Bitcoin Forum
August 05, 2026, 12:45:13 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Do Most Bitcoiners Confuse Owning a Hardware Wallet With Being Secure?  (Read 136 times)
Exitoral (OP)
Member
**
Offline

Activity: 112
Merit: 17

In Bitcoin we trust


View Profile
August 01, 2026, 05:29:58 PM
 #1

The recent coldcard hack has made people question hardware wallet security. It's not news that we all glorify self custody as it's the best. But this recent hack has raised questions that needs answers. But there's something we also need to keep in mind, there's no perfect system out there. Well, Bitcoin just made my statement obsolete. Back to the topic.

What caught my attention was not really the vulnerability, but a statement from this site I read the news from.

https://www.coindesk.com/markets/2026/08/01/binance-founder-cz-says-diversify-your-wallets-following-usd70-million-coldcard-exploit

It says critical flaws has remained undetected for years.

That got me thinking.

Many of us spend so much time picking the best wallet to secure our Bitcoin. But have we really solved it?
Hardware wallet reduces certain risks. But it doesn't eliminate all risk. Coldcard hack shows that a vulnerability can go undetected for years until someone finds it and exploit it. Developers can make mistakes no doubt, even users too can unknowingly put themselves at risk.

So this makes me wonder whether just owning the best wallet to protect your Bitcoin is really all that is?

To me coldcard incident doesn't prove that hardware wallet are not safe. But it just shows that we can't just trust our Bitcoin to just one manufacturer. What if an incident occurs where the news says a hardware wallet you use is at risk, what are you going to do?

So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
Jammy01
Newbie
*
Offline

Activity: 23
Merit: 3


View Profile
August 01, 2026, 06:59:13 PM
 #2



So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
I think there are  things you can do even if you already have a hardware wallet, don't leave your seed phrase online
Make sure it is somewhere safe offline and don't take picture of it

And if you are the type of person that hold a lot of bitcoin, you can also look into using multisig
coinlary
Sr. Member
****
Offline

Activity: 728
Merit: 275


Make decisions without looking back


View Profile
August 01, 2026, 07:52:45 PM
 #3

So this makes me wonder whether just owning the best wallet to protect your Bitcoin is really all that is?
No, at this point, consider adding your own security.
Coldcard has always been a recommendable wallet , it's source verifiable even thought it's  not open source, that specifically made the vulnerability  stayed hidden for years until now.
Quote
So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
Just as I've  mentioned above already, add your own extra  security layer like passphrase and cosigner (s) apart from the necessary steps needed to keep the seedphrase  safe .


Stalker22
Legendary
*
Offline

Activity: 2310
Merit: 1612



View Profile
August 01, 2026, 08:24:11 PM
 #4

I think there are  things you can do even if you already have a hardware wallet, don't leave your seed phrase online
Make sure it is somewhere safe offline and don't take picture of it

Keeping your seed phrase offline protects you from user error, not a zero-day hardware exploit or a hidden flaw in the device firmware (as was the case with coldcard hw.)  If the hardware or firmware itself is compromised, offline paper seed will not save your funds from hackers.

Quote
And if you are the type of person that hold a lot of bitcoin, you can also look into using multisig

Yes, that is better.  Another option is to add a passphrase to your seed phrase.  Even if someone manages to extract your seed through a hardware exploit or theft, your funds remain completely invisible and out of reach without that exact passphrase.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
ColdLava40
Full Member
***
Offline

Activity: 462
Merit: 158


Bitcoin


View Profile WWW
August 01, 2026, 09:30:09 PM
 #5

So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
I stated yesterday in a response that there's no 100% secured wallet.

Coldcard was just one of the many that will be flawed.investors when they think of hardware wallet as the golden card to full security I wonder if they understand that these devices were created by a company and by people who we can't tell of genuity.

There's no better way than the paper and pen we are used to. Being a bit completely can cause compromise to our funds. With paper and pen, you just need to be sure the seeds are safe and way from damage.

