|
YellowSwap (OP)
|
 |
Today at 08:19:47 AM |
|
I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.  The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
|
|
|
|
un_rank
Legendary

Activity: 1526
Merit: 1107
|
 |
Today at 09:21:12 AM |
|
If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
- Jay -
|
|
|
|
Crypto Library
Legendary

Activity: 1666
Merit: 1190
Leading Crypto Sports Betting & Casino Platform
|
 |
Today at 10:19:36 AM |
|
If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay -
I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent  dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
MusaMohamed
|
 |
Today at 10:29:57 AM |
|
The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
- let's start considering passphrase with recovery seeds.
It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. - let's start considering multisig if possible.
It's right but multisig wallet will cost you more in transaction fees. And single sig wallet or multisig wallet, you must create your wallet offline, make backup, test backup, and do right things in security. Multisig wallet can not save your fund if you still have bad security practice. You possibly knew that some projects got their company treasuries/ project treasuries hacked even they used multisig wallets. Creating a multisig wallet.- let's start considering the Dice 🎲 rolling method for entropy
As a normal Bitcoin user, I don't mind about that. I only choose old and trusted wallets to use. Discuss about it and innovating new method of doing that can cause terrible things for my fund.
|
|
|
|
Antidote47k
Jr. Member

Activity: 56
Merit: 40
|
 |
Today at 10:55:03 AM |
|
I think the biggest take away for me from this Coldcard incident is the complacency, the longer a tool builds a reputation for being secure the more complacent we get and we stop questioning what we normally do cause we trust the product. Let’s not forget that that bitcoin security has always been about minimizing trust and that shouldn’t apply only to custodians and exchanges. Often times we talk about not trusting exchanges, perhaps we should also avoid putting all our confidence in one hardware wallet vendor and diversify a little to reduce impact if one layer fails. Another factor to consuder is incident response, how quickly can one react in similar situations, how quickly can you access your backup and move your coins? Prevention is important, but so is being prepared to react.
Now that Coinkite has published its technical analysis, the broader lesson still stands, this wasn’t just a Coldcard problem, it’s also a reminder not to become complacent and no single device/vendor should be treated beyond scrutiny, that being said I still agree with OP regarding hardwallets still being one of the safest option for self custody, this incident shouldn’t discourage people from using them, instead strengthen your security by layering with passphrases, multisig or independent generated entropy. that is why knowledge is very important, we should keep our practices up to date.
|
|
|
|
|
Zaguru12
Legendary

Activity: 1498
Merit: 1249
Instant Crypto Withdrawals
|
 |
Today at 11:13:03 AM |
|
the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
I don’t think 2FA should be in this particular discussion because it has nothing to do with seed phrases it only adds extra security to the outer password of the wallet which is only used when you have physical access to the hardware wallet itself but for this hack the attackers actually went through the seed phrase itself which already was vulnerable through its way of generation. I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
This doesn’t mean anything you just need to actually buy a reputable one and generate your own seeds and then use add passphrase to it or you simply use multi sig wallet or use two or more different wallet (hardware wallet) to spread yiur holdings Or better still stay away from hardware wallet and built a very good cold wallet with a software wallet like electrum, this should be on an airgapped device
|
|
|
|
|
348Judah
|
 |
Today at 11:28:26 AM |
|
Even though I'm not a fan of using a hardware wallet, one thing I don't know about this incident is whether the same risk extends to other hardware will let users sign transactions, or only found with coldcard hardware wallet.
I will also go with the idea of using a multisig wallet because this one still has a better advantage, as it permits more than one cosigner to sign a transaction before it can be processed.
|
|
|
|
|
Comeacross
|
 |
Today at 11:56:56 AM |
|
the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
I don’t think 2FA should be in this particular discussion because it has nothing to do with seed phrases it only adds extra security to the outer password of the wallet which is only used when you have physical access to the hardware wallet itself but for this hack the attackers actually went through the seed phrase itself which already was vulnerable through its way of generation. I observe that people misunderstood the purpose of 2FA, seed phrase and password. If your seed phrase is exposed, both password and 2FA becomes irrelevant because they can import your wallet into a new device. 2FA only protect unauthorised access to your app. If your login details are exposed, 2FA will protect you here and prevent logging in even when they have your password. If seed phrase is exposed, the only thing that'll save you is transferring the coins before the attacker does because no security feature would save you.
|
|
|
|
|
|
KiaKia
|
 |
Today at 12:17:17 PM |
|
The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it?
If any mobile wallet has passphrase+ recovery seeds then there is really no reason to run after hardware wallets anymore, I am really disappointed in this ColdCard company and their team together.
Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before.
|
|
|
|
Nothingtodo
Sr. Member
  

