Private Keys are Mathematics, Wallets are Business: The Chaos of Web3 Wallets in 2026

By: rootdata|2026/07/27 05:29:55

Private keys are mathematics, wallets are business.


Written by: Fugui


Three news stories, plus one invisible, all talk about the same thing


On July 16, blockchain detective ZachXBT blasted on Telegram, claiming that all hardware wallets are garbage and not recommended for signing or storing large assets. He specifically criticized Ledger Live for its frequent updates and glitches, suggesting using a dedicated iPhone instead of a hardware wallet. The news caused an uproar online, with "hardware wallets are dead" trending everywhere. A Trezor executive later gave a somewhat weak response, admitting that hardware wallets and usability have yet to find a balance, but argued that ZachXBT was applying the most complex institutional scenarios to all ordinary users. This statement makes sense, but ordinary users remember the first half of it.


Ten days later, a lawsuit from a federal court in California made this debate even more ironic. Three users collectively lost $1.8 million in Bitcoin due to a counterfeit Sparrow Wallet in the App Store. The official Sparrow had never created an iOS client, yet the counterfeit app had been in the store for a long time. Developers reported it multiple times, but Apple was slow to respond, even marking the developer's own account as a violation and removing it. Users did not trust the wallet itself; they trusted Apple's golden brand. When that brand crumbled, the safety of the wallet became a secondary issue.


In the same week, Phantom announced it would stop supporting the Monad network starting August 26, meaning users would not be able to check balances or send transactions through the app. Although assets remained safely on-chain, the channel was effectively closed. Interestingly, the day before Phantom shut down Monad, it announced integration with Robinhood Chain. A new public chain launched while an old one was taken down, all within the same week’s product schedule. There might be real data supporting the decline in Monad's transaction volume, but users had no voting rights in this matter, and that is the crux of the issue. These types of wallets fundamentally do not allow users to customize RPC networks; the life and death of a chain depend on the product manager's resource scheduling, not on whether users want to use it.


Another issue, which did not make headlines but has been quietly brewing in developer forums for months, occurred in February 2026 when the official skill market of the OpenClaw ecosystem (ClawHub) suffered a supply chain attack. Thousands of malicious skill packages infiltrated the official market, specifically targeting hundreds of wallet formats and browser credentials. The victims were not ordinary retail investors but early users attracted by the "AI automated trading" selling point. This incident did not have a triggering point like ZachXBT's, but it burst a bubble much larger than the hardware wallet debate.


These news stories belong to four dimensions: the debate over security concepts, the collapse of distribution channels, centralized access rights, and the trust crisis in AI automation. Viewed together, they actually speak to the same issue: wallets have never truly returned control to users as they advertise. Each generation of wallets promises better security and more freedom, but each also plants new single points of failure within its own processes. The failure point of hardware wallets is human, while for software wallets, it is the distribution channel. For Agent wallets, the failure point is that AI brain which can be manipulated and is unclear about where the instructions come from.


The entry point to Web3 starts with a browser plugin


Ethereum's earliest official client, Mist, required syncing dozens of gigabytes of full node data, which ordinary people could neither afford nor use, making it merely a geek's toy with a rough interface and command-line operations. It was quietly discontinued in 2019. MyEtherWallet solved the issue of transferring and receiving coins but lacked the ability to interact with DApps. Users had to manually copy private keys and piece together transaction data; one wrong step could result in losing the private key. Both of these wallets predated MetaMask but could not be considered usable Web3 entry points; they were essentially just key storage boxes with interfaces.


In 2016, MetaMask launched, turning wallets into browser plugins that injected window.ethereum into web pages, allowing DApps to directly request signature approvals from wallets for the first time. Users no longer needed to run nodes or copy private keys; they could simply open a webpage, connect their wallet, and click confirm. The Connect Wallet paradigm became the industry standard from then on. EtherDelta, Compound, MakerDAO, and the later prosperity of DeFi and GameFi all grew on this foundational infrastructure. It can be said that before MetaMask, there were only addresses and private keys; after it, there were truly meaningful Web3 users. However, the cost of lowering the barrier to entry to ankle height left the entire mess of security for users to handle themselves, with malicious authorizations, fake plugins, and mnemonic phrases in cloud notes all capable of wiping out assets overnight.


