Is Your iPhone Safer? ZachXBT Challenges Hardware Wallets for Crypto Security






Crypto Wallet Security Under Fire: ZachXBT Ignites Debate, Proposing iPhones Over Hardware Wallets



By Max, CryptoCity


Crypto Wallet Security Under Fire: ZachXBT Ignites Debate, Proposing iPhones Over Hardware Wallets

The world of digital asset security is rarely calm, but a recent provocative statement from prominent on-chain detective ZachXBT has sent shockwaves through the crypto community. Criticizing the current state of hardware wallets as “complete garbage,” ZachXBT has put forth a radical alternative: repurpose an old iPhone as a dedicated, offline crypto wallet.

This bold suggestion has not only sparked widespread discussion but also shifted the focus from mere private key protection to the more nuanced risks associated with transaction signing. The debate highlights a critical vulnerability: even with robust private key security, users can still be tricked into approving malicious transactions, as evidenced by the $1.5 billion Bybit attack in February 2025.

Image source: X/@DantoshiTrezor | Trezor CBO Danny Sanders responded, stating that while a dedicated old iPhone might enhance hot wallet security, it remains a general-purpose computing device with a far greater attack surface than purpose-built hardware wallets.

The Missing Piece: BIP39 Passphrases and Mobile Wallet Gaps

While acknowledging the merit in ZachXBT’s iPhone concept, Roman Storm, a developer behind Tornado Cash, quickly identified a critical missing component: the widespread lack of BIP39 passphrase support in mainstream mobile wallets.

A BIP39 passphrase acts as an additional layer of security beyond the standard 12 or 24-word seed phrase. By adding a unique passphrase, the same seed can generate an entirely different set of wallets. This means that even if a seed phrase is compromised, attackers might only gain access to an empty “decoy” wallet, with the true assets safely tucked away in an address protected by the passphrase.

This vital feature is a staple in most leading hardware wallets, including Trezor, Ledger, Coldcard, Keystone, and BitBox. However, its adoption in mobile wallets is notably sparse. Storm pointed out that major players like MetaMask and Trust Wallet still lack this functionality, and Rabby offers it primarily on desktop, with limited mobile options.

For a dedicated old iPhone to truly rival the security of a hardware wallet as a cold storage solution, mobile wallet applications must integrate both BIP39 passphrase support and the ability to sign transactions offline, ensuring the device never needs to connect to the internet for confirmation.


Hardware Wallet Manufacturers Push Back: The Inherent Risks of General-Purpose Devices

Unsurprisingly, hardware wallet providers have not taken ZachXBT’s critique lying down. Danny Sanders, Trezor’s Chief Business Officer, countered that while a dedicated old iPhone might offer an upgrade in hot wallet security, its fundamental nature as a general-purpose computing device presents a significantly larger attack surface than a specialized hardware wallet.

Sanders highlighted various vulnerabilities inherent to smartphones, including zero-click exploits, malicious applications, system-level attacks, iCloud backup risks, clipboard data leaks, and even physical coercion scenarios like border checks demanding device unlocking.

Image source: X/@DantoshiTrezor | Trezor CBO Danny Sanders responded, stating that while a dedicated old iPhone might enhance hot wallet security, it remains a general-purpose computing device with a far greater attack surface than purpose-built hardware wallets.

A key advantage of hardware wallets, as argued by manufacturers, is their independent second screen and physical confirmation process. If a phone is compromised, the displayed transaction details could be maliciously altered. A hardware wallet, however, provides an isolated display for verification, mitigating risks even if the host device is under attack.

Yet, even proponents of hardware wallets concede a critical flaw: user experience. Overly complex transaction details, confusing signing screens, or the simple act of a user confirming a transaction based solely on the address and amount can render even the most secure hardware model vulnerable to social engineering.


Ledger’s AI Agent Stack: A New Frontier in Security

Amidst this ongoing debate, Ledger has unveiled its Ledger Agent Stack, an innovative approach that extends hardware security to AI agent applications. This open-source framework allows AI agents to perform tasks like reading wallet balances, analyzing portfolios, preparing transactions, and suggesting payments. Crucially, every sensitive operation requires explicit user approval via a Ledger hardware device.

Dubbed “Agent proposes, Human approves,” Ledger’s initiative aims to prevent AI agents from autonomously moving funds if compromised or manipulated. Furthermore, the tool is designed to safeguard sensitive credentials within AI applications and enable Ledger devices to function as physical security keys for services such as GitHub, Discord, and 1Password.

This strategy stands in stark contrast to ZachXBT’s critique. Ledger firmly believes that hardware devices remain the ultimate safeguard for human authorization and private key protection. ZachXBT, conversely, questions the efficacy of current hardware wallets in preventing erroneous signings during real-world attack scenarios.

The urgency of this debate is underscored by alarming statistics. Chainalysis data reveals 158,000 personal wallet intrusion incidents in 2025, affecting approximately 80,000 victims and resulting in losses totaling around $713 million. A particularly stark example involved a UK holder losing an estimated $172 million after their Trezor seed phrase was recorded by a home surveillance camera.

These incidents underscore that the discussion around crypto wallet security transcends a simple “hardware versus phone” dichotomy. It delves into the intricate interplay of seed phrase protection, passphrase implementation, transaction readability, offline signing capabilities, AI agent authorization, and, ultimately, user habits. As AI agents increasingly participate in asset management, the battleground for wallet security is expanding beyond private key custody to encompass how humans truly confirm and authorize their digital asset movements.


(The above content is an excerpt and reproduction authorized by our partner “CryptoCity”, original link)


Disclaimer: This article is for market information purposes only. All content and views are for reference only, do not constitute investment advice, and do not represent the views and positions of BlockBeats. Investors should make their own decisions and trades. The author and BlockBeats will not bear any responsibility for direct or indirect losses caused by investor transactions.


About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these