Bitcoin Forum
August 04, 2026, 08:41:04 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: For nontechnical people, how are we supposes to know Trezor, Ledger, are safe  (Read 365 times)
FinneysTrueVision
Legendary
*
Offline

Activity: 2464
Merit: 1178



View Profile
August 03, 2026, 10:10:01 AM
 #21

Coldcard is close source. The source code of Coldcard is only for verifiable but not open source.

It is not closed source because you could still inspect and modify their source code as long as you weren’t using it for commercial purposes. Their website still refers to it as being open source but it is somewhat downplayed by instead using the term ‘verifiable’ sometimes. If you read through comments on this forum and social media, most people do not consider them to truly be open source because of their restrictive license.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Ucy
Sr. Member
****
Offline

Activity: 3304
Merit: 438


Compare non-kyc instant exchanges. Get best deal


View Profile
August 03, 2026, 10:24:48 AM
 #22

Nothing is safe until little to zero fault/issue can be found in it. Open Source does not gurantee faultless work, what can guarantee it is having the most awoken people reviewing it (or you could use their guides) but without limiting reviews from others..so it has to be some sort of permissionless review environment.
Other reviewers may spot issues here and there depending on how bright they are, but the brightest reviewers (awoken ones) could spot the whole issues, including what others can spot.  

Opensourcing your work/idea makes it more likely to be found and reviewed by the brightest, but if close sourced, the possibility will be very much diminished since they are unlikely to get hired by people who dislike opensource or who fear certain people can easily spot their dark secrets in their work.
If the awoken are not part of a work, and it becomes too contentious/difficult, you could indirectly(or directly) ask them where they are likely to see your question and answers them. They may avoid opensource environment if it's too toxic

Important to note that good or thorough review should include hardware. Don't just believe it if they say it's airgapped or something like that. There may be unknown or careful disguised part/parts that can be used to spy on your device activities



▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Nathrixxx
Sr. Member
****
Offline

Activity: 602
Merit: 292


Bitz.io Best Bitcoin and Crypto Casino


View Profile
August 03, 2026, 10:45:40 AM
 #23

If you don't know about the technical aspects of Bitcoin, then you can ask experienced users in a community like this for the best recommendations for those that are open source and those that are not. This is why this forum was created to share and discuss Bitcoin; then we can also pick up a challenge to learn over time in order to know how we can increase our knowledge about Bitcoin's technical aspects and be able to do some findings independently.

█ 
███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io█ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀██
███████████████▐▌
███████████████▐▌
███▄▄████▄▄▄██▄▄
▄█████████████████████▄
████████████████████
██
█████████████████████
▀██
█████████████████████▀
▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
███████████████▄
▄███████████████████▄
▄██████████████
██████▄
▄██████████████████████
████████████████████████
███████████████████████
██████████████████████
████████████████████████
▀█████████████████████▀
███████████████████▀
███████████████▀
▀▀███████▀▀
HIGH
ODDS
 
█████████   ██

......PLAY NOW......

██   █████████
█ 
Artemis3
Legendary
*
Offline

Activity: 2282
Merit: 1632


CLEAN non GPL infringing code made in Rust lang


View Profile WWW
August 03, 2026, 10:46:30 AM
 #24

However, this recent event definitely shattered trust on hardware wallets. I'm thinking is there a way you make your own hardware or software wallet or just use open source? What are the pros and cons if I make my own?
The create your own cold/offline  wallet remains the best option until date for me. Just get an airgapped device and then use electrum in offline mode or any reputable open source wallet and then create your seed phrase, add passphrase and then broadcast your  transaction from watch only software wallets.

PROS: you’re not trusting anybody but rather yourself.
CONS: the point of failure is your set up wasn’t actually offline, you might have used a bad device which is not totally cold device
So basically, the only thing that will make this bad is yourself and how you set it up, and you really need to be a tech-savvy individual to DIY or probably knows basic safety and can read instructions to do this. Never done this before tbh but curious and might make one. This hack was all over my X timeline so was curious if there's a possibility.

This is what i would suggest: Boot pc in Linux (maybe from an usb thumbdrive). Install Electrum, create wallet, write down seed words by hand in paper, copy lots of addresses electronically, delete wallet, turn off PC. That paper with written words is your cold wallet, and you can monitor it without recreating it in case you want to see your deposits.

