Bitcoin Forum
August 01, 2026, 08:31:11 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: So with the cold wallet hack I am thinking about using core 29 to store.  (Read 114 times)
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12305


'The right to privacy matters'


View Profile WWW
July 31, 2026, 05:27:32 PM
 #1

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.

So I have a core 29 with a tiny amount of btc in it.

How to make the core 29 wallet be safe is the question.

I never encrypted it.

So I suppose I can make a long passhrase.

Like:

 abcdefgh87654321HGFEDCBA

Encrypt it.

Then test that I can get into the wallet.

Then make 5 backups of the  wallet.

I WOULD guess that is safer than a hardware wallet.

Also should I upgrade to core 30 or stay on core 29

Or use core 28.

I DO NOT WANT KNOTS .


So  ideas of setting up a  core to store a few btc.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6466


Leading Crypto Sports Betting & Casino Platform


View Profile
July 31, 2026, 05:43:22 PM
 #2

I do not know much maybe Bitcoin Core can be offline while you still run it as a node. If possible the wallet can be offline, it will be better.

You can have your own Electrum server and still have an Electrum wallet setup on an airgapped device and make use of your server on a watch-only wallet for transactions.

I am not a node runner, but there is option to use Electrum with Tor and have a seed phrase (+passphrase) set up on it.  This has been the option for me.

You would have seen on some of my posts that I do not like hardware wallet because it can reduce people's privacy. But getting one and setup a wallet with passphrase to extend the seed phrase will make that kind of Coldcard attack not possible.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
retaur
Member
**
Offline

Activity: 196
Merit: 34


View Profile
July 31, 2026, 06:06:47 PM
Merited by NotATether (10), Welsh (2)
 #3

Airgapping and cold storage is superior to everything.

Next is multisigging with different hardware wallets.

If you've not got much to store, you can use core and other software wallets. If you know what you're doing you can use software only with a decent amount of funds but it's really not recommended (I just used to do it with electrum though).
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22396


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 31, 2026, 06:33:45 PM
Merited by ABCbits (1), Charles-Tim (1)
 #4

I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.

Quote
Then make 5 backups of the  wallet.
Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
OgNasty
Donator
Legendary
*
Offline

Activity: 5544
Merit: 6435


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
July 31, 2026, 07:36:57 PM
 #5

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12305


'The right to privacy matters'


View Profile WWW
July 31, 2026, 09:19:31 PM
 #6

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

og my fear would be  if one company can be exploited  due to a 40 bit vs a 256 bit search

then maybe other wallets may do short cuts.  making shorter search areas for a pc to crack the wallet.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
nc50lc
Legendary
*
Offline

Activity: 3220
Merit: 8944


Self-proclaimed Genius


View Profile
Today at 03:59:17 AM
 #7

Also should I upgrade to core 30 or stay on core 29

Or use core 28.
If you're using a descriptor wallet anyways, go for 30.2+ (skip 30.0 and .1).

And if you're using a descriptor wallet, you can use a Cold-Storage Bitcoin Core setup by exporting the no-secrets descriptors to a watch-only Bitcoin Core wallet.
Transaction creation, export and signing procedures are supported by the GUI so it should be easy.
The only complicated part is the first time setup
Or wait for this in the next release version: github.com/bitcoin/bitcoin/pull/32489

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22396


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 04:14:33 AM
Merited by Welsh (1)
 #8

if one company can be exploited  due to a 40 bit vs a 256 bit search then maybe other wallets may do short cuts.
If that's your fear, why don't you use dice rolls or coin tosses to create your seed?

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10031


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 08:45:18 AM
 #9

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

That's right, there's no panic unless you used Coldcard hardware wallets to generate your seed.

If your seed was generated from non-coldcard hardware, you are safe.

If it was generated with coldcard hardware with firmware preceding v4, you are also safe.

Multisig is superior to all this anyway, and it is the method you should be using when you have a bunch of hardware wallets.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7667



View Profile WWW
Today at 03:26:00 PM
 #10

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.
~snip~


Given that you are a Trezor user, the simplest thing would be to create a new account in the same device, choose passphrase as additional protection (a unique password of 10+ characters, letters, numbers) and then transfer all your coins to that protected account. A seed generated with such low entropy is not something that users of other hardware wallets should worry about, because this is obviously an isolated case.

I think there is no room for panic, everyone can protect their coins today in the very simple way already mentioned. Additionally, an air-gapped wallet + strong passphrase are more than enough protection to allow you to sleep peacefully until super quantum computers and some perhaps still unknown threats appear.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Satofan44
Sr. Member
****
Offline

Activity: 462
Merit: 1175


Don't hold me responsible for your shortcomings.


