Bitcoin Forum
August 24, 2026, 05:55:22 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: So with the cold wallet hack I am thinking about using core 29 to store.  (Read 610 times)
philipma1957 (OP)
Legendary
*
Offline

Activity: 4956
Merit: 12412


'The right to privacy matters'


View Profile WWW
August 23, 2026, 03:02:17 PM
 #41

Honestly, I no longer care about hardware wallets and such things. This is the best approach to my mind: buy a cheap new laptop without any OS installed, do not connect it to the internet, remove wifi and bluetooth parts from it. Stick a usb flash drive with Tails installed on it (verify the Tails image before creating the USB), open an electrum wallet, generate a wallet and that's it, you have an air-gapped computer with cold wallet that's more secure than any hardware wallet.
I agree with everything, except one small detail that I can no longer sleep easy at nights: Computer RNG. I genuinely want to have the randomness confirmed with my own eyes from now on; and I know the recent incident with Coldcard has nothing to do with flawed CSRNG, but I'm afraid that everything happening on the computer is going to be heavily scrutinized by AI, and there MAY be weaknesses on deeper levels as well, like urandom or the hardware component itself.

Rolling a dice will become the new paranoid's standard, but you can't import dice entropy in Electrum.

yes but how big can you make the 25th word on electrum .

I did an electrum years ago and it was a 12 word seed. they said I could add a 13th word but I do not remember the rules about adding the extra word as a passphrase if you can do a big word it is easy use my punch method

https://www.amazon.com/gp/product/B0GWCLMR3V/ref=ox_sc_act_title_1?smid=ATVPDKIKX0DER&th=1


use 32 of the 36 punches over and over again

32x32x32x32x32x32x32x32=1.0995×10¹²   

 1.099 trillion cube it

or 24 characters long   and you get 120 extra bits randomly

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22521


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 23, 2026, 03:32:40 PM
 #42

This is the best approach to my mind: buy a cheap new laptop without any OS installed, do not connect it to the internet, remove wifi and bluetooth parts from it. Stick a usb flash drive with Tails installed on it (verify the Tails image before creating the USB), open an electrum wallet, generate a wallet and that's it
Why buy a new laptop just to run Tails OS? The whole idea of Tails OS is that it's can be used on any computer.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Synchronice
Legendary
*
Offline

Activity: 1694
Merit: 1182



View Profile
August 23, 2026, 04:51:06 PM
 #43

I agree with everything, except one small detail that I can no longer sleep easy at nights: Computer RNG. I genuinely want to have the randomness confirmed with my own eyes from now on; and I know the recent incident with Coldcard has nothing to do with flawed CSRNG, but I'm afraid that everything happening on the computer is going to be heavily scrutinized by AI, and there MAY be weaknesses on deeper levels as well, like urandom or the hardware component itself.

Rolling a dice will become the new paranoid's standard, but you can't import dice entropy in Electrum.
Electrum doesn't let you to import dice entropy but it can be fixed if you convert your physical dice rolls into a standard mnemonic seed phrase. Roll physical dice to create 128 bit entropy, then convert it into 12-words BIP39 seed and then import BIP39 seed into Electrum.

This is the best approach to my mind: buy a cheap new laptop without any OS installed, do not connect it to the internet, remove wifi and bluetooth parts from it. Stick a usb flash drive with Tails installed on it (verify the Tails image before creating the USB), open an electrum wallet, generate a wallet and that's it
Why buy a new laptop just to run Tails OS? The whole idea of Tails OS is that it's can be used on any computer.
The whole idea of buying a new laptop is that you are buying a fresh, untouched hardware. Tails can protect you from infected OS but it can't protect you from compromised BIOS, physical keyloggers and altered hardware. If you have an old laptop at home, then no problem, use it. But if you don't have a laptop and you have to buy, I would still choose a new, cheap laptop over second-hand.

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████▀█▀████████████████▀████████████████▀█████████████████████████████▀████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████████████████████████▀██████▀█████▀████████▀█████
██████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████▄█▄████████████████▄████████████████▄█████████████████████████████████▄██████▄█████▄████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
 🍒   ⚽️    IIIIIFASTEST GROWING CASINO & SPORTSBOOK     Play Now    
Cricktor
Legendary
*
Offline

Activity: 1596
Merit: 4337



View Profile
August 23, 2026, 05:27:17 PM
Merited by LoyceV (4)
 #44

The whole idea of buying a new laptop is that you are buying a fresh, untouched hardware. Tails can protect you from infected OS but it can't protect you from compromised BIOS, physical keyloggers and altered hardware. If you have an old laptop at home, then no problem, use it. But if you don't have a laptop and you have to buy, I would still choose a new, cheap laptop over second-hand.
What makes you think a "newly bought" cheap (=consumer grade) laptop is cleaner than a second-hand business laptop (=usually easier to open and inspect fully) which I can properly reset, reflash with published firmware from the vendor?

From my personal experience with few consumer laptops, those were sometimes a pain in the ass to open to get access to various components and inspect them. While the experience was quite different and much more pleasant with decent business laptops from Dell, HP and ThinkPads (IBM or later Lenovo).

I'm not paranoid enough to consider a laptop with newly flashed firmware and a properly reset BIOS to be still compromised. Storage media properly wiped, of course.

LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22521


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 23, 2026, 05:51:31 PM
Merited by philipma1957 (1)
 #45

The whole idea of buying a new laptop is that you are buying a fresh, untouched hardware.
Some people trust old hardware more than new hardware when it comes to Bitcoin. How sure are you the manufacturer didn't install a backdoor already?

