Thought leadership | 09/30/2026
When It Comes To Wallet Security, Hardware Wins Over Software
Crypto theft shows no sign of slowing. $1.65 billion was lost in the first seven months of 2026 alone*, following a record-breaking $11 billion in losses across 2025. The data is clear: the fastest-growing attacks succeed because software wallets store private keys on internet-connected devices, increasing exposure to many common attack vectors. Secure hardware devices like signers can help to solve this, so why do software wallets remain more popular?
Before You Dive In:
- As Ledger CTO Charles Guillemet notes, AI is already reducing the costs of researching and exploiting security vulnerabilities.
- In 2025, the FBI logged over 181,000 crypto-related complaints totalling more than $11 billion in losses, while on-chain data recorded 158,000 personal wallet theft incidents, nearly triple the number seen in 2022.
- The dominant attack vectors of 2025, silent infostealer malware and transaction-approval phishing, succeed specifically because software wallets store private keys on devices that are already connected to the internet.
- Given the security concerns stemming from software wallets, why do they remain so popular with users, and how can secure hardware reach wider adoption?
Crypto theft is no longer a niche problem. In 2024, the FBI’s Internet Crime Complaint Center (IC3) recorded nearly 150,000 crypto-related complaints, with reported losses reaching $9.3 billion, a 66% jump in a single year. In 2025, that figure climbed further to more than $11 billion across 181,000 complaints. Americans over 60 alone reported around $7.7 billion in cybercrime losses overall, up 37% year over year, with crypto-related fraud accounting for a significant and growing share.
Behind those numbers is a story about wallet architecture. The attacks driving this surge don’t rely on cracking encryption or exploiting obscure blockchain bugs. More often than not, they succeed because many users inherently prioritize convenience over security. While modern smartphones and computers deliver a UX optimized for holding attention and managing many daily tasks, these internet-connected devices are simply not built to secure secrets.
This may have been a sacrifice that users were willing to gamble on in the past. However, with the emergence of AI-aided security threats changing the calculus, the need to secure your digital life with purpose-built hardware is becoming clearer than ever. That’s exactly what Ledger signers are designed to do.

The Scale of the Problem: Crypto Theft Is Now Mainstream
On-chain analysis from Chainalysis reinforces what the FBI data shows at the macro level. Researchers recorded roughly 158,000 personal wallet theft incidents in 2025, nearly triple the 54,000 seen in 2022. The number of unique victims grew from around 40,000 to at least 80,000 over the same period. Solana, one of the most active personal wallet chains, accounted for the single largest share at around 26,500 victims.
Significantly, total dollars stolen from individuals reached $713 million in 2025, even as personal wallets’ share of all stolen value appeared to fall. That apparent decline is almost entirely explained by the February 2025 Bybit hack, a single $1.5 billion exchange incident that inflated the year’s total. Strip that outlier out, and the personal wallet share rises to roughly 37%. The pattern is clear: more people are being targeted, for smaller amounts, more often.
Notably, 2025’s IC3 report was the first time the FBI featured a section on AI scams, with a reported cost to Americans of around $893M, putting a further exclamation point on AI’s growing relevance as a growing attack vector.
The Economics of Scams
Criminals tend to follow the path of least resistance toward the highest return, which is why the same economic logic that drives bank fraud, card skimming, and fake Amazon listings now drives crypto theft.
The asset class is new enough that many holders may not yet have built the healthy skepticism they apply to a suspicious email claiming to be from their bank. That unfamiliarity creates a window of opportunity, and attackers are exploiting it at scale; the data shows an increasingly broad cross-section of holders across every chain and experience level falling victim to scams.
How Attackers Actually Steal Keys
The standout threat of 2025 was infostealer malware. Across all credential types, researchers at Flashpoint and DeepStrike documented more than 1.8 billion credentials harvested from roughly 5.8 million infected devices across 2025, representing an approximately 800% surge in recent years.
Silent Key Theft by Malware
Crypto wallets are among the targets these tools are specifically hardcoded to seek out, alongside browser-extension wallets, and a theft can be completed in seconds while the victim notices nothing.
The consequence is permanent. Once a seed phrase is exposed, it cannot be changed or revoked. There is no chargeback and no dispute process. If an attacker drains the wallet, the funds are likely gone, with the chances of restitution limited.
Tricking You Into Signing
The second major attack vector works differently: rather than stealing your key, it tricks you into authorizing a malicious transaction. Drainers are phishing tools that impersonate legitimate crypto services. Once you sign, the transfer executes within seconds and cannot be reversed.
This category has become increasingly professionalized. Drainer-as-a-service operations exist that pair developers who maintain malicious infrastructure with affiliates who distribute phishing lures and share in stolen proceeds.
A Shift in Attack Vectors
Behind the data, there is a shift toward harder-to-track attack vectors, namely private-key compromises and targeted social engineering. Many of these attacks target the private key itself, which a software wallet keeps on an internet-connected device.
A growing share of that shift involves attacks that begin long before any transaction is attempted. Attackers use open-source intelligence (OSINT) gathering, scanning social media, blockchain explorers, and data-broker records, to identify holders worth targeting before building personalised, long-con scams.
Pig butchering is one of the most industrialised forms, a technique where attackers cultivate trust over weeks or months before introducing a fraudulent investment opportunity.
Why a Signer Is Structurally Safer
Every attack described above ultimately needs one thing: your private key, or your signature. The most important security decision you make as a crypto owner is therefore where your private keys are stored.
Where Your Keys Live
A software wallet stores your private key on an internet-connected device, the exact environment infostealer malware is designed to raid. The moment that device is compromised, the key can be exfiltrated remotely, often in seconds.
