Ledger app In testing
Ledger app

XE for Ledger

Read it on the device. Then sign.

An app for Ledger devices that signs XE payments and messages. The key stays on the device, which shows each request in full before you approve it.

In testing. Not in Ledger Live. Run on Ledger's emulator only, never on a real device. Use a device that holds nothing of value.

Install version 0.1.0

About ten minutes of typed commands. Your recovery phrase is never needed.

Nano X: cannot be sideloaded. Ledger allows only apps from Ledger Live on it. Stax: no build in 0.1.0.

Nano S Plus on macOS
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In Terminal. Needs Python 3 from python.org.

    python3 -m venv xe-ledger
    source xe-ledger/bin/activate
    pip install ledgerblue
  3. Download the install file for the Nano S Plus.

    curl -O https://ledger.xe.marketized.io/releases/0.1.0/nanosplus/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    shasum -a 256 app-xe.apdu
    fbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33100004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    32a965947298af77d66bd2ab137f5a3fad74389f2ee1ee4957aded821d5b6687

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Nano S Plus on Linux
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In a terminal. The first line lets your user reach the device and asks for your password; replug the device after it.

    wget -q -O - https://raw.githubusercontent.com/LedgerHQ/udev-rules/master/add_udev_rules.sh | sudo bash
    python3 -m venv xe-ledger
    source xe-ledger/bin/activate
    pip install ledgerblue
  3. Download the install file for the Nano S Plus.

    curl -O https://ledger.xe.marketized.io/releases/0.1.0/nanosplus/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    sha256sum app-xe.apdu
    fbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33100004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    32a965947298af77d66bd2ab137f5a3fad74389f2ee1ee4957aded821d5b6687

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Nano S Plus on Windows
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In PowerShell. Needs Python 3 from python.org, installed with "Add python.exe to PATH" ticked.

    py -m venv xe-ledger
    xe-ledger\Scripts\Activate.ps1
    pip install ledgerblue
  3. Download the install file for the Nano S Plus.

    curl.exe -O https://ledger.xe.marketized.io/releases/0.1.0/nanosplus/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    certutil -hashfile app-xe.apdu SHA256
    fbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33100004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    32a965947298af77d66bd2ab137f5a3fad74389f2ee1ee4957aded821d5b6687

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Flex on macOS
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In Terminal. Needs Python 3 from python.org.

    python3 -m venv xe-ledger
    source xe-ledger/bin/activate
    pip install ledgerblue
  3. Download the install file for the Flex.

    curl -O https://ledger.xe.marketized.io/releases/0.1.0/flex/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    shasum -a 256 app-xe.apdu
    e649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646c
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33300004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    280d667db866b08275567afda60f4c92ca2aed92290af8e7aa30450ad9ae7eae

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Flex on Linux
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In a terminal. The first line lets your user reach the device and asks for your password; replug the device after it.

    wget -q -O - https://raw.githubusercontent.com/LedgerHQ/udev-rules/master/add_udev_rules.sh | sudo bash
    python3 -m venv xe-ledger
    source xe-ledger/bin/activate
    pip install ledgerblue
  3. Download the install file for the Flex.

    curl -O https://ledger.xe.marketized.io/releases/0.1.0/flex/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    sha256sum app-xe.apdu
    e649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646c
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33300004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    280d667db866b08275567afda60f4c92ca2aed92290af8e7aa30450ad9ae7eae

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Flex on Windows
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In PowerShell. Needs Python 3 from python.org, installed with "Add python.exe to PATH" ticked.

    py -m venv xe-ledger
    xe-ledger\Scripts\Activate.ps1
    pip install ledgerblue
  3. Download the install file for the Flex.

    curl.exe -O https://ledger.xe.marketized.io/releases/0.1.0/flex/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    certutil -hashfile app-xe.apdu SHA256
    e649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646c
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33300004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    280d667db866b08275567afda60f4c92ca2aed92290af8e7aa30450ad9ae7eae

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Nano Gen5 on macOS
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In Terminal. Needs Python 3 from python.org.

    python3 -m venv xe-ledger
    source xe-ledger/bin/activate
    pip install ledgerblue
  3. Download the install file for the Nano Gen5.

    curl -O https://ledger.xe.marketized.io/releases/0.1.0/apex_p/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    shasum -a 256 app-xe.apdu
    70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33400004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    99e54d53c8b0e431f72941be689779b43d4ee1e9cb5e8d8b38527a9d98ea6a89

