Yishi|Aug 26, 2026 01:53
yesterday a friend told me something that left me with mixed feelings.
three years ago, after two major crypto exchanges were hacked for more than $200m, professional security teams spent a lot of time tracing the stolen funds. using onchain data, ip fingerprints, and other sources, they eventually found that some of the funds were linked to onekey devices.
we later learned that north korean hackers had ppl in mainland china buying onekey devices for them, then moving them through dandong and into pyongyang. they were most likely using the devices to handle some of those funds.
i’ve never talked about this publicly before.
i’m actually pretty cautious about stuff like this. there are too many ppl and institutions involved, and i’ve always felt safer saying less.
but hearing about the investigation in this much detail still felt strange.
because we’ve also sold a lot of devices to law enforcement.
we know onekey has been purchased by police in yancheng, yuehai in shenzhen, hong kong, tokyo, and parts of northeastern china. a small number have also been purchased by the us military. there are probably more we simply don’t know about.
so you end up with the same hardware wallet being used by north korean hackers, police investigating crimes, and the military.
when we started building hardware wallets, the idea was simple. your keys should actually belong to you. onekey doesn’t know who you are or how much money you have. we can’t freeze your assets. once a device is yours, we don’t have some button somewhere that can suddenly turn it off.
this all used to feel pretty abstract.
then you find out that people on completely different sides of the real world are using something you built.
and you start wondering who you’re actually helping.
we’d never knowingly sell devices to north korean hackers or help someone commit a crime. but if someone gets a onekey through other channels, we genuinely can’t decide whether they’re allowed to use it.
it’s the same when police buy our devices. we’re giving them a tool to protect private keys. we don’t know what they hold, and we don’t gain any control over their assets.
i used to think “anyone should be able to securely hold their own private keys” was a pretty simple idea.
now i realize “anyone” is a much heavier word than i thought.
i still don’t really know how i feel about all of this.
i still believe that as a hardware wallet company, we shouldn’t have the power to freeze someone’s assets, remotely control their device, or decide whether a transaction is allowed to happen.
but seeing something we built end up in the hands of all these different people still makes me wonder how much responsibility we should have for who ultimately uses it and what they use it for.(Yishi)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink