{"id":70044,"date":"2026-08-08T19:19:26","date_gmt":"2026-08-08T16:19:26","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=70044"},"modified":"2026-08-08T19:19:26","modified_gmt":"2026-08-08T16:19:26","slug":"smartphone-cold-wallet","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/smartphone-cold-wallet\/","title":{"rendered":"Using a Smartphone as a Cold Wallet: Why It\u2019s a Bad Idea"},"content":{"rendered":"\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Why is using a smartphone as a cold wallet a bad idea? We look at the numbers, reports, and CVE records to explain why ZachXBT&#8217;s advice to replace a hardware wallet with a dedicated iPhone does not hold up from an architectural perspective.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On July 16, 2026, on-chain investigator ZachXBT wrote on Telegram that all hardware wallets were basically useless and suggested using a dedicated iPhone for crypto instead. The next day, Incrypted published a step-by-step guide on turning an ordinary smartphone into a cold wallet for zero cost.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The idea spread quickly because it sounds appealing: there is an old phone sitting in a drawer, and suddenly someone tells you it can replace a $100 device.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">We sell hardware wallets, so there is an obvious conflict of interest, and we are not going to pretend otherwise. That is why there will be no marketing here. We will look at CVE numbers, Google Threat Intelligence reports, exploit broker price lists, and forensic support matrices. You can verify every factual claim through the links in the article.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Our conclusion after checking the evidence is simple. The problem is not that ZachXBT is wrong about Ledger \u2014 some of his criticism is fair. The problem is that his proposed solution does not actually follow from that criticism.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A phone loses to a dedicated hardware device not because of the brand, but because of its architecture: the amount of code, the number of radio modules, and the fact that the screen and transaction signing live inside the same system.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What ZachXBT actually said \u2014 and what he did not<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70014\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-1024x573.jpg\" alt=\"ZachXBT avatar against an on-chain investigation data background\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">First, the facts, because social media retellings have already picked up details that were never in the original post.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On July 16, 2026, ZachXBT posted in his Telegram channel that \u201call hardware wallets are complete garbage\u201d and advised against using them for signing transactions or storing funds. He singled out Ledger as the worst option.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Instead, he suggested keeping a separate iPhone used exclusively for crypto. He also added that this setup is only suitable for technically experienced users.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>His main complaint about Ledger is the software, not the hardware.<\/strong> The company renamed Ledger Live to Ledger Wallet and added buying, swaps, staking, and yield features. Updates arrive frequently and, according to ZachXBT, can break basic functionality at exactly the moment you need to sign a transaction urgently.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Now for what the post did not contain. He did not demonstrate a vulnerability. He did not claim the Secure Element had been compromised. And he did not publish the kind of technical breakdown he is respected for in other areas.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is the opinion of an experienced practitioner, not a security study. That distinction matters, because \u201cthis device is badly designed\u201d and \u201cthis device has been hacked\u201d are two very different claims to verify.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>The second point that almost everyone missed:<\/strong> ZachXBT recommended a dedicated iPhone, not an air-gapped device with no network connectivity at all. That is an isolated hot wallet: the phone is still online, the app receives updates, and transactions are signed online.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The Incrypted guide takes the idea in a different direction: factory reset, SIM removed, radios disabled, and transactions signed through QR codes between two devices. That is no longer the same setup ZachXBT suggested. We cover both approaches because online discussions have largely merged them into one.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Danny Sanders, Trezor&#8217;s Chief Commercial Officer, responded the same day. He acknowledged that hardware wallets can be inconvenient and that a firmware update can genuinely get in the way of an urgent transaction.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">But he pointed to the key issue: a phone remains a general-purpose device where transaction verification and signing happen within the same trust domain. We will return to this in a dedicated section because it is the strongest argument in the entire debate.<\/p>\r\n\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>Neither side of this debate is claiming that private keys have been leaking directly out of hardware wallets. In 2026, funds are far more often stolen through fake apps, phishing, and address substitution. Keep that in mind when deciding which problem you are actually trying to solve.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">The category mistake: a cold wallet on a smartphone is not cold storage<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Cold storage means the private key has never been, and will never be, in an environment connected to a network. Not \u201calmost never.\u201d Not \u201cI turned off Wi-Fi.\u201d Never.