Hardware wallet vs software wallet vs seedless: a 2026 market analysis
By Al Jobson · 12 min read · September 2026
The self-custody wallet market is fragmenting. Ledger and Trezor still dominate the hardware category, MetaMask and Phantom still dominate the browser and mobile category, and a third category — seedless wallets built on MPC or Shamir plus secure enclaves — is growing fast on the back of every seed-phrase drain and every wrench-attack headline. This is a look at where each design actually stands in 2026, using the numbers rather than the marketing.
Market context: who owns the wallet layer in 2026
MetaMask, still the reference EVM wallet, reported roughly 30 million monthly active users at its 2022 peak and has hovered near the low-to-mid teens of millions of MAU through 2024–2025 as activity migrated to L2s and to mobile-native competitors[1]. Phantom crossed 15 million MAU in 2024 on the back of the Solana memecoin cycle and raised at a $3B valuation[2]. Trust Wallet claims more than 200 million installs across iOS and Android[3].
Hardware is a smaller, stickier market. Ledger has shipped over 7 million devices since 2014 and Trezor more than 2 million[4][5]. Coldcard, Foundation Passport, BitBox, and Keystone split the remainder of a hardware-wallet TAM that Grand View Research put at roughly $600M in 2024 and projected past $2B by 2030[6].
The third category — MPC and threshold-signature wallets — is where the interesting institutional and prosumer money went. Fireblocks last raised at an $8B valuation[7]. ZenGo, Coinbase Wallet (via WaaS), Web3Auth, and newer seedless self-custody wallets including Veyrnox split the retail slice.
The threat side scaled with the market. Chainalysis measured $2.2B stolen from crypto services and wallets in 2024 across 303 incidents; $2.17B in H1 2025 alone — the Bybit exploit in February 2025 accounted for ~$1.5B, the largest single crypto theft on record[8][9]. Scam Sniffer reported $494M stolen from ~332,000 addresses in 2024 via phishing signatures alone — a 67% jump[10]. Almost every one of those drains happened on software wallets after a user signed a malicious payload; almost none required the attacker to touch a private key.
Attack surface: a real comparison
The wallet-security debate collapses into one question — where does the signing key live, and what has to be true for it to sign something the user didn't intend?
| Dimension | Hardware (Ledger, Trezor, Coldcard) | Software (MetaMask, Trust, Phantom) | Seedless / MPC / SSS |
|---|---|---|---|
| Key material | 12/24-word seed on secure element | Seed encrypted on device, decrypted in RAM at sign time | No seed. Key shards (MPC) or Shamir shares (SSS) across enclaves + backups |
| Remote drain (phishing signature) | Possible — user still approves on-device with small screen[11] | Highest exposure — one bad signature drains[10] | Same signature risk unless wallet parses + warns; policy engines can block |
| Supply-chain risk | Real — Ledger Connect Kit compromise drained ~$484k in Dec 2023[12] | Extension-store + NPM dependency risk | App-store review + reproducible builds where offered |
| Seed-phrase phishing | Primary loss vector — recovery-phrase scams[13] | Same — every drainer kit asks for the seed as fallback | N/A — no phrase to phish |
| Coercion / $5 wrench | Poor — attacker gets device + PIN + seed[14] | Poor — attacker unlocks app under duress | Varies — decoy PIN, duress accounts, threshold policies reduce loss |
| UX friction | High — cables, screens, firmware | Low — one tap | Low to medium — biometric unlock, no phrase to store |
| Retail cost | $79–$220 + shipping | Free | Free tier + paid safety tiers common |
What hardware wallets actually solve
They isolate the signing key from a compromised host. A keylogger on a laptop cannot lift a seed off a Ledger Nano or a Coldcard. For a passive attacker model (malware, remote code execution on the daily-driver machine), hardware wallets remain the strongest single-device answer.
