Trezor Pushes Back on ZachXBT as Dedicated iPhone Debate Exposes Crypto Wallet Trade-Offs
Trezor executive Danny Sanders has defended hardware wallets against criticism from blockchain investigator ZachXBT, arguing that dedicated smartphones introduce a broader range of attack risks even if they can form part of a more advanced security setup.
The dispute has reopened a long-running debate over how cryptocurrency holders should protect private keys while retaining the ability to move funds quickly. It also highlights a basic problem in self-custody: the most secure setup on paper may become difficult to use precisely when a transaction is urgent.
ZachXBT said earlier this week that he considered current hardware wallets unsuitable for important tasks such as storing large balances or signing high-value transactions. He recommended using a separate iPhone dedicated exclusively to cryptocurrency storage and transaction signing.
The device, under that approach, would not be used for normal browsing, messaging, social media or other everyday activity. Restricting its purpose could reduce exposure to malicious applications, phishing links and other common attack routes associated with a user’s primary phone.
ZachXBT’s criticism was unusually broad.
“All hardware wallets are complete garbage, and I do not advise using them for important tasks like signing transactions or storing funds,” he wrote in a Telegram post.
Sanders, Trezor’s chief commercial officer, acknowledged that the frustration behind the criticism was not entirely misplaced. Hardware-wallet users can encounter software compatibility issues, mandatory firmware upgrades, connection failures and other interruptions when trying to complete transactions.
Those problems become more serious when the user is moving a large amount of cryptocurrency or responding to a time-sensitive event.
“I actually get it, and I agree that we have clunky solutions out there,” Sanders said. “It’s really hard to build on the edge of security and usability.”
Hardware wallets are designed to isolate private keys from internet-connected computers and phones. Transactions are prepared on another device but must be confirmed and signed using the hardware wallet, which is intended to prevent the private key from leaving the secure device.
That separation can reduce the risk posed by malware on the connected computer. It can also create additional steps, dependencies and failure points.
A firmware update appearing immediately before a large transfer, for instance, may force a user to decide between delaying the transaction or installing unfamiliar software under pressure. Connection problems, unsupported transaction formats or a malfunctioning screen can create similar difficulties.
Sanders argued that these limitations do not justify dismissing the entire hardware-wallet category. In his view, ZachXBT was drawing conclusions from the needs of sophisticated users who manage unusually large sums in high-risk environments.
“People who have to manage a lot of value in high-stakes environments need different setups, and just a single hardware wallet is not the best solution for that,” Sanders said. “But it doesn’t mean you can just say everything is garbage.”
For professional traders, investigators, funds, wealthy holders and other advanced users, a single signing device may provide insufficient protection. Such users may require multisignature wallets, separate signing devices, geographic key distribution, transaction policies and recovery procedures.
A dedicated iPhone could play a role in one of those setups, Sanders said.
He rejected the idea that it was automatically safer than a hardware wallet, however. Even a stripped-down smartphone runs a complex operating system and contains numerous communication components.
“You have Wi-Fi and Bluetooth and iMessage and cellular,” Sanders said. “Even generating your keys on a wallet on your iPhone is more risky than with a hardware wallet.”
Disabling those services may reduce exposure, but it does not remove the underlying hardware, operating system or firmware complexity. A smartphone was designed as a general-purpose connected computer, not solely as an isolated device for generating and protecting cryptocurrency keys.
Hardware wallets typically use a smaller operating environment with a narrower purpose. Many models also provide a separate screen on which users can verify the destination address, transaction amount and other details before approving a transfer.
That screen matters because malware on a laptop or phone could alter a destination address before a transaction is signed. A user who checks only the computer interface may unknowingly approve the attacker’s address. Verifying the details on an independent hardware-wallet display can expose the substitution.
Sanders described hardware wallets as the strongest currently available form of self-custody for the average cryptocurrency holder.
That claim does not mean they are immune to failure. Hardware wallets can be compromised through malicious firmware, supply-chain attacks, insecure backups, phishing, physical extraction attempts or user mistakes. An attacker who obtains a recovery phrase may not need to compromise the device at all.
The broader security model therefore depends on more than the hardware wallet itself.
Users must protect recovery phrases, verify transaction details, install authentic firmware and understand how to restore access if a device is lost or damaged. A secure signing device cannot compensate for a seed phrase stored in cloud notes, photographed on a phone or entered into a phishing website.
Tornado Cash co-founder Roman Storm also entered the debate, leaning closer to ZachXBT’s position while identifying a major weakness in the dedicated-phone approach.
Storm said mobile wallets generally lack support for BIP39 passphrases, sometimes informally described as an additional word attached to a recovery phrase.
A BIP39 passphrase works together with the seed phrase to generate a separate wallet. The same recovery words combined with different passphrases produce different sets of addresses and private keys.
This can protect funds if an attacker discovers the written seed phrase but does not know the additional passphrase. It can also allow users to maintain decoy wallets or separate balances derived from the same seed backup.
The feature introduces its own risks. A forgotten or mistyped passphrase cannot normally be recovered, even when the underlying seed phrase remains available. There is no central provider that can reset it.
