Update on hardware wallets security and vulnerabilities, as of July 20, 2026

Update on hardware wallets security and vulnerabilities, as of July 20, 2026

By I_g_o_r | Various topics | 16 hours ago


In one of the previous post (see [1]), we looked into popular myths about cyber security of hardware wallets. In this post we look into arguments of prominent crypto experts and security researchers, regarding the modern state of cyber security and vulnerabilities of hardware wallets.

 

The most critical vulnerability of hardware wallets is not a digital exploit, but the human element and physical world—specifically, the reliance on a single, fragile paper backup of the recovery seed phrase and the risk of physical coercion.

 

Prominent crypto experts and security researchers—most notably on-chain investigator ZachXBT—have criticized hardware wallets, describing them as "complete garbage" for signing critical transactions and storing large assets. 

The primary arguments driving this criticism include:

  • Companion App Failures & Bloat: Experts point out that hardware losses and asset drains often stem from companion software and app ecosystems (such as Ledger Live), rather than the offline device itself. Frequent software updates frequently break simple functions, add unnecessary bloat, and expand the software attack surface.

  • "Blind Signing" Risks: Hardware wallets often fail to protect users from malicious smart contracts. Because devices lack the ability to fully decode complex Web3 transactions, users blindly sign approvals, leading to the theft of funds once a transaction is verified.

  • Physical & Supply Chain Vulnerabilities: The myth that hardware wallets provide infallible cold storage has been challenged by physical manipulation (e.g., extracting keys using voltage manipulation) and supply chain attacks, where malicious actors intercept or tamper with the device before it reaches the user.

  • Software Inefficiencies & Usability: Users often encounter physical friction, connectivity issues, and operational latency, which can be fatal for traders needing to respond to rapid market movements.

  • Data Privacy & Phishing: Some hardware manufacturers suffer from recurring customer data breaches (such as the 2020 and early 2026 incidents involving Ledger), doxing users' names, physical addresses, and emails, which subjects them to severe physical and digital extortion.

  • The Seed Phrase Fallacy: Hardware wallets generate a 12- to 24-word recovery seed phrase. If this single physical backup is lost, destroyed in a fire, or improperly stored, the funds are permanently irretrievable.

  • Physical Coercion ("Wrench" Attacks): Because the device provides excellent digital security, bad actors increasingly target the user directly. Thieves can physically force the owner to input their PIN and unlock the device.

  • Supply Chain Interception: Wallets purchased from untrusted third-party resellers or opened during transit can be tampered with. Attackers can pre-install malicious firmware to steal user funds as soon as the wallet is initialized.

 

While more complex than physical theft, hardware-level vulnerabilities can expose private keys if an attacker gains physical possession of the device:

 

  • Laser/Voltage Fault Injection: Security researchers (such as the Ledger Donjon team) have successfully extracted secure data from chips by utilizing lasers or manipulating the voltage supplied to the device, causing it to skip password verifications.

  • Side-Channel Attacks: By monitoring the electromagnetic emissions or power consumption of a hardware wallet while it processes a PIN, advanced hackers can deduce the cryptographic keys or the PIN itself.

  • Supply Chain Firmware Flaws: Hackers inject malicious JavaScript into wallet user interfaces to change destination addresses during a transaction, bypassing cryptography entirely by manipulating what the user sees on their screen.

 

There are multiple historical examples.

 

Physical Extraction Exploits (Hands-on Access)

These attacks require a malicious actor to have direct, physical possession of the hardware wallet.

  • Trezor Unfixable Key Extraction (Voltage Glitching): In 2019, security researchers (including Kraken Security Labs) demonstrated that a hacker with physical access could extract the 12/24-word seed phrase from a Trezor One or Trezor Model T in under 15 minutes. By using custom hardware to alter the chip's power supply ("voltage glitching"), they bypassed the chip’s memory protections. Because older Trezor models relied on a standard STM32 microcontroller instead of a hardened Secure Element chip, this flaw is unfixable via software updates. Mitigation: Users must use a strong optional passphrase.

  • Ledger Nano S Bootloader & MCU Exploits (2018): Researcher Saleem Rashid demonstrated that a 258-bit malicious payload could be placed into the microcontroller (MCU) of the Ledger Nano S. This tricked the device's secure element into verifying non-genuine firmware, potentially allowing a physical attacker to extract secrets or alter transactions. Ledger patched this via the 1.4 firmware update.

  • Unciphered Trezor Safe 3 Exploit (2025): Ledger’s security unit (Donjon) demonstrated a complex physical supply chain attack on the newer Trezor Safe 3. It highlighted that even newer iterations could face hardware-level tampering risks if intercepted by highly sophisticated physical attackers.

 

Supply Chain Attacks (Counterfeit Hardware)

Rather than breaking the encryption, scammers alter the hardware before it ever reaches the user.

  • Pre-Seeded & Flash-Modified Wallets: Scammers purchase legitimate Ledger Nano or Trezor devices, physically open them, and modify the internal components or flash them with altered firmware. The box is then resealed with a pre-generated 24-word seed phrase card. When an unsuspecting user transfers crypto to the device, the scammer (who already knows the seed phrase) instantly drains the wallet.

  • Marketplace Clones: Rogue sellers on third-party online marketplaces have shipped counterfeit Ledger Nano S Plus units. These modified devices contain hardware alterations that transmit PIN codes and seed phrases to attacker-controlled servers the moment the device is plugged in.

 

Software/Ecosystem Ecosystem & Social Engineering Hacks

These attacks do not compromise the physical hardware, but instead target the companion apps or user databases.

  • The 2020 Ledger Marketing Database Breach: This remains the most damaging incident in hardware wallet history. Attackers breached Ledger’s e-commerce database, stealing the personal details (names, phone numbers, and home addresses) of over 270,000 customers. While no crypto keys were stolen, this triggered massive, hyper-targeted phishing campaigns, death threats, and physical extortion attempts against the affected users.

  • Malicious Companion App Clones: Hackers continuously upload counterfeit versions of Ledger Live or Trezor Suite to the Microsoft Store, Google Play, or macOS App Store. One fake Ledger Live app successfully drained over $9.5 million from more than 50 victims by prompting users to type their 24-word recovery phrase directly into the desktop computer screen.

  • Ledger Connect Kit Exploit (2023): A former employee's account was compromised, allowing hackers to inject malicious code into Ledger’s "Connect Kit" library (used by decentralized apps to connect to Ledger hardware). The exploit injected malicious pop-ups onto major Web3 frontends, tricking users into signing rogue transactions that drained roughly $600,000 from connected wallets.

 

The biggest loss, about $1.4 bln. was when Bybit lost 1.4 bln., which was controlled by the private keys stored on the Ledger hardware wallet. See, [2].

 

 

References:

 

1. https://www.publish0x.com/simple-solutions-to-complex-problems/a-simple-way-to-verify-validity-of-marketing-myths-xlgepqq

 

2. https://www.ledger.com/blog-learning-from-the-bybit-safe-attack

How do you rate this article?

3


I_g_o_r
I_g_o_r

I am curious about science, technologies and their applications to solving real problems.


Various topics
Various topics

This blog is about various different topics.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.