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Now look at the process described in the guide. The phone has to be activated, updated to the latest supported version, connected to an app store, and used to download the wallet before it is isolated. On iOS, there is no way around this stage: activation and the App Store require a network connection.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So the device on which you later generate the seed phrase has already been online, has already received third-party code, and already has a history you did not verify.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/lwallet.com.ua\/en\/hardware-wallet-vs-exchange\/\">A hardware wallet<\/a> takes a different path. It generates entropy \u2014 the random data used to create the key \u2014 inside a Secure Element on a device that does not have a full general-purpose network stack. This is not a matter of user discipline; it is a property of the device architecture.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So the accurate description is this: an isolated smartphone gives you a hot wallet with a reduced attack surface. That is better than running MetaMask on your everyday phone. But it is not true cold storage, and calling it a full cold-wallet replacement is misleading.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">More code means more attack surface \u2014 and the numbers show it<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70017\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-1024x573.jpg\" alt=\"Codebase size comparison between Mobile OS and Hardware Wallet OS\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is the first point we can support with numbers rather than intuition.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A smartphone runs a full operating system: GPU drivers, a Bluetooth stack, font renderers, image parsers, media codecs, a browser engine, and vendor background services. Every one of those components was written by people, and every one can contain bugs.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Hardware-wallet firmware has a much narrower job than a full mobile OS. Its core role is to handle keys securely, display transaction details, and produce signatures.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">What does that mean in practice? In its <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/2025-zero-day-review\" rel=\"nofollow noopener\" target=\"_blank\">2025 review<\/a>, Google Threat Intelligence Group counted 90 zero-day vulnerabilities \u2014 flaws unknown to the vendor before exploitation \u2014 that were used in real-world attacks.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Of those, 39 affected operating systems, while mobile zero-days rose to 15 from 9 the year before. One Android security bulletin in December alone patched more than 100 vulnerabilities. Ledger or Trezor firmware does not see anything close to that volume simply because there is far less code involved.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A good example of how this works is LANDFALL,<\/strong> commercial-grade spyware that <a href=\"https:\/\/unit42.paloaltonetworks.com\/landfall-is-new-commercial-grade-android-spyware\/\" rel=\"nofollow noopener\" target=\"_blank\">Unit 42 analyzed<\/a> in November 2025. CVE-2025-21042 was located in Samsung&#8217;s image-processing library. The exploit was delivered through a specially crafted DNG image in a messenger app, often without any user interaction.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Samples date back to July 2024, while the patch arrived in April 2025. In other words, the vulnerability appears to have been used in the wild for roughly nine months before it was later added to CISA&#8217;s catalog of actively exploited vulnerabilities.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The important point is that none of these vulnerabilities were in a crypto wallet. They were in an image parser, a graphics driver, or a font engine.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">But any one of them can lead to privilege escalation, and once an attacker has system-level access, everything becomes visible \u2014 including the memory of the wallet app holding your key.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">The industry built around breaking into phones<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70020\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-1024x573.jpg\" alt=\"Cybercriminals working with phones and cash at a desk\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic4.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is the second point, and it is the one that concerns us most. Phones are constantly researched not just by hobbyists, but by commercial companies with serious budgets.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Look at the prices. Exploit broker <a href=\"https:\/\/www.crowdfense.com\/exploit-acquisition-program\/\" rel=\"nofollow noopener\" target=\"_blank\">Crowdfense<\/a> publicly offers up to $7 million for an iOS zero-click chain \u2014 an attack that requires no action from the victim \u2014 and up to $5 million for Android. Its overall exploit acquisition budget was $30 million.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Russia-based Operation Zero has said it is willing to pay up to $20 million for a full chain. For comparison, Google paid roughly $17 million in bug bounties across 2025. In some cases, a researcher can make more by selling a vulnerability to a broker than by reporting it to the vendor.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That creates a market. In its 2025 review, GTIG recorded for the first time that commercial surveillance vendors had overtaken state-backed groups in attributed zero-day use: 18 of 42 attributed cases were linked to commercial surveillance vendors.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Now consider Israeli mobile forensics, which is often misunderstood. Cellebrite and GrayKey \u2014 originally Grayshift, now part of Magnet Forensics \u2014 do not need to attack the protected chip directly. They exploit weaknesses in the operating system to bypass the lock screen and then extract data through the system itself.