Storm nevertheless argued that mobile support for the feature is necessary before a dedicated-phone setup can meet the needs of users protecting meaningful balances.
“ZachXBT’s got the right idea,” Storm wrote. “There’s just nothing on mobile to actually do it with.”
He called on mobile-wallet developers to add both BIP39 passphrase support and air-gapped transaction signing.
Air-gapped signing allows a device to approve a transaction without being directly connected to the internet or physically attached to an online computer. An unsigned transaction can be transferred to the offline signer through a QR code or another restricted method. The signed transaction is then moved back to an online device for broadcast.
The private keys remain on the offline device throughout the process.
Supporters argue that this limits the opportunity for remote attackers to reach the signing environment. Critics note that air-gapped systems still depend on secure software, accurate transaction verification and safe methods of transferring data between devices.
The debate ultimately reflects different threat models rather than a simple contest between two products.
A typical holder protecting a modest long-term balance may benefit from a reputable hardware wallet, an offline recovery backup and careful transaction verification. The device offers a relatively accessible way to keep private keys away from everyday internet activity.
An advanced user managing millions of dollars while responding to hacks, liquidations or time-sensitive trading events may have very different requirements. Speed, redundancy and the ability to recover from a device failure can become as important as isolating the private key.
Neither a hardware wallet nor a dedicated iPhone solves every part of that problem alone.
The argument has also drawn attention to the need for better mobile self-custody tools. Smartphones are already the main computing device for many users, but wallet applications often force them to choose between convenience and stronger isolation.
Adding passphrase support, transaction-policy controls and air-gapped signing could make dedicated phones more credible as part of advanced custody systems. Yet each additional feature also increases complexity, creating more opportunities for configuration errors and lost access.
For wallet manufacturers, the criticism is a reminder that security cannot be separated from usability. A device that protects keys but fails during an urgent transaction may be secure in a narrow technical sense while still failing the user.
Sanders conceded that current products remain clunky.
His disagreement with ZachXBT was not over whether hardware wallets need improvement. It was over whether their weaknesses make a general-purpose smartphone the safer default.
For most holders, Trezor’s answer remains no.
Hardware Wallets Are Clunky, but Replacing Them With an iPhone Is Not the Easy Win It Sounds Like
ZachXBT went for the throat.
Not “hardware wallets need improvement.” Not “this model has poor firmware support.” All of them are garbage. Use a dedicated iPhone instead.
I understand why that landed.
Anyone who has tried to move serious money and suddenly been hit with a firmware update understands it too. The wallet application refuses to connect. The device freezes. A transaction type is not supported. The cable works until the exact minute you need it.
Now imagine the transfer is worth several million dollars.
Maybe an exploit is active. Maybe an address has been exposed. Maybe you are racing an attacker. The hardware wallet decides this is the perfect moment for maintenance.
That is not a minor inconvenience.
It is an operational failure.
Sanders was right to admit it instead of pretending hardware wallets are frictionless little fortresses. They aren’t. Some feel like calculators from 2009 attached to software that changes every few months.
Still, ZachXBT’s conclusion jumps too far.
A dedicated iPhone is not magically a cold wallet because you deleted Instagram.
It remains a huge general-purpose computer. Cellular modem. Wi-Fi. Bluetooth. Complex operating system. Background services. App framework. Baseband firmware. Cloud-account hooks. Notification systems. Features stacked on features stacked on features.
That is a lot of surface area.
You can shut most of it down. You can remove the SIM, disable wireless connections and install a single wallet application. Good. That lowers the risk.
It does not turn the phone into a purpose-built signing device.
That distinction matters.
A hardware wallet is supposed to do very little. Generate keys. Store keys. Display transaction details. Sign when the user approves.
Limited scope is part of the security model.
An iPhone does thousands of things, even when the owner wants it to do one.
My view? ZachXBT’s setup makes sense for ZachXBT-style users.
People handling high-value wallets under pressure do not have average threat models. They may need to move assets immediately after spotting an exploit. They cannot afford to discover that their signing device needs an update or that the desktop wallet stopped recognizing it.
For them, availability is security.
A perfectly isolated key that cannot be used in time is not very helpful.
This is where hardware-wallet defenders sometimes lose the plot. They discuss extraction resistance while ignoring operational reality. The user does not care that the secure element performed beautifully if the transaction could not be signed before the attacker drained the wallet.
But the reverse mistake is just as bad.
A device that is always ready but easier to compromise is not automatically superior.
The real fight is not hardware wallet versus iPhone. It is isolation versus reliability.
Most people need both.
That usually means redundancy, not one magical device.
I would not keep a life-changing balance behind a single hardware wallet and call the job finished. One device creates a glass floor. Lose it, break it, hit a software incompatibility or forget the exact recovery process, and the entire setup becomes dependent on whether your backup plan actually works.
Yet I would not place the same balance in a normal mobile wallet on a repurposed phone and feel clever either.
Not without passphrase support.
Not without offline signing.
Not without a tested recovery process.
