bitmover
Legendary
Online
Activity: 3108
Merit: 7649
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
August 01, 2026, 04:59:06 PM |
|
I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
It's normal to feel that way after an incident like this. However, there's no need to generalize and assume that all hardware wallets will and have the same issue. Trezor has been in the industry for more than a decade with a strong security track record. If you're planning to buy a hardware wallet, i'd stick with one that has been around for years and has built a solid reputation, such as Trezor. Longevity, regular security audits, and a proven track record are all good indicators when choosing a device. Trezor is Certainly the best option. If you dont buy a hardware wallet, what wallet will you use? A mobile wallet? A web wallet? Airgapped computers are risky to setup and use.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
PostQuantumBTC
Full Member
 

Activity: 308
Merit: 148
Bitz.io Best Bitcoin and Crypto Casino
|
 |
Today at 12:36:35 AM |
|
Airgapped computers are risky to setup and use.
How is it risky? Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper. But I will likely if you correct me because my understanding about the cold airgapped device may be limited.
|
|
|
|
|
TypoTonic
|
 |
Today at 01:41:26 AM |
|
Airgapped computers are risky to setup and use.
How is it risky? I would assume that the majority of people don't have the technical knowledge to properly setup an air gapped computer. A small mistake could compromise your setup entirely, which makes it risky. So unless you know exactly what you're doing, it's better to just stick with a hardware wallet and use a strong passphrase.
|
|
|
|
BALIK
Copper Member
Hero Member
   
Online
Activity: 2884
Merit: 633
🍓 BALIK Never DM First
|
 |
Today at 03:56:52 AM |
|
Just because coldcard had a security issue does not mean other hardware wallet manufacturers are also insecure. If you no longer trust HW because of the Mk3 incident, would you also stop trusting other wallets if Electrum happened to suffer a similar issue one day?
Electrum is an open source wallet. There are many hardware wallets, open source and close source. Cold card is not an open source hardware wallets. Their problem comes from many factors but close source is one of reasons. [LIST] Open Source Hardware Wallets.As I understand it, coldcard is open source, and their firmware is published publicly and can be self built and self verified. That is why when the entropy bug happened, the community was able to trace the root cause so fast. If it had been closed source like Ledger, we would probably still have no idea what caused it unless they decided to disclose it themselves. Coldcard is open source but the hardware itself is not fully open source. However, this incident was caused by a firmware bug, not the hardware. https://github.com/Coldcard/firmwarehttps://github.com/Coldcard/firmware/blob/master/hardware/README.md
|
|
|
|
tbct_mt2
Legendary

Activity: 3052
Merit: 1049
|
 |
Today at 04:31:38 AM |
|
As I understand it, coldcard is open source, and their firmware is published publicly and can be self built and self verified. That is why when the entropy bug happened, the community was able to trace the root cause so fast. If it had been closed source like Ledger, we would probably still have no idea what caused it unless they decided to disclose it themselves. Coldcard is open source but the hardware itself is not fully open source. However, this incident was caused by a firmware bug, not the hardware. https://github.com/Coldcard/firmwarehttps://github.com/Coldcard/firmware/blob/master/hardware/README.mdThey are not open source wallet and their hardware wallet source code, including firmwares are only available and verifiable. It's different than reproducible that is only for open source hardware wallets. https://walletscrutiny.com/?platform=allPlatforms&page=0&query-string=coldcardThe code has been available for public scrutiny for 5 years and no one ever found it. Coldcard isn't open-source but its code is publicly verifiable. No security expert found the vulnerability.
Coldcard is not open-source. The code is publicly available for verification, but it's not open-source. I guess the right term is "source-verifiable code." With an open-source license, you are allowed to use the code, build upon it, and release your own products. Coldcard doesn't allow you to do that. In the beginning, it was open-source, but NVK changed it to prevent other companies from copying the Coldcard code to create similar (competitor) products. That was a bad decision.
Security vulnerability was found and reported two years ago. https://www.youtube.com/watch?v=oj_W3xOlt6U
|
RAZED | | | 100% | WELCOME BONUS | │ | █████████████████████ █████████████████████████ ████████████▀░░░░▀███████ ██████████▀░░▄▀▀▄░░▀█████ ██████████▄▄██▄▄██▄░▀████ █████▀░░░░░░░▀██░░█░░████ ████░░████▀▀█░░██▀░░▄████ ████░░████▄▄█░░█░░▄██████ ████░░█▀▀████░░██████████ ████░░█▄▄███▀░░██████████ █████▄░░░░░░░▄███████████ █████████████████████████ █████████████████████ | █████████████████████ █████████████████████████ ██████████▀▀░░░░░▀▀██████ ████████▀░░▄▄█░░▀▄░░█████ ██████▀░░▄█████▄░░▀░░████ █████░░▄████▄▀░░█▄▄░░████ ████░░▄███▄▀░░▄▀██▀░░████ ████░░▀▀██░░▄▀███▀░░█████ ████░░▄░░▀█████▀░░▄██████ █████░░▀▄░░█▀▀░░▄████████ ██████▄▄░░░░░▄▄██████████ █████████████████████████ █████████████████████ | | |
NO KYC | | | RAZE THE LIMITS ► PLAY NOW |
|
|
|
|
YellowSwap (OP)
|
 |
Today at 06:57:44 AM |
|
the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
I don’t think 2FA should be in this particular discussion because it has nothing to do with seed phrases it only adds extra security to the outer password of the wallet which is only used when you have physical access to the hardware wallet itself but for this hack the attackers actually went through the seed phrase itself which already was vulnerable through its way of generation. I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
This doesn’t mean anything you just need to actually buy a reputable one and generate your own seeds and then use add passphrase to it or you simply use multi sig wallet or use two or more different wallet (hardware wallet) to spread yiur holdings Or better still stay away from hardware wallet and built a very good cold wallet with a software wallet like electrum, this should be on an airgapped device Yes you are right but if you can just read again I used that 2FA authentication as an example of extra security for password, I was just proving that 2FA helped secure password for websites even more, not crypto related in any way. PassPhrase can also had something similar (security wise) to everyone's recovery seed, it's all about making people understand more, it has nothing to do with crypto wallets like you said but I only use this as an example for better clearance of what Passphrase can do. I don't blame this guy you quoted that said they could think of buying a hardware wallet, such incident shouldn't be happening with hardware wallets, even Electrum wallet that's software wallet never generated recovery seeds using weak RNG.
|
|
|
|
Pmalek
Legendary