Where they fail
They do not solve the two loss vectors that actually dominate the numbers. First, blind signing: the drainer sends a permit or a set-approval-for-all, the small on-device screen shows an opaque hash, the user approves, funds gone. Ledger's own Clear Signing initiative exists because this is the majority of hardware-wallet losses[11]. Second, the seed itself: Kraken Security Labs demonstrated physical seed extraction from a Trezor One in 15 minutes with $75 of equipment in 2020[15]; Ledger Donjon and wallet.fail have published multiple hardware advisories[16]; and the Ledger Recover launch in May 2023 — firmware capable of exporting seed shards to a third party — became the most-discussed trust event in the category's history[17].
MPC and seedless: where the newer designs fit
MPC wallets replace the seed with a threshold signing scheme — the private key never exists as a single object, and a signature is jointly computed from shares across parties. GG18 and GG20 are the reference protocols for threshold ECDSA[18]; Lindell17 covers the two-party case that most retail MPC wallets use[19]. Trail of Bits and others have published breaks and fixes for early implementations — TSSHOCK against GG18/GG20 in 2023 is the best-known[20]. MPC's security is protocol-dependent, not automatic.
Shamir Secret Sharing, published by Adi Shamir in 1979[21], takes a different route: the signing key exists inside a hardware-backed enclave (Apple Secure Enclave, Android StrongBox), and only the backup is split into m-of-n shares distributed across trusted parties, cloud storage, and offline media. Trezor's SLIP-39 uses the same primitive[22]. Veyrnox uses SSS for backup and the phone's Secure Enclave for signing.
| Property | Seed-based (BIP-39) | MPC / TSS | SSS backup + enclave signing |
|---|---|---|---|
| Private key exists as one object? | Yes | Never | Yes, sealed in secure hardware; never exported |
| User-visible secret | 12 or 24 words | None | None (shares distributed at setup) |
| Recovery model | Reveal phrase, restore | Reshare / key refresh | Reconstruct m-of-n shares |
| Coercion resistance | Weak | Depends on policy engine | Depends on duress features |
| Examples | Ledger, Trezor, MetaMask | Fireblocks, ZenGo, Coinbase WaaS | Veyrnox, Trezor SLIP-39 backups |
Coercion: the vector no wallet marketing likes to discuss
Jameson Lopp maintains a running list of documented physical attacks on crypto holders — the count crossed 170 incidents by mid-2025, with sharp spikes tied to price cycles[23]. Kidnappings in France, home invasions in the US, torture cases in Thailand and the UAE have all made mainstream press in 2024 and 2025[24]. Every one of these bypasses cryptography by attacking the human.
The traditional hardware-wallet answer is the passphrase — a 25th word that opens a different wallet. This works for the sophisticated user who can keep the story straight under stress. It fails most people because it looks nothing like the normal-use flow: there is a checkbox, a pause, a different balance. A determined attacker who has read the same Ledger documentation the victim did will ask, "and now the one with the passphrase."
Design-level duress features — decoy PINs that open a plausible small-balance wallet, duress accounts that silently trigger alerts, threshold policies that require a co-signer for withdrawals above a limit — are where seedless and MPC categories can differentiate. Veyrnox's Safety Plus tier ships decoy PIN and duress protection; Casa's multisig product has offered a functionally similar answer at higher setup cost for years[25].
Recovery: the second most-lost-funds category
| Recovery model | Who can restore | Common failure |
|---|---|---|
| Written seed phrase | Anyone who finds the paper | Fire, flood, loss, phishing, theft, spouse |
| Metal backup plate | Same as above, durable | Same threat, better substrate |
| Ledger Recover | User + 3 custodians[17] | Trust in third parties; regulatory exposure |
| Multisig (Casa, Unchained) | M-of-N key holders | Setup complexity, on-chain cost |
| Social recovery (Argent, Safe) | Guardian set | Guardian coordination, compromise |
| MPC reshare | Provider + user share | Provider dependency |
| Shamir (SLIP-39, Veyrnox) | M-of-N share holders | Share distribution discipline |
Chainalysis has estimated roughly 3.7 million BTC — around 20% of supply — are likely lost, most from forgotten keys and lost phrases[26]. Recovery UX is not a nice-to-have; it is where a large fraction of self-custody funds already went to die.
