Bitcoin Forum
August 06, 2026, 02:53:56 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?  (Read 147 times)
dim_mak5 (OP)
Member
**
Offline

Activity: 207
Merit: 17


View Profile
August 05, 2026, 07:55:23 PM
 #1

Hello,

Bitcoiners are told the main motto/slogan is Verify not Trust.

How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.

I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?

The ColdCard hardware wallet hack is nothing compare to Quantum computers. If human hackers can do hacks like this today without quantum computers and with assistance from Ai then imagine what Ai hack bots can do when Ai gets quantum computers to find vulnerabilities in Entropy chips in older hardware wallets instead of brute forcing 12 or 24 words Shocked

For example can anyone confirm that the first Ledger & Trezor hardware wallets will be safe from Entropy vulnerabilities in 50 years time or even in 5 years time?

Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.

Governments want people to store their bitcoin on centralized exchanges so governments can easily confiscate people bitcoin so governments are going to attack the hardware wallet entropy of bitcoin to persuade people not to self custody. Blackrock dont want hodlers to self custody Bitcoin so they are investing $Billions in hacking Entropy chips.

There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability? As of now Ai Hackers have the edge over Ai Audits because Ai audits are not jailbroken like Ai hackers and Ai hackers are always 1 step ahead while Ai audits are playing catch up always 1 step behind.

Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.

Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?

This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank Roll Eyes









Zaguru12
Legendary
*
Offline

Activity: 1512
Merit: 1255


Instant Crypto Withdrawals


View Profile WWW
August 05, 2026, 08:17:26 PM
 #2


How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.

The thing is even the manufacturers do not know how random your seed phrase was generated because it’s the underlying software that does this mathematical calculations. My straight answer is even if hardware wallets say they are random but you do not believe them, simply just generate your own seed phrase either with dice or other software you trust then proceed to add extended words (Passphrase).

There is an ongoing discussion about why this wallets cannot even identify their own randomness here https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210


Quote
Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.

Do you know hardware wallets are simply part of self custody, self custody means you are taking junk of the risk alone. So I don’t understand why you even blame Satoshi for something you want them to implement which is insurance, the exact example you give is the reason why bitcoin is for everyone. If someone has $1trillion then $1k is cheap to and then if they don’t have such high amount it’s not worth it and that’s why bitcoin is for eveyone

For me if you want insurance you definitely have to use centralized platforms like exchange or ETF not actually claiming to be your own self custody and wants insurance. Although due to some negligence I understand your point but hardware wallets running on insurance have the right to ask for your seed phrase as a security feature which is bad

CryptoBuds
Legendary
*
Offline

Activity: 2716
Merit: 1074


HODL


View Profile
August 05, 2026, 08:48:55 PM
 #3

Bitcoiners are told the main motto/slogan is Verify not Trust.

How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.

I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?

Verify, don't trust, doesn't mean I have to test every transistor on a hardware wallet myself. Verification in Bitcoin is a spectrum, that mean verification exists on a spectrum. You need to minimize trust by combining source code, deterministic build, firmware signature, reproducible build, BIP-39 compatibility, open review and your own operational security. You can never eliminate trust completely. Using hardware means there will be some trust assumptions.

█████████████████████████
█████████████████████████
█████████████████████████
███████████▀▄▀███████████
██▄▀▀▀██▀▄███▄▀██▀▀▀████
██▌▐███▄▄█████▀███████▐██
████████████████████████
███▌▐████████████████▐███
████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
  rizzy  █▌█▌█▌████
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌████
██████████████████████████████████████████████████████████████████
 
THE HOME OF THE
   MOST REWARDING   
GAMING EXPERIENCE

██████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████
 100% DEPOSIT
MATCH
+ 100 FREE SPINS
 
██████████████████████████████████████████████████████████████████
████▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
████▐█▐█▐█
 
    PLAY NOW    
un_rank
Legendary
*
Offline

Activity: 1540
Merit: 1107



View Profile WWW
August 05, 2026, 09:06:29 PM
 #4

I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
A paper wallet is free and it can safely store all the bitcoins that are in circulation with no hitches, every other security precaution you can apply like multi signatures and passphrase are all also free. You're thinking so much interest of the conventional financial system which is why you're looking for an insurance.

Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
How would a hardware wallet insure what technically is in your custody? This would just overcomplicate a simple system and not make anyone safer for it.

- Jay -

Moreno233
Sr. Member
****
Offline

Activity: 1148
Merit: 464


Trust the process, imbibe consistency


View Profile
August 05, 2026, 09:26:48 PM
 #5

I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
A paper wallet is free and it can safely store all the bitcoins that are in circulation with no hitches, every other security precaution you can apply like multi signatures and passphrase are all also free.
Are you indirectly saying that we should go for software wallets rather than hardware wallets? If yes, a lot of people are weighing the risk already following what happened to Coldcard but then, additional security tips are needed to make this option feasible.


You're thinking so much interest of the conventional financial system which is why you're looking for an insurance.
The insurance aspect is not entirely bad though because it will eliminate the possibility of hardware manufacturers from colluding with external players to exploit their system, something we know can happen especially when their is something enticing on the table. Although I know this will not going to happen.












██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
Texac
Hero Member
*****
Online Online

Activity: 2534
Merit: 554


how do you define success?


View Profile WWW
August 05, 2026, 10:04:26 PM
 #6

Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.

So, you have described dice roll feature is red flag? But I see it quite differently, man.

Offering dice option implies that company acknowledges that any user could reduce their reliance on device's RNG if they wish. In fact option to generate your seed using pure dice entropy is the best way to minimize trust issue, because you generate the entropy yourself and can even verify the calculation if you choose.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
joniboini
Legendary
*
Offline

Activity: 3010
Merit: 1914



View Profile WWW
August 05, 2026, 10:16:32 PM
 #7

Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?
Not sure I get this question. You mean an update might change the chip software and making the entropy worse? Or if the manufacturer update the software to introduce a backdoor or something similar?

If someone is that paranoid there's always the option to pick the open source ones and verify every single bit of code on their own. Another option is to build our own as mentioned many times above. Splitting to multiple devices or multi-sig might also be an option.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
ColdLava40
Full Member
***
Offline

Activity: 476
Merit: 158


Bitcoin


View Profile WWW
August 05, 2026, 10:43:57 PM
 #8

Are you indirectly saying that we should go for software wallets rather than hardware wallets? If yes, a lot of people are weighing the risk already following what happened to Coldcard but then, additional security tips are needed to make this option feasible.
What i can think of would be choices in wallet type. If you are going for a software wallet then some open source wallet like electrum should be understandable.

I can already imagine the doubt people now have in hardware wallets. Coldcard won't be the only hardware wallet which people would fear for flaws. Things like ledger which already offers a cloud service to users might be worse in this case.

The insurance aspect is not entirely bad though because it will eliminate the possibility of hardware manufacturers from colluding with external players to exploit their system, something we know can happen especially when their is something enticing on the table. Although I know this will not going to happen.
This is why I will go with un_rank on this. We cannot even tell if these wallets were flawed to begin with. We simply trust these electronics to store our coins on a long term.

BlackBoss_
Hero Member
*****
Offline

Activity: 1456
Merit: 705


Rollbit is for you. Take $RLB token!


View Profile
Today at 03:35:17 AM
 #9

What i can think of would be choices in wallet type. If you are going for a software wallet then some open source wallet like electrum should be understandable.
Close source or open source is only one of factors that technically makes a wallet is secure or insecure. Ledger wallet is close source but it was not hacked and exploited massively like Coldcard wallet. Coldcard is not actually open source as some people said, code is only verifiable but not reproducible.

Quote
I can already imagine the doubt people now have in hardware wallets. Coldcard won't be the only hardware wallet which people would fear for flaws. Things like ledger which already offers a cloud service to users might be worse in this case.
People will still try to prioritize open source hardware wallets because they can check the code and know that how good or bad that hardware wallet is in entropy of seed creation.
[LIST] Open Source Hardware Wallets.
[GUIDE] How to buy a Hardware Wallet the right way.

It is crazy to know after the Coldcard hack that years ago, there was a person who predicted about a hardware wallet scam exit.
JW Weatherman posted in November 2020.
Quote
Anyone want to bet a hardware wallet will exit scam within the next 5 years?

Probably by blaming an accidental bug or rogue employee.

Basically exactly like an exchange, but this time a hardware wallet.

Coldcard even sneak peeked about that risk and possible exploitation.
In October 2021.
Quote
It’s when the project makers could have a “bug” in the entropy generation for later retrieval.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Darker45
Legendary
*
Offline

Activity: 3402
Merit: 2133



View Profile
Today at 04:14:22 AM
 #10

To a great extent, I'm with you. But did Satoshi really say Bitcoin is for everyone? It made me remember the "I don't have time to try to convince you, sorry" statement.

"For everyone" is equivocal. In a sense, Bitcoin is for everyone because everybody's welcome to take advantage of it. In another sense, it isn't because even the slogan 'don't trust, verify' is obviously exclusive to those few who are capable.

If a Bitcoin layman like me buys a hardware wallet, there's no way I can verify the true random ability of the generator the hardware company is using, the true randomness of the words generated, and so on. Moreover, there's no way I can verify that the chip used inside the device can be trusted. Software updates, firmware updates, and the like are also things beyond my capacity to scrutinize detail by detail. In the end, I usually rely on so-called experts. Some of them recommended Coldcard.

shinratensei_
Legendary
*
Offline

Activity: 3920
Merit: 1054


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 04:23:52 AM
 #11

You don't have to trust them, simply roll the dice if you can't trust the hardware wallet manufacturers. If the code is open source, you can look around, Hardware wallet have TRNG but coldcard case is outlier, the wallet don't use the TRNG for the seed generation because of bug. If the firmware isn't buggy the TRNG will work.
Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.
You are paying for the device and its Secure Element chip but you're free to use the dice roll if you don't trust the manufacturer, as always don't trust but verify. A dice roll isn't inferior to built-in TRNG on a hardware wallet as far as I know. 100+ rolls give more than 256-bit of raw entropy about the same as TRNG 24 word entropy.

If you're still in doubt, almost all hardware wallet manufacturers has released official statement about how their wallet generation works + explanation about the entropy and find out yourself if you're gonna trust them or not. If you're still paranoid, just use multi vendor multi signature setup.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
pooya87
Legendary
*
Offline

Activity: 4186
Merit: 12409



View Profile
Today at 06:10:47 AM
 #12

There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability?
Well countless open source contributors have gone through millions of lines of code from popular projects ever since "open source" became a thing and they did find many bugs and fixed them. That's how things work. If you expect something 100% secure, then you're gonna get disappointed because no such thing exists.
The only option we have is to choose the most secure and most reviewed open source software to reduce the risk to near zero.

This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank Roll Eyes
That's a big leap you are making there buddy. It's like saying "Cash is useless because if you leave it on a bench in a park and come back the other day, it won't be there"! That's not a fundamental problem with cash, that is a fundamental problem with the way you used it.

Bitcoin is about self-custody and that means self-responsibility as well. It's not enough that you have access to your own keys, you have to understand how things work and how to do things correctly.
Has anyone ever lost their bitcoins after sending them to a key safely generated by a trusted and reviewed wallet such as bitcoin core or electrum? No!
Meanwhile so many people have lost their coins by sending them to weak keys and by falling victim to vulnerabilities in weak tools that were closed source, half-open, etc.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
BlackBoss_
Hero Member
*****
Offline

Activity: 1456
Merit: 705


Rollbit is for you. Take $RLB token!


