Bitcoin Forum
August 25, 2026, 10:52:37 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 [29] 30 »
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 10236 times)
BlackHatCoiner
Legendary
*
Offline

Activity: 2128
Merit: 10071



View Profile
August 23, 2026, 01:27:16 PM
 #561

I think it highly likely that they did deliberately plant 'tricks' on the device (incl firmware), and if so, they almost certainly wouldn't hesitate to load it up with a variety of such tricks.
If they did not deliberately plant this, can you explain me how this critical vulnerability was written by Coinkite's CEO pretending to be someone else? Source: https://x.com/oomahq/status/2085717166884618584.

The CTO and this "switck" account were talking with each other, pretending like they are different people. It is highly UNLIKELY this is not an inside job.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
tvbcof
Legendary
*
Online Online

Activity: 5306
Merit: 1344


View Profile
August 23, 2026, 07:11:28 PM
Merited by BlackHatCoiner (1)
 #562

I think it highly likely that they did deliberately plant 'tricks' on the device (incl firmware), and if so, they almost certainly wouldn't hesitate to load it up with a variety of such tricks.
If they did not deliberately plant this, can you explain me how this critical vulnerability was written by Coinkite's CEO pretending to be someone else? Source: https://x.com/oomahq/status/2085717166884618584.

The CTO and this "switck" account were talking with each other, pretending like they are different people. It is highly UNLIKELY this is not an inside job.

Does the above highlight help?  I guess you were not necessarily mis-reading, but rather emphasizing?  Yes, the CTO's activities where shady as fuck, and that's a major reason why I believe this is a deliberate attack of some sort.  There might be some question about whether ~nvk was just a good-natured non-technical dunce and barely knew the CTO.  That seems very far-fetched to me, and it is even more suspicious that IDF guys like Wartharmer are popping up trying to make ~nvk the victim to feel sorry for.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
BlackHatCoiner
Legendary
*
Offline

Activity: 2128
Merit: 10071



View Profile
August 23, 2026, 07:18:37 PM
 #563

Does the above highlight help?
My bad! So we agree!

I absolutely disagree with the idea of keeping the Coldcard, though. If you haven't lost any funds, I'd consider moving them to a reputable signing device like SeedSigner, and throw that thing to the trash.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
PrivacyG
Legendary
*
Offline

Activity: 1624
Merit: 2969

Fight for Privacy.


View Profile
August 23, 2026, 07:23:01 PM
Merited by vapourminer (1)
 #564

I agree, any body who has a Coldcard should IMMEDIATELY dispose of it.  There are so many better ways to do this, Coldcard is like wearing the most comfortable pants but you know there is an open blade in one of the pockets.  You know you have not tripped in years so it will not kill you but you also never know when the next time you are going to trip is.

Or.  Frame it and put it on some kind of wall of shame.
tvbcof
Legendary
*
Online Online

Activity: 5306
Merit: 1344


View Profile
August 23, 2026, 08:34:29 PM
Merited by vapourminer (1)
 #565

Does the above highlight help?
My bad! So we agree!

I absolutely disagree with the idea of keeping the Coldcard, though. If you haven't lost any funds, I'd consider moving them to a reputable signing device like SeedSigner, and throw that thing to the trash.

Let me make it clear that I don't recommend that anyone other than highly technical people do anything with any of Coinkite's products.  I consider them unsafe.  Yes, it's 'playing with fire', but at the same time, so is playing with ANY hardware device at this point in time.  Indeed, playing with Bitcoin itself is now and always has been 'playing with fire.'

SeedSigner has the distinct advantage of letting the user have more control of the supply chain.  The potential in-built weakness (at the 'pi' or processor level) are unlikely to be narrowly targeted toward subverting crypto-currency except insofar as they may exist to attack cryptography generally.  I've not researched the SeedSigner project in detail, but I would assume that they now (or will be soon) taking pains to deal with the entropy issue, and there will always be the issues associated with cold attacks on storage of secrets for any hardware device.

I would mention again that I hope people do NOT throw these things in the trash.  They could be useful for further analysis in some sort of an attempt to further understand this fairly devastating attack on the Bitcoin community at large.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Meuserna
Sr. Member
****
Offline

Activity: 357
Merit: 634


View Profile WWW
August 23, 2026, 10:55:39 PM
 #566

~snip~
If I was a Coldcard user, there is nothing that NVK or anyone else from Coinkite could do to regain my trust, regardless if I lost money in the hacks or not. They have failed horribly. Game over.


It seems to me that they are trying to show that they are doing something just to have something to say in their defense if they ever find themselves in court. The other option would be silence and ignoring, which in the future could be interpreted as an admission of guilt.

