|
YellowSwap (OP)
|
 |
September 10, 2026, 09:15:12 AM |
|
The more valuable Bitcoin gets over time the more I believe that this can be possible.
I can wake up one day and device to build my own hardware wallet for the world, I'm going to spend some large amount of money, I get it but the goal is to have the biggest Gold mine at my disposal.
Get people's attention, do buying bonuses and keep introducing patches and updates overtime. In few years time I will gain the trust of many people, hire YouTubers to do adverts, saying mine is better than Trezor and others.
My goal is to have access to people's Bitcoin without them even realising it until THE DAY. 200 BTC, 1000BTC, 20BTC, you think I'm crazy? It's going to worth it. ..
Then one day I just pull the rug on them all, putting the blame on some North Korea hackers or glitches in the system, like tell me how this isn't even possible?
I had this conversation with a foreign friend yesterday night, since he have the idea about copying codes and baking your own wallet up, and he laughed saying that's some La casa de papel shit.
I think it's just waaaay better to stick with Trezor and old crypto hardware wallet that are open source fully, few new players are coming into this space introducing new hardware wallet while Bitcoin is on its way to 1 million dollars some years in the future, don't bother telling me that this is a joke..
These moth****s can take years to plan this Bitcoin heist up and you won't see it coming, call me crazy 🤣🤣 it's just a thought.
|
|
|
|
|
Aanuoluwatofunmi
|
 |
September 10, 2026, 09:25:15 AM |
|
I can wake up one day and device to build my own hardware wallet for the world, I'm going to spend some large amount of money, I get it but the goal is to have the biggest Gold mine at my disposal.
If not the wrong mentality and orientation, with some hoodlums getting involved in the digital space and technology today, I don't see why someone would invest his time and money to developsomething thatt will eventually lead to attacking others, when they could actually maintain their reputation and provide a benefit to the entire world with what they have developed. For someone to have this kind of mindset and ability to build a Bitcoin wallet and also be corrupted by the intention to use it for an exit scam when others have been fully aware of his development, and he's intention was to rip them off their assets, what a wrong mentality and wasted effort that does not justify the process of acquiring wealth.
|
|
|
|
_act_
Legendary

Activity: 1736
Merit: 1984
|
 |
September 10, 2026, 09:43:59 AM |
|
What if you plan it, but AI helped other hackers to know the vulnerability earlier and exploit it?  All I know is that anything is possible. The wallet will definitely be a close source wallet because it it is open source, but is also possible that the vulnerability will be reported and patched if the hacker is not a bad one.
|
|
|
|
hmbdofficial
Full Member
 

Activity: 308
Merit: 134
Spinly.io - Next-gen Crypto iGaming Platform
|
 |
September 10, 2026, 10:09:46 AM |
|
I think this is a valid threat plot to think about, especially as the value secured by hardware wallets increases. But i think most people will not fall for this because of the recent incident with some hardware wallets, a lot of people have actually learn about firmware annd possible vulnerabilities and also knowing and ensuring more about open source wallet. Now people are even more focus on finding perfect hardware wallet and more on avoiding a single point of failure.
|
|
|
|
|
YellowSwap (OP)
|
 |
September 10, 2026, 10:11:58 AM |
|
What if you plan it, but AI helped other hackers to know the vulnerability earlier and exploit it?  All I know is that anything is possible. The wallet will definitely be a close source wallet because it it is open source, but is also possible that the vulnerability will be reported and patched if the hacker is not a bad one. I don't want to sound like dullard, this is all for learning sake. Is AI capable of detecting a vulnerability on a chip itself? Because I believe there is limit to what AI can detect, probably software based. I can be wrong and I am open to learning anytime, any day. What if a back door is built on the hardware wallet chip itself? Few hardware wallets are not even completely open source, if you know what I am getting at.
|
|
|
|
|
CucakRowo
|
 |
September 10, 2026, 10:20:18 AM |
|
I think it's just waaaay better to stick with Trezor and old crypto hardware wallet that are open source fully, few new players are coming into this space introducing new hardware wallet while Bitcoin is on its way to 1 million dollars some years in the future, don't bother telling me that this is a joke..
Yeah your hypothetical scenario sounds absolutely crazy to me. However underlying threat here isn't entirely imaginary. No matter how secure your hardware wallet is, risk ranging from malicious firmware to counterfeit device and supply chain attack always persist. I am not sure if you are aware, but even with older Ledger Nano S, attacker could modify firmware to pre configure their own 24word seed on device. Device would then appear to user as if it were generating brand new seed. In reality, that seed displayed to user was one the attacker had already set up. Consequently, if user stored Bitcoin using that seed, attacker would also possess same seed. Ledger later mitigated this vulnerability through firmware update. You could know more about this by searching as MCU fooling.
|
|
|
|
_act_
Legendary

