Bitcoin Forum
October 05, 2026, 10:32:27 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 [40]
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 13857 times)
Leon Zimmer
Jr. Member
*
Offline

Activity: 42
Merit: 92


View Profile
September 27, 2026, 07:48:20 AM
 #781


ColdCard was NOT open source. ColdCard was Source Verifiable.

What's the difference? Open source means anybody can use the code, even in their own work.

Source verifiable means anyone can read the code, but they can't use it in their own work. So, what's the incentive for experts to read it? And even for those who do read it... some bugs aren't likely to be spotted on sight. It isn't until you tinker with it that you realize something behaves unexpectedly.

ColdCard got greedy. They didn't want people using their code. Their hubris and greed led to them getting wrecked, and that would be great if ColdCard users didn't get wrecked too.

Which brings us to Coinkite’s “open” code. The last part is key. If you’d used MIT or GPL, others could fork it or provide fixes for a fee or sell competing products. With the current license anyone can read it, but they can’t make competing commercial products. That means the only people with an incentive to deeply analyze the code are researchers looking to make a reputation, who are unlikely to closely review entropy generation, or people looking to exploit it, who are likely to closely review entropy generation.

Deeply analyzing entropy generation happens if you get paid to do so, or if you’re trying to exploit it. That’s why this bug sat around for 5 years. Coinkite gets the PR of open source, with the legal protections of closed. They got the marketing benefit of both models and the security benefit of neither. Illusory security through questionable licensing.
Cricktor
Legendary
*
Offline

Activity: 1638
Merit: 4574



View Profile
September 27, 2026, 01:39:47 PM
Merited by vapourminer (4)
 #782

Who has an incentive to look closely at the code? At least those, who want to benefit from potential exploits, as happened in the recent Coldcard debacle.

Do security researchers have an incentive? It depends on minimum two prerequisites:
a) a fair bug bounty program
b) a company which is open to a constructive discourse about bugs, issues, flaws of their product

To be fair, I don't know if Coinkite has a bug bounty program in place. Dealing with reported issues, maybe also including bugs, my reception isn't really positive on how Coinkite and nvK handled it in the past (I'm certainly somewhat more negatively biased here, as I paid more attention to negative behavior than the opposite).

This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later. If you're in that business, you don't really want to be brushed off by some arrogant dudes who think their product is superior.

Well, and voluntarily auditing the code? I doubt there are many with good enough expertise to do it for free or "for the merits". Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it because the company management's behavior to date has completely repelled me.

Danish Ali
Member
**
Offline

Activity: 84
Merit: 167


View Profile
September 27, 2026, 04:38:13 PM
Merited by ryzaadit (1)
 #783

Who has an incentive to look closely at the code? At least those, who want to benefit from potential exploits, as happened in the recent Coldcard debacle.

This is also, I think, a good example of how just because it's reviewable doesn't mean it will be reviewed properly, as the bug was discovered by gmaxwell looking at code. Several people reached the same conclusion by disassembling the firmware. Either way, people were able to go and look at the code/firmware, but this doesn't mean that most people can/will. It takes a highly-skilled analyst to recognize what went wrong here. Openness alone is no panacea, since it took someone as good as gmaxwell to recognize a #define/#ifdef mixup.


This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later.

And the real crux: assuming a researcher is able to find such a subtle vulnerability, and finding an RNG whitening bug is no cake-walk either, they may very well decide to exploit it, sell it or report it. Selling/exploitation will get them way more money than bug bounty will. And potentially millions.

So, unless you want to compete with black-market in offering bounties , your company’s bounty policy, however generous, will be irrelevant. Ethics and professional reputation are the only things keeping such researchers from exploiting vulnerabilities they discover.


Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it

Aside from the RNG issue itself, I think it's important to comment on the treatment of outside researchers. It doesn't take long before it becomes common knowledge in security circles if a company is going to ignore outside researchers. The next person who finds something really serious at this company might not be jumping through hoops to report it for free. At best, they'll say nothing. At worst, they'll sell it on the black market.
ryzaadit
Legendary
*
Offline

Activity: 3346
Merit: 1563



View Profile WWW
September 27, 2026, 08:08:28 PM
Merited by vapourminer (1)
 #784

To be fair, I don't know if Coinkite has a bug bounty program in place. Dealing with reported issues, maybe also including bugs, my reception isn't really positive on how Coinkite and nvK handled it in the past (I'm certainly somewhat more negatively biased here, as I paid more attention to negative behavior than the opposite).