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Leaked support matrices <a href=\"https:\/\/www.404media.co\/email\/372da444-490f-4eec-9d7c-d281d26fb815\/\" rel=\"nofollow noopener\" target=\"_blank\">published by 404 Media<\/a> show a clear pattern: older devices and older OS versions often support full data extraction, while newer versions are marked as still under research.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That is an uncomfortable conclusion for anyone using a phone as a wallet. Secure Enclave or Titan M2 does not solve the problem if the path in is through firmware or OS vulnerabilities. No one needs to attack a protected element under a microscope when there is a cheaper route: bypass the lock screen and work with the system as root.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">And the worst part is that the exact device people usually recommend pulling out of a drawer \u2014 an old phone without current patches \u2014 is often the easiest category to extract data from.<\/p>\r\n\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>If your threat model includes physical access to the device \u2014 theft, loss, a border search, or seizure \u2014 keeping a seed phrase on a phone is one of the riskiest options. Most modern hardware wallets protect access with a PIN or another local authentication mechanism and limit brute-force attempts.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">The air gap that is not really there<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70023\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-1024x573.jpg\" alt=\"Disassembled smartphone with integrated radio modules on the board\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Third point. Guides usually tell you to remove the SIM card, enable airplane mode, and separately disable Wi-Fi and Bluetooth in settings. Those are sensible steps, but they do not create a true air gap. Here is why.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Airplane mode is a software flag. The operating system decides whether the transmitter is actually powered down. If the system is compromised, the flag itself no longer guarantees anything.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">You cannot simply remove the radios from a modern smartphone either. Wi-Fi and Bluetooth are typically integrated into the same combo chip, while the cellular modem is built into the SoC or soldered nearby.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Trying to physically remove them turns the phone into a brick, not an air-gapped device. You are not removing the radio; you are removing the phone&#8217;s ability to function.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">It gets more interesting from there. Since iOS 15, Bluetooth, NFC, and UWB chips can continue operating in a low-power mode for up to 24 hours after an iPhone is switched off, supporting features such as Find My, car keys, and payments.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Researchers at TU Darmstadt&#8217;s Secure Mobile Networking Lab showed in \u201c<a href=\"https:\/\/arxiv.org\/pdf\/2205.06114\" rel=\"nofollow noopener\" target=\"_blank\">Evil Never Sleeps<\/a>\u201d that the Bluetooth chip firmware was neither signed nor encrypted and that secure boot was not enabled for it. On a compromised device, code could be placed there and continue running even while the phone appeared to be off.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So \u201coff\u201d on a phone ultimately means \u201cthe system says it is off.\u201d Dedicated hardware wallets usually expose a much narrower set of interfaces, and some models have no wireless connectivity at all. COLDCARD Mk4, for example, physically includes NFC, but it is disabled by default and can be permanently disabled at board level if desired.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Tangem does have NFC, but it has neither a general-purpose operating system nor a battery, so there is nothing that can keep running invisibly in the background without the owner knowing.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">One screen, one trust domain<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This argument was not part of the original list of talking points, but in our view it is the most important one. It is not about a specific vulnerability; it is about architecture, which means a software patch cannot eliminate it.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">When you sign a transaction with a hardware wallet, the recipient address and amount are shown on a separate device with its own screen. An infected computer can display anything it wants, but the hardware wallet shows what is actually about to be signed, and you confirm it with a physical action on that device. That gives you a second, independent check.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On a phone, both the address display and the signature are produced within the same system. If that system is compromised, there is no independent verification left: the same software environment that prepares the transaction also controls what you see on screen.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is not theoretical. At ACM CCS in October 2025, researchers presented <a href=\"https:\/\/www.pixnapping.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Pixnapping<\/a> (CVE-2025-48561), an attack in which a malicious app with no special permission can reconstruct what another app displays by exploiting a side channel in the graphics pipeline.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Researchers extracted two-factor authentication codes in under 30 seconds on Pixel 6-9 devices and the Galaxy S25. They bypassed the September patch, and Google released another fix in December.