Activity: 3570
Merit: 9409
|
 |
Today at 07:04:45 AM |
|
That wasn't Coldcard's fault. That happened because the person used only one die roll in the creation of his seed and wallet. If the recommended number of dice rolls for enough entropy is 100, the wallet that user created was significantly less secure and was therefore easy to brute force. The same thing would/could have happened regardless what you used for the creation of such a seed. What Coldcard could have done better in that case is to show a warning, informing the user that they are supposed to enter many more dice rolls to increase the security of their keys.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
|
Sally9256
|
 |
Today at 07:58:25 AM |
|
The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it?
If any mobile wallet has passphrase+ recovery seeds then there is really no reason to run after hardware wallets anymore, I am really disappointed in this ColdCard company and their team together.
Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before.
Of course no where is totally safe and keeping all your Bitcoins in a single wallet can be costly but this incident doesn't entirely make hardware wallets less reliable, they are still the safest wallet around. I think the lesson should be knowing even hardware wallets can be vulnerable so it's better to use a device from a more reputable company. Hardware wallets are not the only ones offering a passphrase, even mobile wallets offer it too although not many of them do but being connected to the internet makes them less safe than hardware wallets. Many wouldn't trust the company again and sadly people who had held on to Bitcoin for years will be discouraged to return to Bitcoin. It's really a terrible experience. That wasn't Coldcard's fault. That happened because the person used only one die roll in the creation of his seed and wallet. If the recommended number of dice rolls for enough entropy is 100, the wallet that user created was significantly less secure and was therefore easy to brute force. The same thing would/could have happened regardless what you used for the creation of such a seed. What Coldcard could have done better in that case is to show a warning, informing the user that they are supposed to enter many more dice rolls to increase the security of their keys. A good company will have their customers best interest at heart. If they had issue out warnings that one dice roll or any number less than the recommended number would create a less secure seed people would have been aware and avoid making the mistake because no one wants to lose their assets. They are the manufacturer, they set the standard so they should have made the wallet display a warning sign at least to informed their customers earlier so they should be taking the blame here, they were being careless.
|
|
|
|
|
free-bit.co.in
|
 |
Today at 08:42:15 AM |
|
How is it risky?
I would assume that the majority of people don't have the technical knowledge to properly setup an air gapped computer. A small mistake could compromise your setup entirely, which makes it risky. So unless you know exactly what you're doing, it's better to just stick with a hardware wallet and use a strong passphrase. From what I have learned, air gapped is considered one of the most secure way to store Bitcoin, on par with a hardware wallet. However, setting it up requires you to know exactly what you are doing. It's not as simple as using a hardware wallet, so most of the risk comes from user error rather than from the method itself. To set up air gapped properly, you need clean operating system. You also need to make sure wifi, and bluetooth are completely disabled at the hardware level, and that any device used to transfer data is trustworthy...Even a small mistake during the setup process can cost you dearly. As mentioned, the risks may lie with the user and the setup process.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
bitmover
Legendary
Online
Activity: 3108
Merit: 7649
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
Today at 10:02:45 AM |
|
Airgapped computers are risky to setup and use.
How is it risky? I would assume that the majority of people don't have the technical knowledge to properly setup an air gapped computer. A small mistake could compromise your setup entirely, which makes it risky. So unless you know exactly what you're doing, it's better to just stick with a hardware wallet and use a strong passphrase. Exactly. Most people fail to make completely safe airgapped setups and lose their coins. There are dozens/hundreds of threads in the forum and over the internet about it. Hardware wallets are safe. But you must chose a good one. Coldcard was never a good one, although people thought it were. But it is closed source, people trusted it
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
Iranus
|
 |
Today at 12:01:42 PM |
|
I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
It's normal to feel that way after an incident like this. However, there's no need to generalize and assume that all hardware wallets will and have the same issue. Trezor has been in the industry for more than a decade with a strong security track record. If you're planning to buy a hardware wallet, i'd stick with one that has been around for years and has built a solid reputation, such as Trezor. Longevity, regular security audits, and a proven track record are all good indicators when choosing a device. Yes, I have started seeing some people become skeptical of hardware wallet. There's nothing wrong with that, because skepticism is necessary to protect our asset. However, it would be incorrect to assume that all other hardware wallet on the market are no longer secure simply because of what happened with Coldcard. Each wallet has its own codebase, design, and security model. I also believe that choosing a wallet should be based on many factors such as transparency, security audit and security track record, not just on brand or age. Ledger is also a long established and well known wallet brand, yet it is arguably worse than some newer wallets.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
PostQuantumBTC
Full Member
 