This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later. If you're in that business, you don't really want to be brushed off by some arrogant dudes who think their product is superior.

Well, and voluntarily auditing the code? I doubt there are many with good enough expertise to do it for free or "for the merits". Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it because the company management's behavior to date has completely repelled me.
No wonder you have a negative bias against CoinKite/nVk. I think other people feel the same way you do. Since we all know nVk has been known for anti-open source and has a history of sending someone cease-and-desist letters. In the past few days and weeks, they have also started to block everyone on X. I don't think that's a good reason to block everyone while they should take any word (including a negative opinion) since they already make people lose their entire life-saving.


Source: https://x.com/asanoha_gold/status/2102631552039727456/



This is someone who reported being drained from mk4 even before the tragedy, resulting being blocked from the channels.


I don't think voluntary auditors, researchers, white-hats, and bug hunters want to dealing with these behaviors. Mostly, they're just being ignored.

Wind_FURY
Legendary
*
Offline

Activity: 3794
Merit: 2226



View Profile
September 29, 2026, 11:58:11 AM
 #785

Currently only know DART. I checked both DART & Crypto Recovery Trust, and they're really new. I guess DART is taking this case as a pro bono case for the security portfolio of their service.

What are their terms for payment? Do they get a percentage of what they get from those wallets that weren't adequately secured?

Plus do those white-hat hacking services get licenses from the government for them to be allowed to operate? I believe not.

Don't you find it strange that these companies, despite having existed for some time and having no publicly verifiable cases of previous recoveries,


Plus the government probably doesn't give licenses for cyber security companies start hacking as "White-Hats".

Quote

suddenly appear directly involved in recovering the funds from the Coldcard hack?


They're probably looking for vulnerable wallets to "recover" without the owners knowing that they're being "recovered".



Quote

It's just a question I'm leaving open. Maybe I'm seeing things where they aren't there.


You have your right to question, especially if Bitcoin is involved, even it's not your Bitcoin.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
gmaxwell
Staff
Legendary
*
Offline

Activity: 4872
Merit: 11599



View Profile WWW
September 29, 2026, 07:21:35 PM
Merited by LoyceV (4), ABCbits (2), vapourminer (1), JayJuanGee (1), ryzaadit (1), stwenhao (1)
 #786

Who has an incentive to look closely at the code?
People who want to use it to secure their assets, or people working on behalf of people who do!

Unfortunately, CC has quite a few technical (and social) smells...  so they got rejected by many people *before* they looked at it close enough that they might have discovered that issue. (or even before that issue was introduced).

You follow?  -- imagine yourself a technical expert, you're interested in CC for your own use... so you go look at it and you see it's mixing in some absolutely useless joke of a PRNG.  Then you go nope, close the window.  The fact that you see some stupid but apparently benign design feature is enough to move on.  You didn't *know* there was anything actually wrong with it, it just didn't reek of competence.  I even made a reddit post remarking on CC long back riffing on some bad smell from just their public marketing copy (specifically on the point that mixing in a security useless PRNG could mask fatal security bugs-- which is in fact a thing that happened here! ... sucks to be right).

Unfortunately you need to know there is an actual issue to seriously warn people off of it... but most of the people who might spot one don't bother going that far.

Independent outside security auditing is something people should want to see here.  Though in this specific case it might not have helped: any audits are inherently at a point in time and this was not a day-0 vulnerability, they introduced it along the way.  The rewrite they did was substantial enough that it deserved a new audit (certainly in hindsight!) but I dunno that users would have known to demand one.  I'm been the receiving end of several different third party commercial audits of Bitcoin Core and am a bit dubious of their value-- they tend to produce a lot of nitpicking and have missed more subtle but serious issues we knew existed but couldn't fix yet-- but this kind of "doesn't use the RNG" thing is exactly the sort of issue those audit firms are pretty good at finding.

Cricktor
Legendary
*
Offline

Activity: 1638
Merit: 4574



View Profile
September 29, 2026, 07:54:25 PM
 #787

...
I guess very few potential users or buyers would actually do such source code level scrutiny to not fall into the trap that Coldcard produced either by negligence/arrogance or even some sort of malice. I agree and get your point.

