Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

ST33K1M5: the secure element in the Ledger Nano S Plus

TL;DR

The ST33K1M5 is a secure microcontroller from STMicroelectronics, the kind of chip used in bank cards. In the Ledger Nano S Plus it holds your keys, signs transactions and drives the screen, all under Ledger’s own closed operating system.

What it is

A member of STMicroelectronics’ ST33 family of secure microcontrollers. These chips are built to resist physical attacks: probing, power analysis and fault injection. Ledger states the secure element in the Nano S Plus is certified CC EAL6+.

What it does in a Ledger

  • Generates and stores your private keys.
  • Runs BOLOS, Ledger’s operating system, which keeps apps such as the Bitcoin app separated.
  • Signs transactions.
  • Decides what the screen shows; a small helper chip only passes that on to the display.

Open or closed

The Bitcoin app that runs on it is open source. BOLOS and the chip’s own internals aren’t public; secure element makers generally only share details under non-disclosure agreements. You trust Ledger and STMicroelectronics for that part. See open vs closed source hardware wallets.

Why it’s fine in a multisig

In a 2-of-3 the Ledger can’t move anything on its own. Even if its closed code had a flaw, an attacker would still need a key from Trezor or BitBox. You get the chip’s physical protection, and a flaw in its closed code can’t cost you your coins on its own.

Other Ledger models

Ledger says the Nano X uses a secure element certified EAL5+, and the Nano S Plus and Stax use EAL6+ chips. Check the Ledger Nano S Plus review for how it fits in this setup.

Ledger Nano S Plus: Buy from Ledger · Buy on Amazon