
Quick answer: Yes, security researchers have broken into hardware wallets, but every documented case required something most attackers will never have: physical possession of your device, often combined with disassembling it, a missing passphrase, or a tampered unit from before you ever opened the box. A 2018 conference called Wallet.fail cracked open a Trezor One and a Ledger Nano S on stage. A 2024 discovery called EUCLEAK showed that even certified security chips can leak secret keys given a few minutes of lab access. None of this happened remotely, and none of it happened to someone who set up their device correctly and kept it in their own hands. The famous “Ledger got hacked” story from 2020 was not a wallet hack at all, it was a leaked customer mailing list. The real lesson from the research is narrower and more useful than the headlines suggest.
The headline and the fine print
Search “can a hardware wallet be hacked” and you get a wall of alarming headlines. Search engines reward the scary version of a story, not the accurate one. The accurate version is this: yes, dedicated security researchers have extracted private keys from hardware wallets, published their methods, and gotten vendors to patch the holes. No, nobody has done this to a stranger’s wallet over the internet while that stranger was using the device normally.
That gap between “hacked in a lab” and “hacked in your pocket” is where almost every scary headline about crypto hardware falls apart. It is also the gap worth understanding before you decide whether a hardware wallet is overkill or the bare minimum.
Wallet.fail: three wallets, one stage, zero internet connections
In December 2018, at the Chaos Communication Congress in Leipzig, three researchers, Dmitry Nedospasov, Josh Datko, and Thomas Roth, presented a project called Wallet.fail. They had bought Trezor, Ledger, and KeepKey devices and spent months taking them apart.
On the Trezor One, they extracted the private key stored on the device. The catch: this only worked because the wallet did not have a passphrase set. A passphrase, sometimes called a 25th word, adds a second secret on top of the recovery phrase, and it closes this exact attack path.
On the Ledger Nano S, they compromised the device’s bootloader and installed custom firmware. As proof, they got the device to run the video game Snake, a cheeky way to show they had full code execution. Ledger’s secure element, the chip that actually guards the private key, stayed intact. The attack broke the surrounding firmware, not the vault itself.
Researchers also described a scenario for remotely triggering a signed transaction from a Ledger Nano S. Ledger’s team pushed back hard on this part, calling the required setup an “unpractical scenario” that assumed a computer was already compromised in a very specific way.
What every one of these attacks had in common: the researchers needed the physical device in their hands, usually opened up with a screwdriver, sometimes for hours.

A 15-year-old found the supply chain problem
A few months before Wallet.fail, in March 2018, a then-15-year-old security researcher named Saleem Rashid published a different kind of finding on the Ledger Nano S. Rashid showed that the device’s non-secure microcontroller, the chip that talks to your computer, could be made to lie to the secure element about what firmware was genuinely installed.
The practical risk Rashid described was not someone hacking your wallet while you used it. It was a wallet tampered with before it ever reached you, during manufacturing or shipping, then resold or intercepted. Ledger patched the flaw and has since emphasized buying only from its own site or verified resellers, precisely because this class of attack depends on intercepting the supply chain, not breaking the cryptography.
EUCLEAK: a 2024 reminder that certification is not invincibility
In 2024, a research outfit called NinjaLab published an attack they named EUCLEAK. It targeted a cryptographic library, made by the chipmaker Infineon, used inside security chips found in YubiKey authentication devices and, more broadly, in other hardware relying on the same chip family, including some crypto hardware wallets.
The flaw had sat unnoticed for roughly 14 years, surviving around 80 separate Common Criteria security evaluations, the same certification process hardware wallet vendors point to as proof of their devices’ strength. NinjaLab’s method pulled a secret key off the chip using electromagnetic side-channel measurements, a few minutes of highly specialized lab work with equipment a casual thief will not have lying around.
EUCLEAK is a useful gut check: certification reduces risk, it does not eliminate it, and the strongest-sounding compliance badge does not mean a flaw is impossible, only that it has not been found yet.
