ZachXBT kicked off a fresh round of debate on crypto custody in July 2026 — this time arguing that hardware wallets aren't suitable for important transactions and calling Ledger the worst among them.
His criticism centered on software. In a Telegram post, he argued that frequent updates to Ledger's companion app can break basic functionality, and said he personally prefers using a dedicated iPhone for crypto transactions instead.
His comments matter because he's spent years tracking hacks, stolen funds and social-engineering attacks. Still, they weren't a technical audit of Ledger or a controlled comparison with competing products.
The timing also gave the discussion more weight. Soon after his posts circulated, Zilliqa confirmed a serious vulnerability in its Ledger application. Ledger had also disclosed a separate issue affecting an older version of its Monero app earlier in the year.
Neither incident proves that every Ledger device is compromised. What they do highlight is that self-custody security goes beyond keeping your recovery phrase offline — the software ecosystem around it is just as critical.
What Did ZachXBT Say About Ledger?

ZachXBT wrote that he would not recommend hardware wallets for storing funds or signing important transactions. He singled out Ledger and criticized Ledger Wallet, previously known as Ledger Live, for updates that he believes complicate routine operations.
His preferred setup is a dedicated iPhone used only for crypto. Such a device could avoid the email, browsing, messaging and general software exposure found on an everyday phone. Apple’s application sandboxing and regular security updates may also make that approach attractive to technically experienced users.
A dedicated phone is not cold storage, though. It remains connected to the internet and relies on the security of its operating system, installed wallet applications, cloud settings and app-distribution process.
A hardware wallet uses a different model. Its purpose is to keep private keys inside a dedicated device and require physical confirmation before signing. The connected computer or phone prepares the transaction, but the hardware signer is supposed to prevent the private key from leaving the device.
The comparison therefore cannot be reduced to “iPhone safe, hardware wallet unsafe.” Each setup has its own attack surface, and the user’s habits still matter.
What Happened to Zilliqa Ledger Users?
The most significant development since ZachXBT's criticism involves a signing flaw in the Ledger application for legacy Zilliqa accounts.
According to Zilliqa's incident report, transactions signed through the affected app leaked small fragments of the private key. A single signature wasn't enough to compromise it, but once several signatures were publicly visible on-chain, an attacker could reconstruct the key. Zilliqa noted that an account could become vulnerable after roughly four affected signatures. Some wallets were reportedly drained without the owners ever revealing their recovery phrase or approving a malicious transaction.
The issue is limited in scope but serious. It affects only the older, non-EVM side of Zilliqa and the application used to sign those transactions. Zilliqa EVM activity is safe, and assets on other networks (Ethereum, Bitcoin, Solana, etc.) using the same Ledger device are not automatically exposed.
Zilliqa paused legacy transactions, launched an address checker, and began preparing a migration and recovery plan to prevent any further movement while the response is underway.
This distinction matters. The incident wasn't a general breach of Ledger devices — it was a cryptographic implementation error in one blockchain app. Still, users depended on that app to produce secure signatures, and in this case, it didn't. That's the real takeaway.
The Monero Application Had a Separate Vulnerability
Ledger published another relevant disclosure in June 2026 involving its Monero application.
The vulnerability could allow an attacker to recover a user’s Monero view key and spend key from data returned by the application. Exploiting it required several conditions: the Ledger device had to be unlocked, the vulnerable Monero application had to be open, and the connected computer had to be compromised.
Those requirements limited the opportunity for a practical attack, but the potential impact was severe. The vulnerable command did not require additional confirmation on the device.
Ledger says it identified the problem during an internal security review and fixed it in Monero application version 2.1.4. Users of the application were advised to install that version or a later release.
The Zilliqa and Monero cases share an important lesson. A hardware wallet’s secure element may continue working as designed while an individual blockchain application introduces a dangerous signing or key-handling error.
Does This Mean Ledger Hardware Is Compromised?
To be clear: there's no evidence of a universal compromise affecting all current Ledger devices, recovery phrases, or supported assets.
The core design still holds — private keys remain inside the secure hardware, and transactions require physical confirmation on the device. A vulnerability in one blockchain application does not automatically expose keys tied to other networks.
Still, that's not the same as saying the entire user experience is risk-free. People interact with more than just the chip — firmware, blockchain apps, Ledger Wallet, the connected device, third-party services, and the information displayed before confirmation all play a role.