Unfortunately you need to know there is an actual issue to seriously warn people off of it... but most of the people who might spot one don't bother going that far.
I can imagine nobody wants to stick their head into the shit storm tornado. Sad, but unfortunately it is what it is.

I take from an audit in the past, depending how verbose it actually is, an overview of maybe design and code quality or if there are fundamental code architectural flaws. But I doubt an audit is ordered in such an open and general way because it's going to be very expensive. And yes, it's a snapshot of a state of the past. New code on top of the audit snapshot needs to be very carefully re-evaluated, not easy for people who aren't proficient in such things.


Wind_FURY
Legendary
*
Offline

Activity: 3794
Merit: 2226



View Profile
September 30, 2026, 07:15:52 AM
 #788

Who has an incentive to look closely at the code?
People who want to use it to secure their assets, or people working on behalf of people who do!

Unfortunately, CC has quite a few technical (and social) smells...  so they got rejected by many people *before* they looked at it close enough that they might have discovered that issue. (or even before that issue was introduced).

You follow?  -- imagine yourself a technical expert, you're interested in CC for your own use... so you go look at it and you see it's mixing in some absolutely useless joke of a PRNG.  Then you go nope, close the window.  The fact that you see some stupid but apparently benign design feature is enough to move on.  You didn't *know* there was anything actually wrong with it, it just didn't reek of competence.  I even made a reddit post remarking on CC long back riffing on some bad smell from just their public marketing copy (specifically on the point that mixing in a security useless PRNG could mask fatal security bugs-- which is in fact a thing that happened here! ... sucks to be right).

Unfortunately you need to know there is an actual issue to seriously warn people off of it... but most of the people who might spot one don't bother going that far.

Independent outside security auditing is something people should want to see here.  Though in this specific case it might not have helped: any audits are inherently at a point in time and this was not a day-0 vulnerability, they introduced it along the way.  The rewrite they did was substantial enough that it deserved a new audit (certainly in hindsight!) but I dunno that users would have known to demand one.  I'm been the receiving end of several different third party commercial audits of Bitcoin Core and am a bit dubious of their value-- they tend to produce a lot of nitpicking and have missed more subtle but serious issues we knew existed but couldn't fix yet-- but this kind of "doesn't use the RNG" thing is exactly the sort of issue those audit firms are pretty good at finding.


OK, now knowing about Cold Card's issue and their incompetent developers,  I will ask - Which hardware wallet, from what we see right now, would be the safest device to store our Bitcoin?

We'll take your suggestion NOT as an endorsement of a product, but as a form of guidance from a technical expert in Bitcoin development.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Meuserna
Sr. Member
****
Offline

Activity: 385
Merit: 700


View Profile WWW
October 04, 2026, 03:17:15 AM
Merited by Wind_FURY (1)
 #789

OK, now knowing about Cold Card's issue and their incompetent developers,  I will ask - Which hardware wallet, from what we see right now, would be the safest device to store our Bitcoin?

We'll take your suggestion NOT as an endorsement of a product, but as a form of guidance from a technical expert in Bitcoin development.

I swear by Krux and ShieldSigner (ShieldSigner is a fork of SeedSigner that adds additional encryption and security features).

Both are DIY and fully open source. Both run on off the shelf hardware.

Both are Airgapped (online thieves can't reach it) and Stateless (your seed & wallet aren't saved on it, which means there's nothing to lose if a thief finds it). Both offer passphrase QR. This lets you easily enter very strong passphrases by just scanning a QR code. Both offer encrypted SeedQR. This means, your seed is saved on a QR code that is encrypted. So, even if a thief finds it, they can't scan it.

ShieldSigner also supports smartcards, like SeedKeeper and Satochip.

I use both Krux and ShieldSigner. The beauty of having both is that I can always easily doublecheck anything, to verify the device is doing exactly what it says it is.

I swear by this way of working, but it's definitely not for those who want to trust a company and keep their seed on a device (I don't recommend doing that).

joker_josue
Legendary
*
Offline

Activity: 2534
Merit: 7539


**In BTC since 2013**


View Profile WWW
October 04, 2026, 07:12:50 AM
 #790

I swear by Krux and ShieldSigner (ShieldSigner is a fork of SeedSigner that adds additional encryption and security features).

I'm having trouble deciding whether to use SeedSigner or ShieldSigner.

