Bitcoin Forum
August 01, 2026, 10:35:19 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: So with the cold wallet hack I am thinking about using core 29 to store.  (Read 86 times)
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12304


'The right to privacy matters'


View Profile WWW
July 31, 2026, 05:27:32 PM
 #1

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.

So I have a core 29 with a tiny amount of btc in it.

How to make the core 29 wallet be safe is the question.

I never encrypted it.

So I suppose I can make a long passhrase.

Like:

 abcdefgh87654321HGFEDCBA

Encrypt it.

Then test that I can get into the wallet.

Then make 5 backups of the  wallet.

I WOULD guess that is safer than a hardware wallet.

Also should I upgrade to core 30 or stay on core 29

Or use core 28.

I DO NOT WANT KNOTS .


So  ideas of setting up a  core to store a few btc.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6465


Leading Crypto Sports Betting & Casino Platform


View Profile
July 31, 2026, 05:43:22 PM
 #2

I do not know much maybe Bitcoin Core can be offline while you still run it as a node. If possible the wallet can be offline, it will be better.

You can have your own Electrum server and still have an Electrum wallet setup on an airgapped device and make use of your server on a watch-only wallet for transactions.

I am not a node runner, but there is option to use Electrum with Tor and have a seed phrase (+passphrase) set up on it.  This has been the option for me.

You would have seen on some of my posts that I do not like hardware wallet because it can reduce people's privacy. But getting one and setup a wallet with passphrase to extend the seed phrase will make that kind of Coldcard attack not possible.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
retaur
Member
**
Offline

Activity: 196
Merit: 32


View Profile
July 31, 2026, 06:06:47 PM
Merited by NotATether (10)
 #3

Airgapping and cold storage is superior to everything.

Next is multisigging with different hardware wallets.

If you've not got much to store, you can use core and other software wallets. If you know what you're doing you can use software only with a decent amount of funds but it's really not recommended (I just used to do it with electrum though).
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22392


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 31, 2026, 06:33:45 PM
Merited by ABCbits (1), Charles-Tim (1)
 #4

I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.

Quote
Then make 5 backups of the  wallet.
Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
OgNasty
Donator
Legendary
*
Offline

Activity: 5544
Merit: 6432


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
July 31, 2026, 07:36:57 PM
 #5

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12304


'The right to privacy matters'


View Profile WWW
July 31, 2026, 09:19:31 PM
 #6

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

og my fear would be  if one company can be exploited  due to a 40 bit vs a 256 bit search

then maybe other wallets may do short cuts.  making shorter search areas for a pc to crack the wallet.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
nc50lc
Legendary
*
Offline

Activity: 3220
Merit: 8944


Self-proclaimed Genius


View Profile
Today at 03:59:17 AM
 #7

Also should I upgrade to core 30 or stay on core 29

Or use core 28.
If you're using a descriptor wallet anyways, go for 30.2+ (skip 30.0 and .1).

And if you're using a descriptor wallet, you can use a Cold-Storage Bitcoin Core setup by exporting the no-secrets descriptors to a watch-only Bitcoin Core wallet.
Transaction creation, export and signing procedures are supported by the GUI so it should be easy.
The only complicated part is the first time setup
Or wait for this in the next release version: github.com/bitcoin/bitcoin/pull/32489

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22392


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 04:14:33 AM
 #8

if one company can be exploited  due to a 40 bit vs a 256 bit search then maybe other wallets may do short cuts.
If that's your fear, why don't you use dice rolls or coin tosses to create your seed?

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10021


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 08:45:18 AM
 #9

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

That's right, there's no panic unless you used Coldcard hardware wallets to generate your seed.

If your seed was generated from non-coldcard hardware, you are safe.

If it was generated with coldcard hardware with firmware preceding v4, you are also safe.

Multisig is superior to all this anyway, and it is the method you should be using when you have a bunch of hardware wallets.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!