Practical guidance
- Small day-to-day balance you actually spend. A software wallet is fine. Turn on transaction simulation (Rabby, Pocket Universe, Blockaid) and treat every signature like an outbound wire.
- Long-term holdings you don't touch. A hardware wallet remains the mainstream answer. Store the seed on metal, in two locations, and never type it into anything ever.
- You travel, live somewhere with physical-attack risk, or your holdings are known. A wallet with real duress features matters more than the choice of secure element.
- You cannot be trusted to safely store a seed phrase. A seedless design (MPC or SSS + enclave) removes the failure mode that causes the majority of self-custody losses.
- You're moving institutional size. MPC with a policy engine (Fireblocks, Copper, Anchorage) is the category answer.
Bottom line
Hardware wallets solved the remote-malware problem in 2014 and still solve it in 2026. They did not solve blind signing, seed phishing, or coercion, and the numbers from Chainalysis and Scam Sniffer are unambiguous about where losses now come from. Software wallets solved UX and lost almost half a billion dollars to signature phishing last year. MPC and seedless designs solved the seed-phrase failure mode and introduced protocol and provider risks of their own.
The right wallet in 2026 is not a category; it is a match between how you actually hold, spend, and get attacked. For most retail users, "no phrase to lose, no phrase to phish, and a duress story that isn't a passphrase" is the shape of the answer — whether that ships as MPC, as Shamir plus enclave, or as multisig.
Try the seedless model
Veyrnox is a seedless, self-custody wallet for iOS and Android. Keys are generated and used inside the phone's Secure Enclave; backup is Shamir m-of-n; the Safety Plus tier adds decoy PIN and duress protection. Download or read the security model.
Sources
- Consensys, "MetaMask MAU." consensys.io
- Phantom, Series C announcement 2025. phantom.com
- Trust Wallet, "About." trustwallet.com
- Ledger, corporate press. ledger.com
- Trezor / SatoshiLabs, milestones. trezor.io
- Grand View Research, "Hardware Wallet Market 2024–2030." grandviewresearch.com
- Fireblocks Series E, $8B valuation. fireblocks.com
- Chainalysis, "2025 Crypto Crime Report." chainalysis.com
- Elliptic, "Bybit hack analysis." elliptic.co
- Scam Sniffer, "2024 Phishing Report." drainer.io
- Ledger, "Clear Signing initiative." ledger.com
- Ledger, "Connect Kit exploit post-mortem." ledger.com
- FBI IC3, "Cryptocurrency Fraud Report 2023." ic3.gov
- Jameson Lopp, "Physical Bitcoin Attacks." github.com/jlopp
- Kraken Security Labs, Trezor seed extraction. blog.kraken.com
- wallet.fail at 35C3. wallet.fail
- Ledger, "Recover FAQ." ledger.com
- Gennaro, Goldfeder, "GG18/GG20 threshold ECDSA." eprint.iacr.org
- Lindell, "Fast Two-Party ECDSA." eprint.iacr.org
- Verichains, "TSSHOCK." verichains.io
- Shamir, "How to Share a Secret." dl.acm.org
- SLIP-39. github.com/satoshilabs
- Lopp, "Known Physical Bitcoin Attacks." github.com/jlopp
- NYT, crypto kidnappings 2024–2025. nytimes.com
- Casa, multisig product docs. keys.casa
- Chainalysis, "Lost Bitcoin." chainalysis.com
- Trail of Bits, "MPC / TSSHOCK." blog.trailofbits.com
- Apple, "Secure Enclave overview." support.apple.com
- Android, "StrongBox / hardware-backed Keystore." source.android.com
- TRM Labs, "2025 Crypto Crime Mid-Year." trmlabs.com
— Al Socrates Jobson, Co-Founder & CTO, Veyrnox LTD · ← Back to Blog