Ledger has had issues across this broader environment. In 2020, its e-commerce database was breached, exposing customer names, addresses and phone numbers. Keys weren't compromised, but the data gave scammers material for targeted phishing. In 2023, the Connect Kit incident stemmed from a malicious package uploaded after a former employee was phished. That impacted third-party dApps using the compromised library, not the hardware itself.
These are different types of incidents. Painting them all as "Ledger wallets were hacked" would be inaccurate. Dismissing them entirely because the secure element wasn't breached would also miss the real risks users have faced.
Ledger Wallet Is Becoming a Larger Platform
Ledger has continued expanding its companion application despite ZachXBT’s criticism. A July 2026 update added real-time profit and loss information, aggregated balances, cross-chain execution and access to trading, staking and other financial services. Ledger says more than 50 providers now compete for transactions across over 100 networks inside the application.
The private key still remains on the hardware signer, according to Ledger. Users must approve transactions on the device.
The expansion brings convenience, but it also raises the importance of clear transaction information. A simple balance application presents fewer decisions than an interface connecting users to swaps, bridges, staking providers, tokenized products and perpetual markets.
Ledger has been working to reduce blind signing, where a user approves data that cannot be understood from the device screen. In September 2026, its Ethereum application is expected to remove an older EIP-712 blind-signing path. Developers using the outgoing LedgerJS packages must migrate to Ledger’s Device Management Kit to preserve compatibility.
Removing blind signing may improve transaction clarity. The migration can also create temporary compatibility problems for applications that do not update on time. That tension between security, features and reliable operation is close to the concern raised by ZachXBT.
Is a Dedicated iPhone Safer?

A separate iPhone can be a sensible part of a custody setup, particularly if it is kept updated and used only with carefully verified wallet applications. It limits exposure to everyday browsing, email attachments and unrelated apps.
It does not provide the same isolation as a hardware signer. The phone stores or accesses wallet secrets within a general-purpose operating system and remains capable of connecting to the internet. A malicious wallet application, compromised cloud backup or account takeover could still create problems.
The better choice depends on the threat being considered.
Someone worried about malware on a personal computer may prefer a hardware signer. A user who frequently interacts with new decentralized applications may separate long-term storage from an active transaction wallet. Someone holding a large portfolio may use several devices, multisignature custody or geographically separated backups rather than trusting one piece of hardware.
No device can protect a user who enters a recovery phrase into a phishing website or approves a transaction without checking the destination and amount.
The Debate Is Bigger Than Ledger
Calling Ledger the worst hardware wallet produces a strong headline, but it does not settle the custody question.
Ledger has a large customer base, an extensive software environment and broad blockchain support. That makes it a visible target for scammers and exposes it to more integration risks. The company also operates a hardware security research team, publishes vulnerability bulletins and has disclosed fixes for problems found in its applications.
What matters is whether a wallet’s security model matches the way it is being used. Long-term Bitcoin storage, daily DeFi trading and institutional treasury management are not the same task. They should not rely on identical custody arrangements.
Hardware wallets remain useful because they isolate private keys from general-purpose computers and phones. Their protection is not absolute. Application bugs, unclear transaction displays, compromised computers, phishing and poor recovery-phrase handling can still lead to losses.
ZachXBT’s criticism is best understood as a warning against treating hardware as a complete security solution. The Zilliqa incident gives that warning real context, but it does not prove that every Ledger user should abandon their device.
Readers can follow more crypto security coverage and market education through Tapbit. Existing users can log in here, while new users can create an account.
Frequently Asked Questions
Is Ledger the worst hardware wallet?
That is ZachXBT’s personal assessment, not the result of a standardized technical comparison. Ledger has faced software, privacy and integration incidents, but there is no authoritative ranking establishing it as the worst hardware wallet.
Are all Ledger devices currently compromised?
No universal compromise affecting all Ledger devices has been identified. Recent vulnerabilities involved specific blockchain applications and did not automatically expose recovery phrases or assets on every supported network.
What was the Zilliqa Ledger vulnerability?
The legacy Zilliqa Ledger application generated signatures that leaked information about an account’s private key. After several affected signatures became publicly available, an attacker could potentially reconstruct the key. Zilliqa EVM and unrelated blockchain accounts were not affected.