SeedSigner is the original and most validated project.
ShieldSigner, despite being a fork, has more extras that generate an additional validation point. But it also has the feature of encrypting the QR code, which I find interesting.

A small dilemma. Huh

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
Meuserna
Sr. Member
****
Offline

Activity: 385
Merit: 700


View Profile WWW
October 04, 2026, 07:50:24 PM
Merited by joker_josue (2), Cricktor (2), tvbcof (1), JayJuanGee (1)
 #791

I swear by Krux and ShieldSigner (ShieldSigner is a fork of SeedSigner that adds additional encryption and security features).

I'm having trouble deciding whether to use SeedSigner or ShieldSigner.

SeedSigner is the original and most validated project.
ShieldSigner, despite being a fork, has more extras that generate an additional validation point. But it also has the feature of encrypting the QR code, which I find interesting.

A small dilemma. Huh

They both run on the same hardware, so why not try both? That being said... if you want to use a smartcard to store your seed (or seeds?), SeedSigner doesn't offer that. ShieldSigner does, by adding support for SeedKeeper.

BTC Hardware Solutions sells smartcard compatible hardware. It's basically the same SeedSigner hardware plus a smartcard slot.

SeedSigner doesn't have passphrase QR. I view that as a security risk because it encourages the use of weak passphrases, or not using a passphrase at all. The idea that somebody is going to enter an uncrackable passphrase manually every time isn't realistic. ShieldSigner solves this by adding passphrase QR.

For me, that alone was a reason to choose ShieldSigner. I've been using 50+ character passphrases since 2020. In fact, I'm a big believer in using a passphrase that consists of 7 words or more. Uncrackable, yet easy to back up on paper and metal. The ColdCard catastrophe proved why strong passphrases are so important. Even if a seed becomes compromised, a strong passphrase cannot be hacked.

SeedSigner doesn't have encrypted SeedQR. I view that as a bigger security risk because anyone who finds your SeedQR finds a scannable version of your seed. So, with SeedSigner, you have to keep your SeedQ locked up at all times. For home use, that's doable. But what about when you travel? Or in an emergency? ShieldSigner solves this by adding encrypted SeedQR.

P.S. SeedSigner and ShieldSigner are both great for opsec. Flash a game to the micro SD card. The device becomes a video game. When you want a hardware wallet, flash SeedSigner or ShieldSigner to micro SD and pop that in. It becomes a hardware wallet. This is especially good for travel.

joker_josue
Legendary
*
Offline

Activity: 2534
Merit: 7539


**In BTC since 2013**


View Profile WWW
Today at 07:34:48 AM
 #792

SeedSigner doesn't have passphrase QR. I view that as a security risk because it encourages the use of weak passphrases, or not using a passphrase at all. The idea that somebody is going to enter an uncrackable passphrase manually every time isn't realistic. ShieldSigner solves this by adding passphrase QR.

~~

SeedSigner doesn't have encrypted SeedQR. I view that as a bigger security risk because anyone who finds your SeedQR finds a scannable version of your seed. So, with SeedSigner, you have to keep your SeedQ locked up at all times. For home use, that's doable. But what about when you travel? Or in an emergency? ShieldSigner solves this by adding encrypted SeedQR.

What really caught my attention was the SeedQR encryption.
Creating a QR code that I can carry in my wallet, and if someone scans it they'll see some other text, I think that's an incredible advantage.

Thank you for sharing your experience.

Do you use two QR codes? One for the seed and another for the passphrase key?

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
Meuserna
Sr. Member
****
Offline

Activity: 385
Merit: 700


View Profile WWW
Today at 08:12:19 AM
Merited by joker_josue (1)
 #793

Do you use two QR codes? One for the seed and another for the passphrase key?

I use three.

One for the encrypted SeedQR. One for the Seed QR decryption key. And one for the passphrase.

I'm sure somebody will read that and think "That's terrible! What if you lose one of the QRs?!?!?"

You're supposed to have everything for your wallet backed up on paper and metal, right? Thus, if you lose a QR, no worries. It just means you have to manually enter the part you lost (and then, make a new QR). Always have everything backed up on metal.

I like the Ellipal Metal "Seed Phrase Steel" backup thingamabobs because it folds closed and has a hole you can run a padlock through. Back it all up on metal. Pop the metal backup in a safe. And get something like an Aqara home automation hub and a sensor for the safe. The sensor will instantly send you notifications on all of your devices if the safe gets opened or moved. I think I spent maybe $60 on my Aqara hub & sensor.