View Profile
Today at 06:58:23 AM
 #13

Bitcoin is about self-custody and that means self-responsibility as well. It's not enough that you have access to your own keys, you have to understand how things work and how to do things correctly.
Has anyone ever lost their bitcoins after sending them to a key safely generated by a trusted and reviewed wallet such as bitcoin core or electrum? No!
Be self-custodial, be responsible, be knowledgeable and be careful are most important things people have to do if they are in Bitcoin and go self-custodial with wallets and their bitcoins. There are things to read, learn and practice to have experience as well as to master it but the first and biggest barrier is whether people are ready to start in a right way. If they are ready to do that, they can learn and become skillful Bitcoin users so that they surely are able to secure their wallets and funds.

They can learn about Bitcoin from fundamentals to technical with http://learnmeabitcoin.com/. There is a explorer search box to find resources about anything to learn.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1612



View Profile
Today at 07:27:31 AM
 #14

Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?
Not sure I get this question. You mean an update might change the chip software and making the entropy worse? Or if the manufacturer update the software to introduce a backdoor or something similar?

This is exactly what happened in ColdCard case.  They introduced a low entropy bug in their devices with firmware v.4.0.0 (and subsequent v.4.0.1).  Devices with older firmware are safe.

If someone is that paranoid there's always the option to pick the open source ones and verify every single bit of code on their own.

This is not possible for regular users (the vast majority of users).  People do not have the technical expertise to verify such complex software code on their own.  And if we take the Coldcard case as an example again, the flaw in their software went undetected for over five years, even by some of the best security experts in the world.


█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
OcTradism
Legendary
*
Offline

Activity: 2562
Merit: 1031



View Profile
Today at 07:33:47 AM
Merited by Stalker22 (1)
 #15

If someone is that paranoid there's always the option to pick the open source ones and verify every single bit of code on their own.
People as non developers can not know about code and how to check bugs in code, so they have to rely on the wallet manufacturers as well as community reviews to choose a hardware wallet to use.

They have to trust some other parties and the most important principle in my opinion is choosing an oldest and best reputation wallet to use. Like it's very rightly to choose Bitcoin Core to use as if Bitcoin Core has security problems, we can easily imagine what happen with Bitcoin community.

This is not possible for regular users (the vast majority of users).  People do not have the technical expertise to verify such complex software code on their own.  And if we take the Coldcard case as an example again, the flaw in their software went undetected for over five years, even by some of the best security experts in the world.
It's like a Security Pandora box with normal users who are not expertise in programming and security but Coldcard issue with not enough random and entropy in their seed creation was actually reported in the past years.

Not all people in the community knew that, not all security experts found that but it was actually known and reported to Coldcard team too. It's only their irresponsibility with their hardware wallet customers to ignore sincere reports from community.

YellowSwap
Full Member
***
Offline

Activity: 644
Merit: 198



View Profile
Today at 11:11:48 AM
 #16

I have read online that hardware wallet companies can offer insurance too, some already have this to cover specific risks like theft during transits but you aren't going to get anything if the loss happened due to users errors.

Which is why I will never understand what ColdCard wallet is doing, all those lost Bitcoin should be their problem, they should be able to refund all affected wallets.

Full coverage will never be available though, because users will be the ones controlling their keys not the hardware wallet companies, insurance on something that's your responsibility makes no sense.

Lida93
Hero Member
*****
Online Online

Activity: 1568
Merit: 787



View Profile WWW
Today at 01:01:30 PM
 #17

There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability?
Well countless open source contributors have gone through millions of lines of code from popular projects ever since "open source" became a thing and they did find many bugs and fixed them. That's how things work. If you expect something 100% secure, then you're gonna get disappointed because no such thing exists.
The only option we have is to choose the most secure and most reviewed open source software to reduce the risk to near zero.
Perhaps @dim_mak5 haven't known it before now that there are advance AI models right now that can poke around a device system to discover if there's any bug with a wallet code to exploit it. But just as you clearly highlighted it, there's no sufficient security with any wallet, whether open source or not, it's about going for the most secured one.

