Core Reasons for the Warning
Published 7/16/2026, 9:08:38 AM
Blockchain investigator ZachXBT has issued strong warnings against hardware wallets, specifically labeling Ledger as "the worst" and describing hardware wallets in general as "complete garbage" for high-stakes operations [Source: https://crypto.news/zachxbt-calls-hardware-wallets-garbage-says-ledger-is-the-worst/]. His criticism is not based on a direct failure of the hardware's private key isolation, but rather on usability failures, unstable software updates, and the vulnerability of users to social engineering [Source: https://t.me/investigations/355].
Core Reasons for the Warning
ZachXBT's warnings center on the gap between the theoretical security of hardware and the practical reality of how users interact with them.
| Reason | Details |
|---|---|
| Unstable Software | ZachXBT criticizes Ledger for frequent, unnecessary UI/app updates that "break simple actions." He noted that Ledger Live was renamed to "Ledger Wallet" (v4.8.0) with overhauls that prioritize interface changes over stability [Source: https://t.me/investigations/355]. |
| Social Engineering | The hardware wallet brand name creates a false sense of security that attackers exploit. Users are frequently tricked into entering recovery phrases into fake apps on official stores [Source: https://www.theblock.co/post/397388/fake-ledger-app-apple-app-store-crypto-theft-bitcoin-tron-solana-zachxbt]. |
| Data Privacy | Past data breaches (such as those involving third-party processor Global-e) exposed customer contact details, providing attackers with a "hit list" for phishing and physical threats [Source: https://bitcoinfoundation.org/news/crypto-companies-news/ledger-worst-hardware-crypto-wallet-zachxbt-says/]. |
| Usability Failures | He argues that current hardware solutions fail to balance security and usability, making them unsuitable for signing critical transactions or storing large amounts of capital [Source: https://crypto.news/zachxbt-calls-hardware-wallets-garbage-says-ledger-is-the-worst/]. |
Major Security Incidents Cited
ZachXBT has documented massive losses resulting from the ecosystem surrounding these devices:
- Apple App Store Scam (April 2026): Over 50 victims lost $9.5 million by entering their recovery phrases into a fraudulent "Ledger Live" app [Source: https://www.coindesk.com/business/2026/04/14/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto].
- Microsoft Store Scam: A fake Ledger app on the Microsoft Store stole approximately $768,000 (including 16.8 BTC) from users who believed they were downloading official software [Source: https://digifinex.medium.com/beware-fake-ledger-wallet-app-on-microsoft-store-swindles-768k-in-crypto-b226e6e95889].
- Large-Scale Social Engineering (January 2026): Attackers stole $282 million in BTC and LTC by targeting hardware wallet users through sophisticated social engineering tactics [Source: https://t.me/investigations/355].
ZachXBT's Alternative Recommendation
Instead of traditional hardware wallets, ZachXBT has suggested that technically proficient users consider using a dedicated iPhone initialized solely for cryptocurrency transactions [Source: https://t.me/investigations/355].
- The Method: Wipe the phone, remove all non-essential apps, and use it as a "clean" signing device.
- The Rationale: He believes this provides better control and fewer vulnerabilities than the current hardware wallet ecosystem, which he views as increasingly bloated and prone to user-facing errors.
In summary, ZachXBT's warning is a critique of the "security theater" he believes hardware wallet companies provide, arguing that their software and data practices actually increase the attack surface for most users.