The primary mission of a wallet is to securely store private keys + provide controlled and secure signing capabilities externally.


Going around in circles, the aim is to clarify what wallets are actually for. In the blockchain world, the only legitimate proof of any action is a signature. Transferring funds is signing a transaction, authorizing is signing a command, logging into a website is signing a message, and multi-signatures and permission delegation still fundamentally rely on layers of signature verification. The primary mission of a wallet is to securely store private keys and then provide controlled and secure signing capabilities externally. Transferring funds, managing assets, and connecting to DApps are merely the external packaging scenarios of the signing process. Without signing, a wallet is just an address display page, indistinguishable from a ledger. This statement serves as a common denominator for every section that follows; whether hardware, non-custodial, custodial, or Agent, the debate revolves around how to effectively accomplish this task.



The trust chain does not break from hardware; it starts breaking from the moment random numbers are generated


Theoretically, a private key is a 256-bit true random number, and brute-forcing it is akin to dreaming. However, in December 2020, a batch of Bitcoin was transferred from a mining pool address, amounting to approximately $3.5 billion at the time. The attack method did not involve breaking any device but rather stemmed from the wallet software using a weak random number generator when generating keys, leaving only about 32 bits of effective entropy. Modern computers could complete the exhaustive search in just a couple of hours, as thousands of addresses were opened like being unlocked with a master key. This incident only entered the public eye in 2025 when the U.S. Department of Justice announced the confiscation of the assets, which originally belonged to the LuBian mining pool controlled by Chen Zhi. The flaw that the private key carried from its inception cannot be compensated for by hardware isolation; that string of numbers you thought was impregnable might have been defective from the day it was born.


This case illustrates a very simple truth: the trust chain does not start with hardware; it begins the moment random numbers are generated. Every subsequent layer, whether firmware is open-source, whether the supply chain has been tampered with, how strict App Store reviews are, and whether customer service can be deceived by scripted responses, are all links in this chain. If any link is loose, all previous physical isolation becomes meaningless.


The logic of hardware wallets is straightforward: private keys are generated and signed in offline chips, never connected to the internet, physically isolating them from remote attacks. It sounds flawless, but when looking at the theft cases from the past six months, the $282 million loss in January stemmed from customer service tricking users into giving away their mnemonic phrases; in April, a fake Ledger Live client on the App Store stole $9.5 million; and in July, the Sparrow lawsuit resulted in a loss of $1.8 million. None of these cases involved the hardware chip itself being compromised; all fell victim to supporting software, phishing apps, and human gullibility.


ZachXBT's statement that "hardware wallets are garbage" certainly carries a provocative tone, but it does touch on a real pain point: hardware wallets only protect the private key, not the person holding the key. Interestingly, there has always been a self-deprecating recognition within the hardware wallet industry that "hardware wallets over $20 are a false demand." Indeed, the material cost of a secure chip cannot exceed $20, but turning it into a trustworthy product involves certification, auditing, and supply chain protection, each layer adding to the cost. Therefore, expensive does not necessarily mean it’s all false demand. However, when you realize that an old Android phone with a camera can be acquired for $20, loaded with an open-source wallet, and kept in airplane mode for offline signing before broadcasting online, a simple cold wallet can be established at a lower cost than the dedicated iPhone recommended by ZachXBT, without having to worry about App Store reviews. After all, Apple’s own store also faced issues this time. At this point, the saying "$20" takes on another meaning: rather than blindly trusting a box that costs hundreds of dollars, it’s better to think about how to simplify the signing process. Hardware wallets are not dead; what has died is the fairy tale of "plugging in means security." They can at most be considered the smallest unit of asset security, and users still need to build their own walls.


-- Price

--

Non-custodial wallets: The main force of Web3 and the largest conflict of interest


When private keys are held by users themselves, and platforms do not touch the assets but only provide interfaces, nodes, and aggregation services, these wallets are the main battleground for capital migration today. Regulators generally do not touch the wallet itself but only manage fiat currency channels and DEX aggregation services, which is also the institutional reason for the continuous increase in non-custodial wallet shares. On-chain data clearly indicates that over 70% of asset thefts are due to user behaviors like phishing and malicious authorizations, while pure code vulnerabilities account for a very low percentage; ultimately, the responsibility lies with the users themselves.