Activity: 1036
Merit: 321
Crypto Casino with No KYC on routine deposits
|
 |
Today at 12:36:37 PM |
|
The Coldcard hardware wallet hack on July 31 was an unexpected incident, although it was unexpected, but one thing can definitely be observed from that compromised incident that no matter how popular the wallet is, if the security phrase is not stored properly or if there is a weak server system, then in that case, an unwanted incident like hacking can occur. Bitcoin should never be stored in a single wallet, but rather in multiple wallets. There is a saying in the digital currency world where it is said that do not put all your eggs in one basket, if one basket falls to the ground unexpectedly, then all your eggs will break. If you keep Bitcoin in just one wallet, if it gets compromised for some reason, then all the Bitcoins will be hacked. Therefore, instead of keeping it in a single wallet, you should store the wallet phrase in different wallets with security.
|
| | | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | ████████████████████████████ 100 FREE SPINS ████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | █████████████████████████████████████████████ CLAIM BONUS █████████████████████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
|
|
|
|
Agbamoni
|
 |
Today at 12:38:13 PM |
|
If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
- Jay -
I cannot agree less. This was obviously what I had in mind ever since I heard about the incident. I dont need anyone to preach about Bitcoin security to me, when I know that safety is never assured. Mistakes and vulnerability can come from anywhere. It can come from our end. It may come from the software provider or from the device we use. We, the owners of the coin, can only play our own role by using the most preferred wallet and storing our seed phrase while we hope that the wallet provider fulfills the promise by using the most secure database to protect the funds. Coldcard has made an error, but the owners are the ones who lost. Or is there any published article with promises of Coldcard returning the money that was lost through their mistake?
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Hyphen(-)
|
 |
Today at 12:56:38 PM |
|
Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before.
I really sympathize with the victims and I wish something can be done about it, but we all know how Bitcoin transactions work, it is irreversible, and from what happened, their wallet is the reason for this because that’s where the problem come from that give the scammers access to their wallets and sent their previous Bitcoin out. We believe in open source wallets to save our Bitcoin and I still think it is valid and most secured wallet, so we just need to use the most popular once that has been in existence for a very long time and no cases of such scams because as it is like this, no close source wallet is safe to hold your Bitcoin.
|
|
|
|
|
HelliumZ
|
 |
Today at 01:10:54 PM |
|
So far, about 1200 Bitcoins have been stolen from the coldcard Hardware wallet and there is nothing else to do but express condolences to the holders whose Bitcoins were stolen. However, such an incident has occurred due to the mistake of the Coldcard Hardware Wallet authorities. In that case, I would say that I would not have understood how big a loss such a mistake can cause by the authorities without seeing this incident. It is unimaginable that such a popular hardware wallet would make such a mistake and how much loss has the general public suffered due to this mistake? I learned a lesson from this that no matter how popular the wallet is, if it finds a simple weakness, the wallet can get hacked, which has been observed in the past.
|
|
██ ██ ██████ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ██████ ██ ██ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ██████████████ THE #1 SOLANA CASINO
██████████████ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | [ [ | 5,000+ GAMES INSTANT WITHDRAWALS | ][ ][ | HUGE REWARDS VIP PROGRAM | ] ] | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████████████████████████ PLAY NOW ████████████████████████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
|
|
|
BALIK
Copper Member
Hero Member
   

Activity: 2884
Merit: 633
🍓 BALIK Never DM First
|
 |
Today at 01:25:41 PM |
|
If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay -
I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent  dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. This isn't a problem with hardware wallets in general. More accurately, this is a failure in Coldcard's security review process. Because only the MK3 running firmware versions 4.0.1-5.0.3 has been confirmed to be affected, while other models appear to remain safe. Just because coldcard had a security issue does not mean other hardware wallet manufacturers are also insecure. If you no longer trust HW because of the Mk3 incident, would you also stop trusting other wallets if Electrum happened to suffer a similar issue one day? Every manufacturer and every wallet has its own design, codebase, and security process. We shouldn't assume all HW is the same.
|
|
|
|
tbct_mt2
Legendary

