A hardware wallet closes one hole: the key no longer sits on a phone with internet. But the device is not empty. It has firmware, updates, a desktop program, a screen, a box, a seller with your address — and each detail adds an attack surface you did not have before. Below are eight such details: what reviews say, how money was taken through them, how to close the hole, and whether our kit has that detail.

A key is a huge random number, and firmware makes it. One bug there — and there are far fewer keys than you think: they get brute-forced across all owners at once, without device access, years after purchase. The chip is irrelevant; the hole sits above it.

Every update is a moment when firmware can be swapped. Tampered firmware hides seed fragments in two or three ordinary signatures while the device looks normal from the outside. Skipping updates is not an option either: holes are patched by those same updates.
You buy a device for one reason: to stop trusting the computer. For it to work, you must install a background service on that same computer. You did not write it, did not start it, and do not control it: it launches with the OS, listens on a port any program on your machine can hit, and is doing something right now — what exactly, you do not know and will never verify.
It kept running in the background after you closed the wallet. For years. At one of the largest vendors it was a separate “bridge” service; in 2025 they hid it inside the app itself — the service is still there, it just dies with the window. For most others, without a desktop program the device is a keychain fob. On Linux add udev rules or the system will not hand over USB.
So the thing you bought to stop depending on computer programs does not work without a computer program. And not the one you see — the one that runs underneath it.
You wanted a house for privacy. You bought it. Then you needed security — installed. And for the security plan to work, they asked you to let a uniformed person into the house who lives in your utility closet around the clock, holds keys to every door, and reports to someone else. You did not hire him, cannot fire him, and what he does at night — you do not know.
He is “one of ours,” of course. It says so in the contract. You wanted privacy and got a surrogate: a house with a tenant you did not choose.
Open source was invented so people could share programs and fix them together. As a collaboration tool it is excellent. It was never a quality seal that “this software will not steal your money,” and here is why: you do not use the source code. You use what you downloaded.
Between a GitHub repo and the file on your phone sit the build, the app store, the update, the server. At any of those steps one line can enter the code that pulls anything from anywhere — and it will not be in the repo. You cannot compare your copy to the source: stores ship a compiled file; a web wallet gets whatever code the server chose to serve you today; a browser extension updates silently at night.
“Open” means some people can check some version on some day. What your copy is doing right now — it does not mean that.

The screen is tiny, and often it shows a hash or “contract call,” not the address and amount. You confirm what you cannot see — and the signature is still honest, yours. The screen gives a feeling of control that is not there.

A physical device means shipping, intermediaries, and “discount” marketplaces. The wallet arrives pre-set, with a seed on a slip inside. Or a lookalike app in the store asks you to “enter the seed to activate.”

To buy the device you give the manufacturer your name, email, and shipping address. Your security now depends on their database. If it leaks — for years you will get messages to “confirm the seed on a new device,” sometimes with packages.

The more parts, the more breaks: connector, screen, battery. Recovery hangs on one seed slip — soaked, lost in a move, photographed “just in case.” The most common cause of loss is not a hack.
Eight details for eight flaws. The list fits any wallet — hardware, mobile, browser. Tick what the one you are choosing has — and ours too.
Cards arrive empty. You create the key in Mitilena Air on a phone with no internet and write it yourself. Signing is through Mitilena Keys, also offline: the transaction travels by QR. Five identical copies in the box: 2 NFC cards and 3 stealth stickers in waterproof plastic. 18 networks, 20,000+ coins, including USDT.
One big pro: the key is not on a phone with internet. The cons are the eight details above — each adds attack surface. A good hardware wallet is the one with fewer details, not more.
With a card on your main phone the key appears in an isolated environment for the second of signing — the same risk as any phone wallet, only shorter. For amounts that scare you — a second layer: sign on a separate offline device the transaction reaches by QR.
Without the password the card and sticker are useless plastic — the key on them is encrypted. A lost copy is replaced by the other four: two cards and three stickers from the box are mirrors.
If the vendor closed a hole — yes, and that is exactly when firmware can be swapped: check the source and the signature. A carrier with no firmware has no such choice — nothing to update, nothing to swap.
Fewer intermediaries: no cable, driver, background service, or desktop program. One intermediary — your phone’s NFC chip — and it answers to you and the OS, not the wallet vendor.
It means checkable by someone, sometime. You use not the code but what you downloaded, and you cannot compare one to the other. Safety comes from architecture where the key is not where foreign code can reach it.