I wrote a novel about a Bitcoin thief who hunts seed phrase backups... so, yeah, I take that stuff seriously.

Actually, I take all of this stuff seriously... because I'm a diehard hodler, but also because I'm a problem solver. I look at self custody every step of the way and say to myself, "Where are the flaws, and what can I do better?"

I love Bitcoin. I do wish top-notch self custody was easier. I think it's easy, but only because I learned how to make it easy. For newcomers, it's nowhere easy enough, in my opinion. I hope that changes in years to come (without people needing to trust companies!).

BlackHatCoiner
Legendary
*
Offline

Activity: 2170
Merit: 10160


A swap that needs a hand? zeto.cash@proton.me


View Profile
Today at 02:35:48 PM
 #794

I'm having trouble deciding whether to use SeedSigner or ShieldSigner.
This is how I take decisions like these:

  • Do many people use either of them?
  • Do I trust the SeedSigner developers for not screwing things up somewhere?
  • Does the additional trust from ShieldSigner's devs increase the risk that someone has screwed up things somewhere along the way?
  • Considering the above, would I sleep easy in a single-sig or multi-sig setup?

Munshi Prem Chand
Newbie
*
Offline

Activity: 16
Merit: 2


View Profile
Today at 03:41:17 PM
 #795

Do you use two QR codes? One for the seed and another for the passphrase key?

You need to be careful storing the two QRs, because if you put the SeedQR + QR with decryption key in the same wallet/bag/safe/etc, you havent gained much security-wise. Chances are good if someone gets one they have the other also. Its "two factors", but only in name. Storing them separately can offer some real benefit though, as one QR is in one location (on your person, for instance) and other is somewhere else (in a safe, with a friend, whatever, somewhere with different threat model).

Additionally, it's a new codebase, which is true, since its a fork of SeedSigner, which is a good thing, since that part has at least the benefit of years of audits and eyes on it. But ShieldSigner does have code SeedSigner doesnt, for encryption. Has that been reviewed? Can people be confident there's nothing like a weak KDF or predictable nonces or...? Its not ok for that code to simply get a pass because "it has more features." before loading up real funds on it.

TLDR The three-QR option sounds interesting, but is only as good as your ability to OPSEC the storage locations, as well as people being comfortable with the extra encryption-related code ShieldSigner has over SeedSigner.
Meuserna
Sr. Member
****
Offline

Activity: 385
Merit: 700


View Profile WWW
Today at 06:46:27 PM
Last edit: Today at 07:00:36 PM by Meuserna
 #796

The three-QR option sounds interesting, but is only as good as your ability to OPSEC the storage locations, as well as people being comfortable with the extra encryption-related code ShieldSigner has over SeedSigner.

You don't have to use 3 QRs.

You need a QR for your seed, because your seed isn't saved on the device. Your seed and wallet get wiped when the device shuts down or reboots.

If you want to encrypt your SeedQR, you could just use a PIN code for the decryption key and type it instead of saving it as a QR to scan. A decryption key can be whatever you want it to be, which means it can be as weak or strong as you want it to be.

And of course, you only need a passphrase QR if you use a strong passphrase.

In the end, it all comes down to the kind of security model you want. I decided I didn't want my seed saved on a device, because the device becomes a risk. I prefer something stateless, but it's a different way of accessing a wallet than most hardware wallets use.

I think most hardware wallets unintentionally encourage the use of weak passphrases by expecting the user to type the whole thing every time they use it. That's not realistic, and it encourages those who do use passphrases to pick something short which can easily be cracked. And, really, passphrases are only for those who truly understand what passphrases are and are ready for advanced security.

This whole thread is about the ColdCard catastrophe. Those hackers cracked some weak passphrases and stole coins that way. They cracked a few 2-of-3 multisigs too.

There is no "best" way to do self custody. It's a sliding scale of simple vs complex, and weak vs strong. But also on that scale is the user's ability to understand their setup and do it right. I've been shocked by how many people have large amounts of Bitcoin secured by hardware wallets they don't understand. Lots of people learned ugly lessons during the ColdCard catastrophe. I learned my lesson when Ledger added key extraction to their firmware, but luckily, the lesson cost me nothing and greatly improved my security (P.S. I HATE Ledger).

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 [40]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!