By contrast, a Ledger signer is designed to prevent remote key extraction by isolating private keys in a certified Secure Element, a fundamentally different architecture from software wallets.
What Makes the Architecture Different
Three properties set a Ledger signer apart from any software-based approach.
Your keys stay offline, in the Secure Element.
Private keys are generated and locked inside a Secure Element chip, a certified, tamper-resistant component also used in banking cards and passports. Transactions are signed inside the chip, and the device is designed to send only the resulting signature to your computer or phone, so your private keys are not exposed to malware running on it.
Every transaction requires on-device confirmation.
Before any outgoing transaction executes, the details appear on the signer’s own Secure Screen for physical review and approval. The Secure Screen is driven by the Secure Element and designed to resist tampering by software on your laptop or phone. Reviewing the details there helps you spot the fake-interface tricks used in drainer attacks.
Clear Signing translates code into plain language.
Blind signing means approving a transaction without understanding its full details, and it was the direct cause of the Bybit hack and countless individual losses. The Clear Signing standard translates complex smart contract code into human-readable information on the Secure Screen: recipient address, amount, token name. You see exactly what you are signing before you confirm it.
Threat-by-Threat: Software Wallet vs. Ledger Signer
| Threat | Software wallet | Ledger signer |
| Infostealer malware reads the key off your device | Key sits in device storage | Key isolated in the Secure Element |
| Keylogger or clipboard hijack | May be susceptible | Nothing typed reveals the key |
| Malicious transaction approval (drainer) | May be invisible in the wallet interface | Forced on-device review of destination and amount via Clear Signing |
| Remote or network exploit | Possible while online | Keys isolated in the Secure Element; extracting them typically requires physical access to the device |
Don’t Make Me Think
Despite the overwhelming evidence showing the security risks of using software wallets, they remain the most popular method for managing digital assets, presenting something of a paradox; yet this is exactly how human nature works. There is a huge array of hard-wired behavioural biases – simple rules of thumb inherited from our ancestors for fight-or-flight scenarios – that, in a world of information overload, seem to act against our own best interests. Normalcy bias is one example.
Normalcy bias is the tendency to underplay threat warnings, assuming life will just continue as normal. When coupled with the natural inclination to stick to default behaviours and the allure of convenience that smartphones offer, many crypto users assume bad things will happen to someone else and stick with their cherished devices.
So what is the solution?
Education will remain a central mantra in the drive toward furthering digital ownership adoption, but Steve Krug’s seminal work on UX, ‘Don’t Make Me Think,’ hints at how adoption shifts meaningfully away from insecure phones. The key is improving the UX of hardware signers to the point where convenience-focused users don’t notice the difference.
The good news is that hardware security has come a long way since the earliest days of crypto. Hardware devices like modern Ledger signers are built to be intuitive and fast, while keeping your private keys offline and protected against remote attacks. In tandem, buying crypto, swapping assets, staking, and managing a portfolio across chains can all be done through a single app**, with a single physical confirmation on a secure screen.
Security in the Agentic Era
That same model now extends into the AI agent era. With Ledger Agent Stack***, agents can read your accounts and prepare transactions, while sensitive actions are routed to your signer for physical confirmation. As a result, there is no longer a need to choose between convenience and security; users can have both, but there remains a limit to what a signer can protect users from.

The Honest Limit
A Ledger signer prevents remote key extraction, but it does not stop you from typing your seed phrase into a phishing website. No device can do that.
That is why the right approach combines three habits: keep your keys offline with a signer, verify every transaction on the device’s Secure Screen, and never enter your Secret Recovery Phrase anywhere except the device itself. These three habits, working together, close the door on nearly every loss documented above.
Ledger Wallet™: Your Secure Gateway to Digital Ownership
The data from 2025 makes the architecture argument clear. 158,000 incidents of personal wallet compromises. $11 billion in reported losses. Malware that can drain a software wallet in seconds, and the accelerating improvement in AI reducing the cost of hacking all the time. Ledger signers are built to meet these baseline threat conditions for anyone holding digital assets today, and security continues to evolve to meet the changing security landscape of tomorrow, improving, not sacrificing, convenience to settle the argument that when it comes to protecting your digital assets, signers win over software wallets.
While a Ledger signer provides the security foundation, Ledger Wallet™ provides the interface, as the all-in-one app through which you buy, sell, stake, swap, send, and receive across chains, with every transaction routed through your signer for final approval**.
Ledger Wallet™ connects you to the full breadth of the crypto ecosystem, and that breadth is about to get wider. This October, new ways to pay and borrow land in the app, each one still routed through your signer for a physical confirmation before it moves. Security and convenience work as a unified system, one that keeps adding capability without asking you to trust anything more than the screen in your hand.
Ready to secure your digital assets? Explore Ledger signers in the Ledger shop and take control of your digital ownership today.
JF Rochet, Executive VP Consumer Services
*Source Nominis
**Crypto transaction services are provided by third-party providers. Ledger provides no advice or recommendations on use of these third-party services.
*** Agent Stack consists of technology tools providing cryptographic signing capabilities and developer resources. They are not financial advice or execution services. All transactions require affirmative physical confirmation on your Ledger device before execution. Ledger does not hold your assets, control AI agent parameters or outcomes, or warrant these early-stage tools. Use of the Ledger Wallet CLI is subject to the Ledger Wallet Terms of Use and respective terms and conditions of any third-party services available through this tool. Learn more at https://developers.ledger.com/docs/ai-tools/overview.