Activity: 1736
Merit: 1984
|
 |
September 10, 2026, 10:21:49 AM |
|
I don't want to sound like dullard, this is all for learning sake. Is AI capable of detecting a vulnerability on a chip itself? Because I believe there is limit to what AI can detect, probably software based.
Most of the vulnerabilities recently, AI were used to detect it. Even the Coldcard hardware wallet vulnerability was said to be AI that detected it. AI has been so useful for bad hackers recently, but I think those companies are now also using AI to look for vulnerability to make faster corrections. I can be wrong and I am open to learning anytime, any day. What if a back door is built on the hardware wallet chip itself?
Few hardware wallets are not even completely open source, if you know what I am getting at.
It is very possible.
|
|
|
|
Alex077
Legendary

Activity: 4508
Merit: 2127
Bitz.io Best Bitcoin and Crypto Casino
|
 |
September 10, 2026, 11:26:37 AM |
|
No matter how secure your hardware wallet is, risk ranging from malicious firmware to counterfeit device and supply chain attack always persist. I am not sure if you are aware, but even with older Ledger Nano S, attacker could modify firmware to pre configure their own 24word seed on device. Device would then appear to user as if it were generating brand new seed. In reality, that seed displayed to user was one the attacker had already set up. Consequently, if user stored Bitcoin using that seed, attacker would also possess same seed. Ledger later mitigated this vulnerability through firmware update. You could know more about this by searching as MCU fooling. I get your point. Tbh, this is sensitive matter and given how such issue is being discussed in this thread, it is important to consider some practical aspect. It is not surprising that people losing trust after recent event involving company like Coldcard and other hardware wallet manufacturer. IRL, when you rely on any 3rd party device for security and then loophole emerge on that device, it's normal to get frustrated. totally WTF moment! The thing is, we primarily use hardware wallet to keep our private key completely offline. So if any company leaves in backdoor or bug, that is definitely cause for concern. However, if you look at open source solution, like using Electrum with your custom dice based recovery or wallet entropy customization then your risk can be significantly reduced.
|
|
|
|
joniboini
Legendary

Activity: 3038
Merit: 1926
|
 |
September 10, 2026, 11:29:10 AM |
|
I guess you can also blame supply chain attacks that upload malicious updates to steal users funds, if we're going with "stealing people funds" route. Then again, it depends on how many people actually used HW or softwares that aren't fully open source. I kinda doubt there'll be a lot after the Coldcard incident tbh. But if somehow you can acquire users like that, then it's possible to target them. On the other hand, the amount of people warning others to be careful about their HW and so on will also increase. Especially if they follow basic principle like "don't trust, verify" closely.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
PostQuantumBTC
Full Member
 

Activity: 350
Merit: 161
Bitz.io Best Bitcoin and Crypto Casino
|
 |
September 10, 2026, 11:33:37 AM |
|
The thing is, we primarily use hardware wallet to keep our private key completely offline. So if any company leaves in backdoor or bug, that is definitely cause for concern.
This is the reason I can not use any close source wallet like Ledger that nobody know how the wallet is producing seed phrases. No one know if it is generated in a way that the company know the seed phrases. Also people should not have it in mind that all hardware wallets keep private key offline. Some Ledger users send their seed phrase to backups companies online.
|
|
|
|
tbct_mt2
Legendary