The myth that will not die: “Ledger got hacked in 2020”
This is the one that causes the most confusion, because the headline is technically true and almost completely misleading. In June 2020, Ledger’s e-commerce and marketing database was breached. Roughly one million email addresses and about 270,000 physical addresses and phone numbers of customers were exposed, and some of that data later surfaced in a public leak.
What was not touched: recovery phrases, private keys, or any funds. The breach hit the database that stored order history and shipping labels, a completely separate system from the secure element inside the device itself. Nobody’s wallet was drained because of this breach. People did get a wave of targeted phishing emails afterward, because attackers now knew exactly who owned a hardware wallet and what their mailing address was, which is a real and ongoing annoyance, just not a wallet compromise.
Conflating “a company’s customer database leaked” with “the hardware got hacked” is the single most common error in how this story gets repeated.
What actually keeps you safe, based on what the research shows
Pulling the real lessons out of five years of published attacks gives a short, specific list rather than a vague “be careful”:
Set a passphrase. It is the one feature that directly defeated the Wallet.fail key-extraction attack on the Trezor One, and it protects against anyone who gets physical access to your device or its recovery phrase later.
Buy direct, or from a vendor the manufacturer explicitly names as authorized. Rashid’s finding and similar supply-chain concerns only work if an attacker can intercept or pre-configure a device before it reaches you.
Keep the device, not just the seed phrase, somewhere a stranger cannot casually access it. Every attack above needed hours of uninterrupted physical access, often with the case opened.
Update firmware when the vendor tells you to. Both Wallet.fail-era issues and EUCLEAK led to firmware or hardware revisions. A device running years-old firmware is carrying flaws the vendor has already fixed for everyone else.
Treat a secure element as a strong default, not a guarantee. Chips with dedicated secure elements and a track record of surviving public scrutiny are a meaningfully better starting point than a software wallet on a general-purpose phone or laptop that is constantly exposed to the internet.
Our take: a hardware wallet with a passphrase enabled is the single strongest defense the research above actually supports. Trezor has one of the longest public track records in the space, partly because its devices have been a research target since 2014, and partly because its response to that scrutiny (open-source firmware, passphrase support, documented fixes) is part of why the device shows up in security writeups instead of silently failing.
The bottom line
Every publicly documented hardware wallet compromise needed physical possession, a missing passphrase, or a tampered device from before purchase. None of them worked against a normal user who bought from an authorized source, set a passphrase, and kept the device in their own custody. The 2020 Ledger story that still scares people off hardware wallets was not a wallet hack at all, it was a mailing list leak.
Hardware wallets come out of this research looking solid, not shaky. The handful of ways researchers have actually gotten in only confirm how narrow the opening really is.
If you have not set one up yet, our hardware vs. software wallets guide walks through the decision, and protecting your seed phrase from common scams covers the other half of the same problem.
Common questions
Can a hardware wallet be hacked remotely over the internet? No documented case has compromised a hardware wallet’s private key remotely while it was in normal use. Every attack published by security researchers, including the 2018 Wallet.fail demonstrations and the 2024 EUCLEAK research, required physical possession of the device, often disassembled, or a device tampered with before it reached the owner.
Was Ledger’s hardware actually hacked in 2020? No. The 2020 incident was a breach of Ledger’s e-commerce and marketing database, exposing customer emails, addresses, and phone numbers. Private keys, recovery phrases, and funds were never accessible through that breach, because the database was entirely separate from the device’s secure element.
Does setting a passphrase actually stop these attacks? Yes, at least against the specific attacks published so far. The Wallet.fail researchers confirmed their Trezor One key-extraction method did not work on a device with a passphrase enabled, since it adds a secret that is never stored on the device itself.
Should I still use a hardware wallet after reading about these hacks? The research supports hardware wallets more than it undermines them. Every successful attack needed hours of physical access, specialized lab equipment, or a tampered supply chain, a far higher bar than the remote attacks that regularly drain software wallets and browser extensions.
Leave a Reply