Logo
My Crypto News AI

Why a Top Crypto Investigator Says Hardware Wallets Are Failing Users

ZachXBT, one of the crypto industry's most respected onchain investigators, has challenged the conventional wisdom that hardware wallets are the gold standard for protecting digital assets. In a recent statement, he argued that current hardware wallets are fundamentally unsuitable for critical transactions or storing significant amounts of cryptocurrency, and he singled out Ledger, one of the largest hardware wallet manufacturers, as particularly problematic.

What's Wrong With Hardware Wallets Today?

ZachXBT described hardware wallets as "complete garbage" and said he does not advise using them for important tasks. His strongest criticism targeted Ledger, which he called "the worst." According to ZachXBT, Ledger Live, the software interface for Ledger devices, receives "regular updates for UI and apps for no good reason that break simple actions". These frequent updates, he argued, interfere with basic wallet functions and create unnecessary friction for users trying to manage their assets securely.

It's important to note that ZachXBT did not claim Ledger devices had suffered a new security breach or that their private-key protection had been compromised. Rather, his criticism focused on the user experience and software reliability. Ledger has since renamed Ledger Live to Ledger Wallet, and the company continues to promote hardware-based signing as a way to keep private keys separate from internet-connected devices.

Why Are Hardware Wallet Users Still Getting Hacked?

ZachXBT's criticism arrives at a critical moment, as attackers continue targeting hardware wallet owners through methods that bypass the physical device's security entirely. These attacks rely on social engineering and fake applications rather than breaking the wallet's technical defenses. In January, a crypto holder lost more than $282 million in Bitcoin and Litecoin following a hardware wallet social engineering scam, with attackers quickly moving stolen funds through multiple services and converting portions into Monero.

The most striking recent example involves fake Ledger applications. In April, a fraudulent Ledger Live application listed on Apple's App Store stole at least $9.5 million from more than 50 victims in just one week. The fake app copied Ledger's branding and appeared in search results, convincing users it was the official product. Victims who entered their recovery phrases into the counterfeit application gave attackers full control of their wallets, resulting in losses of Bitcoin, Ethereum, Solana, Tron, and XRP. Apple eventually removed the fraudulent application from its store.

How to Protect Your Crypto Assets: Alternative Approaches

  • Device Separation Strategy: ZachXBT proposes using a dedicated iPhone reserved exclusively for cryptocurrency transactions, keeping it isolated from everyday browsing, messaging, and other online activity that could expose it to malware or phishing attacks.
  • Operational Security Practices: Whether using hardware wallets or dedicated devices, users must protect recovery phrases from exposure, avoid clicking suspicious links, and verify that applications are legitimate before entering sensitive information.
  • Understanding Attack Vectors: Recognize that most successful attacks target user behavior rather than device security, including phishing attempts, fake applications, social engineering, and recovery phrase theft.

ZachXBT's recommendation of a dedicated iPhone would reduce exposure associated with using a general-purpose device for crypto management. However, a smartphone still depends on its operating system, installed software, backup practices, and the user's security habits. The debate ultimately comes down to different philosophies for self-custody, which refers to individuals holding their own private keys rather than relying on third-party custodians.

Hardware wallets focus on keeping private keys isolated from general-purpose internet-connected devices, while ZachXBT favors strict device separation through a phone used only for crypto. In both cases, users can still face risks from phishing, fake applications, exposed recovery phrases, and social engineering. The key difference is that ZachXBT believes the operational simplicity and dedicated focus of a single-purpose device may provide better protection than the complexity of managing hardware wallet software updates and interfaces.

As the crypto industry matures, the conversation around custody is shifting from "which device is most secure" to "which approach best balances security with usability for the average person." ZachXBT's critique suggests that the current hardware wallet ecosystem may not have fully solved that equation, and users should carefully evaluate their own security practices regardless of which tool they choose.