Yes you can improve this process a bit by going airgapped, faraday cage, acoustic isolated room, etc; then move a file to another secure OS pc net connected to broadcast etc; especially if its meant to handle money of others (ie. exchange, pool, etc).

So: Install Electrum, write seed words (by hand), copy addresses, delete wallet.

You can always familiarize yourself with the process by recreating the wallet using the seed words in a different pc.

I'm not against hardware wallets, but I'm against the use of hardware wallets as a form of cold wallet. IMO a hardware wallet is optional, not a must. It may be preferable to people with malware infested OSes that can't bother to boot Linux or *bsd. Also never forget that flash memory retains its data for like 5 years, so don't be throwing a hardware wallet in a safe and think you can use it later. Seed words are easy to hide too, be clever, take a book, mark some words in it, etc.

██████
███████
███████
████████
BRAIINS OS+|AUTOTUNING
MINING FIRMWARE
|
Increase hashrate on your Bitcoin ASICs,
improve efficiency as much as 25%, and
get 0% pool fees on Braiins Pool
sunsilk
Hero Member
*****
Online Online

Activity: 3724
Merit: 656



View Profile
August 03, 2026, 10:52:59 AM
 #25

With the suggestions about another brand of HW to be trusted. I think that the worry remains there despite that there will be more audits and volunteer developers to check their open source codes.

The best practice for the non technical holders is to split the holdings you have.

Maybe do it like this;

30% in the HW(Trezor, etc.)
30% in Electrum
20% in Blue wallet
20% up to you, but not with exchanges.

So this is just an example allotment but you do you.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
decodx
Hero Member
*****
Offline

Activity: 1484
Merit: 962


#kycfree 🗽


View Profile
August 03, 2026, 11:32:01 AM
Merited by vapourminer (4)
 #26

Coldcard is close source. The source code of Coldcard is only for verifiable but not open source.

It is not closed source because you could still inspect and modify their source code as long as you weren’t using it for commercial purposes. Their website still refers to it as being open source but it is somewhat downplayed by instead using the term ‘verifiable’ sometimes. If you read through comments on this forum and social media, most people do not consider them to truly be open source because of their restrictive license.

Coldcard's software is not considered open source because it doesn't meet the core principles of what open source actually means.

Sure, they put their code on GitHub so anyone can read it, but viewing code isn't the same as open source. It's more like "source-available." They put commercial restrictions on their code so other companies and developers can't take it and build competing devices. it was a total dick move, pure and simple. They built Coldcard's original foundation directly on top of MicroPython, a purely open-source, MIT-licensed project built by the community. They happily took advantage of years of free, open-source labor from thousands of independent devs to get their product off the ground.

I mean, from a business perspective, I can understand why they did it. But it was a wrong decision. When you lock down the license to prevent commercial use, you lose the benefit of hundreds of extra eyes auditing your product for free. The recent firmware exploit proved that just having public code doesn't magically make it safe.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
EL MOHA
Sr. Member
****
Online Online

Activity: 1218
Merit: 494



View Profile
August 03, 2026, 11:57:17 AM
 #27

The best practice for the non technical holders is to split the holdings you have.

Maybe do it like this;

30% in the HW(Trezor, etc.)
30% in Electrum
20% in Blue wallet
20% up to you, but not with exchanges.

So this is just an example allotment but you do you.

I am not against the practice of splitting bitcoins into different wallets it’s one of the most secure means of storing your bitcoins but that is subjected to if you can handle the redundancy of storing your seed phrases and also possibly passphrase because they must not be stored in same place and you still need to have more than one back up for each seed phrase at different locations, this is where redundancy comes in.

For this your setup though I am not comfortable with it, you have total of 50% of the coin in electrum and BlueWallet to which both are actually hot wallet except you wish to run them as cold wallet, if not halve of your holdings already is online and will have one point of failure which is your device, once it gets compromised both wallet can be affected on that device 

sunsilk
Hero Member
*****
Online Online

Activity: 3724
Merit: 656



View Profile
August 03, 2026, 12:11:33 PM
 #28

The best practice for the non technical holders is to split the holdings you have.

Maybe do it like this;

30% in the HW(Trezor, etc.)
30% in Electrum
20% in Blue wallet
20% up to you, but not with exchanges.

