Bitcoin Forum
August 05, 2026, 09:16:55 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: So with the cold wallet hack I am thinking about using core 29 to store.  (Read 297 times)
philipma1957 (OP)
Legendary
*
Offline

Activity: 4942
Merit: 12323


'The right to privacy matters'


View Profile WWW
August 03, 2026, 05:31:52 PM
 #21

Playing with trezor 5.

There are some ways to make a passphrase via the trezor.

But if you access weeks later I am not  sure how to enter a passphrase offline.

I think I can.

To me if you want a 1 btc cold wallet trezor.

You could do

0.1 20 word seed
0.3 20 word seed with passphrase
0.3  "   "
0.3 "   "

1 btc total

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
nc50lc
Legendary
*
Offline

Activity: 3220
Merit: 8958


Self-proclaimed Genius


View Profile
August 04, 2026, 03:42:47 AM
 #22

Isn't there an option to prompt your Trezor to enter the passphrase on the HW's screen itself?
Most attack vectors wont work if your use that instead.
~snip~

Is it even possible for such sensitive information to be entered through a user interface?
In Trezor Suite?
It should be enabled in the settings and there should be an option to create Passphrase wallets,
then the passphrase will prompted in the UI or a button to enter it on the device when you need to create/access a wallet with passphrase.

AFAIK, only older models don't have that option to enter the passphrase on the hardware wallet's screen.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Cricktor
Legendary
*
Offline

Activity: 1568
Merit: 4204



View Profile
August 04, 2026, 06:03:12 AM
 #23

but don’t lose it or you are fucked.
It certainly sounds like a broken record: if you use one or more mnemonic passphrases, make sure to very carefully and redundantly document them! Because if you loose or can't reproduce a mnemonic passphrase, you instantly loose access to your coins, which you expressed more casually.

It may sound obvious, but some people screw up the basic documentation. Human brains will inevitably forget complex mnemonic passphrases, so proper documentation is mandatory.


also the trezor has its seed my trezor 5 uses 20 words
IIRC, I don't use modern Trezors yet, it's Trezor's SLIP-39 new standard recovery word backup which encodes additional metadata and uses Shamir Secret Sharing (embedded entropy is 128 bits equivalalent to standard 12-word BIP-39 backup).


I hope other hardware wallet companies didn't fuck up their code paths for entropy generation and properly use embedded TRNGs in contrast to Coinkite's Coldcard mess. At least some companies did code audits, but those don't guarantee you find every flaw in your code base.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
philipma1957 (OP)
Legendary
*
Offline

Activity: 4942
Merit: 12323


'The right to privacy matters'


View Profile WWW
August 04, 2026, 09:05:29 PM
 #24

but don’t lose it or you are fucked.
It certainly sounds like a broken record: if you use one or more mnemonic passphrases, make sure to very carefully and redundantly document them! Because if you loose or can't reproduce a mnemonic passphrase, you instantly loose access to your coins, which you expressed more casually.

It may sound obvious, but some people screw up the basic documentation. Human brains will inevitably forget complex mnemonic passphrases, so proper documentation is mandatory.


also the trezor has its seed my trezor 5 uses 20 words
IIRC, I don't use modern Trezors yet, it's Trezor's SLIP-39 new standard recovery word backup which encodes additional metadata and uses Shamir Secret Sharing (embedded entropy is 128 bits equivalalent to standard 12-word BIP-39 backup).


I hope other hardware wallet companies didn't fuck up their code paths for entropy generation and properly use embedded TRNGs in contrast to Coinkite's Coldcard mess. At least some companies did code audits, but those don't guarantee you find every flaw in your code base.

yeah I am going to make 10 passphrases using a set of punches

the punches are
A to z     thus 26  
 0 to 8    thus  9
and *     thus 1

that is a set of 36 different punches.


shake them in a box pull 1 punch
replace it in the box pull 1 punch

so 1/36 x 1/36 until I do  a large passphrase

2 pulls is                       1296    combos
3 pulls is                     46656    combos
4 pulls is                 1679616    combos
5 pulls is.              60466176     combos
6 pulls is           2176782336    combos
7 pulls is         78364164096    combos
8 pulls is 2,821,109,907,456     combos


now I can fit 8 punch marks on a stainless steel washer.    
and 1 washer means     2.82 trillion   which only slows the attacker some what
but 2 washers mean     2.82 trillion squared better
and 3 washers means  2.82 trillion cubed  even better


now if you have a 20 word seed and 3 washer 24 symbol passphrase you have a decent stoppage of a hack.


▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
PrivacyG
Legendary
*
Offline

Activity: 1596
Merit: 2931


Fight for Privacy.


View Profile
August 04, 2026, 10:42:34 PM
 #25

My opinion is.  For both philipma1957 and everyone else reading.  I understand the Coldcard situation made a lot of people nervous.  Including me.  But I just replied to another situation on the Wasabi Wallet Topic a short while ago (https://bitcointalk.org/index.php?topic=5476197.msg67012172#msg67012172) and I see this trend of people all of a sudden moving their Bitcoin to a 'safer place'.

