Member-only story
The Wallet Wars
Breakthrough Semiconductor ReRAM Technology
If you can’t verify the chip, you don’t own the coins.
This is my open-silicon argument for CrossBar, written for anyone who still thinks “secure element” is a synonym for “safe.”
THE DAY “TRUST US” BROKE
May 2023. Ledger, the company that sold more than seven million hardware wallets on the premise that your seed phrase never leaves the secure element, announced a service called Ledger Recover. For $9.99 a month, your seed would be split, encrypted, and entrusted to three custodians for cloud-backed recovery.
The price wasn’t the problem. The architectural admission was.
Until that morning, every Ledger user operated under one assumption: keys go into the chip, signatures come out, and nothing else ever leaves. The secure element was a one-way vault. The Recover announcement quietly contradicted that. A firmware update, the same kind Ledger ships routinely, could now reach into the secure element, extract a representation of the seed, and send it out the door. Encrypted, yes. Split, yes. But extractable.
Crypto Twitter detonated. Ledger’s official account posted a tweet that has since been deleted but lives forever in screenshots: “It is…
