1.0 source. Made for Ledger OS API level 27. Stax is not offered: its code carries a path from the build machine.
Nano S Plus
- Install fileapp-xe.apdufbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274
- App identifierapp-xe.sha256a953c98377bf7134753a7d91f2a1956f621fe0094de8b882b8dd507bfe448da4
Flex
- Install fileapp-xe.apdue649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646c
- App identifierapp-xe.sha256d0f515e5f7fd5829cfd0ad79707b140edd2d34971b591b3c47902c27ab90dc44
Nano Gen5
- Install fileapp-xe.apdu70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8
- App identifierapp-xe.sha25665f18b2edee2ff18f4eb5b8c41e4e17acb6345dfdc3d350b447d89544c8d77e3
Status in fullNo audit, source not public yet, and the key path.
- Not reviewed by Ledger. You install it yourself with Ledger's developer tool, which is called sideloading.
- Emulator only. Every screen was checked on Ledger's emulator for each model. Nobody has run this build on a real device.
- The "not genuine" warning appears when you install the app and when you open it, because Ledger has not signed it. A malicious app would show the same warning, so check the hash and the identifier.
- No security audit.
- Source not public yet. It will be published with the first public release. Until then these files cannot be checked against it.
- Key path
m/44'/22597'/n', wherenis the account number. 22597 is provisional: XE has no registered coin type. - Same accounts as the XE MetaMask Snap from the same recovery phrase. Never type a Ledger's phrase into MetaMask.
- Ledger's developer tools call the Nano Gen5 "Apex P".