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Now remember what the guide itself says about generating a seed phrase: 12 or 24 words are displayed in plain text on screen, and that is exactly when the phrase is most exposed. On a hardware wallet, that screen does not belong to a general-purpose operating system. On a phone, it does.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Operation Triangulation: when even Apple hardware is not enough<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is worth a separate look for anyone who believes Apple silicon settles the security question by itself. In 2023, Kaspersky disclosed <a href=\"https:\/\/securelist.com\/operation-triangulation-the-last-hardware-mystery\/111669\/\" rel=\"nofollow noopener\" target=\"_blank\">Operation Triangulation<\/a>, a chain of four zero-days that infected iPhones through an invisible iMessage with no interaction from the victim.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The most interesting link in the chain was CVE-2023-38606. The attack used an undocumented hardware feature in Apple chips: special registers that allowed the attackers to bypass hardware memory protection. The feature appeared in neither public documentation nor drivers, and it is still unclear how the attackers learned about it.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Why does this matter here? Secure Enclave and similar protected zones do not exist in a vacuum; they live inside the same SoC as the rest of the system. When researchers discover hidden mechanisms inside that SoC, claims about \u201cbank-grade security\u201d only hold until the next layer of research.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A hardware wallet may also contain a Secure Element, but the surrounding attack surface is usually a few buttons, a screen, and a limited set of interfaces \u2014 not a full operating system running a messenger that accepts incoming content from anyone in the world.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">A smartphone is a consumer device \u2014 it was not built for this<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70026\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-1024x573.jpg\" alt=\"Cold wallet on a smartphone \u2014 why a phone is not designed for this\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Fourth point. Smartphones are designed for multitasking, media, connectivity, and convenience. Their trade-offs are made in favor of features, not in favor of preserving one secret safely for many years. You can see that in three very practical areas.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Support ends sooner than you think<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">As of February 2026, more than 40% of active Android devices \u2014 over one billion phones \u2014 were running Android 12 or older versions for which Google no longer provides full system-level patching.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The old phone sitting in a drawer is exactly the kind of device this affects. The guide correctly says the phone should still receive security updates, but that removes the main argument about the setup costing nothing.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">The battery ages even inside a safe<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Lithium batteries age with time, not only with charge cycles. After several years in storage, you may end up with a swollen cell pressing against the screen and motherboard.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Hardware wallets either draw power from USB or use their own battery, while a card-format device such as Tangem has no battery at all.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Bringing the device back to life years later is harder than it sounds<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">To bring an iPhone back online after it has spent years in a safe, you may need Apple activation servers, an account, and the password for that account. That creates an external dependency on a company, its policies, and your ability to remember the credentials years later.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A hardware wallet can be powered over USB without asking anyone for permission. If the device itself fails, the seed phrase can be restored on any compatible wallet in minutes.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-table\">\r\n<table class=\"has-fixed-layout\">\r\n<thead>\r\n<tr>\r\n<th><strong>Criterion<\/strong><\/th>\r\n<th><strong>Smartphone used as a cold wallet<\/strong><\/th>\r\n<th><strong>Hardware wallet<\/strong><\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr>\r\n<td>Codebase size<\/td>\r\n<td>Full OS: drivers, image parsers, GPU, media stack, radio stacks<\/td>\r\n<td>Specialized firmware with a much narrower feature set<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Radio modules<\/td>\r\n<td>Physically present; disabled through software controls<\/td>\r\n<td>Depends on the model; some devices have no wireless radios<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Verification screen<\/td>\r\n<td>The same system that signs the transaction<\/td>\r\n<td>Separate screen and confirmation on the device itself<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Support lifetime<\/td>\r\n<td>3-7 years of updates, then the device remains exposed to known flaws<\/td>\r\n<td>No constant system updates required; signing happens on the device itself<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Power<\/td>\r\n<td>Lithium battery that continues to age even in a safe<\/td>\r\n<td>USB, built-in battery, or no internal power at all (card formats)<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Recovery after 3 years<\/td>\r\n<td>Activation, account credentials, vendor servers<\/td>\r\n<td>Seed phrase restored on any compatible device<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Real cost<\/td>\r\n<td>A supported phone, roughly $200-400<\/td>\r\n<td>From around $60 for a dedicated storage device<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/figure>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">The app store is part of the supply chain too<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The phone-based setup depends on one assumption: the wallet app you install is genuine. April 2026 showed how expensive that assumption can be.