As a piece of hardware, the Flex is the most pleasant signing device we have used. The E Ink panel is large enough to display a full destination address and a decoded contract call without scrolling, which removes the most common source of user error: approving something you could not actually read.

Setup is quick and the desktop and mobile companion apps are stable. Asset coverage remains Ledger's structural advantage — if a chain exists in any meaningful size, there is almost certainly an app for it, and that breadth is difficult for smaller vendors to match.

The reservations are not about engineering. Ledger's firmware is closed source, so users are asked to trust audit reports rather than verify the code themselves. That was an acceptable trade for many buyers until the Recover seed-backup service demonstrated that firmware could, in principle, be extended to move key material off the device under some conditions.

Ledger's own position — that the secure element still gates any such operation behind explicit consent — is defensible and no exploit has been demonstrated in the wild. But threat modelling is about what a system could be made to do, not only what it does today, and that is a legitimate reason for some users to choose a fully open alternative.

Who should buy it: holders with a wide spread of assets who value polish and support, and who are comfortable with a vendor-trust model. Who should not: anyone whose security policy requires auditable firmware, or anyone who simply wants equal protection for less money. Four out of five.