Hardware wallets are 'complete garbage' for serious crypto use, according to on-chain sleuth ZachXBT. In a blunt critique posted this week, he suggested users ditch devices like Ledger and instead run a separate iPhone as their primary signing tool. The take has sparked a heated debate across crypto security circles, with responses from Trezor, Keystone, and even Tornado Cash co-founder Roman Storm.
The critique
ZachXBT didn't hold back. He specifically called out Ledger, saying Ledger Live forces unnecessary updates that break simple actions. He listed a litany of hardware wallet headaches: dead batteries, forced firmware upgrades, UI changes that confuse users, and bugs that prevent multisig signing. His bottom line: these devices aren't reliable enough for people managing serious money.
Instead, he argued, a dedicated iPhone — stripped of apps and used only for signing — offers a better balance of security and usability. No forced updates, no dying batteries, no UI surprises.
The counterpoints
Security researcher Axel Bitblaze agreed with the core criticism but questioned the phone-as-wallet fix. He recommended a 2-of-3 Safe multisig setup with separate signer devices, arguing that approach spreads risk better than a single phone.
Roman Storm, co-founder of Tornado Cash, said he liked the idea but pointed out a key gap: mobile wallets generally don't support BIP39 passphrases, a feature hardware wallet users rely on for extra seed protection. That's a real trade-off.
Trezor fired back directly, noting that phones run full operating systems with countless attack surfaces — malware, phishing apps, zero-days. Hardware wallets, they said, keep private keys away from general computing environments by design.
Keystone Wallet acknowledged the potential of an isolated phone but argued most users lack the discipline to maintain it properly. Purpose-built hardware, they said, is still the safer bet for the average person.
Ledger's defense
Ledger didn't directly address ZachXBT's complaints. Instead, the company posted that its core security model keeps private keys offline, making them immune to phishing, deepfakes, and prompt injection. The message was clear: the device itself isn't the weak link.
The human factor
But hardware can't fix human error. Earlier this year, a victim lost $282 million in Bitcoin and Litecoin from an offline device through a social engineering scam. The attacker didn't hack the hardware — they tricked the person. That incident highlights what critics say is the real vulnerability: the user, not the gadget.
The debate leaves an open question. If hardware wallets are too clunky and phones too exposed, what's the right setup for someone holding seven figures in crypto? No one's landed on a clean answer yet.