View Profile
Today at 05:07:02 PM
Last edit: Today at 07:40:21 PM by Satofan44
Merited by stwenhao (1)
 #11

Airgapping and cold storage is superior to everything.
Superior by far yes, but not recommended for those that don't know what they are doing which represents a majority of users. Perhaps you or other users of this forum would be surprised how many people are not able to create proper backups of 24 words -- which is literally among the easiest things in the world, therefore we need to be careful what we suggest and to whom. I can completely see cases of people using a cold storage airgap system, eventually getting frustrated with it and entering their wallet details on onlinecoldstorage.com.  Cheesy

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.
~snip~

Given that you are a Trezor user, the simplest thing would be to create a new account in the same device, choose passphrase as additional protection (a unique password of 10+ characters, letters, numbers) and then transfer all your coins to that protected account. A seed generated with such low entropy is not something that users of other hardware wallets should worry about, because this is obviously an isolated case.

I think there is no room for panic, everyone can protect their coins today in the very simple way already mentioned. Additionally, an air-gapped wallet + strong passphrase are more than enough protection to allow you to sleep peacefully until super quantum computers and some perhaps still unknown threats appear.
Correct. People keep over complicating these topics because of anxiety and fear. The attack vector that was used here is completely mitigated by using a passphrase. Nobody is going to be brute-forcing all the seed phrases that they have managed to re-generate from a vulnerability with the hope that one of them will have a matching passphrase before the Sun runs out of fuel. Always use a strong passphrase with every hardware wallet, it could not get more simple than that. This prevents the low entropy attack vector, and it does not require additional hardware, knowledge, or multisig. It does not require anything at all. People, don't be modern day NPC overthinking machines, and just solve problems with the best and simplest solutions.

philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12305


'The right to privacy matters'


View Profile WWW
Today at 07:23:19 PM
 #12

I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.

Quote
Then make 5 backups of the  wallet.
Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version.


I made a reply to this post and the mod to the bot did not realize that it was a reply thus deleted it.

quotes are from the pm

"Deleted Post
« Sent to: philipma1957 on: Today at 06:21:09 AM »
Reply with quoteReply with quote  Remove this messageDelete  
A reply of yours, quoted below, was deleted by a Bitcoin Forum moderator. Posts are most frequently deleted because they are off-topic, though they can also be deleted for other reasons. In the future, please avoid posting things that need to be deleted.


Quote
Quote from: LoyceV on July 31, 2026, 02:33:45 PM
Quote from: philipma1957 on July 31, 2026, 01:27:32 PM
I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.  yeah sorry I thought I was being obvious with that.



Quote
Then make 5 backups of the  wallet.

Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version. "




If you look at the bold my reply was on topic.

and an attempt to show that my original post was not clear enough about  the passphrase


my intention to make a passphrase is to make this chart it shows the 94 letters numbers and symbols of my keyboard

01 ~       11 %         21 )        31 E            41  I           51  |        61 G        71 :      81 V       91 >
02 `       12 6          22 -         32 r            42  o           52 a         62 h        72 ‘      82 b        92 /
03 1       13 ^          23 _        33 R           43  O          53 A         63 H        73 “      83 B        93 ?
04 !        14 7          24 =        34 t           44 p            54 s          64  j        74 z      84 n        94 5
05 2       15 &         25 +         35 T           45   P         55 S          65 J         75 Z     85 N
06 @      16 8          26 q        36 y            46 [           56 d          66 k         76 x     86 m
07 3       17 *          27 Q        37 Y           47  {          57 D          67 K        77 X      87 M
08 #      18 9          28 w        38 u            48   ]         58 f           68 l         78 c       88 ,
09 4       19 (          29 W       39 U            49    }        59 F          69 L         79 C      89 <
10 $       20 0         30 e         40 i             50   \          60 g         70 ;         80 v       90 .


I will buy this from amazon

https://www.amazon.com/100pcs-Wooden-Number-Wedding-Decoration/dp/B07MBJ3DLR/ref=sr_1_9?


I will  put numbers 1 to 94 in a bag shake them

pull out a tile

mark it down

put tile back

pull out a tile mark it down

do this 24 times

giving me a random passphrase of 94 to the 24 power or


The full number form of 94 to the 24th power is 22,650,014,605,289,804,187,822,243,772,656,756,034,402,621,8496


      Ai missed a comma but this should be a tough passphrase

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!