Quote
This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank Roll Eyes
That's a big leap you are making there buddy. It's like saying "Cash is useless because if you leave it on a bench in a park and come back the other day, it won't be there"! That's not a fundamental problem with cash, that is a fundamental problem with the way you used it.

Bitcoin is about self-custody and that means self-responsibility as well. It's not enough that you have access to your own keys, you have to understand how things work and how to do things correctly.
Has anyone ever lost their bitcoins after sending them to a key safely generated by a trusted and reviewed wallet such as bitcoin core or electrum? No!
Meanwhile so many people have lost their coins by sending them to weak keys and by falling victim to vulnerabilities in weak tools that were closed source, half-open, etc.
Just as the popular phrase of Lawrence Lessig "code is law" that's how it's also work for bitcoin wallet security. The code is the money and vis-versa, whoever can crack/bruteforce the wallet code automatically is entitled to the funds in it. So going for a complete open source bitcoin wallet with a stronger layer of security shouldn't be dismissed.

▄████████████████████████▄
██████████████████████████
██████▀████████████▀██████
████████▀████████▀████████
███▀█████▀████▀█████▀███
████▄▀█▄███▀████▄█▀▄████
██████▄██████▄███▄██████
██████████▄███████████████
██████████████████████████
█████████████████████████
████████████▄█████████████
██████████████████████████
▀████████████████████████▀

.GOATED....
░░░░░░░▄▄▄██████
░░░░▄▄▀██████▀▀▀
░░░███████████
▄████████▄█████
▀▀▄▄██████▄██
██████████████▄
█████▀█████████
█████▄█████████
█▄▄▀██████▀▄██
░░███████████▀▄
░░░▀████████████
░░░░░▀████▄▄▄███
░░░░░░░░░▀▀▀████
▄████████████████▄
█████████████░▄░██
█████████████░▄░██
██████████████████
███▀░░░▀█▀░░░▀████
███░░░░░░░░░░░████
███▄░░░░░░░░░▄████
█████▄░░░░░▄██████
███████▄█████████████
█████████████████████
██░▀░████████████████
██░▀░████████████████
▀████████████████████

....THE #1 CRYPTO CASINO....
|
|
|
.PLAY NOW.
Son Of Blockchain (SOB)
Full Member
***
Offline

Activity: 630
Merit: 138


Recognized among the best crypto casino options.


View Profile
Today at 01:31:08 PM
 #18

To a great extent, I'm with you. But did Satoshi really say Bitcoin is for everyone? It made me remember the "I don't have time to try to convince you, sorry" statement.

"For everyone" is equivocal. In a sense, Bitcoin is for everyone because everybody's welcome to take advantage of it. In another sense, it isn't because even the slogan 'don't trust, verify' is obviously exclusive to those few who are capable.

If a Bitcoin layman like me buys a hardware wallet, there's no way I can verify the true random ability of the generator the hardware company is using, the true randomness of the words generated, and so on. Moreover, there's no way I can verify that the chip used inside the device can be trusted. Software updates, firmware updates, and the like are also things beyond my capacity to scrutinize detail by detail. In the end, I usually rely on so-called experts. Some of them recommended Coldcard.

The fact that everyone can do whatever they want with Bitcoin is the reason why some chose to do illegals with it by stealing from others, well it's not Satoshi's fault, that's not the reason for creating Bitcoin, his intentions was for a good cause but some decided to use it as a tool for crime, that's why some feel it supports criminals activities but "you don't blame the gun but the man behind the gun" and anyone that's not truely convinced about it should go for other options they feel is better.
 For someone to verify a hardware before using, cryptography is supposed to be understood by the person to a great extent so it could be audited properly but those who ain't capable of doing that should just go for extra security with an open source wallet that's non custodial and can be strengthened with passphrase.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!