Back to Freedom.Tech Back
All Ledger Live Desktop releasesAll versions
Release Fri, Aug 14, 2026 6 min read

Ledger Live Desktop 4.16.0

Original release notes

4.16.0

Minor Changes

The @ledgerhq/errors package is removed from the monorepo: no workspace source imported it anymore, every error class it held now lives in the package that owns it (@ledgerhq/ledger-wallet-framework/errors for the ones shared across coin modules). createCustomErrorClass and the serializeError / deserializeError stack are gone with it - define errors as native classes and branch on error.name.

@ledgerhq/errors@6.37.0 stays on npm for external consumers, but is no longer published from this repo.

No workspace package declares it anymore, and none may again: enforce-boundaries now fails CI on any manifest that does. The classes it held live in the package that owns them, with @ledgerhq/ledger-wallet-framework/errors as the shared home below the coin layer.

The package itself stays in the repo so it keeps being published for external consumers, and is bridged to the external coin packages that still peer-depend on it via pnpm.packageExtensions using workspace:* (which reuses the single in-repo copy, so the dependency graph keeps exactly the physical copies it had before). LedgerHQ/coin-modules#752 removes that peerDependency upstream; once it is released the bridge can be dropped, but the package still needs publishing.

  • #20315 4b73f81 Thanks @RobinVncnt! - Portfolio upsell banner and Braze content cards can now coexist on Portfolio (Mobile: shared carousel; Desktop: side-by-side grid when Braze placement is enabled, otherwise upsell stacked above the Braze carousel).
  • #20624 e74a4a3 Thanks @LucasWerey! - Retarget desktop off the dada-client shims onto @features/platform-aggregated-assets and @domain/api-aggregated-assets
  • #20404 0f89b44 Thanks @liviuciulinaru! - Replace the legacy Pay Card placeholders with the shared authentication flow on desktop and mobile
  • #20585 feaf2fc Thanks @claudiiafg! - Require signer confirmation before opening address delete confirmation in Contacts.

@ledgerhq/live-wallet no longer owns sync infrastructure. src/cloudsync/, src/walletsync/, src/accountName.ts and src/store.ts are removed in favour of @shared/cloud-sync, @shared/wallet-sync, @features/platform-wallet-sync, @domain/entity-account-name and @domain/entity-recent-addresses. What remains is the account list sync module (src/accounts/) plus src/walletSyncComposition.ts, which assembles the sync modules into the wallet-sync schema.

Desktop and mobile replace the monolithic wallet reducer with a combineReducers of the entity slices (accountNames, starredAccountIds, walletSync, recentAddresses, nonImportedAccountInfos) and wire the watch loop and trustchain lifecycle from @features/platform-wallet-sync at bootstrap. @ledgerhq/live-common drops its @ledgerhq/live-wallet runtime dependency: the wallet-api, platform and CSV-export helpers now take an AccountNamesState instead of the whole WalletState.

  • #20608 4033c32 Thanks @vladyslavchupovskiy-ext-art! - Add deriveShieldedAddress(ufvk) to derive the Orchard unified address host-side from a UFVK without requiring a device connection. Persists shieldedAddress in ZcashPrivateInfo with backward-compatible serialisation (null fallback for legacy accounts).
  • #20595 43bf6d8 Thanks @ysitbon! - Make every new-architecture barrel a pure regrouping point, and enforce it.

An index.* under shared/, domain/ or features/ may now contain only export * from "./x" lines, plus an optional default re-export. Having to sort in the export (export { a, b } from "./x") proved the target file mixed public and private code; an index.* holding actual code proved it more loudly. A new nx plugin infers a lint:structure target on each of the 49 packages and fails on both, along with two related rules: a barrel may not re-export a private internals location, and it may not re-export another workspace package.

That last rule removes the proxies. A package that re-exported a neighbour gave the same symbol two import paths and hid who actually provided it. Consumers now import the original provider and declare the dependency, which is why the two apps gain @features/flow-contacts-add-contact and the desktop app gains @features/platform-contacts.

Renamed or relocated, with the import specifier unchanged for consumers in every case except where noted:

  • @domain/entity-account-name no longer exports the setAccountNames alias; use

bulkSetAccountNames, the name the slice actually defines.

  • @shared/cloud-sync exports getCloudSyncApi as a named export from its api module instead of

re-exporting a default under a different name.

Five packages are left untouched behind temporary exclusions, each recording how to remove it:

  • @shared/env, the facade over the legacy @ledgerhq/live-env, which carries the wrapping in its

barrel.

  • the @ledgerhq/engagement and @ledgerhq/ptx packages (flow-analytics-consent,

flow-large-screen-upsell, flow-lazy-onboarding-banner, flow-pay-card-auth), so each owning team lands the change on its own schedule. Conformant barrels were prepared and verified for them before being reverted, so the work is deferred rather than open.

  • #20627 7af726b Thanks @YazhuEth! - Explain the higher network fees when sending to an address that does not exist yet. EIP-8037 charges account creation substantially more gas, and nothing in the send flow told the user why the fee jumped. The gas we send is unchanged: eth_estimateGas remains the only source.
  • #20439 65beee5 Thanks @deepyjr! - Fix the Contacts currency selection list so it fills the modal height.
  • #20455 f77b3fa Thanks @deepyjr! - Add invalid and sanctioned address feedback to the Desktop Contacts flow.
  • #20641 1dde844 Thanks @semeano! - Add a warning on Zcash accounts that the private balance excludes Sapling and Orchard shielded funds.
  • #20216 593231c Thanks @semeano! - Restrict the Zcash balance, operations and shielded send flow to the Ironwood pool only.
  • #20207 aee0e64 Thanks @lysyi3m! - Add Internet Computer (ICP) neuron staking to the coin module: create and top up neurons, start/stop dissolving, disburse, set/increase dissolve delay, follow, split, spawn, stake maturity, and add/remove hot keys, plus neuron listing. Governance operations are routed through the NNS governance canister via the device's update-call signing, alongside the existing ledger transfer path, and account synchronization now carries neuron data. Adds the STAKE_NEURON and TOP_UP_NEURON operation types, with matching icons and labels in the desktop and mobile operation history. (LIVE-28469)
  • #20557 3e0ae80 Thanks @claudiiafg! - Render Desktop Contacts address edit signer mismatch error from shared flow state.

The package now exposes ./accounts and ./walletSyncComposition and nothing else. ordering.ts and addAccounts.ts move to @ledgerhq/live-common/account/*, and accountRawToAccountUserData joins live-common/account/serialization next to fromAccountRaw. The liveqr/ folder is gone: importAccounts.ts and accountToAccountData were unreachable, and accountDataToAccount - whose only callers rehydrated a wallet-sync descriptor - becomes accounts/descriptorToAccount. live-common no longer depends on live-wallet.

  • #20510 a1bd49e Thanks @claudiiafg! - Model Me as the default self contact with shared display-name formatting, external address counts, and a Ledger Wallet accounts intent.