Davidvictorson
Hero Member
*****
Offline

Activity: 1792
Merit: 988



View Profile
August 01, 2026, 10:46:22 PM
 #6

So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
In statistics there is always 95% confidence that your results is significant.
This analogy is what I’d apply here with bitcoin wallets too. You can only be 95% confident that your bitcoin is secure. The other 5% uncertainty is always present which in this case the vulnerability that has existed for years which can be exploited once discovered. And in all honesty, there is really nothing you can do about that 5% you have have to keep your fingers crossed and hope that nothing happens.

█████████████████████████
█████████████████████████
█████████████████████████
███████████▀▄▀███████████
██▄▀▀▀██▀▄███▄▀██▀▀▀████
██▌▐███▄▄█████▀███████▐██
████████████████████████
███▌▐████████████████▐███
████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
  rizzy  █▌█▌█▌████
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌████
██████████████████████████████████████████████████████████████████
 
THE HOME OF THE
   MOST REWARDING   
GAMING EXPERIENCE

██████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████
 100% DEPOSIT
MATCH
+ 100 FREE SPINS
 
██████████████████████████████████████████████████████████████████
████▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
████▐█▐█▐█
 
    PLAY NOW    
Emjay24
Sr. Member
****
Offline

Activity: 560
Merit: 314



View Profile
August 01, 2026, 10:53:18 PM
 #7

What caught my attention was not really the vulnerability, but a statement from this site I read the news from.

https://www.coindesk.com/markets/2026/08/01/binance-founder-cz-says-diversify-your-wallets-following-usd70-million-coldcard-exploit

It says critical flaws has remained undetected for years.

That got me thinking.
It was actually detected, but they didn't take the warning seriously until reality hit

The bug was incredibly simple, it's shocking it was not discovered earlier.
This was said but nvk and his team perhaps ignored this warning two years ago and anytime till this exploitation days ago.
https://www.youtube.com/watch?v=oj_W3xOlt6U

Perhaps hackers used AI to scan these things, found that video and took action for their jobs.

No wallet is 100% safe from social engineering as long as it is a hot wallet, but HW is better than wallet in hot devices, although cold storage remains the best since it's offline use eliminates to a very high extent the possibilities of social engineering. I always recommend using a passphrase of at least 25 word long to add extra layer of security to your seed phrases.

AVE5
Sr. Member
****
Offline

Activity: 980
Merit: 362


Winning & Loosing is the option. Take a decision


View Profile
August 01, 2026, 10:59:44 PM
 #8

So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
I think you're looking out for how you'll be convinced to the point of 100% trusting third parties or the manufacturers even when you learns that it's truly impossible.
After acknowledging about the recent of the hacked hardware wallet and the mechanical or engineering sides that can make it vulnerable not to be reliable, then you should believe there's no storage source that should be that reliable to be trusted 100%.
Prioritizing on privacies also strengthens users security.

Hypnotizer
Full Member
***
Online Online

Activity: 336
Merit: 223



View Profile
August 03, 2026, 08:11:04 PM
 #9

The recent coldcard hack has made people question hardware wallet security. It's not news that we all glorify self custody as it's the best. But this recent hack has raised questions that needs answers. But there's something we also need to keep in mind, there's no perfect system out there. Well, Bitcoin just made my statement obsolete. Back to the topic.

From what I understand, the security isn’t even about the hardware itself rather it’s the software/firmware that the hardware company has. So Self Custody is still best but the responsibility are cumbersome to an extent, so adding a little more security layer like passphrase or multisig would help. Also the people that generated their seedphrase outside the wallet were not drained in this exploit, so maybe generating your phrase yourself with an RNG with good entropy is better.

Quote
So this makes me wonder whether just owning the best wallet to protect your Bitcoin is really all that is?

No, owing “the best” wallet is not all that will protect your coins, there is a lot more to the security of your wallet than just buying a good and trusted hardware wallet.