In the open-source camp, established software like Electrum and MyEtherWallet have all their code available on GitHub, allowing anyone to audit it and trace issues back to their source. In the closed-source camp, MetaMask and Phantom rely on user experience and ecological barriers to retain users, but opening the settings page reveals that whether one can add a custom RPC is the watershed for determining how open a wallet truly is. When Phantom shut down Monad, many users realized for the first time that they had no choice at all.


As for how wallets make money, it is not mysterious at all. Built-in swaps are the main source of income, with MetaMask's service fee consistently around 0.875% and Phantom around 0.85%. Trust Wallet takes a different approach, offering zero fees on the front end and relying on commissions from aggregators to survive. DApp listings and homepage recommendations follow closely behind, with monthly fees and revenue sharing, and top placements are often bid on year-round. Cross-chain bridge integrations can also share a piece of the pie, with protocol parties offering targeted commissions while wallets do not raise prices, leaving users completely unaware.

An awkward question arises here: can a homepage recommendation position that has received payment from the project party still fairly inform users about the risks of this DApp? It can inform, but it may not always be willing to do so. The business model of wallets and the safety interests of users are at odds in this scenario. Recommending a high-risk DApp with high commissions guarantees short-term profits, but when users encounter issues, the accountability chain is long, and it is highly likely that the responsibility falls back on the users for not clearly understanding the authorization. Non-custodial wallets are not charitable organizations; they are businesses that need to make a profit. This is not inherently problematic, but the issue lies in their simultaneous claim to be decentralized infrastructure. This label creates a natural conflict of interest with paid rankings, and the industry has yet to establish even basic disclosure mechanisms for this conflict.


Custodial Wallets: Worry-Free Bills Hidden from View


Custodial wallets are managed by exchanges or licensed institutions that hold the private keys, while users only have an account password. This is the smoothest entry point for outsiders into the crypto space. The benefits are direct: if you lose your mnemonic phrase, you can recover it; KYC is fully compliant; financial management and staking leverage are integrated, with almost zero operational thresholds. The downsides are equally direct: if it’s not your private key, it’s not your coins. If the platform runs away, is hacked, or is frozen by regulators, users have no means of resistance. All transactions leave traces, and privacy is virtually nonexistent.


With the implementation of MiCA and the promotion of the GENIUS Act, compliance costs have surged, leading nearly 20% of small platforms in the EU to shut down. Large withdrawals are collectively flowing into hardware cold wallets, and users have long voted with their feet, treating custodial wallets as a stepping stone rather than an endpoint. The profit structure of custodial wallets is more brutal than that of non-custodial ones. Built-in swaps charge explicit fees and also profit from the internal liquidity pool by taking advantage of the buy-sell price difference, creating dual profits. If cross-chain transactions are recorded on an internal ledger, with zero protocol fees and zero gas, it’s purely a business of moving numbers to pocket profits. The built-in MiniApp ecosystem is the most tightly controlled and also the most lucrative, with NFT transaction fees reaching 2% to 3% and chain game recharge fees ranging from 3% to 8%. This follows the logic of Apple’s tax, where all funds are settled through the platform’s liquidity pool, with T+7 to T+15 before being paid to the project party. Convenience has never been free; it’s just a different way of billing.


Agent Wallets: The Hottest Narrative of 2026 and the Naked Reality of Permission Systems


Now we can talk about Agent wallets, which are the hottest narrative in the entire crypto space for 2026, without exception. MetaMask, Coinbase, Binance, and TON are all promoting their own Agent wallet products. Whether it’s sub-wallet isolation or MPC three-party sharding, they all tell the same story: users set the rules, and AI automatically completes exchanges, dollar-cost averaging, and arbitrage, allowing users to earn passively.


The story sounds good, but it can easily falter upon implementation. Those who truly need automated trading have never lacked tools. Quantitative teams and MEV players build their own SDKs, using commercial MPC or HSM services like Turnkey or HashiCorp Vault for private key custody, and pulling a dedicated internal line in the data center. The signing nodes are physically locked, and logs are immutable. This level of rigor is far more stringent than any consumer-grade Agent wallet. They don’t need wallet manufacturers to grant them an automation button; they have already built the infrastructure themselves. In other words, Agent wallets are not aimed at knowledgeable users; their target audience is precisely those who are not familiar with command lines or programming but want to benefit from AI automation.


