Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

Hardware vs Software Wallets, What the Research Actually Shows

"Just get a hardware wallet" is common advice. It's usually right, but the reasoning behind it is often skipped. Here's what the actual research says about where each type fails. The data on where thefts come f

"Just get a hardware wallet" is common advice. It's usually right, but the reasoning behind it is often skipped. Here's what the actual research says about where each type fails.

The data on where thefts come from

Chainalysis's 2025 Crypto Crime Report found that private key compromises made up 43.8% of all stolen crypto in 2024, the largest single category. A mid-2025 update from the same firm showed personal wallet compromises rising to about 23% of all stolen-fund activity, nearly double the share from two years earlier. Most of that growth is phishing and social engineering against software wallets, not cryptographic breaks.

What academic testing of hardware wallets found

A team from Masaryk University published a large-scale security analysis of hardware wallets at the 2025 ARES conference. They built an automated rig to physically test 17 hardware wallet models from 11 vendors, collecting 3.4 million recovery phrases and signatures. Their finding: no significant cryptographic weaknesses across any of the devices tested, despite known ECC vulnerability classes like Minerva and TPM-Fail affecting similar hardware elsewhere.

That's a meaningfully strong result. It doesn't mean hardware wallets are unbreakable, though. The same paper cites earlier disclosed attacks, including Ledger's Donjon team demonstrating an unfixable seed-extraction attack against a Trezor model back in 2019, and a documented case of glitching a Trezor via electromagnetic fault injection through its enclosure. Those are physical attacks requiring the device in hand, a very different threat model from remote phishing.

So what's the actual split

  • Software wallets get compromised remotely. Phishing pages, fake browser extensions, malware, clipboard hijacking. The attacker never needs to touch your device.
  • Hardware wallets hold up well against that entire category, since signing requires physical interaction and keys never touch an internet-connected machine. Their weak point is physical possession: supply chain tampering, fault injection, or theft of the device itself.

Neither wins outright. They fail to different attackers.

Practical takeaway

For funds you're actively using, day-to-day spending, DeFi, frequent swaps, a software wallet is the reasonable choice. For anything you're not touching for months, the research supports moving it to hardware. That's also the framing most guides converge on informally, but it's worth knowing it holds up under actual academic testing rather than just being received wisdom.

The one thing that protects you against both categories equally: your seed phrase never gets typed into a website, ever. That's the step both phishing kits and most hardware attacks still depend on you getting wrong.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.