Bitcoin Forum
August 08, 2026, 06:09:09 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 [22]  All
  Print  
Author Topic: Large-scale Coldcard compromise (1485.77 BTC stolen so far)  (Read 7255 times)
flatt
Newbie
*
Offline

Activity: 15
Merit: 1


View Profile
Today at 09:55:35 AM
Merited by vapourminer (1)
 #421

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.

it's called decoy for a reason. once the owner see their decoy is gone , the owner can immediately move the funds. it does not increased the risk at all, it literally does increased the security for the funds. and in this case (the worst case ever displayed on this day UNTIL probably 100 next years), the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.

FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 267


View Profile
Today at 10:04:42 AM
Merited by vapourminer (1)
 #422

You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy?

It's not 40 bits of entropy, more like 23 (or even less, CC would know better of their die cutting parameters). Watching the official YouTube easy guide "5 minutes setup" of a fresh CC adds some 6 additional bits. Each dice adds around 2 bits on top of this. So that's only around 2 to 3 billion guesses for all seeds out of all entropies + one dice rolls. A laptop can break that in an hour.

bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7659


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
Today at 11:09:28 AM
Merited by vapourminer (1)
 #423

I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.

If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.

And to be frank with all of you, I'm starting to think this is very justifiable to a point.

Owning a Bitcoin ETF is not the same as owning Bitcoin!

What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.

I think both points are valid.

But it is much better to own a bitcoin ETF than to own a hacked wallet.

Maybe it will make sense for some people to have both.

I am also affraid that when you own a bitcoin ETF you do not own a permitionless money, but you can at least have some protection against inflation.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7342


**In BTC since 2013**


View Profile WWW
Today at 11:19:59 AM
 #424

Someone on Twitter [1] did their own investigation and is claiming a possible inside job.

It's a thread of many tweets, the link is here

I had heard him talk about this investigation, but I hadn't found it yet.
Thank you for sharing.

Things are going to get very ugly for the Coldcard team. It remains to be seen when the first lawsuits will start to come.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
vapourminer
Legendary
*
Offline

Activity: 5124
Merit: 6657


what is this "brake pedal" you speak of?


View Profile
Today at 11:51:30 AM
Merited by LoyceV (6), BlackHatCoiner (4), bitmover (2)
 #425

I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.

If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.

And to be frank with all of you, I'm starting to think this is very justifiable to a point.

its always been this way really. ive always recommended (shudder) a registered exchange for noobs. because they expect to be able to "reset" passwords (pins, passphrases) on demand. the fact that they lose a piece of paper and it gone for good? thats not for most of the people i meet.

so only after they fully understand self custody do i recommend hardware airgaped wallets etc.

most people in general arent ready for self custody and it seems many here werent ready either.

im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
BlackHatCoiner
Legendary
*
Offline

Activity: 2114
Merit: 10019


Cross Chain Crypto Swap


View Profile
Today at 11:56:08 AM
Merited by vapourminer (1)
 #426

its always been this way really.
I know, but I used to tell to newcomers that you can "just get a hardware wallet and sleep easy" in case they didn't want to trust an exchange (and many don't trust them). Now I'm not sure what the correct suggestion is. Expecting them to use a signing device and roll dice is not something I can recommend to everyday people.

Quote
im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
I never trusted my computer's RNG in the first place, and I remember asking in this forum how most people do trust it. (I know the Coldcard issue was not the hardware's RNG per se, but I still would rather trust something I can verify with my own eyes.)

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Cricktor
Legendary
*
Offline

Activity: 1582
Merit: 4216



View Profile
Today at 12:09:10 PM
Merited by LoyceV (6), joker_josue (1)
 #427

The only way to be prepared anywhere in the world is to always have your seed with you.
How many of us have all the seeds with us 365 days a year, always?
If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.

Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...

I must say, I'm genuinely surprised how badly a hardware wallet vendor screwed this up like Coinkite did. I thought light-hearted that this shouldn't be possible because it's such a basic and important functionality to NOT screw up the random stuff when you have TRNGs available. I'm still puzzled...


The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.

And also make a BIP39 passphrase for your seed.
This can only work if users learn and understand how to safely and properly generate their own mnemonic seeds. There are many ways to screw this up without being easily able to notice it.

A mnemonic passphrase (the additional thing) needs to be complex enough to withstand brute-force attacks (it's also computationally somewhat expensive as each guess iteration requires 2048 rounds of PBKDF2 with HMAC-SHA512), but it adds a security layer with no margin for error if you fail to document it properly and highly recommended also redundantly. Commonly you should also separate it from your mnemonic recovery words, so it needs separate secure storage places.

That's quite a (necessary) burden with many possibilities for people to screw up.