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Nano Gen5 on Linux
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In a terminal. The first line lets your user reach the device and asks for your password; replug the device after it.

    wget -q -O - https://raw.githubusercontent.com/LedgerHQ/udev-rules/master/add_udev_rules.sh | sudo bash
    python3 -m venv xe-ledger
    source xe-ledger/bin/activate
    pip install ledgerblue
  3. Download the install file for the Nano Gen5.

    curl -O https://ledger.xe.marketized.io/releases/0.1.0/apex_p/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    sha256sum app-xe.apdu
    70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33400004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    99e54d53c8b0e431f72941be689779b43d4ee1e9cb5e8d8b38527a9d98ea6a89

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Nano Gen5 on Windows
  1. Get the device ready. Update it in Ledger Live, then close Ledger Live. Plug the device in, unlock it and stay on its home screen.

  2. Install Ledger's tool. In PowerShell. Needs Python 3 from python.org, installed with "Add python.exe to PATH" ticked.

    py -m venv xe-ledger
    xe-ledger\Scripts\Activate.ps1
    pip install ledgerblue
  3. Download the install file for the Nano Gen5.

    curl.exe -O https://ledger.xe.marketized.io/releases/0.1.0/apex_p/app-xe.apdu
  4. Check it. This command must print the hash below it. If it does not, delete the file.

    certutil -hashfile app-xe.apdu SHA256
    70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8
  5. Install.

    python -m ledgerblue.runScript --targetId 0x33400004 --fileName app-xe.apdu --apdu --scp

    The device asks you to allow a manager it calls not genuine. That warning is expected for an app from outside Ledger Live.

    Then it shows the app's identifier. It must be this, or reject:

    99e54d53c8b0e431f72941be689779b43d4ee1e9cb5e8d8b38527a9d98ea6a89

    Confirm and enter your PIN.

  6. Use it. Open XE on the device. In Chrome or Edge, go to wallet.xe.marketized.io, choose Ledger, then Connect over USB.

Reference

What you see when signingFour reviews, word for word from the app's tests.

A review is a title, one page per value, then the question. On a Nano you page with the right button and approve with both. On a touchscreen you swipe, then hold to sign. Addresses are shown in full, in eight groups.

Review transaction to send XETest network: XE here has no value

From
Account #0
Amount
2.5 XE
To
894d59e0 c55aea5a 5c6535b1 9b29a21a f0c4d3f7 67e827ec 102b6eb0 ebb29f39
Memo
"x402:ca04a86ee2cb3785"
Pays
x402 invoice ca04a86ee2cb3785
Fees
None
Balance after
7.5 XE
Network
XE Sim - xe-sim-0001

Sign transaction to send XE?

A payment of 2.5 XE that settles an invoice.

Review transaction to receive XETest network: XE here has no value

From
de0d6432 c89794f3 e9532e1e dc0afcca 3b3a6dce 9d679a27 0fe05c76 ad2b611e
Amount
2.5 XE
Account
Account #0
Claims payment
264a6a60 a8c6c079 ce6309e1 7c4f441b a300b6bc 9e470bd2 e6bd2603 9ce3040f
Balance after
12.5 XE
Network
XE Sim - xe-sim-0001

Sign transaction to receive XE?

Receiving a payment.

Review message

Account
Account #0
Address
9a9c3f26 644be432 4ac28a5f 72f19657 1ab039b5 1f9ca69c 8e1c1e52 3df0a4dd
Message
hello world

Sign message?

A text message.

A sign-in to a site is titled "Review message to sign in" and adds two lines: Site, taken from the signed text, and Purpose, "Sign in to" that site, "Not a payment."

Warning, shown first

You would not control this account alone

After this change, other keys could change who controls this shared account, or you could not change it without them.

Continue or Reject

Review transaction to change signersTest network: XE here has no value

Shared account
a97dcf46 da33b022 97e83215 5107279f 76d8053c 21ec21d1 19ba24ed 9da26af4
Signed with
Your key (account #0)
Signers after
payments need weight 2 of 6, key changes 5
Your keys
1 key, weight 1 of 6
You alone can
nothing
Other keys together can
pay and change keys
Balance after
3 XE
Network
XE Sim - xe-sim-0001

Sign transaction to change signers?

A change to a shared account's signers that would leave you unable to act alone.
  • Memos are public. One with characters outside plain ASCII is shown as hexadecimal, labelled "Memo (hex)".
  • "Balance after" comes from the wallet. If it is wrong the network rejects the block; the amount paid cannot differ from the one shown.
  • A receive shows "From" and "Amount" only when the wallet hands over the payment for the device to check.
  • A request that breaks the app's rules is refused before any screen appears.
What it cannot do yetTest networks and XE only, and a few cases it refuses.
  • No main network: XE Sim and the XE testnet only. XE on them has no value.
  • XE only. It refuses XUSD, leases and burns.
  • It will not sign as another account's delegated key. It can grant such a key limits on your account, on XE Sim only, and revoke it.
  • It will not change your representative, the account your voting weight follows.
  • A passphrase attached to a PIN on the Ledger gives different XE accounts from the plain recovery phrase.
  • A 24-word phrase from the XE command-line wallet gives different accounts when restored on a Ledger.
  • A block longer than 4,096 bytes, such as a very large shared account's, is refused.
If something goes wrongThe install's error numbers and what to do about each.
What you seeWhat to do
No device foundUnlock the device, close Ledger Live and any wallet page using it, and try a cable that carries data.
Error 5515The device is locked. Enter your PIN.
Error 6d00 or 6e00An app is open. Go back to the device's home screen.
Error 511fThe build does not match the device's software. Update the device in Ledger Live. If it is up to date, this build is too old for it.
Error 5120This model only takes apps from Ledger Live. That is the Nano X.
Error 6a84 or 6a85The device is full. Remove an app.
Error 6985You rejected it on the device. Run the command again.
python or pip not foundIn a new terminal window, run the "activate" line of step 2 again.
ledgerblue fails to install on Linuxsudo apt install libudev-dev libusb-1.0-0-dev python3-dev python3-venv, then repeat step 2.
The wallet cannot find the deviceUse Chrome or Edge on a computer, and open the XE app on the device first.

The numbers are the ones Ledger's own installer names. They come at the end of the terminal output.

Remove itOne command. Your keys are not affected.

With the device unlocked on its home screen, in the terminal from step 2. Installing again brings the same accounts back.

Nano S Plus

python -m ledgerblue.deleteApp --targetId 0x33100004 --appName XE

Flex

python -m ledgerblue.deleteApp --targetId 0x33300004 --appName XE

Nano Gen5

python -m ledgerblue.deleteApp --targetId 0x33400004 --appName XE
Every file and its hashEach version's files with their SHA-256.

The same list for scripts: /releases/manifest.json.

Version 0.1.0. Built 2026-10-10 from the 0.1.0 source. Made for Ledger OS API level 27. Stax is not offered: its code carries a path from the build machine.

Nano S Plus

  • Install fileapp-xe.apdu
    fbd0d680729ad4c08c907f5a76c248d1fc7deef9e503d14dcc2cab2fc153d274
  • App identifierapp-xe.sha256
    a953c98377bf7134753a7d91f2a1956f621fe0094de8b882b8dd507bfe448da4

Flex

  • Install fileapp-xe.apdu
    e649fb6846187ca88b57d5d421d10cd444026c30f57bf83bdec08685e873646c
  • App identifierapp-xe.sha256
    d0f515e5f7fd5829cfd0ad79707b140edd2d34971b591b3c47902c27ab90dc44

Nano Gen5

  • Install fileapp-xe.apdu
    70f3ecf17407a82905cdb0026488970bbd5d7b867d7bdade385b644681822ca8
  • App identifierapp-xe.sha256
    65f18b2edee2ff18f4eb5b8c41e4e17acb6345dfdc3d350b447d89544c8d77e3
Status in fullNo audit, source not public yet, and the key path.
  • Not reviewed by Ledger. You install it yourself with Ledger's developer tool, which is called sideloading.
  • Emulator only. Every screen was checked on Ledger's emulator for each model. Nobody has run this build on a real device.
  • The "not genuine" warning appears when you install the app and when you open it, because Ledger has not signed it. A malicious app would show the same warning, so check the hash and the identifier.
  • No security audit.
  • Source not public yet. It will be published with the first public release. Until then these files cannot be checked against it.
  • Key path m/44'/22597'/n', where n is the account number. 22597 is provisional: XE has no registered coin type.
  • Same accounts as the XE MetaMask Snap from the same recovery phrase. Never type a Ledger's phrase into MetaMask.
  • Ledger's developer tools call the Nano Gen5 "Apex P".