Cryptomultiplier
Sr. Member
****
Offline

Activity: 1526
Merit: 314



View Profile WWW
August 03, 2026, 08:53:45 PM
 #10

So this raises the question, even after getting a secure wallet, what other steps can one take to make sure your Bitcoin is safe?
I think you're looking out for how you'll be convinced to the point of 100% trusting third parties or the manufacturers even when you learns that it's truly impossible.
After acknowledging about the recent of the hacked hardware wallet and the mechanical or engineering sides that can make it vulnerable not to be reliable, then you should believe there's no storage source that should be that reliable to be trusted 100%.
Prioritizing on privacies also strengthens users security.
I can only advice we at least learn to diversify our portfolio into different hardware wallets because of such scare that hit coldcard users recently. Even at that, anything can happen.

If you use a hardware wallet at least have a time frame in mind you are holding for, so as to move the funds or diversify it or withdraw it for a better use before a bug is exploited and hackers steal the sweat of your patience and toil.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
████████████████████████
 
EARNBET 
 
████████████████████████
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

HIGHEST
VIP REWARDS

 G U A R A N T E E D   
|
█▀▀









█▄▄
 
🜲

▀▀█









▄▄█
KING OF
THE CASTLE

$200K in prizes
| 
[PLAY NOW]
promise444c5
Legendary
*
Offline

Activity: 1092
Merit: 1066


All things are numbers


View Profile WWW
August 04, 2026, 08:04:22 PM
 #11

It’s not about hardware wallet, it can be any wallet so far there’s a flaw in their code that can possibly be exploited in future..you never know, the future can be now.

If you use a hardware wallet at least have a time frame in mind you are holding for, so as to move the funds or diversify it or withdraw it for a better use before a bug is exploited and hackers steal the sweat of your patience and toil.
A bug can bet detected at any time, could even be the day you bought and deposit on it.. so your solution doesn’t help.

For now, it’s better to use an open source wallet.. open source has a lot of contributions and as a result it has less probability of having a serious bug than a wallet that is not open source. But that doesn’t mean  you shouldn’t add your own extra security.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
EL MOHA
Sr. Member
****
Offline

Activity: 1218
Merit: 494



View Profile
August 04, 2026, 08:47:57 PM
 #12

No, at this point, consider adding your own security.
Coldcard has always been a recommendable wallet , it's source verifiable even thought it's  not open source, that specifically made the vulnerability  stayed hidden for years until now.

If you read the discussion thread about this vulnerability you will notice that the vulnerability wasn’t just discovered now but rather was exploited now because there were proofs of people warning against the vulnerability of the TRNG used for the generation of the coldcard seed phrase and it was not actually that random, first it was 40 bits and then upgraded to 72bits entropy, if by all this accusations we all can confirm that Coldcard negligence should be held accountable.

There's no better way than the paper and pen we are used to. Being a bit completely can cause compromise to our funds. With paper and pen, you just need to be sure the seeds are safe and way from damage.

What do you mean by the paper and pen, it’s generating your own seed phrase by yourself like with dice and or picking words, if that’s it then it considered safe if they’re is enough entropy. But you need back up on steels as paper can damage easily

ColdLava40
Full Member
***
Offline

Activity: 462
Merit: 158


Bitcoin


View Profile WWW
August 04, 2026, 08:57:17 PM
 #13

What do you mean by the paper and pen, it’s generating your own seed phrase by yourself like with dice and or picking words, if that’s it then it considered safe if they’re is enough entropy. But you need back up on steels as paper can damage easily
Backup, that's what I meant.

IjawMan
Full Member
***
Offline

Activity: 518
Merit: 241



View Profile
August 04, 2026, 11:53:56 PM
 #14

With what happened with the Coldcard wallet it made us to know that there could be one vulnerability lying down quietly in any of the wallets we call the best software or hardware wallets,

And it just a matter of time before some one may discover that particular vulnerability which can be very difficult also to discover. It is for us to pray nobody discovered it, else, we might have another Coldcard saga.

Where the above is yet to be, every other measures to securing your coins with a hardware wallet is in your hands as a responsibility.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!