A real incident has already occurred, not involving a large amount, but the attack vector is worth noting. In May of this year, someone transferred an NFT to a wallet automatically generated by Grok. This NFT served as a master key within the linked trading robot system, Bankr, allowing its holder to bypass conventional transfer limits. The attacker then concealed a command in Morse code on X, which Grok parsed and approved a transfer according to the command: thirty billion DRB tokens, valued at approximately $150,000 to $180,000, were sent to the attacker. About 80% of the funds were recovered afterward, and the loss was not catastrophic, but it’s important to note where the problem lay: it was not that the AI was tricked into making an illegal operation; it was that the permission system itself left a backdoor, allowing anyone to grant themselves a green light by sending an NFT. The AI was merely the signer executing the order. The security community breaks down this type of attack into two halves: one half is prompt injection, and the other half is excessive authorization. Only when these two are combined do we have a complete attack chain.


This is not an isolated case. A report from a security research institution in July indicated that attackers have begun to hide commands in web pages and technical documents, specifically targeting AI agents that search the internet for information and execute tasks. The success rate is so high that researchers have used phrases like "alarmingly well" to describe it. Some baiting methods are as simple as making the AI mistakenly believe it is just paying a few dollars in service fees.


There is a technical paradox here. The legitimate design philosophy of mainstream Agent wallets is not to let AI rely on its own judgment to follow the rules, but to hard-code limits and whitelists into smart contracts or policy engines, expecting that even if the AI is compromised, the hard limits remain intact. The downfall of Bankr this time was precisely because permissions could be reissued by an external NFT, effectively creating a backdoor for these hard limits. When auditing an Agent wallet, the question should not be whether the AI's judgment is reliable, but rather who can reassign permissions to this AI and whether this process has been locked down.


Another layer of risk lies upstream, where the skills and plugin ecosystem itself can be poisoned, which is entirely different from the AI being induced during runtime. The supply chain attack against the AI Agent ecosystem in February involved thousands of malicious skill packages infiltrating the official market, specifically targeting hundreds of wallet formats and browser credentials. Many victims were those who were drawn in by the promise of automated trading. This is a supply chain issue; the skill packages installed are malicious software, which is completely different from prompt injection. Together, they represent the full spectrum of risks faced by Agent wallets today.


The final layer, and the one that no one wants to address, is who bears responsibility when something goes wrong. The current industry consensus is that high-risk operations must undergo manual secondary confirmation, and AI can only perform standardized repetitive actions within preset rules. This is why most serious Agent wallet product lines currently dare not open all switches. However, projects like Bankr have already automated execution to the point where no manual confirmation is needed. When something goes wrong, the loss falls on the user, and there is currently no clear legal framework to determine liability. Hardware wallets are criticized as garbage, but at least the attack surface is confined to one person and one device. Agent wallets expand the attack surface to the entire software supply chain and permission system, yet liability remains a blank slate.


Single Point of Trust Has Never Been Reliable


Looking back at the opening news: ZachXBT criticized hardware wallets because manufacturers have inflated single-point security into full-line security, leaving the ecosystem riddled with holes; fake wallets in the Apple store arise from centralized distribution that cannot accurately identify Web3 risks; Phantom's closure of Monad is due to the centralization of wallet permissions; Agent wallets face issues because external NFTs can reissue permissions, amplifying the attack surface of the skill ecosystem. The common root cause is single-point trust—trusting chips, stores, or permissions that can be easily reissued. If any of these fail, the game is over.


Multi-signature solutions (like Gnosis Safe) can prevent the loss of single-signature control, but they cannot guard against weak random numbers, fake applications, permission backdoors, or malicious contract recommendations, and they do not solve the complete pollution of the trust chain.


Three sentences for survival in 2026: Use open-source hardware cold storage for large assets; physically isolate mnemonic phrases on metal plates; do not trust ecosystems and customer service; wallets downloaded from stores may be fake; if there is no legitimate version, do not search for it, verify official signatures; only put money you are willing to lose in Agent wallets, and large amounts must undergo hardware secondary confirmation, treating AI as an intern. Private keys are mathematical and never lie; every layer of hardware, software, distribution, and automation must be verified, not trusted. This is the only conclusion worth taking away from this farce.

Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com