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">From April 7 to 13, a <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto\/\" rel=\"nofollow noopener\" target=\"_blank\">fake Ledger Live app<\/a> published by Leva Heal Limited was available in the macOS App Store. It copied the interface, passed review, and asked users to enter their seed phrase for \u201crecovery.\u201d<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In six days, more than 50 victims lost about $9.5 million. The three largest losses were all seven figures: $3.23 million in USDT, $2.08 million in USDC, and $1.95 million in BTC, ETH, and stETH. Musician G. Love lost 5.9 BTC accumulated over ten years.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">ZachXBT himself published the investigation into this scheme. That creates an awkward contradiction in his own recommendation: \u201cinstall a wallet from the app store on a separate phone\u201d still relies on the same distribution platform whose moderation failure he documented.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Android is not necessarily safer; the process is simply different. Users may need to move APK files manually and verify digital signatures themselves, something almost nobody does in practice.<\/p>\r\n\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>The rule is device-agnostic: no legitimate wallet will ever ask you to type your seed phrase into an app. If it does, assume theft, regardless of where you downloaded the software.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What a \u201cfree\u201d cold wallet actually costs<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Let us price the setup honestly using the guide&#8217;s own requirements. The device must still receive security updates, must not be rooted or jailbroken, must be used only as a wallet, and must never reconnect to the network after preparation.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A 2018 phone from a drawer already fails the first requirement. That means you need a currently supported model, which puts the cost around $200-400.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So you end up buying a $300 phone to avoid buying a purpose-built device that costs roughly $60-130. On top of that, you inherit the job of monitoring battery health and OS support.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The \u201cI will buy a used phone on OLX\u201d option adds another risk. You do not know the device history, you cannot see what may have been done to the firmware, and you have no realistic way to verify all of that at home. With a new hardware wallet, factory packaging and an authenticity check during initial setup address much of that uncertainty.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For users in Ukraine, there are two more practical considerations. First, blackouts: a phone needs charging, while a Tangem card or a Coldcard device does not require power simply to preserve access credentials.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Second, serviceability: if an end-of-life phone that is no longer supported by the manufacturer dies, a repair shop may not be able to help. A hardware-wallet setup, by contrast, can simply be restored from the seed phrase on another compatible device.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Where ZachXBT is right \u2014 and what to do instead<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Now for the fair part. His criticism hits a real problem; the conclusion is where we disagree.<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li>Companion apps really do keep growing. Ledger Live became Ledger Wallet with buying, swaps, staking, and yield features. That means more code in the exact place where users make financial decisions.<\/li>\r\n\r\n\r\n\r\n<li>Updates really can get in the way. If you need to sign a transaction urgently, a mandatory app update is a genuine problem, and Trezor has acknowledged that.<\/li>\r\n\r\n\r\n\r\n<li>Most theft does not require breaking the hardware. Fake apps, phishing, social engineering, clipboard address replacement. In January 2026, one victim lost roughly $282 million in a social-engineering incident even though the device itself worked as designed.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">But none of that means \u201cuse a phone instead.\u201d The more useful conclusion is to choose a device with less software around the signing process and design your setup so that one mistake cannot cost you everything.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">What we recommend instead:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li>An air-gapped device if you want to reduce dependence on companion software: Keystone 3 Pro can transfer data through QR codes, while Coldcard can use microSD without exposing private keys to an online environment.<\/li>\r\n\r\n\r\n\r\n<li>A passphrase on top of the seed phrase. It acts as an additional factor that is not stored with the seed and cannot leak with it.<\/li>\r\n\r\n\r\n\r\n<li>2-of-3 multisig for amounts that would be painful to lose. Compromising one device is no longer the end of the story.<\/li>\r\n\r\n\r\n\r\n<li>Clear signing and address verification on the wallet screen rather than in a browser. Always compare at least the first and last four characters.<\/li>\r\n\r\n\r\n\r\n<li>A small test transaction before the first large transfer. This applies to any setup, including a phone-based one.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Roman Storm, the Tornado Cash developer, <a href=\"https:\/\/beincrypto.com\/zachxbt-iphone-crypto-wallet-idea\/\" rel=\"nofollow noopener\" target=\"_blank\">made a sensible suggestion<\/a> in the same discussion: mobile wallets should add BIP39 passphrase support and offline signing. That is a path toward improving hot wallets, not replacing cold wallets with them.