Author: Yan Krivonosov
Here comes one piece of news after another, and every time you get goosebumps. On July 30 this year, in just 41 minutes, people had 1,082 bitcoins stolen — at the time, that was nearly 70 million dollars. They simply emptied 1,196 Coldcard wallets. And the wildest part is that these devices weren’t even connected to the internet; they were sitting in safes, and the money still got transferred. Why? It turned out that the random number generator in the firmware malfunctioned, making the seed phrases predictable. The attacker didn’t even hack the device itself — they just tried combinations on their computer and found the wallets where something was stored. That’s a serious blow to the reputation of hardware wallets, don’t you think?
But Coldcard isn’t an isolated case. Hardware wallets have been plagued with problems for a long time. Remember KeepKey — specialists from Kraken Security Labs found that with only 15 minutes of physical access to the device, you can extract the seed phrase using voltage glitching. And this issue can’t be fixed by firmware, because it’s built into the microcontroller itself. Or Trezor, where last year researchers found a vulnerability that allows the mnemonic to be extracted with physical access to an unlocked device. Or a recent Ledger Donjon study showing that it’s possible to hack a hardware wallet via side-channel attacks on HMAC-SHA-2 without any physical contact with the device at all. There were also cases where manufacturers’ own software leaked seed phrases — either through a backdoor in the firmware or because the developer simply didn’t fully test the code. And now this Coldcard story, which is already the second wave, has affected more than 2,500 addresses, and people still don’t know whether their phrases are compromised or not. There’s no test that would verify this.
Now about hot wallets — Trust Wallet, MetaMask, Phantom, and similar ones. The important thing to understand is this: your assets are never stored on the phone and not stored in the wallet itself. All coins always live in the blockchain, and the wallet is just a viewer that shows your balance and lets you sign transactions. But your private keys and your seed phrase are stored on your device — encrypted, but still on the phone or computer that’s connected to the internet. And there are risks here as well.
The main problem is malicious software. If you have Android, it’s easy to catch a virus that will monitor everything you do: which buttons you press, which apps you open, where you go. And at some point it will simply intercept your seed phrase when you enter it or when it’s stored in the phone’s memory. For example, recently they found a critical vulnerability in MediaTek processors found in every fourth Android smartphone. An attacker with physical access to the phone could extract the PIN code and private keys from wallets in less than a minute. Or the FakeWallet and SeaFlower campaign, where fake apps disguised themselves as MetaMask, Ledger, Trust Wallet, and simply stole seed phrases during generation. Or supply-chain attacks through the Snap Store, where attackers compromised accounts of trusted developers and published malicious updates — people entered their phrases themselves, thinking they were updating the official wallet.
In this regard, iPhone’s closed system is indeed safer. There’s less chance of running into a phishing app, because the App Store strictly checks software, and installing from unverified sources is practically impossible without jailbreaking. Plus, the Secure Enclave handles key storage at the hardware level. But even this isn’t a cure-all — if you yourself expose your seed phrase somewhere, no iPhone will save you. And to me, the risks are even lower here than with hardware wallets, which one after another keep proving their unreliability.
So what should you do? How do you store your assets properly so they don’t get stolen? I’ve said this more than once already, but I’ll repeat it.
First, diversify your holdings. If you have Bitcoin, don’t keep everything in one place. Split at least 50% across two different wallets.
If someone steals half from one device, the second half will remain—and sooner or later it will grow back and return what you lost.
Second, do this. Take an old iPhone, not older than model 11 or 12. Completely erase it and reset all settings to factory defaults. Create a new Apple ID, a new email address that you don’t use anywhere else. Don’t insert a SIM card. Share the internet from another phone via Wi‑Fi—so this iPhone never connects to a cellular network. Install Trust Wallet or another trusted wallet on it, create a new wallet, write the seed phrase on paper (note — not on the phone, not in photos, not in the cloud, only on a physical medium). Transfer your assets there, verify everything has arrived, and then turn the phone off and put it away in a drawer. Turn it on only when you need to send something or check the balance. And between sessions, it just stays off.
Hacking such a device, which is 99% of the time not interacting with the internet and is actually turned off, is practically impossible. The only way to lose money is to lose the seed phrase. So pay maximum attention to how you store it: a secure location, backups with trusted people, and protection from fire and water.
And remember the main thing — I repeat this on purpose: your assets are never stored either on the phone or in the wallet. They’re always on the blockchain. Hardware wallets and hot wallets like Trust Wallet or MetaMask are just interfaces, keys to your money. The difference between custodial storage, like exchanges or other third-party services where they store crypto for you, is that they actually take your coins into their internal wallet and only show you a balance in the app. I would advise avoiding that—you don’t control your keys, which means you don’t control your money. No matter whether you trust an exchange or not, there’s always a risk of hacking, bankruptcy, or account lock.
To sum up: hardware wallets are no longer the standard anymore—dozens of incidents over the past couple of years have proven that. Hot wallets on an iPhone, with reasonable precautions, can even be safer. The main rules: spread things across different places, use a dedicated old smartphone without a SIM card, keep the seed phrase only on paper, and never display it on the internet. Nobody will protect your money better than you will.