Activity: 3052
Merit: 1049
|
 |
Today at 02:44:40 PM |
|
Just because coldcard had a security issue does not mean other hardware wallet manufacturers are also insecure. If you no longer trust HW because of the Mk3 incident, would you also stop trusting other wallets if Electrum happened to suffer a similar issue one day?
Electrum is an open source wallet. There are many hardware wallets, open source and close source. Cold card is not an open source hardware wallets. Their problem comes from many factors but close source is one of reasons. [LIST] Open Source Hardware Wallets.
|
RAZED | | | 100% | WELCOME BONUS | │ | █████████████████████ █████████████████████████ ████████████▀░░░░▀███████ ██████████▀░░▄▀▀▄░░▀█████ ██████████▄▄██▄▄██▄░▀████ █████▀░░░░░░░▀██░░█░░████ ████░░████▀▀█░░██▀░░▄████ ████░░████▄▄█░░█░░▄██████ ████░░█▀▀████░░██████████ ████░░█▄▄███▀░░██████████ █████▄░░░░░░░▄███████████ █████████████████████████ █████████████████████ | █████████████████████ █████████████████████████ ██████████▀▀░░░░░▀▀██████ ████████▀░░▄▄█░░▀▄░░█████ ██████▀░░▄█████▄░░▀░░████ █████░░▄████▄▀░░█▄▄░░████ ████░░▄███▄▀░░▄▀██▀░░████ ████░░▀▀██░░▄▀███▀░░█████ ████░░▄░░▀█████▀░░▄██████ █████░░▀▄░░█▀▀░░▄████████ ██████▄▄░░░░░▄▄██████████ █████████████████████████ █████████████████████ | | |
NO KYC | | | RAZE THE LIMITS ► PLAY NOW |
|
|
|
|
goldphysicalbitcoin
|
 |
Today at 03:24:56 PM |
|
For long-term BTC holdings, I still rely on the traditional paper wallet approach: generating private keys using mainstream wallets, encrypting them via the BIP38 standard, and laser-etching the resulting QR codes onto steel plates for long-term preservation. I keep a small amount of funds on centralized exchanges (CEXs) for short-term trading, while other cryptocurrencies requiring frequent DeFi interaction are stored in hardware wallets.
|
|
|
|
PrivacyG
Legendary

Activity: 1596
Merit: 2906
Fight for Privacy.
|
 |
Today at 03:45:35 PM |
|
Electrum is an open source wallet.
It would still be a similar catastrophe if a vulnerable code some how reached in a public version release unnoticed. It would not be catastrophic for us who have older Bitcoin Seeds but just like the Coldcard exploit, the people who generate using the newest version would still be affected. And not much can be done about it once it runs publicly. The first preventive thing to do is to not install the newest version in the first day of its release in order to avoid a zero day vulnerability. But few people do, most are actually excited to download it first day.
|
|
|
|
bitmover
Legendary

Activity: 3108
Merit: 7648
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
Today at 03:59:58 PM |
|
Just because coldcard had a security issue does not mean other hardware wallet manufacturers are also insecure. If you no longer trust HW because of the Mk3 incident, would you also stop trusting other wallets if Electrum happened to suffer a similar issue one day?
Electrum is an open source wallet. There are many hardware wallets, open source and close source. Cold card is not an open source hardware wallets. Their problem comes from many factors but close source is one of reasons. Bad software can be open source or closed source. To make the source code open it only costs one click, to change project to "public" on github. The problem was the seed generation method, which was insecure. Their randomness chip was being skipped, and the seed entropy dropped from 128 bits to 40. Other wallets, even closed source ones like ledger, do not have this vulnerability.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
OcTradism
Legendary

Activity: 2548
Merit: 1030
|
 |
Today at 04:01:13 PM |
|
I observe that people misunderstood the purpose of 2FA, seed phrase and password.
If your seed phrase is exposed, both password and 2FA becomes irrelevant because they can import your wallet into a new device. 2FA only protect unauthorised access to your app. If your login details are exposed, 2FA will protect you here and prevent logging in even when they have your password. If seed phrase is exposed, the only thing that'll save you is transferring the coins before the attacker does because no security feature would save you.
People can disable 2FA and import the wallet seed phrase to recover it. It's easy, like this. 2FA Electrum Wallet Recovery. The most important information is wallet seed phrase and passphrase (if it was used when creating a wallet), not wallet password or 2FA. The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it?
No, there are many wallets that offer passphrase to add more security to a wallet. https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adocRecovery Code Passphrases
The BIP39, Electrum v2, Aezeed, and SLIP39 schemes may all be used with an optional passphrase. If the only place you keep this passphrase is in your memory, it has the same advantages and disadvantages as memorizing your recovery code. However, there’s a further set of trade-offs specific to the way the passphrase is used by the recovery code.
|
|
|
|
PX-Z
Legendary

Activity: 2254
Merit: 1360
Wallet Transaction Notifier - @txnNotifierBot
|
 |
Today at 04:21:54 PM |
|
I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
It's normal to feel that way after an incident like this. However, there's no need to generalize and assume that all hardware wallets will and have the same issue. Trezor has been in the industry for more than a decade with a strong security track record. If you're planning to buy a hardware wallet, i'd stick with one that has been around for years and has built a solid reputation, such as Trezor. Longevity, regular security audits, and a proven track record are all good indicators when choosing a device.
|
|
|
|
|