Ledger launches agent stack for AI payment approvals
Mon, 20th Jul 2026 (Yesterday)
Ledger has launched Ledger Agent Stack, an open-source toolkit for developers building AI agents. The product extends its hardware-based approval model to agent-driven payment and wallet tasks.
The toolkit lets AI agents read information and propose payment operations without controlling private keys. Any sensitive action must still be approved by a human through a Ledger signer before execution.
That model runs across several parts of the stack. Wallet CLI gives agents programmable access to wallet functions, including sending, receiving, swapping and tracking balances across supported blockchains, while keeping transaction approval on the hardware device.
For institutional users, Ledger has also introduced an Enterprise CLI and an Enterprise Multisig CLI. These tools target treasury and governed transaction workflows, with policy enforcement tied to hardware security modules and support for proposing, querying, signing and executing multisignature operations.
The stack also includes what Ledger calls Device Management Kit Skills, described as markdown instruction sets that let large language model runtimes and other agent systems connect to Ledger hardware. The goal is to spare developers from building wallet integrations from scratch when adding secure approval flows to agent software.
Ledger is presenting the release as part of a broader push into AI security products. It describes the launch as the first major delivery in its AI roadmap, with further work planned around agent identity, agent intents and policies, and proof of human.
Security focus
The announcement comes as technology companies and security specialists debate how much autonomy software agents should have when handling money, credentials and sensitive data. Ledger's answer is to separate suggestion from execution, allowing software to draft and prepare actions while leaving final approval to a human.
Ledger argued that this matters because security failures often involve both weak software and human error. It cited research suggesting human error is involved in about 60% of security breaches and that roughly 26.1% of agent skills contain at least one security vulnerability.
By placing the final signing step on dedicated hardware, the system is intended to limit the damage if an agent's software environment is compromised. In that model, software can still analyse balances, draft transactions or suggest swaps, but it cannot move funds or expose protected information without a person confirming the action on a Ledger signer.
Ledger is also extending that hardware security model beyond crypto wallet operations. Two device apps are part of the wider offering for developers and operators using agents in production environments.
One is OpenPGP, which can encrypt agent secrets so they remain unreadable unless the Ledger signer is connected, with an optional tap-to-access setting. The other is Security Key, intended to put logins to services such as GitHub, npm, 1Password and Discord behind the hardware device, reducing the risk from stolen passwords.
Broader push
Ledger has built its business around hardware tools for securing digital assets, and the new release adapts that model for AI systems that may initiate financial and operational tasks. Its existing wallet suite covers consumer, enterprise and multisignature users, and Agent Stack now lets developers bring those wallet functions into agent workflows.
Ian Rogers, Chief Human Agency Officer at Ledger, said the new product is meant to make that transition straightforward while preserving the approval standards already used in crypto custody.
"Ledger has the most full-featured suite of wallets. The most chains, providers for buy, swap, and yield. Also, Ledger has wallets for Enterprise and Multisig users. Now your agent is your trusted partner in operating these secure wallets," Rogers said.
He added that the same approval model used by people can now be applied to software agents.
"Crypto wallets have protected billions on this standard for years. Ledger Agent Stack allows your agent to use these wallets just as easily as humans," Rogers said.
Strategic partners including MoonPay and Shisa.ai have already used the Device Management Kit to add Ledger support to their products, while students have also built applications with the Wallet CLI. Ledger said it has sold more than 8 million signers in more than 165 countries, and that almost 30% of bitcoin and more than 30% of dollar stablecoins held by retail investors are secured by its devices.