Quote
Tails can protect you from infected OS but it can't protect you from compromised BIOS, physical keyloggers and altered hardware.
How likely is this if you buy a laptop from Craigslist? I'm not worried about a compromised BIOS, nor am I worried about physical keyloggers in an air-gapped laptop. If that's going to happen, it's going to be a targeted attack, and the attacker can just as well install it inside the laptop you have at home already.

Quote
If you have an old laptop at home, then no problem, use it. But if you don't have a laptop and you have to buy, I would still choose a new, cheap laptop over second-hand.
I prefer hardware that lasts many years, and I expect a new budget laptop to last less long than a (cheaper) second hand business laptop. And I don't want to pay $2000 for a laptop I'll only use for accessing cold storage once a year.
Let's agree to disagree on the details, I'm pretty sure both options are quite secure anyway.

From my personal experience with few consumer laptops, those were sometimes a pain in the ass to open to get access to various components and inspect them. While the experience was quite different and much more pleasant with decent business laptops from Dell, HP and ThinkPads (IBM or later Lenovo).
I've been thinking about physically removing anything I don't need from an old laptop for a while now, but never actually did it. But like you said: business laptops with full Youtube explanation of how to open them are generally much easier than consumer laptops.
For the truly paranoid:
  • remove network card + socket
  • remove bluetooth module + antenna
  • remove Wifi + antenna
  • poor epoxy on the memory modules to prevent liquid nitrogen removal (even if they're soldered, you can't be careful enough)
  • remove all USB connectors you're not going to use, fill the holes with epoxy
  • remove webcam
  • remove microphone + jack
  • remove SSD if you don't use it
  • remove microSD slots
  • add epoxy all around the casing before you screw it back together
  • fully encrypt the SSD if you install anything on it
  • rig it with C4 let's not do that
But again, I haven't done this yet Smiley

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
philipma1957 (OP)
Legendary
*
Offline

Activity: 4956
Merit: 12412


'The right to privacy matters'


View Profile WWW
Today at 03:29:19 AM
 #46

The whole idea of buying a new laptop is that you are buying a fresh, untouched hardware.
Some people trust old hardware more than new hardware when it comes to Bitcoin. How sure are you the manufacturer didn't install a backdoor already?

Quote
Tails can protect you from infected OS but it can't protect you from compromised BIOS, physical keyloggers and altered hardware.
How likely is this if you buy a laptop from Craigslist? I'm not worried about a compromised BIOS, nor am I worried about physical keyloggers in an air-gapped laptop. If that's going to happen, it's going to be a targeted attack, and the attacker can just as well install it inside the laptop you have at home already.

Quote
If you have an old laptop at home, then no problem, use it. But if you don't have a laptop and you have to buy, I would still choose a new, cheap laptop over second-hand.
I prefer hardware that lasts many years, and I expect a new budget laptop to last less long than a (cheaper) second hand business laptop. And I don't want to pay $2000 for a laptop I'll only use for accessing cold storage once a year.
Let's agree to disagree on the details, I'm pretty sure both options are quite secure anyway.

From my personal experience with few consumer laptops, those were sometimes a pain in the ass to open to get access to various components and inspect them. While the experience was quite different and much more pleasant with decent business laptops from Dell, HP and ThinkPads (IBM or later Lenovo).
I've been thinking about physically removing anything I don't need from an old laptop for a while now, but never actually did it. But like you said: business laptops with full Youtube explanation of how to open them are generally much easier than consumer laptops.
For the truly paranoid:
  • remove network card + socket
  • remove bluetooth module + antenna
  • remove Wifi + antenna
  • poor epoxy on the memory modules to prevent liquid nitrogen removal (even if they're soldered, you can't be careful enough)
  • remove all USB connectors you're not going to use, fill the holes with epoxy
  • remove webcam
  • remove microphone + jack
  • remove SSD if you don't use it
  • remove microSD slots
  • add epoxy all around the casing before you screw it back together
  • fully encrypt the SSD if you install anything on it
  • rig it with C4 let's not do that
But again, I haven't done this yet Smiley

I have a lenovo laptop running core 25.

Pulled the wifi card

Encrypted the ssd a 2tb nvme.2 Samsung

It runs mint os.

It has a 24 character passphrase .

So i think It has 32gb ram

I should check it it has been sitting with 0.001 btc In it.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
nc50lc
Legendary
*
Offline

Activity: 3248
Merit: 9023


Self-proclaimed Genius


View Profile
Today at 04:49:31 AM
 #47

yes but how big can you make the 25th word on electrum .
You'd be surprised, here's an extreme case test done by o_e_l_e_o,

Reference quote:
There is theoretically no limit to how long a passphrase can be. The passphrase is simply used as a salt for the PBKDF2 function, which turns mnemonic phrase in to seed. (You can read more here: https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki) As a quick test, I just created and then recovered an Electrum wallet with a passphrase of 20,000 characters.

I'm pretty sure that Electrum's "seed extension" lines of code haven't been updated to set a hard limit since that reply,
But the GUI seems to have a cap of how many characters it can take (a little more than 32000), I haven't tested using CLI.

LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22521


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 07:42:37 AM
 #48

I'm pretty sure that Electrum's "seed extension" lines of code haven't been updated to set a hard limit since that reply,
But the GUI seems to have a cap of how many characters it can take (a little more than 32000)
At that point, just use the sha256sum of the long text as seed extension. It's just as safe, much easier to do and you can literally make it as long as you want.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!