So this is just an example allotment but you do you.

I am not against the practice of splitting bitcoins into different wallets it’s one of the most secure means of storing your bitcoins but that is subjected to if you can handle the redundancy of storing your seed phrases and also possibly passphrase because they must not be stored in same place and you still need to have more than one back up for each seed phrase at different locations, this is where redundancy comes in.
Welp, that's another thing to be done and how we're going to keep our passphrases safe somewhere in our house. I don't think that's a problem if you're a privy person and rarely have visitors in the house.

But if you're in a house where you're also living with your fam, you have to off limits some areas where it's only limited to you to be accessed.

For this your setup though I am not comfortable with it, you have total of 50% of the coin in electrum and BlueWallet to which both are actually hot wallet except you wish to run them as cold wallet, if not halve of your holdings already is online and will have one point of failure which is your device, once it gets compromised both wallet can be affected on that device 
That's only an example of what I have demonstrated. If you have other means of what you think is safer, you do what you think is the better option for you.

I have used electrum for a long time and did installed it in a laptop that's quite old for several and never had got issues with it.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
decodx
Hero Member
*****
Offline

Activity: 1484
Merit: 962


#kycfree 🗽


View Profile
August 03, 2026, 12:32:01 PM
Merited by vapourminer (1)
 #29

This is what i would suggest:
<...>

This is a terrible suggestion that doesn't really fix the issue. You just replaced ColdCard with Electrum. If a critical vulnerability or flaw were found in Electrum instead of the ColdCard firmware, you'd end up facing the exact same outcome. 

I'm not against hardware wallets, but I'm against the use of hardware wallets as a form of cold wallet.

So you don't trust hardware wallets and their developers, but you trust Electrum software? Can you explain why?

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
citywise2
Full Member
***
Offline

Activity: 188
Merit: 100



View Profile
August 03, 2026, 01:28:24 PM
 #30

If the unsafeness on the Cold card wallet was not noticed by the developers for 5 years, we in this forum certainly cannot know the real safeness of these other hardware wallets. We will only need to trust the people who created these devices.

Also, there is this very headshaking news hehehehe.



Unlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges

Security issues in the crypto market often push investors in predictable directions. For instance, following the collapse of the FTX exchange in November 2022, investors rushed to withdraw large volumes of coins from centralized platforms and move them into self-custody solutions, including hardware wallets and personal devices.

Now they are doing the opposite by moving coins to exchanges, as the ongoing multi‑million‑dollar Coldcard hardware‑wallet incident, which began Friday, has raised fresh questions about the safety of self‑custody.


Read in full https://www.coindesk.com/markets/2026/08/02/unlike-the-ftx-collapse-the-usd88-million-coldcard-exploit-has-investors-sending-bitcoin-back-to-exchanges
We are living in a fast paced society now and what is termed secured and recommendable today most likely would be reviewed tomorrow with a higher and smarter technology or approach and then the centre would no longer hold and people start to run helter-skelter.  What to do - never ignore the threat, someday there could be improvement and if many are in agreement with them, why not, join them.

███████████    B I T L I S T        🔄 MIXERS     📈 EXCHANGES     🎰 CASINOS    ███████████
████████████████████     CATALOG CRYPTO WEBSITES #KYCFREE    ████████████████████
███████████    |   Bitcointalk Archive   |   Image Hosting   |  Currency Converter  |    ███████████
fenican
Hero Member
*****
Offline

Activity: 1405
Merit: 507


View Profile
August 03, 2026, 01:37:26 PM
 #31

The random number generator used by Ledger is a hardware true random generator that was evaluated by third-party labs and holds an EAL5+ and AIS-31 security certification. Ledger hardware wallets use a custom-built operating system named Ledger OS and I seriously doubt they'd be stupid enough, like Coldcard apparently was, to also include an unreliable software random generator. A True Random Number Generator (TRNG) works by capturing unpredictable physical noise from the environment—such as thermal noise, atmospheric noise, or oscillator jitter—and converting it into digital bits rather than using a math formula.