Activity: 308
Merit: 148
Bitz.io Best Bitcoin and Crypto Casino
|
 |
Today at 01:18:25 PM |
|
I would assume that the majority of people don't have the technical knowledge to properly setup an air gapped computer. A small mistake could compromise your setup entirely, which makes it risky. So unless you know exactly what you're doing, it's better to just stick with a hardware wallet and use a strong passphrase.
Also a small mistake can let you lose you bitcoin on a hardware wallet. I do not see anything hard in making your device to be airgapped, but maybe that is me, some people may find it difficult. Exactly. Most people fail to make completely safe airgapped setups and lose their coins.
But from what I think, airgapped wallet is safer than many hardware wallets. There are dozens/hundreds of threads in the forum and over the internet about it.
Hardware wallets are safe. But you must chose a good one. Coldcard was never a good one, although people thought it were. But it is closed source, people trusted it
Please can you let me know a topic or some topics that people lose their money on wallets on airgapped devices? I have not seen any on this forum, but I know you will know better. The threads that I have seen this year on this forum are people that lost their money on hardware wallet like Ledger Nano, Trezor and now Coldcard. The one for Trezor and Ledger Nano is because of the users mistake.
|
|
|
|
|
bhadz
|
 |
Today at 01:35:22 PM |
|
So we see now people who are scared of using their hardware wallets, don't think of it in general that the other HWs are unsafe. All of them are not perfect but you see how they eliminate the risk for us users through firmware updates and increase the protection through it. User intervention is also important and make ourselves updated and informed from time to time with issues like this, I still believe in the reputation that the known brands have. Ledger is also a long established and well known wallet brand, yet it is arguably worse than some newer wallets.
It was loved and liked by the community before, despite it being closed source, but not until they had their Ledger Recover and the series of hacks of their customers' data had been leaked.
|
|
|
|
hd49728
Legendary

Activity: 2898
Merit: 1360
|
 |
Today at 01:50:33 PM |
|
So we see now people who are scared of using their hardware wallets, don't think of it in general that the other HWs are unsafe. All of them are not perfect but you see how they eliminate the risk for us users through firmware updates and increase the protection through it. User intervention is also important and make ourselves updated and informed from time to time with issues like this, I still believe in the reputation that the known brands have.
Hardware wallets or software wallets, let's add another layer of security by using wallet passphrase. You must to keep your wallet passphrase safely like how to keep your wallet mnemonic seed backup safely. If you use strong passphrase, you already increase security of the wallets you created by any hardware- / soft-ware wallets. This advice I do use my ColdCard as my primary hardware wallet, but none of my seeds were generated on it. I used a different method/device to generate my seeds and I use strong passphrases on every wallet, including the ones that are mostly transitory. When generating the seed for my cold wallet I added analogue entropy as well.
It was loved and liked by the community before, despite it being closed source, but not until they had their Ledger Recover and the series of hacks of their customers' data had been leaked.
They have user data breach but did not wallet drain like this one with Coldcard.
|
|
|
|
|