There is definitely nothing to fix, their reputation is completely destroyed and they can be happy that they don't end up in prison or that some desperate person who lost his life savings doesn't take revenge on them.

I have to assume they would be soooo screwed in court.

"Mr. Novak, here is a list of all public statements you made following the catastrophe your firmware caused."

Quote
...silence...

"And here's a list of tweets you retweeted in the week following the catastrophe:"

Quote
...pages and pages and pages and pages and pages...

"And here's a list of your own tweets that you deleted in the week following the catastrophe:"

Quote
...pages and pages and pages and pages and pages...

I cannot take anyone seriously if they ever trust that clown or that company again.

cAPSLOCK
Legendary
*
Offline

Activity: 4480
Merit: 8127


Balakay2b edition!


View Profile
August 23, 2026, 11:41:18 PM
Merited by vapourminer (1)
 #567

I imagine there is likely more than one class action being cooked up.

They may be in for quite the ride.  Many are questioning the principal actors silence, but I am assuming their council has already put the kabash on them uttering a single word in public.  And if/when they do you can rest assured it was vetted and allowed.

In a perfect world I would like to see them open source the hardware and software.

I see a two edged sword here.  Bitcoin has NEVER been something all people could use in a sovereign way.  And the need for "Bitcoin Banks" as one cypherpunk posted here has been an inevitability.  This sort of clears the fog when it comes to the silly holy doctrines of the negative side of the Maxi cult.  (I identify as a nearly maxi... but not a religious kind).

We don't need to make sure everyone holds their own keys.

We just need to make sure they always can.

And to that end the other silver lining is a hardening of practices, and resources.  New signer projects, and better understanding for those in the group that DO want to hold their own keys.
Monetarium
Newbie
*
Offline

Activity: 7
Merit: 7


View Profile
August 24, 2026, 01:55:28 AM
Merited by Pmalek (3), vapourminer (1)
 #568

At least 65 key presses. I guess it's presses on the keyboard of the device.
Yes, on the device itself, and the timing is the point rather than the digits. The wording in the release notes is "at least 65 key presses with unpredictable timing", so what they are collecting is the intervals, not what you typed. Same requirement now applies to generated Temporary Seeds and CCC Key C, not just the main seed.

Worth pulling one thing out of that same section for anyone here still deciding about an old seed. Dice are not only a new option, they are also the exception in the July advisory. On affected firmware the device hashed its own seed together with every roll entered through Add Dice Rolls, and Coinkite's wording is that with at least 50 fair, independent, private rolls they do not consider the resulting seed at risk from the RNG issue alone. So whether an old seed is in the weak set depends on whether dice went into it, and that is a question worth answering before the migration decision rather than after.

There is a catch in the new release that reads straight onto that exception. Seed entry was tightened so that holding a key no longer counts as repeated dice rolls. If anyone reached 50 by holding the key down, those were never 50 independent rolls, and the exception does not cover them.
Pmalek
Legendary
*
Offline

Activity: 3598
Merit: 9486



View Profile
August 24, 2026, 06:38:10 AM
Merited by vapourminer (1)
 #569

I'm certainly biased because I didn't and still don't like the stance of Coinkite regarding their source code base and especially the strange attitude nvK displayed so far.

I'm not a Coldcard user and will never become one after what happened. It's not that I can't forgive a company which made errors, but how Coinkite screwed up and failed is systematic and I frankly don't know what they would have to do and change to even have a chance to regain my trust.

For me they were already done with their "verifiable source code drama", more so now with their stupid flawed firmware screw-up and subsequent handling of it. Did they even once admit that they badly screwed up and some of their customers loosing their coins in consequence? Yeah, rhetorical question...

They deserve "Game over!", indeed.
Coinkite used to claim that they were open-source on their website even after changing their license to a non-open source one. Only after people complained that the information isn't showing the truth, they changed the open-source claim to a source-verifiable one. NVK used every opportunity to attack other brands and use their mistakes and vulnerabilities to basically laugh at people and gloat when something went wrong. There was a very bad aura whenever he spoke. And people are now rightly asking if the people working for Coldcard turned malicious years ago.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
joker_josue
Legendary
*
Online Online

Activity: 2492
Merit: 7412


**In BTC since 2013**


View Profile WWW
August 24, 2026, 06:49:25 AM
Merited by tvbcof (2), vapourminer (1)
 #570

SeedSigner has the distinct advantage of letting the user have more control of the supply chain.  The potential in-built weakness (at the 'pi' or processor level) are unlikely to be narrowly targeted toward subverting crypto-currency except insofar as they may exist to attack cryptography generally.  I've not researched the SeedSigner project in detail, but I would assume that they now (or will be soon) taking pains to deal with the entropy issue, and there will always be the issues associated with cold attacks on storage of secrets for any hardware device.