On the other hand, with the necessary knowledge and understanding, I'm with you. I just have doubts it will work out for the masses.


I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
If the additional mnemonic passphrase is brute-forceable, the creator has failed already badly. It does not make sense to me, e.g. to use just a few additional words from the BiP39 wordlist. The mnemonic passphrase needs to be complex enough that brute-force attacks are not feasible.

With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).

LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22425


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 12:22:57 PM
 #428

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

Quote
the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.
There have already been reports of 2-word passphrases being compromised.

Quote
FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.

I know, but I used to tell to newcomers that you can "just get a hardware wallet and sleep easy" in case they didn't want to trust an exchange (and many don't trust them). Now I'm not sure what the correct suggestion is.
I used to recommend Ledger or Trezor, until Ledger went nuts. Now I'd recommend Trezor only, just because they've been around for a long time. But even though I know one fuckup doesn't mean another hardware wallet will do the same, the rate at which hardware wallets are disappearing from being trusted is not comforting. I've also seen hardware wallets that simply lose support after a few years, and users will have to buy a new one again. This is something for the long run, if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.

With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).
The one major reason for me to choose a hardware wallet over offline cold storage, is that it's much more convenient to make a payment. If I have to manually enter 12 randon words on a devide with 2 buttons each time I want to make a payment, I don''t really see the point of using it anymore.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
vapourminer
Legendary
*
Offline

Activity: 5124
Merit: 6657


what is this "brake pedal" you speak of?


View Profile
Today at 12:43:16 PM
 #429

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.

one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison


[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.

pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
philipma1957
Legendary
*
Offline

Activity: 4942
Merit: 12333


'The right to privacy matters'


View Profile WWW
Today at 01:30:05 PM
 #430

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.

one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison


[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.

pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.

Yeah I ended up adding passphrase to my trezors.

3 washers with 8 characters each

I decided on 32 of my 36 punches knock out 0OIL

so my passphrases are 32 to the 8th cubed or

1099511627776 x 1099511627776 x 109951162776

that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.


as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3

passphrases have say 0.32BTC total 1 of  btc

what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending

issues.

do I like it no





▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Woodie
Hero Member
*****
Offline

Activity: 2632
Merit: 970


🏰 KING OF THE CASTLE 🏰


View Profile WWW
Today at 01:43:17 PM
 #431

Someone on Twitter [1] did their own investigation and is claiming a possible inside job.

It's a thread of many tweets, the link is here


~snip~

Inside job would be an understatement, see shared tweet.. is this possible that this was left as a backdoor for themselves ?

They had a light moment about the entropy bug 🐛 and some years pass they get hit by the very entropy generation bug. Definitely pulled a retirement job on their clients and it was just a matter of time!



https://x.com/COLDCARDwallet/status/1447213375398846473

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
flatt
Newbie
*
Offline

Activity: 15
Merit: 1


View Profile
Today at 01:56:14 PM
 #432

Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

There have already been reports of 2-word passphrases being compromised.

That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.

In this case, and many similar cases to come, a passphrase is still a good way to secure your funds, and letting hackers eat the decoy as a warning to move your funds immediately. This still doesn't increase the risk as you claim. The rest depends on how the user uses the "passphrase." The user could even use a one-word passphrase with 64 hexadecimal characters, and the funds would still be there until next Christmas when the user is ready to move the funds.

In short, it depends on:
1. How the attacker detects whether it's a decoy address and decides to invest all their resources in a single wallet that they believe "It's a decoy, got a correct passphrase and you'll get the whale." which there's no script / tools exist for detecting such things.
2. (MOST IMPORTANTLY) how the user leverages the passphrase instead of entering their Instagram password to secure their real funds.

I still believe in SHA256, and accessing my funds from anywhere I want without letting a company give me the keys to my funds or storing my own keys in SDB is far worse.
flatt
Newbie
*
Offline

Activity: 15
Merit: 1


View Profile
Today at 02:22:40 PM
 #433

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.

one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison


[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.

pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.

Yeah I ended up adding passphrase to my trezors.

3 washers with 8 characters each

I decided on 32 of my 36 punches knock out 0OIL

so my passphrases are 32 to the 8th cubed or

1099511627776 x 1099511627776 x 109951162776

that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.


as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3

passphrases have say 0.32BTC total 1 of  btc

what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending

issues.

do I like it no






I would never make myself harder than before like that, but currently I choose my favorite signature, hashes it and put it as my extra passphrase, which I can access it from anywhere anytime.
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22425


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 02:24:10 PM
 #434

This still doesn't increase the risk as you claim.
You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.

Quote
The user could even use a one-word passphrase with 64 hexadecimal characters
At this point it's easier to just type a private key, it's shorter.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7342


**In BTC since 2013**


View Profile WWW
Today at 02:34:51 PM
 #435

im on team dice but only because i hang on this forum. i easily could of been a victim years ago.

