Bitcoin Forum
August 04, 2026, 04:36:45 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: For nontechnical people, how are we supposes to know Trezor, Ledger, are safe  (Read 347 times)
arwin100
Legendary
*
Offline

Activity: 3528
Merit: 1097


Jack of all trades 💯


View Profile WWW
August 03, 2026, 11:49:31 PM
 #41

Ledger secure element is close source. It is among the wallets that I can not recommend.

Trezor is open source. Its code will be checked from time to times by some other developers. But in case if any bad like this happens, just make sure you use passphrase or go for a multisig wallet to avoid it.

Indeed ledger is not recommendable, since no one can verify how they secured our private keys.

This is what I like about Trezor, since they let community verify those safety protocols that they have done. Also adding those multi sig and passphrase will truly heal people to have more stronger protection even if there's some flaws or troubles shows up.

So with all of this things I believe having good security practice and being transparent is more better than those closed source set ups.

suhadi88
Full Member
***
Offline

Activity: 798
Merit: 110



View Profile
Today at 01:39:54 AM
 #42

Price and storage security are two separate decisions. It's important to remember not to assume any single device is perfect. No secure system is always a matter of initial entropy; everything has weaknesses. Regardless of how clever we are, the key is that storage should be based on risk tolerance.


███████████    B I T L I S T        🔄 MIXERS     📈 EXCHANGES     🎰 CASINOS    ███████████
████████████████████     CATALOG CRYPTO WEBSITES #KYCFREE    ████████████████████
███████████    |   Bitcointalk Archive   |   Image Hosting   |  Currency Converter  |    ███████████
TedMosby
Hero Member
*****
Offline

Activity: 1330
Merit: 553


WAGMI !!!


View Profile WWW
Today at 05:57:12 AM
 #43

It's a good question and it makes this thread worth reading.

Ledger secure element is close source. It is among the wallets that I can not recommend.

Trezor is open source. Its code will be checked from time to times by some other developers. But in case if any bad like this happens, just make sure you use passphrase or go for a multisig wallet to avoid it.

I think what OP meant is how do we know if a wallet is safe or not when we don't even have technical-related skills? Not everyone in the crypto space has that knowledge. Most people choose a wallet based on what other people use or recommend as safe. It's more about trust. Even if they know a wallet is open source or closed source, it doesn't mean much to non technical users. It's difficult for them to verify.

Also, for me, open source is not a guarantee that a wallet is safe or safer than a closed source wallet. It still depends on the people who contribute to the project. Imagine if the developers behind a closed source wallet are a group of elite developers and white hackers with 20 years of cyber security experience. Meanwhile, the open source wallet is developed by mid tier developers with contributions from thousands of other mid tier developers. In that case, how would people with no technical-related skills choose?

Sorry if my thinking is flawed or anything. I just find it interesting and I'm genuinely asking.

Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6467


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 08:37:06 AM
 #44

Also, for me, open source is not a guarantee that a wallet is safe or safer than a closed source wallet.
Yes, but just as I have posted, open source code is available for the public to review, the chance of seeing a bug or vulnerability in open source wallets is far higher than seeing it in close source wallets. Open source wallets are the way to go in my opinion, but only the reputable ones should be used. Open source wallet can be malicious, the reason the ones that are not reputable yet should be avoided.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
buwaytress
Legendary
*
Offline

Activity: 3612
Merit: 4385


I bit therefore I am


View Profile
Today at 01:22:29 PM
 #45

When creating a wallet, click on Options and choose "Extend this seed with custom words".
Type the custom words you want, and you have to back up (write down) both wallet seed words and your custom words.

Yes! lso something I used recommend to people from where I come from (there is almost no interest now). My native language isn't spoken by many, does not have a full formal dictionary, and does not have a very ambiguous latinised spelling. I think most local dialects are similar, and that makes it a natural defence against major language brute force.

If we were to compare the differences between these two wallets, it really comes down to radically different approaches to open-source and transparency. Electrum operates under standard, OSI-approved open-source licenses. Anyone can fork, inspect, modify, host, or re-distribute the code without restriction. A true Open Source. Because it is used as the codebase for countless wallet integrations, and thousands of independent developers regularly fork, test, compile, and stress-test the code.

Coldcard, on the other hand, has the "source available" facade. They transitioned their firmware to a proprietary license with a commons clause. This prevented independent developers from using their code, commercially or non-commercially. Because of this, developers outside of Coinkite had little incentive to actually build with, maintain, or deeply test the firmware.

This is exactly what brought them to their doom, in my opinion. The sheer arrogance and poor licensing decisions of their founder and CEO, Rodolfo Novak (aka nvK).

Then my suspicions, laid out in non-technical terms, are well-founded.

Battle-tested is what I have said before as my preference. A base source that so many people used (when I started out, using alt wallets, I even thought this was simply default, understanding later that almost everything I used simply derived from Electrum). Without needing to know much, just basic observation over the 10+ years I've used Electrum tells me I'm in safe(r) hands than switching to something that, even when open source, is at the bottom limits of the definition.

█████████████████████████
██████████████▀▄▄▄▀██████
████████▀▀▄▄████▄▄▀███
██████████████
████▀▄▄████████████
██▀██▀▀▀▀██
███▄▀▀███████
█▀███████████▄█
█▄▀▄██▀███▄████▄██
███▄█████▄▄▄████
█████▄████▄▄▄▀▀▄▄██████
███████▄▀▀▀▀▄▄▄██████████
█████████████████████████
.
 Jackpot ter .....  COMMUNITY POWERED CRYPTO CASINO  
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▄░▄▄▀██████▀▄██████
███████▄░█▄░███▀▄████████
█████████▄▀█░▀▄██████████
██████████▄▀█▄▀██████████
██████████▀▄░█▄▀█████████
████████▀▄███░██░▀███████
██████▀▄██████░▀▀░▀██████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
███████████████▀▀░░▐█████
███████████▀▀░░░░░░██████
███████▀▀░░░▄▄▀░░░░██████
████▀░░░░░▄█▀░░░░░▐██████
██████▄▄██▀░░░░░░░▐██████
███████████▄░░░░░░███████
██████████████▄░░▄███████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▀░░░▀▀▀▀▀░░░▀██████
█████▀░░░░░░░░░░░░░▀█████
████▀░░░░░░░░░░░░░░░▀████
████░░░░▄█▄░░░▄█▄░░░░████
███▌░░░░▀█▀░░░▀█▀░░░░▐███
███▌░░░░▄░░░░░░░▄░░░░▐███
█████▄▄░▄█▄▄▄▄▄█▄░▄▄█████
█████████████████████████
█████████████████████████
▀███████████████████████▀
 
  PLAY NOW  
YellowSwap
Full Member
***
Offline

Activity: 630
Merit: 197



View Profile
Today at 01:28:40 PM
 #46

Everyone on here are all once nontechnical, they learn and listen to advices on here they are lost who they once were yesterday and turned to new leaves, you can do the same if you are ready to learn.

Avoid any wallet that's not fully open source, like Ledger.
Avoid wallets that have proven to always give problems here and there,, and that's Ledger.

Do you know that ColdCard is new to me? I've never heard the name before until they got hacked.
I am still surprised that someone many people are using ColdCard and I don't know about it.

If those people just decided to stick with Trezor which is completely open source but of those losses will happen to them, ColdCard don't know what they are doing.

MusaMohamed
Sr. Member
****
Offline

Activity: 1582
Merit: 445



View Profile
Today at 03:45:45 PM
 #47

I second that stance on Ledger. I hate that company with a passion for several reasons.
They had some major f-ups in the past: Their user-data got leaked exposing over one million e-mail addresses and associated names and address info of people that purchased Ledger wallets.
See https://haveibeenpwned.com/Breach/Ledger
You can use that site to check history of wallet brands but I feel unsafe to use it to check emails. That site has this feature but I feel risky to enter my email address and check with them.

If I am unsure about my email security, I can reset its password, make a new strong one, reset 2FA for that email, that's enough.
Additionally, if I still feel unsafe, I can abandon that email.

The check for passwords is not helpful with me too.
https://haveibeenpwned.com/Passwords

I will check my password with
Are your passwords in the green (2026)? If I feel my passwords are weak, I will change them with password managers, and no longer manually create my passwords.
[GUIDE] How to Create a Strong/Secure Password.

Quote
Also their feature to restore a wallet is extremely shady and was criticized by the whole Bitcoin-sphere.
It was discussed a lot like a very hot topic in 2023.
Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties.

Kavelj22
Legendary
*
Offline

Activity: 2562
Merit: 1854


🔃EN>>AR Translator🔃


View Profile
Today at 04:22:56 PM
 #48

However for nontechnical people I think it's better to use hardware wallet that is known to have large users which means more money allocated to security audit, which also means lesser chance of bug as critical as this to happen but it's just my opinion..

And your opinion is very misleading because popularity doesn't surely mean security. Coldcard was widely used (proven by the number of transactions broadcasted by the hacker from infected wallets) and nobody doubted its integrity until Boom everything is gone. We already have millions of users sitting on a bomb called Ledger. Don't follow them.

For nontechnical users, their only hope is to follow opinions from devs community who can facilitate things at a basic level. The only community I can mention is bitcointalk technical boards where experts discuss everything especially critical parts. Here everybody can use technical boards to ask about any wallet and every detail without the need for deep knowledge level. Stay tuned.

Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!