SeedSigner does not save any keys on the device.

The equipment is only used to generate the seed, either by inputting data (99 inputs, if I'm not mistaken), or by taking a photo.
Then, whenever you want to sign a transaction, you have to load the seed when you turn on the device (you can use a QR Code), and make the respective signature.

Therefore, in terms of entropy, it already uses what is common and widely used by everyone.

In short, this is what I've analyzed about the project. I have never tried it, nor tested it.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pmalek
Legendary
*
Offline

Activity: 3598
Merit: 9486



View Profile
August 24, 2026, 06:57:36 AM
 #571

SeedSigner does not save any keys on the device.
Keys as in buttons? A Seedsigner has navigation keys on the left and three buttons on the right of the case. There are other casings that change the left-side navigation buttons and turn the device into a GameBoy Advance-looking thing. But there is no keyboard, though.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22534


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 24, 2026, 08:22:49 AM
 #572

I imagine there is likely more than one class action being cooked up.
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
greysonz
Jr. Member
*
Offline

Activity: 34
Merit: 6


View Profile
August 24, 2026, 08:24:21 AM
 #573

Apparently, the ColdCard case led to a total re-implementation of their code by developers of crypto wallets and regular services. The news came out that the Ledger developers, using AI, found and fixed (also using AI) a dangerous vulnerability. The point of the vulnerability was that when a Ledger user signed a transaction, an attacking hacker could substitute the data of this transaction. For example, you will sign a small transfer, and all crypto will be sent, and even to another address. This applies to Ethereum wallets, but there is clear, firm trend is evident to strong code review.
tvbcof
Legendary
*
Online Online

Activity: 5306
Merit: 1344


View Profile
August 24, 2026, 09:38:33 AM
Last edit: August 24, 2026, 10:08:05 AM by tvbcof
Merited by vapourminer (1)
 #574

SeedSigner has the distinct advantage of letting the user have more control of the supply chain.  The potential in-built weakness (at the 'pi' or processor level) are unlikely to be narrowly targeted toward subverting crypto-currency except insofar as they may exist to attack cryptography generally.  I've not researched the SeedSigner project in detail, but I would assume that they now (or will be soon) taking pains to deal with the entropy issue, and there will always be the issues associated with cold attacks on storage of secrets for any hardware device.

SeedSigner does not save any keys on the device.

The equipment is only used to generate the seed, either by inputting data (99 inputs, if I'm not mistaken), or by taking a photo.
Then, whenever you want to sign a transaction, you have to load the seed when you turn on the device (you can use a QR Code), and make the respective signature.

Therefore, in terms of entropy, it already uses what is common and widely used by everyone.

In short, this is what I've analyzed about the project. I have never tried it, nor tested it.

I found out the same thing about on-device storage.  It's certainly less convenient than something like seed vault, and probably opens up some failure modes in terms of lost or compromised seed material on cards.  In some scenarios the trade-off probably goes one way, and in other's, the other.  I must point out that with Coldcard, there is still a PIN for an on-site attacker to get through as opposed to a set of scanable cards or whatever, and the pin offers the opportunity for duress/decoy methods.  To a degree, start-up cards do as well I suppose.  SeedSigner might (be able to or) do such a thing with a device-board card decoder pin type thing.  Maybe with some decryption-code data stored on SD?

To be more clear about the above, it would be undesirable for me to need to maintain a set of relatively plain-text cards containing seeds in proximity to the device.  My off-hand idea would be that an entered start-up pin could be combine with material on an SD such that a scrambled scanable QR card could be unscrambled to the desired seed and thus reduce the threat of plain-text cards being available for theft within easy reach.  The real unscrambled data could be stored for backup purposes on a different continent.

My chief complaint when I was making the decision about what hardware wallet to use was associated with the cam not working very well when I saw people try to use the seed-signer.  Looks like they have a much better screen now which should help.

Going forward I probably never again will rely on a piece of hardware's internal seed generation ability to generate seeds that it uses.  If one is willing to tolerate the weaknesses of BIP-39, there are a huge number of ways to get word lists including doing them by hand on paper+dice.  Then just use the words to 'recover' rather than generate new.  If SeedSigner has a well vetted and well analyzed block of code for seed generation using pics or whatever, I'd probably put it in the mix of things I would use.  Certainly ahead of other devices that I can think of.

The main thing which bothers me would be the device's ability to communicate the seed (or mis-represent a signed block) for the periods of time when it holds the data necessary to sign transactions.  Extremely limited communications paths are a huge feature to me.  Ideally they would consist only of camera/display and SD.  IIRC, SeedSigner meets that criteria, and does so better than ColdCard which has the others (NFC, USB) but _says_ that they may be deactivated.  USB is not a biggie since it is obvious when it is used.

