Loading market data...

Transaction Blindness Cost Crypto Billions in 2026, ZachXBT Pitches Dedicated iPhone Over Hardware W

Transaction Blindness Cost Crypto Billions in 2026, ZachXBT Pitches Dedicated iPhone Over Hardware W

The transaction blindness problem

Hardware wallets isolate private keys from internet-connected devices, but they can't stop a user from signing a bad transaction. Attackers manipulate what appears on the screen — a process described in a five-step flowchart — so the signer approves a transfer to the wrong address or a contract that drains funds. The vulnerability isn't in the key; it's in the interface. Bybit and Radiant Capital both lost money this way.

In April 2026, a fake Ledger application on the Mac App Store stole $9.5 million from over 50 victims, according to ZachXBT. That attack exploited trust in a known brand, not a flaw in the hardware itself.

" So the second paragraph is under h2 "The transaction blindness problem". I'll translate accordingly. Translation of second paragraph: "Hardwarové peněženky izolují soukromé klíče od zařízení připojených k internetu, ale nemohou zabránit uživateli v podepsání špatné transakce. Útočníci manipulují s tím, co se zobrazuje na obrazovce – proces popsaný v pětikrokovém vývojovém diagramu – takže podepisující schválí převod na špatnou adresu nebo kontrakt, který vyčerpá prostředky. Zranitelnost není v klíči; je v rozhraní. Bybit i Radiant Capital tímto způsobem přišly o peníze." Then: "In April 2026, a fake Ledger application on the Mac App Store stole $9.5 million from over 50 victims, according to ZachXBT. That attack exploited trust in a known brand, not a flaw in the hardware itself." Translation: "V dubnu 2026 ukradla falešná aplikace Ledger v Mac App Store 9,5 milionu dolarů od více než 50 obětí, podle ZachXBT. Tento útok zneužil důvěru ve známou značku, nikoli chybu v samotném hardwaru." Next h2: "Why a dedicated iPhone?" -> "Proč dedikovaný iPhone?" Paragraph: "ZachXBT's argument hinges on Apple's Secure Enclave, which stores NIST P-256 keys. But Bitcoin and Ethereum use secp256k1, so wallet apps often generate signatures in software, not inside the Secure Enclave. That means a dedicated iPhone isn't a perfect solution — it still relies on the app's code. Still, the idea is that a phone used only for crypto, with no other apps or browsing, reduces the attack surface compared to a hardware wallet that connects to a compromised computer." Translation: "ZachXBTův argument se opírá o Apple Secure Enclave, která ukládá klíče NIST P-256. Ale Bitcoin a Ethereum používají secp256k1, takže peněženkové aplikace často generují podpisy v softwaru, nikoli uvnitř Secure Enclave. To znamená, že dedikovaný iPhone není dokonalé řešení – stále se spoléhá na kód aplikace. Přesto je myšlenka taková, že telefon používaný pouze pro kryptoměny, bez dalších aplikací nebo prohlížení, snižuje útočnou plochu ve srovnání s hardwarovou peněženkou, která se připojuje k napadenému počítači." Next: "The tradeoff is clear: hardware wallets protect against remote key extraction, but they don't protect against transaction blindness. A dedicated iPhone shifts the risk but doesn't eliminate it." Translation: "Kompromis je jasný: hardwarové peně