钓鱼攻击、漏洞与隐私
A dedicated iPhone and a hardware wallet have different trust boundaries
Calling every hardware wallet “garbage” because Ledger Live has poor UX confuses the frontend with the security boundary.
Original publication · 16 Jul 2026. Figures, claims and opinions reflect the original publication date.
原文为英语,导航提供七种语言。
01
查看 X 原帖 ↗I need to say something about this, because seriously, what the fuck?
A Dedicated iPhone Is Not a Hardware Wallet.
It Is a Hardened Hot Wallet.
Calling every hardware wallet “garbage” because Ledger Live has poor UX confuses the frontend with the security boundary.
Ledger Live constructs and broadcasts transactions.
The hardware device keeps the private key inside an isolated Secure Element, parses the transaction, displays the relevant fields on a separately controlled screen and signs only after physical confirmation.
A compromised computer can manipulate the unsigned transaction, but it cannot silently extract the key.
A dedicated iPhone can reduce exposure by removing messaging apps, browsers and daily activity.
Apple’s Secure Enclave is a serious isolated coprocessor with secure boot, protected key operations and hardware-bound secrets.
But Apple’s public Secure Enclave signing API exposes NIST P-256, while Bitcoin and standard Ethereum accounts use secp256k1.
Therefore, many crypto wallets cannot simply place the actual blockchain signing key inside the Secure Enclave.
They often protect wallet data through the Keychain and hardware-backed encryption instead, which is not the same security model as a non-exportable signing key inside a dedicated signer.
The iPhone’s display and wallet application also run through the main operating system and application processor.
Unless the wallet implements a separate trusted-signing path, malware or a compromised app can alter what is presented before signing.
A proper hardware wallet uses its own trusted display to verify the destination, amount and contract action independently of the host.
That protection disappears during blind signing, which is the legitimate weakness he should have criticised.
He is right that Ledger Live can be bloated, disruptive updates are unacceptable for critical infrastructure, and blind signing remains dangerous.
None of those points invalidate hardware wallets as a category. Ledger Live is replaceable software. Key isolation, transaction parsing and trusted-display verification are architectural properties of the signer.
Replacing a purpose-built signer with a general-purpose, network-capable phone increases the trusted computing base from a small signing environment to iOS, the wallet application, its dependencies, its update channel and the entire transaction-rendering path.
Presenting that as universally safer, followed by an IQ insult, is somehow a failure to distinguish key storage, transaction integrity and interface reliability.
To conclude, every security setup comes with trade-offs. A Ledger is not flawless and can itself become a single point of failure, whether through the device, firmware, supply chain or the way it is used. But the largest and most persistent vulnerability is still the person holding the keys.
For most users, a properly configured hardware wallet remains the safest practical option because it reduces exposure and forces an additional verification step before funds can move.
People can store their assets however they choose, but I would not recommend using an internet-connected Apple device as the primary vault for significant funds.
A dedicated phone may be cleaner than a daily-use device, but it is still a networked general-purpose computer, not an isolated signing environment.




