Particle.news
Download on the App Store

Onchain Investigator Calls Hardware Wallets 'Garbage' and Urges Dedicated iPhone for Crypto

The post refocuses the debate on whether isolating keys in special hardware or locking down what a signature can do will better stop fake apps and social engineering thefts.

Overview

  • ZachXBT posted on Telegram Thursday saying he does not trust current hardware wallets for critical signing or large balances and recommended using a separate iPhone reserved only for crypto, singling out Ledger as the worst.
  • The critique follows a string of user-targeted scams that bypass device isolation, including an April fake Ledger app on Apple’s store that stole at least $9.5 million and a January social‑engineering loss that moved hundreds of millions of dollars.
  • Investigators say the biggest losses often happened after users approved transactions they could not fully read, with attackers manipulating what signers saw to collect valid signatures in the Bybit and Radiant incidents.
  • The industry is advancing technical fixes to reduce signing risk, including the ERC‑7730 protocol for machine‑readable intent, policy‑enforcing wallets, and Ledger’s ongoing Wallet software updates such as version 4.8.0 released in June.
  • Security trade-offs remain: some experts still recommend hardware cold storage for long‑term holdings while others stress documented recovery plans and constrained, everyday wallets to limit human error and reduce large losses.