The problem with Coldcard was a bug that - instead of using true hardware-based randomness - an incorrect macro check caused the device to fall back to a predictable software pseudorandom number generator (Yasmarang) seeded only by non-secret chip data and system timers. Having any fallback to a non-hardware RNG is insane and it's just crazy that open source reviewers failed to catch this, but hackers clearly found it.
buwaytress
Legendary
*
Offline

Activity: 3612
Merit: 4385


I bit therefore I am


View Profile
August 03, 2026, 01:49:35 PM
Merited by MusaMohamed (1), decodx (1)
 #32

Fully open-source is usually where I head to (and I'm non-technical). If you're able to, choose something you know is robust and often tested (an active dev community and constant updates from active discussion is a sign).

One opinion: it might not be the wisest opinion, I know it's certainly not what some people would like to hear, but if you're non-technical, but you don't have very much, you might actually not need a hardware wallet. If you're relatively careful anyway online, it is probably enough to use an open-source digital wallet like Electrum and simply keep the seed phrase safe. Might help you sleep better.

I know decodx above said it's merely a replacement (and it is a good point), but as with Coldcard, the last time a critical vulnerability was discovered in Electrum, it was very quickly and typically more easily fixed (simply by updating the software and a sweep... I suppose coldcard's firmware is as easy but I can't say). Both benefit from being open-source, but I feel (with familiarity bias no doubt) Electrum's community and dev is simply far more discerning than any other I know and use. Coldcard's fallback vulnerability... to my non-technical mind... seems to have been something that should have been caught earlier.


█████████████████████████
██████████████▀▄▄▄▀██████
████████▀▀▄▄████▄▄▀███
██████████████
████▀▄▄████████████
██▀██▀▀▀▀██
███▄▀▀███████
█▀███████████▄█
█▄▀▄██▀███▄████▄██
███▄█████▄▄▄████
█████▄████▄▄▄▀▀▄▄██████
███████▄▀▀▀▀▄▄▄██████████
█████████████████████████
.
 Jackpot ter .....  COMMUNITY POWERED CRYPTO CASINO  
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▄░▄▄▀██████▀▄██████
███████▄░█▄░███▀▄████████
█████████▄▀█░▀▄██████████
██████████▄▀█▄▀██████████
██████████▀▄░█▄▀█████████
████████▀▄███░██░▀███████
██████▀▄██████░▀▀░▀██████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
███████████████▀▀░░▐█████
███████████▀▀░░░░░░██████
███████▀▀░░░▄▄▀░░░░██████
████▀░░░░░▄█▀░░░░░▐██████
██████▄▄██▀░░░░░░░▐██████
███████████▄░░░░░░███████
██████████████▄░░▄███████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▀░░░▀▀▀▀▀░░░▀██████
█████▀░░░░░░░░░░░░░▀█████
████▀░░░░░░░░░░░░░░░▀████
████░░░░▄█▄░░░▄█▄░░░░████
███▌░░░░▀█▀░░░▀█▀░░░░▐███
███▌░░░░▄░░░░░░░▄░░░░▐███
█████▄▄░▄█▄▄▄▄▄█▄░▄▄█████
█████████████████████████
█████████████████████████
▀███████████████████████▀
 
  PLAY NOW  
MusaMohamed
Sr. Member
****
Offline

Activity: 1582
Merit: 445



View Profile
August 03, 2026, 02:04:03 PM
Merited by buwaytress (1)
 #33

One opinion: it might not be the wisest opinion, I know it's certainly not what some people would like to hear, but if you're non-technical, but you don't have very much, you might actually not need a hardware wallet. If you're relatively careful anyway online, it is probably enough to use an open-source digital wallet like Electrum and simply keep the seed phrase safe. Might help you sleep better.
Use Electrum wallet, create a single signature wallet with a passphrase, or if want more security, creating a multisig wallet. It's not hard to create a single signature wallet with a passphrase (custom words).

When creating a wallet, click on Options and choose "Extend this seed with custom words".
Type the custom words you want, and you have to back up (write down) both wallet seed words and your custom words.

Next step will be typing and confirming both seed words and custom words, before creating a wallet password.

Some guides to use Electrum wallet.
Creating an Electrum wallet.
Creating a cold storage wallet in Electrum.
Creating a multisig wallet in Electrum.

Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7684



View Profile WWW
August 03, 2026, 02:08:06 PM
 #34

The random number generator used by Ledger is a hardware true random generator that was evaluated by third-party labs and holds an EAL5+ and AIS-31 security certification. Ledger hardware wallets use a custom-built operating system named Ledger OS and I seriously doubt they'd be stupid enough, like Coldcard apparently was, to also include an unreliable software random generator. A True Random Number Generator (TRNG) works by capturing unpredictable physical noise from the environment—such as thermal noise, atmospheric noise, or oscillator jitter—and converting it into digital bits rather than using a math formula.
~snip~


No, they wouldn't be that stupid, they just built an option into their firmware so that clients can send their seeds remotely to some third parties to store them for them. We can argue about who is stupid and who is dumber in this story, but serious companies don't do stupid things like this if they care about their clients.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Kryptowerk
Legendary
*
Offline

Activity: 2366
Merit: 1566


Crypto Casino with No KYC on routine deposits


View Profile
August 03, 2026, 02:19:23 PM
Merited by vapourminer (1), Lucius (1)
 #35

Ledger secure element is close source. It is among the wallets that I can not recommend.

Trezor is open source. Its code will be checked from time to times by some other developers. But in case if any bad like this happens, just make sure you use passphrase or go for a multisig wallet to avoid it.

I second that stance on Ledger. I hate that company with a passion for several reasons.
They had some major f-ups in the past: Their user-data got leaked exposing over one million e-mail addresses and associated names and address info of people that purchased Ledger wallets.
See https://haveibeenpwned.com/Breach/Ledger

Also their feature to restore a wallet is extremely shady and was criticized by the whole Bitcoin-sphere.

Open-source plus long-lasting flaw-less reputation is a good indicator for a decent HW wallet. There is no guarantee for safety, though.

Older Trezor-wallets were hacked in the past, however afaik it does need physical access to the Trezor device.

▄▄▄▀▀▀▀▀▄▄▄
▄█▀████▄▄▄████▀█▄
▄████▄▄▄▄▄▄▄▄▄████▄
████▄█████▄▄▄█████▄████
██▀▀▀███▄▄█████▄▄███▀▀▀██
█▌█████▀█████████▀███▐█
████████▀█████▀▄██▀████
████▀▄█████▄██████
██▀▄▀▄▐█▌█████████
█████████▐█▌█████████
▀█▄██████▐█▌▄█▀▀▄█▀
▀██▄▄▄▄███▄▄▄▄██▀
▀▀▀█████▀▀▀
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
100
FREE SPINS

 
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
 
  CLAIM BONUS  
_act_
Legendary
*
Offline

Activity: 1694
Merit: 1946



View Profile
August 03, 2026, 02:42:25 PM
 #36

The best practice for the non technical holders is to split the holdings you have.

Maybe do it like this;

30% in the HW(Trezor, etc.)
30% in Electrum
20% in Blue wallet
20% up to you, but not with exchanges.

So this is just an example allotment but you do you.

I am not against the practice of splitting bitcoins into different wallets it’s one of the most secure means of storing your bitcoins but that is subjected to if you can handle the redundancy of storing your seed phrases and also possibly passphrase because they must not be stored in same place and you still need to have more than one back up for each seed phrase at different locations, this is where redundancy comes in.

For this your setup though I am not comfortable with it, you have total of 50% of the coin in electrum and BlueWallet to which both are actually hot wallet except you wish to run them as cold wallet, if not halve of your holdings already is online and will have one point of failure which is your device, once it gets compromised both wallet can be affected on that device 
When the numbers of wallets that I am having is getting higher, I have thought of this before and changed because there is no way I can continue to backup the seed phrase not together and be thinking that it is safe and be thinking one or more of the seed phrases will not be lost.

I changed to passphrase with just a single seed phrase instead which solved the problem. But the passphrase are of long characters. The least characters among them was 30 long in length and it has different unguessable characters which is very secure against todays devices that can be used to brute force them.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
decodx
Hero Member
*****
Offline

Activity: 1484
Merit: 962


#kycfree 🗽


View Profile
August 03, 2026, 07:32:23 PM
Merited by vapourminer (1), buwaytress (1)
 #37

Fully open-source is usually where I head to (and I'm non-technical). If you're able to, choose something you know is robust and often tested (an active dev community and constant updates from active discussion is a sign).

One opinion: it might not be the wisest opinion, I know it's certainly not what some people would like to hear, but if you're non-technical, but you don't have very much, you might actually not need a hardware wallet. If you're relatively careful anyway online, it is probably enough to use an open-source digital wallet like Electrum and simply keep the seed phrase safe. Might help you sleep better.

I know decodx above said it's merely a replacement (and it is a good point), but as with Coldcard, the last time a critical vulnerability was discovered in Electrum, it was very quickly and typically more easily fixed (simply by updating the software and a sweep... I suppose coldcard's firmware is as easy but I can't say). Both benefit from being open-source, but I feel (with familiarity bias no doubt) Electrum's community and dev is simply far more discerning than any other I know and use. Coldcard's fallback vulnerability... to my non-technical mind... seems to have been something that should have been caught earlier.

My comparison of Electrum wallet with ColdCard software is merely to point out that no software is entirely immune to bugs or flaws. even open-source giants with amazing dev communities like Electrum.

But you actually make a fair point for beginners holding a modest funds, a battle-tested software wallet like Electrum on a secure, clean device, combined with a properly backed-up seed phrase can be totally reasonable.

If we were to compare the differences between these two wallets, it really comes down to radically different approaches to open-source and transparency. Electrum operates under standard, OSI-approved open-source licenses. Anyone can fork, inspect, modify, host, or re-distribute the code without restriction. A true Open Source. Because it is used as the codebase for countless wallet integrations, and thousands of independent developers regularly fork, test, compile, and stress-test the code.

Coldcard, on the other hand, has the "source available" facade. They transitioned their firmware to a proprietary license with a commons clause. This prevented independent developers from using their code, commercially or non-commercially. Because of this, developers outside of Coinkite had little incentive to actually build with, maintain, or deeply test the firmware.

This is exactly what brought them to their doom, in my opinion. The sheer arrogance and poor licensing decisions of their founder and CEO, Rodolfo Novak (aka nvK).

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Renampun
Sr. Member
****
Offline

Activity: 3108
Merit: 415


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile
August 03, 2026, 08:02:40 PM
 #38

For non-technical people, it might be harder for them to know whether a hardware wallet is better or worse, due to their limited knowledge, which makes it harder for them to understand. However, that doesn't mean they can't make informed decisions, since reviews from the community and recommendations from more experienced users, especially in this forum, can help them choose the best hardware wallet.. also, there's a website called walletscrutiny.com where non-technical people can find more information about a wallet, it can be a useful reference for non-technical users.

██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
 150 FS NO DEPOSIT BONUS  Subscribe to Our Telegram ( > )  


████
██
██
██
██
██
██
██▄▄
▀▀▀▀
 
████████████████████████████████████████
 
 PLAY NOW
 
████████████████████████████████████████


████
██
██
██
██
██
██
▄▄██
▀▀▀▀
MicroGuy
Legendary
*
Offline

Activity: 2562
Merit: 1036


x.com/realmicroguy


View Profile WWW
August 03, 2026, 08:08:37 PM
 #39

Just keep it simple and use Electrum and backup your wallet to a flashdrive. Keep it simple.
Localhostspeed
Sr. Member
****
Offline

Activity: 420
Merit: 295



View Profile
August 03, 2026, 08:16:15 PM
 #40

Based on what I’ve read, it seems non coldcard wallets are safe. But how do we know if these other mainstream wallets are safe from other exploits that we currently are not aware of?

Luckily, I do not have a coldcard. But I am not sleeping easy right now with my setup.

Has there been real academics or non crypto related researchers (unbiased) that have published findings on the open source Trezor software?

There is no best of best wallets but there are wallets that are industry standard, like open source, popular and well recommended ones are the type you need to go for. Over the years, you will see that people warned about using of ledger wallets, if they tell you to avoid them, make sure you avoid. I'm sure that the people that are using Coldcard don't need to be told before they stop using Coldcard, they will lose all their customers to another hardware company one day.

I think it will make sense to be doing research too, it doesn't have to be techy one. You can randomly be checking the blogs and social handles if there are complain about your wallet. Before this Coldcard hacked occurred, there were multiple reports about the old wallet but the team didn't respond. This might be what to be using for other hardware wallet. If they are don't value reviews or complaints from customers, stay away from them.

Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!