Trezor exec rebuts ZachXBT’s claim that hardware wallets are ‘complete garbage’

4 days ago 6



ZachXBT, the internet’s most prolific on-chain detective, just told the crypto world to throw their hardware wallets in the trash. Trezor’s top commercial executive would like a word.

The investigator posted on Telegram on July 16, calling existing hardware wallets “complete garbage” and advising users against relying on them for signing transactions or storing funds. His alternative recommendation: a dedicated crypto-only iPhone. Trezor’s Chief Commercial Officer Danny Sanders fired back the same day, defending hardware wallets as purpose-built security tools that minimize attack surfaces.

The case against (and for) hardware wallets

ZachXBT’s critique wasn’t subtle. “I do not advise using them for important tasks like signing transactions or storing funds,” he wrote, essentially telling users that the devices marketed as the gold standard of self-custody aren’t fit for purpose.

Sanders disagreed, though not by dismissing the concerns entirely. He emphasized that hardware wallets serve as independent verification devices with dedicated screens, meaning users can confirm what they’re actually signing before broadcasting a transaction. That’s something a general-purpose smartphone, even an iPhone, doesn’t inherently provide.

A history that cuts both ways

Trezor’s track record gives ammunition to both sides of the argument. A 2020 security report demonstrated that researchers could physically extract seed phrases from Trezor devices in roughly 15 minutes, provided they had hands-on access to the hardware.

Then there’s the 2024 support portal breach that compromised data belonging to approximately 66,000 customers, including emails and names. Not seed phrases or private keys, but exactly the kind of personal information that makes social engineering attacks devastatingly effective.

And in January 2026, a Trezor user was caught up in a theft worth roughly $282 million. The cause wasn’t a firmware exploit or a hardware flaw. It was phishing. The device worked as designed. The human didn’t.

Trezor maintains that its air-gapped architecture and open-source firmware provide a security model that general-purpose devices simply can’t match. Open-source matters here because it means independent researchers can audit the code, a transparency advantage that closed-source alternatives don’t offer.

The iPhone alternative has its own problems

Roman Storm, the Tornado Cash developer, pointed out that mobile solutions come with their own limitations, including insufficient passphrase protections. In English: your iPhone might be great at keeping strangers out, but it wasn’t designed from the ground up to protect cryptographic keys the way a dedicated hardware wallet was.

There’s also the centralization angle. Apple controls iOS updates, the App Store, and can theoretically push changes that affect how crypto apps function. A hardware wallet manufacturer can do shady things too, but open-source firmware at least lets the community verify what’s running on the device.

What investors should actually take away

The most constructive voices in this debate aren’t arguing for Team Hardware Wallet or Team iPhone. They’re pushing for multisignature setups, where multiple devices or keys must approve a transaction before it goes through.

Think of it like requiring two keys to launch a missile instead of one. If your hardware wallet gets compromised, the attacker still can’t move funds without access to your other signing device. If your iPhone gets stolen, same protection applies.

For investors holding meaningful amounts of crypto, the takeaway isn’t to panic-sell your Trezor or rush to buy a burner iPhone. It’s to stop relying on any single device as your entire security model.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article