On-chain investigator ZachXBT has stirred the crypto community by arguing that users should NOT rely on hardware wallets to sign major transactions or store large amounts of crypto. In a Telegram post, he slammed such devices as ‘complete garbage.’
His sharpest criticism was directed at Ledger, one of the world’s leading hardware wallet makers. ZachXBT dubbed Ledger ‘the worst,’ claiming routine updates to the Ledger Live app frequently break essential functions. ‘Regular app/UI updates for no apparent reason that break simple actions,’ he wrote. Instead, he suggested an unconventional route: using a dedicated, standalone iPhone solely for managing crypto assets.
Personal Assessment, Not Proof of a Breach
Notably, ZachXBT offered no evidence that Ledger devices have suffered a new security breach or that their private key protections have been compromised. This reflects his personal user experience rather than technical vulnerabilities. Ledger has since rebranded Ledger Live to ‘Ledger Wallet’; according to official release notes, version 4.8.0 rolled out on June 11 with security enhancements, interface tweaks, and minor bug fixes.
The company continues to champion hardware-based signing as the way to keep private keys isolated from internet-connected devices. ZachXBT takes a different approach: strict device segregation via a dedicated smartphone. Two philosophies, one shared goal - keeping assets safe.
Why This Debate Is Surfacing Now
The controversy comes amid a surge in attackers targeting hardware wallet owners through social engineering and fake apps - attacks that rarely compromise the device’s physical security itself. The losses are real and staggering. In January, a crypto holder lost over $282 million in Bitcoin and Litecoin to a hardware wallet social engineering scam; ZachXBT reported that the culprit quickly moved the stolen funds through multiple services and converted a portion into Monero.
In April, a fake Ledger Live app that slipped onto the Apple App Store stole at least $9.5 million from more than 50 victims within just a week. The imposter app mimicked Ledger’s branding to ensnare users seeking official companion software. Victims typed their recovery phrases into the bogus app, granting attackers full wallet control - drained assets included Bitcoin, Ethereum, Solana, Tron, and XRP. Apple subsequently took down the app.
So, Which One Is Safer?
Ultimately, the debate is not about who wins, but about two distinct self-custody models. Hardware wallets focus on isolating private keys from general-purpose online machines, while ZachXBT trusts device segregation through a dedicated crypto-only phone. What users must keep in mind: across both methods, risks from phishing, rogue apps, leaked recovery phrases, and social engineering remain persistent. No matter how secure the device, it cannot protect you if the recovery phrase is entered in the wrong place.
Reported via crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