I guess one other thing I would be looking for in a device would be good shielding.  I very much like the clear case of the Coldcard for the simple reason that it allows me to muse about the chips and compare circuit board arrangements (being ever-concerned about supply chain issues), but shielding to reduce the chances of damage at airports or TEMPEST style attacks would be worth the trade-off.  A nicely shielded case which could be easily taken apart would be the best of both worlds.

Edit:  I would add that ColdCard's self-distruct on bad pin idea is a selling point to me.  Such a thing is fairly irrelevant though on a device with no private key storage.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
ryzaadit
Legendary
*
Offline

Activity: 3304
Merit: 1440



View Profile WWW
August 24, 2026, 10:18:25 AM
 #575

Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.
Maybe the memes will decide.


If they are found guilty, will they have the ability to pay the victim? My answer: NO. But maybe they will pay the fine to Canada authority and get more financial damage. Other scenario, they declare bankruptcy and that means for us they will no longer offer any service at all. Which is good, since we don't want them anymore or deserve any space in here due to selling mallfunction product.

Now for the victim who at least joined the class-action, maybe in the future authority make an arrest and seize the funds. They offering a refund program for the victim, and they're qualified due joined the class action or reported their losses. At least even the chance are small, still worth to tried.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22534


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 24, 2026, 10:21:58 AM
 #576

Other scenario, they declare bankruptcy and that means for us they will no longer offer any service at all. Which is good, since we don't want them anymore or deserve any space in here due to selling mallfunction product.
Then someone will take over the bankrupt company and continue selling the same hardware, maybe after rebranding. The Ledger case shows that even if they can extract the seed from your device, people will still buy it.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
ryzaadit
Legendary
*
Offline

Activity: 3304
Merit: 1440



View Profile WWW
August 24, 2026, 01:02:47 PM
Merited by vapourminer (1)
 #577

Then someone will take over the bankrupt company and continue selling the same hardware, maybe after rebranding. The Ledger case shows that even if they can extract the seed from your device, people will still buy it.
In this case, I hope you don't mind borrowing some of your words.

"Fool me once, shame on you. Fool me twice, shame on me."

"Fool me three times... with a different brand and company... I guess I’ll just straight send my BTC to them".

I agree with you. Some people will still buy it, but pretty sure even if someone takes over their company and sells the hardware with a different brand. The new one has a track record for it, which is COINKITE. The community will also dig them as well, and share just to make sure be aware about them.

If people still buy and use them even though they're on a different team or company. Just don't be surprised anymore if something like these are happening again.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22534


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 24, 2026, 01:18:53 PM
Last edit: August 24, 2026, 03:08:59 PM by LoyceV
Merited by ryzaadit (1)
 #578

"Fool me three times... with a different brand and company... I guess I’ll just straight send my BTC to them".
They're not fooling me Smiley

Quote
I agree with you. Some people will still buy it, but pretty sure even if someone takes over their company and sells the hardware with a different brand. ~
If people still buy and use them even though they're on a different team or company.
I can already predict how this is going to be: "but we're a different company now", "we're not making the same mistake", "someone else made that mistake", "we have nothing to do with it", "here's a list of 16 reasons why we're the best product on the market"....

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
mabji1
Newbie
*
Offline

Activity: 29
Merit: 0


View Profile
August 24, 2026, 06:17:06 PM
 #579

Rebranding is the classic maneuver to escape a tarnished reputation. If the core engineering philosophy remains unchanged, the risks persist. History warns that a new label does not guarantee security improvements. Trust must be earned, not just marketed.
cAPSLOCK
Legendary
*
Offline

Activity: 4480
Merit: 8127


Balakay2b edition!


View Profile
August 24, 2026, 07:14:20 PM
Merited by vapourminer (4), Pmalek (3), joker_josue (2)
 #580

SeedSigner does not save any keys on the device.
Keys as in buttons? A Seedsigner has navigation keys on the left and three buttons on the right of the case. There are other casings that change the left-side navigation buttons and turn the device into a GameBoy Advance-looking thing. But there is no keyboard, though.

I have built a couple of these and the project is extremely impressive. It has its weaknesses and its strengths.

As to your question, it is 99 six-sided dice rolls.  It will take that or derive entropy from its camera and I'm presuming other sources which is more novel and probably less tested. And of course, it can also take a seed phrase in English at least. And it also has a feature to allow you to create a compact seed QR code.  Then these can be scanned when you want to sign a transaction.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 [29] 30 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!