Please do not over complicate this!  If you have a Coldcard with some Bitcoin on it then hurry up and move them to a safe place but other wise do not try to re invent the wheel and keep in mind that caution is still very important!  The person I linked above to lost 6 Bitcoin because they moved from Coldcard to a fake Wasabi Wallet.  Others are probably going to lose by moving from a safe place like a Trezor to a hot wallet on an infected computer and lose every thing instantly.  Or some will insert their Seed on a random web page with the same consequence when the Bitcoin they had was in a secure place already.

Do not rush this process!

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
philipma1957 (OP)
Legendary
*
Offline

Activity: 4942
Merit: 12323


'The right to privacy matters'


View Profile WWW
Today at 02:48:44 AM
 #26

My opinion is.  For both philipma1957 and everyone else reading.  I understand the Coldcard situation made a lot of people nervous.  Including me.  But I just replied to another situation on the Wasabi Wallet Topic a short while ago (https://bitcointalk.org/index.php?topic=5476197.msg67012172#msg67012172) and I see this trend of people all of a sudden moving their Bitcoin to a 'safer place'.

Please do not over complicate this!  If you have a Coldcard with some Bitcoin on it then hurry up and move them to a safe place but other wise do not try to re invent the wheel and keep in mind that caution is still very important!  The person I linked above to lost 6 Bitcoin because they moved from Coldcard to a fake Wasabi Wallet.  Others are probably going to lose by moving from a safe place like a Trezor to a hot wallet on an infected computer and lose every thing instantly.  Or some will insert their Seed on a random web page with the same consequence when the Bitcoin they had was in a secure place already.

Do not rush this process!

Yeah be careful do it step by step.

As of today I have trezor and core holdings.

I also cashed in a good amount of my coins as I will not be able to take a huge hit and get the value back as I dont earn a ton mining. Plus at 69 my time line is likely 20 years or less.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22417


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 09:50:29 AM
 #27

yeah I am going to make 10 passphrases using a set of punches

the punches are
A to z     thus 26  
 0 to 8    thus  9
and *     thus 1
Can you easily distinguish between the ones that look similar, like O<>0 and I<>1 ? If not, it's better to leave them out of the pool.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
philipma1957 (OP)
Legendary
*
Offline

Activity: 4942
Merit: 12323


'The right to privacy matters'


View Profile WWW
Today at 02:03:40 PM
 #28

yeah I am going to make 10 passphrases using a set of punches

the punches are
A to z     thus 26  
 0 to 8    thus  9
and *     thus 1
Can you easily distinguish between the ones that look similar, like O<>0 and I<>1 ? If not, it's better to leave them out of the pool.

one is  1
I     is  l

so they are easy

0 and O may not be easy

I am waiting on a brass plate for fast easy back up sheet {in house}

the washers in bank vault

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
JOSTEN_TOP
Newbie
*
Offline

Activity: 2
Merit: 0


View Profile
Today at 08:19:00 PM
 #29

That worry regarding hardware wallet vendor shortcuts (and recently a Coldcard RNG vulnerability) makes perfect sense. A vulnerability that shrinks the 256 bits of entropy of a 2^256 key down to something an attacker can brute force (like 40 bits) throws out the entire basis of what makes hardware wallets safe in the first place.

However when you go from that to a Bitcoin Core on an internet connected computer it comes with its own set of tradeoffs:

1. Risk Of Internet Connected OS vs The Device:

The wallet.dat on an internet-connected computer is at the mercy of malware such as keyloggers, malware capable of memory scraping and a variety of other attacks that could read your private keys from RAM. Even with a strong encryption passphrase the most critical risk of these types of malware attack is the capability of them reading that passphrase as it is being input on a compromised machine and immediately giving access to your Bitcoin keys.

2. Weak Passphrase vs Entropy Rich Passphrase:

A lot of individuals have issues with thinking that they can come up with a passphrase that has both length as well as variability and will not be easily crackable by modern computer power; anything that utilizes a discernible pattern (eg 123, abcdefg) will eventually succumb to an exhaustive attack using tools like Hashcat. When creating encrypted wallets you need to be very, very confident that your passphrases are of truly random character generation either sourced from something akin to a Diceware style generation (http://en.wikipedia.org/wiki/Diceware) or a long non-patterns based passphrases.

3. Mitigating Single Vendor Flaws without trusting another piece of single-vendor hardware:

As the title describes; if you believe many hardware wallet makers may be taking RNG shortcuts, there's a number of strategies:
• Entropy Supplementation: Utilize wallets and hardware which support inputting random noise from an external source (such as from a true random number generator like bitseed (https://bitseed.org/) or the output of throwing dice, flip coin).
• Air Gap Bitcoin Core or Electrum: Perform all wallet and key generation on a completely air-gapped computer. Set up bitcoin Core or Electrum on it, ensure it's offline, air gap it securely then proceed to generate the keys in that cold environment. Only take the public keys of what you wish to monitor on an online server.
•  Multi Vendor multisig (2-of-3 setup): use three hardware wallets from two different vendors (e.g.,TREZOR/BitBox02, and the air-gapped Electrum/Core system). If an attacker successfully compromises one vendor, the other two wallet pieces will protect your Bitcoin. An attack against the OS of the hardware wallet may occur but unless you utilize all three of your hardware devices at the very moment the OS has become compromised by a malicious piece of software you win regardless of the attempt.

4. Backup Strategy (3-2-1 Rule):

If storing wallet.dat backups or seed phrases, you need at least three copies of your backup data. At least two media are kept at a safe location but are separate and the third is offsite.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!