Not without a second device.
Roman Storm found the useful middle of the argument.
His point about BIP39 passphrases cuts deeper than the hardware debate because the written seed phrase is where many supposedly secure setups collapse.
Users buy a hardware wallet, stamp 12 or 24 words onto metal, hide the plate and assume the funds are safe.
Maybe.
Anyone who finds those words can usually recreate the wallet somewhere else. The hardware device no longer matters.
A strong passphrase changes that. Seed phrase alone? Wrong wallet. The attacker still needs the extra secret.
That is real protection.
Also real: people forgetting it.
There is no “forgot password” button. No support ticket. No emotional appeal to the blockchain.
One missing character and the wallet derived from the phrase may look completely empty. Users can spend years thinking their device failed when they are simply entering a different passphrase.
So yes, mobile wallets should support BIP39 passphrases.
But presenting the feature without hammering the recovery risk would create a fresh pile of lost funds.
This industry loves advanced security tools until normal people use them.
Then somebody stores the seed and passphrase together.
Or picks “bitcoin123.”
Or creates three hidden wallets and forgets which passphrase controls the real one.
Security features do not erase human behavior. They move the failure point.
Air-gapped signing is the stronger part of Storm’s proposal.
Let the online phone build the transaction. Show it to an offline device through a QR code. Verify the address and amount on the offline screen. Sign there. Return the signed data to the connected phone for broadcasting.
Keys never touch the networked device.
Clean model.
Still not foolproof.
The offline signer could run malicious software. A compromised online wallet could present misleading transaction information. Users could scan without checking. QR-based systems can hide complex call data that an ordinary holder cannot interpret.
“Air-gapped” sounds absolute.
It isn’t.
The gap reduces certain attack paths. It does not bless everything that crosses it.
That is why the separate screen on hardware wallets remains useful. The computer might lie. The browser might lie. The wallet extension might lie. The user gets one final chance to compare the amount and address on a device that holds the key.
Of course, most users do not compare the full address.
They look at the first four characters, the last four, then press approve.
Attackers know that.
Address poisoning works because people are rushed. Clipboard malware works because people trust the screen they were already using. Blind signing works because smart contract data looks like gibberish.
The best wallet in the world cannot secure a transaction the owner does not understand.
This debate should not end with “buy Trezor” or “use an iPhone.”
That is lazy.
The right setup depends on what you hold, how often you transact and who might target you.
A person holding $2,000 in bitcoin for five years does not need the same operational machinery as an investigator moving funds while tracking professional thieves.
A long-term holder mostly needs protection from phishing, device loss and a bad backup.
An active DeFi user needs stronger transaction decoding and protection from malicious approvals.
A fund needs multisignature controls, separate personnel, transaction limits and documented recovery procedures.
A high-profile holder may need geographic separation and protection from physical coercion.
Same crypto.
Totally different security problem.
I have seen users spend heavily on premium hardware while ignoring the laptop connected to it, the authenticity of the wallet software, the security of their seed backup and the possibility of physical theft.
That setup looks impressive.
It is still weak.
I have also seen people treat an old phone as secure because it stays in a drawer.
Then they connect it to home Wi-Fi every time they need an update.
That is not air-gapped. That is occasionally offline.
The dedicated-iPhone idea can work, but the details decide everything.
Was the device reset properly?
How was the wallet installed?
Was the seed generated while the phone was connected?
Does the wallet support offline signing?
Can the user verify transaction data independently?
Are cloud backups disabled?
Is the passcode strong?
Does anyone else know the device exists?
Has recovery actually been tested?
Miss enough of those and the “secure phone” becomes an expensive hot wallet.
Hardware wallets face the same brutal checklist.
Was it bought from a trusted channel?
Was the packaging authentic?
Did the device generate the seed itself?
Did the user type the seed into a computer?
Is the firmware genuine?
Does the screen display the real transaction details?
Can the wallet be restored on another compatible device?
Is the recovery phrase stored separately from the passphrase?
There is no idiot-proof option.
That is the part the industry hates admitting.
Self-custody means you own the failure modes too.
No bank fraud desk.
No password reset.
No account recovery team.
No manager who can reverse the transfer.
Just your setup and whatever mistakes you baked into it.
Sanders is right that hardware wallets remain the strongest practical self-custody tool for many average users. They offer meaningful key isolation without requiring someone to become a security engineer.
ZachXBT is right that they can be painfully unreliable in urgent, high-stakes situations.
Storm is right that mobile wallets lack features needed to turn a dedicated phone into a stronger signing tool.
Everyone has a piece of it.
But the loud “everything is garbage” line hides the real lesson.
One device is the problem.
One hardware wallet. One dedicated phone. One seed backup. One signing path.
Any single component can fail at the worst possible moment.
For meaningful balances, the better answer is layered custody: separate signing devices, tested recovery, passphrase protection where appropriate, limited hot-wallet exposure and transaction policies that prevent one mistake from draining everything.
Not glamorous.
No killer device.
Just fewer ways to get nuked.
And honestly, that is what good security usually looks like.