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">When a smartphone wallet can still make sense<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">We do not think this setup is pointless. There are three reasonable use cases.<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li>Learning. If you want to understand air gaps and QR-based signing before buying a dedicated device, build the setup on an old phone and test it with small amounts.<\/li>\r\n\r\n\r\n\r\n<li>A temporary solution for small amounts you can afford to lose completely.<\/li>\r\n\r\n\r\n\r\n<li>One key in a 2-of-3 multisig setup where the other two keys live on hardware devices. Diversity can actually help here because one vulnerability cannot compromise both required signatures.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">What we would not do is keep long-term savings, a life-changing amount of money, or assets intended for family members on a phone. In all three scenarios, user discipline stops being a reliable security component.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Conclusion<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" class=\"wp-image-70029\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-1024x573.jpg\" alt=\"Hardware wallet and metal seed phrase backup stored in a safe\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-768x430.jpg 768w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-350x196.jpg 350w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7-680x381.jpg 680w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/08\/blog-why-cold-wallet-in-smartphone-are-bad-choice-08-08-2026-content-pic7.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This debate is not really \u201cLedger versus iPhone,\u201d even though it is often framed that way. It comes down to three things, and a phone loses on all three by design: the amount of code that has to behave correctly, the number of radio modules you do not physically control, and the fact that the verification screen and the signing environment are part of the same system.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Our working approach after more than a decade in this space is simple. We use a hot wallet on a phone for small everyday transactions and amounts we can afford to lose. The main balance stays on a hardware device, with the <a href=\"https:\/\/lwallet.com.ua\/en\/how-to-store-a-seed-phrase\/\">seed phrase backed up on metal<\/a> and a passphrase on top.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For large amounts, we use multisig. Firmware gets updated when there is a reason to update it, not simply because a banner appears.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you still want to build a phone-based setup after reading this article, do it properly: use a supported model, dedicate the device to one purpose, keep it offline after preparation, store the seed phrase on metal, and run a test transaction. But do not call it equivalent to a purpose-built cold wallet, and do not keep more on it than you are prepared to lose.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Frequently asked questions<\/h2>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Can you actually turn a smartphone into a cold wallet?<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Technically, you can build a setup that signs transactions offline through QR codes. But it is not cold storage in the strictest sense: the device was already online during activation and app installation, and the radio hardware remains physically present.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Is Secure Enclave on an iPhone weaker than a Secure Element in a hardware wallet?<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The chip itself is strong; the question is what it actually protects. A key generated inside it is non-exportable. But that only helps when the wallet app truly uses hardware-backed key storage, something many wallets do not document in detail. And the chip itself has no way to know whether the address you are approving is the address you intended.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Has Ledger really become worse?<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There has been no demonstrated compromise of the private keys. The criticism is about software bloat and frequent updates. If that bothers you, the more logical alternative is an air-gapped device such as Keystone or Coldcard, not a smartphone.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What if I already own crypto but do not have a hardware wallet yet?<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Split the funds. Keep the amount you use or trade daily in a hot wallet, and move the rest to a hardware device once you have one. A dedicated phone can be acceptable as a temporary solution, but only after you have tested the full setup with a small amount.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Why is using a smartphone as a cold wallet a bad idea? We look at the numbers, reports, and CVE records to explain why ZachXBT&#8217;s advice to replace a hardware wallet with a dedicated iPhone does not hold up from an architectural perspective. On July 16, 2026, on-chain investigator ZachXBT wrote on Telegram that all &hellip;<\/p>\n","protected":false},"author":10,"featured_media":70012,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[633],"tags":[],"class_list":["post-70044","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hardware-wallets"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/70044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=70044"}],"version-history":[{"count":4,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/70044\/revisions"}],"predecessor-version":[{"id":70049,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/70044\/revisions\/70049"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/70012"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=70044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=70044"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=70044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}