You build your seeds with the dice and then "retrieve" them in a hardware wallet?



The only way to be prepared anywhere in the world is to always have your seed with you.
How many of us have all the seeds with us 365 days a year, always?
If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.

Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...

Exactly, I agree.

The seed is not meant to be passed around; it should be kept safe and sound in a secure place. Of course, it's good for a person to think about how they can access the seed if they can't return to its original location. But that's a different matter altogether.


 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
flatt
Newbie
*
Offline

Activity: 15
Merit: 1


View Profile
Today at 02:40:44 PM
 #436

This still doesn't increase the risk as you claim.
You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.

Good point, but at that point, there's no such decoy thing if you're not funding on it.
fillippone
Legendary
*
Online Online

Activity: 2982
Merit: 21225


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
Today at 03:39:10 PM
 #437

A very interesting read on an improvement idea that could solve the self custody trilemma:



Waiting for some commercial solution to implement it.

Meuserna
Sr. Member
****
Offline

Activity: 340
Merit: 564


View Profile WWW
Today at 05:33:19 PM
 #438

The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.

The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.

And also make a BIP39 passphrase for your seed.

THIS. It's what I've been doing for a few years, and it's not hard.

Print the BIPP39 wordlist in columns, on paper. Cut the sheets of paper into strips with one word per strip. Put the strips of paper in a large mixing bowl. Pick a word. Write it down. Put the word back in the bowl. Mix 'em up and pick again. Do this 23 times.

It's perfectly safe to let a hardware calculate the checksum word. Out of the entire list of 2048 words, only 7 or 8 will form a checksum for a 24 word seed. So, you're not sacrificing any randomness by letting a hardware wallet calculate the checksum word.

You've now got a totally random 24 word seed phrase. And you know it's random because you did the work.

Pick another 10 words from the bowl of paper strips. That's your passphrase.

I'm sure somebody is thinking "But the paper strips don't weigh exactly the same!" That's right. Any imperfections  just add to the randomness since those imperfections can't be predicted or calculated.

I started doing this after Ledger added key extraction to their firmware. I was a Ledger user back then, and their actions made me question how much I could trust the firmware for any device. So, I figured, if I don't let a device generate my seed phrase, I don't have to trust the device.

I also swear by ShieldSigner, which is a fork of SeedSigner that adds encrypted Seed QR, passphrase QR, and smartcard support (SeedKeeper and Satochip).

This gives me the ability to use my seed on a device which is airgapped and stateless.

I generated the seed, so I know I can't be part of a seed-hunter search like ColdCard's, because I know my seed is truly random.

I use the seed on a device that is airgapped, so I know it can't be reached by online hackers.

I don't save the seed or the wallet on the hardware wallet device. If it gets stolen, there's nothing on it for a thief to find.

For travel, I really like the ability to keep seeds on a SeedKeeper smart card. It's just a java card, but it has a secure element chip, and it wipes itself out after 5 incorrect password attempts. You can even set the number of allowed attempts lower.


The steps for rock solid security:

1. Generate your own seed.

2. Use a strong passphrase.

3. Back up your seed and passphrase on metal.

4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.

5. Choose a hardware wallet that is open source, airgapped, stateless, and offers encrypted seed backup for easy loading. ShieldSigner and Krux make all of this easy.

6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"

7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.

I know this list sounds like a lot, but really it's not.

Meuserna
Sr. Member
****
Offline

Activity: 340
Merit: 564


View Profile WWW
Today at 05:43:45 PM
 #439

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.

it's called decoy for a reason. once the owner see their decoy is gone , the owner can immediately move the funds. it does not increased the risk at all, it literally does increased the security for the funds. and in this case (the worst case ever displayed on this day UNTIL probably 100 next years), the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.

FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.

I've changed my mind about decoy wallets. I now think using the seed-only wallet as a decoy isn't a good idea.

Using the seed-only wallet as a decoy lets whoever finds that seed know the seed phrase has been used. That gives them a reason to start searching passphrases.

The ColdCard attackers had to search billions of seed phrases to find coins. Searching billions of seed phrases isn't hard since the attacker was surely running automated scripts to generate wallets and check addresses. Almost all of the seeds were empty. Maybe a few thousand out of billions of seeds had wallets.

Even in the ColdCard situation, where the total number of possible seeds is limited and known, it's still billions of seeds. It isn't feasible for thieves to try to crack passphrases for billions of wallets, since they don't know which of the billions of seeds might have passphrase wallets except for those which had something at the main seed-only wallet. Those thieves are trying to crack passphrases of seeds they know have been used.

I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 [22]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!