On-chain sleuth ZachXBT criticized hardware wallets as “garbage” and suggested using an old iPhone instead.

On-chain sleuth ZachXBT recently criticized all hardware wallets in the community as “completely garbage,” saying they shouldn’t be used to sign important transactions or store assets. He suggested replacing hardware wallets with a dedicated old iPhone (fully disconnected from everyday web browsing and app downloads) as a cold wallet. ZachXBT’s criticism isn’t just about private-key storage security—it also highlights the risk that users can be tricked into authorizing malicious content in complex transaction-signing screens.

ZachXBT’s Criticism: Hardware Wallets Can’t Prevent Malicious Transaction Signing

ZachXBT’s core objection isn’t that hardware wallets can’t protect private keys, but that they can’t effectively prevent users from authorizing the wrong content in complex transaction-signing screens. In February 2025, Bybit was attacked and lost about $1.5 billion; the key was that attackers induced the signer to approve a malicious transaction. This shows that even when private keys are protected, social-engineering attacks can still steal assets through legitimate signing workflows.

ZachXBT’s proposed alternative is to prepare a dedicated old iPhone, used entirely for crypto wallet purposes, and strictly avoid everyday web browsing, downloading apps, or connecting to other services—thereby significantly reducing the attack surface.

The Technical Gap in BIP39 Passphrase

Tornado Cash developer Roman Storm partially agreed with ZachXBT’s iPhone idea, but pointed to a key technical gap: mainstream phone wallets generally lack full BIP39 passphrase support. A BIP39 passphrase is an extra password added beyond the seed phrase. Using the same 12- or 24-word seed phrase with different passphrases produces completely different wallets; if the seed phrase leaks, what the attacker sees may be an empty wallet, while the real assets remain hidden in the addresses protected by the passphrase.

The main hardware wallets that support this feature include Trezor, Ledger, Coldcard, Keystone, and BitBox. MetaMask and Trust Wallet don’t provide it; Rabby supports it mainly on desktop, with very limited options on mobile.

Trezor’s Danny Sanders Pushback: Six Types of Attack Surface for General-Purpose Mobile Devices

Trezor Chief Commercial Officer Danny Sanders replied that a dedicated old iPhone does provide higher security than a typical hot wallet, but that a phone is still a general-purpose computing device—the attack surface is far greater than that of hardware wallets designed specifically for security. Specific risks include:

Zero-click exploits: attackers can compromise without user interaction

Malicious applications: even without actively downloading, there are still potential risks

System-level attacks: intrusion paths targeting the operating system itself

iCloud backup risks: automatic backups may leak sensitive wallet information

Clipboard leakage: copy-paste actions may expose addresses or private keys

Border-check requirements to unlock: the risk of being forced to unlock the device in certain situations

Sanders also emphasized that hardware wallets provide an independent second screen and a physical confirmation process. If the phone itself is compromised, the transaction information the user sees may already have been tampered with.

The Release of Ledger Agent Stack: Hardware Authorization Mechanism for AI Agents

Ledger released an open-source tool suite called Ledger Agent Stack, aiming to extend its hardware security model to AI agent applications. The design logic is “the agent proposes, the human approves”: an AI agent can read wallet balances, analyze an investment portfolio, prepare transactions, and submit payment suggestions—but every sensitive operation must be explicitly approved by the user through a Ledger hardware device to prevent the AI from moving funds on its own after being hacked or manipulated.

Ledger also said the new tool can protect sensitive credentials in AI applications and allow Ledger devices to serve as physical security keys for services such as GitHub, Discord, 1Password, and more. This approach contrasts with ZachXBT’s criticism: Ledger believes hardware devices remain the final line of defense for human authorization and private-key protection; ZachXBT, meanwhile, questions that existing hardware wallets can’t effectively stop wrong signing in real attack scenarios.

FAQ

Why did ZachXBT criticize hardware wallets, and what are the core conditions of his alternative?

ZachXBT’s core criticism is not about private-key protection, but that hardware wallets can’t prevent users from authorizing malicious transactions in complex signing screens (using the February 2025 Bybit $1.5 billion loss case as an example). His alternative is to use a dedicated old iPhone, strictly avoiding everyday web browsing, downloading apps, or connecting to other services, and pairing it with a wallet app that supports BIP39 passphrases and offline signing.

What is a BIP39 passphrase, and why is it crucial for a phone-wallet solution?

A BIP39 passphrase is an additional password added beyond the seed phrase. The same seed phrase paired with different passphrases leads to entirely different wallets—so even if the seed phrase leaks, attackers may only see an empty wallet. Roman Storm noted that if a phone is to truly replace a hardware wallet, the phone wallet must support this feature; but MetaMask and Trust Wallet currently don’t provide it, which is the main gap in this proposal.

What do Chainalysis’s 2025 personal wallet security data show?

Chainalysis data shows that in 2025 there were 158,000 personal wallet intrusion incidents, affecting about 80,000 victims and causing losses of about $713 million. Separately, one UK holder lost about $172 million after a Trezor seed phrase was photographed by a home monitor, showing that security risks have moved beyond a simple “hardware or phone” either-or debate. The issue spans multiple areas, including seed phrase protection, transaction readability, and user operating habits.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments