Ledger releases the Open Source Toolkit Legger Agent Stack, trying to get AI agents involved in encryption wallet operations while keeping the final authorization on hardware. The product allows AI to read balances, analyse holdouts, generate draft transactions and make payment recommendations, but does not have direct control of the private key.
Sensitivity still requires equipment confirmation.
According to the design of Ledger, AI agents can complete some of the prefixes, including checking wallet information, sorting assets and preparing for signature. Users still need manual approval on the Legger hardware equipment when it really involves money transfers or access to protected information.
This means that AI can assume the role of “assist” but cannot use assets independently. Ledger would like to use this to extend the security model of the hardware wallet to AI applications to avoid a proxy program that triggers a transfer directly if attacked, manipulated or miscalculated.
Open to individuals and institutional developers
Ledger states that the toolkit is open to individual and institutional wallet scenes, whereby developers can support access to their AI applications without having to build a wallet from the top to interact and secure the process.
From a product orientation point of view, Legger Agent Stack is more like a set of bottom-up development tools than an independent application for ordinary users. It focuses on enabling AI to participate in wallet-related processes, while locking the most critical step, namely, transaction approval, on physical equipment.
Hardware security extended to voucher management
Ledger also extends the same set of hardware security ideas to AI voucher management. The new feature allows developers to save sensitive AI vouchers more securely and uses the Legger device as a physical security key for login services such as GitHub, Discord and 1 Password.
According to the company, this design was designed to reduce the risk associated with the invasion of AI agents. Even if the assailant controls the agency, the physical identification of the equipment holder is still required in order to transfer funds or access protected information.
Additional information:Ledger calls this the first product action under its 2026 AI Road Map, showing that the hardware wallet manufacturer is trying to keep manual confirmation as a core security link when AI agents enter the financial operations scene.