Activity: 3094
Merit: 1079
|
 |
September 10, 2026, 12:05:13 PM |
|
This is the reason I can not use any close source wallet like Ledger that nobody know how the wallet is producing seed phrases. No one know if it is generated in a way that the company know the seed phrases.
Also people should not have it in mind that all hardware wallets keep private key offline. Some Ledger users send their seed phrase to backups companies online.
Open source does not automatically mean that wallet is good or better than a close source wallet. You see how Coldcard hardware wallets were exploited even it's open source, whereas the Ledger wallets have yet exploited in security like that. I don't recommend Ledger wallets because they are close source and we have many open source wallets to choose, but after the Coldcard wallet security incident, we must be more careful from choosing to using hardware wallets. [LIST] Open Source Hardware Wallets.
|
|
|
|
|
Aanuoluwatofunmi
|
 |
September 10, 2026, 12:11:19 PM |
|
The thing is, we primarily use hardware wallet to keep our private key completely offline. So if any company leaves in backdoor or bug, that is definitely cause for concern.
This is the reason I can not use any close source wallet like Ledger that nobody know how the wallet is producing seed phrases. No one know if it is generated in a way that the company know the seed phrases. Also people should not have it in mind that all hardware wallets keep private key offline. Some Ledger users send their seed phrase to backups companies online. It is not everything we discover to know about Bitcoin wallet and privacy should be taken with a soft hand, I can't afford to be a mediocre in how I handle my wallet privacy and security, there are some hardware wallet that show be completely prevented from using and has been mentioned that ledger does not have the required privacy we expected from them, cold card just got posted every sent and I know they are good possibly be other ones hanging around yet to be discovered even from those hardware wallet except a rigor search and test are being made upon them.
|
|
|
|
|
obuoma
|
 |
September 10, 2026, 12:14:14 PM |
|
What if you plan it, but AI helped other hackers to know the vulnerability earlier and exploit it?  All I know is that anything is possible. The wallet will definitely be a close source wallet because it it is open source, but is also possible that the vulnerability will be reported and patched if the hacker is not a bad one. That does not rule out the possibility of what the OP is describing already happening. Some of the compromises and exploitations we have seen take the form described in the post and it takes courage to put it as the OP has done. We should not discountenance the advice the OP has given which is to be careful of new wallets that made so many promises, rather we can stick with the old and established ones that are open source eve if they do not offer some of the latest features we see now or even if they are expensive.
|
|
|
|
|
Spaceman1000$
|
 |
September 10, 2026, 01:17:56 PM Last edit: September 10, 2026, 03:25:52 PM by Spaceman1000$ |
|
The more valuable Bitcoin gets over time the more I believe that this can be possible.
I can wake up one day and device to build my own hardware wallet for the world, I'm going to spend some large amount of money, I get it but the goal is to have the biggest Gold mine at my disposal.
Get people's attention, do buying bonuses and keep introducing patches and updates overtime. In few years time I will gain the trust of many people, hire YouTubers to do adverts, saying mine is better than Trezor and others.
My goal is to have access to people's Bitcoin without them even realising it until THE DAY. 200 BTC, 1000BTC, 20BTC, you think I'm crazy? It's going to worth it. ..
Then one day I just pull the rug on them all, putting the blame on some North Korea hackers or glitches in the system, like tell me how this isn't even possible?
I had this conversation with a foreign friend yesterday night, since he have the idea about copying codes and baking your own wallet up, and he laughed saying that's some La casa de papel shit.
I think it's just waaaay better to stick with Trezor and old crypto hardware wallet that are open source fully, few new players are coming into this space introducing new hardware wallet while Bitcoin is on its way to 1 million dollars some years in the future, don't bother telling me that this is a joke..
These moth****s can take years to plan this Bitcoin heist up and you won't see it coming, call me crazy 🤣🤣 it's just a thought.
You know there's a saying that goes like this, "stick to what works for you". This your write up is obviously the reason why old trusted wallet that have been existing for years are the best. So even if somebody wants to say he wants to put in some coins in a new wallet that came in not too long ago, that he or she has decided to vet the wallet to know how trustworthy it is, the point is to what extent did your vetting go, how thorough was it, so my point is instead of wasting so much energy in trying to authenticate a new wallet and know how trustworthy it is, why not just use the existing wallet that people have been using over the years that you know is tested and trusted.
|
|
██ ██ ██████ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ██████ ██ ██ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ██████████████ THE #1 SOLANA CASINO
██████████████ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | [ [ | 5,000+ GAMES INSTANT WITHDRAWALS | ][ ][ | HUGE REWARDS VIP PROGRAM | ] ] | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████████████████████████ PLAY NOW ████████████████████████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
|
|
|
Leon Zimmer
Newbie

Activity: 7
Merit: 1
|
 |
September 10, 2026, 01:20:12 PM |
|
However, if nobody ever does any checking as to what they flash, open source VS closed source issue is not important. Majority of users do not bother reading message that does appear on the screen, and click yes most of the time, without looking at PGP signature or comparing hash with the official repo. That is part that hackers are looking to break into, not so called visibility of source code. Even 100% open source wallet is not very useful, if 95% of wallets' users are unable or unwilling to check that binary block matches the one published with the source code.
What is second that can be added is multisig to practically defend here. If your BTC sits behind 2-of-3 across two different hardware brands (say a Trezor and a Coldcard), a single company going rogue or getting backdoored doesn't drain you. So, single hardware wallet trust, either open or closed source is still single point of failure.
|
|
|
|
|
Alvin_talk
Full Member
 
Online
Activity: 304
Merit: 165
I don't want peace, I love problem always
|
 |
September 10, 2026, 01:48:34 PM |
|
Sure it is possible. That is why open source wallets are recommended. Although, open source wallets are not 100% reliable (firmware codes vulnerability could be discovered by black hearts before volunteers and developers may even notice) but atleast it is way better than closed source where users can't review codes. Also, it is very good to always follow up news regarding the changes and updates your wallet providers are making. Remember that Coldcard was once an open source wallet until Coinkite changed the license from standard open source to one which requires some sort of clause. [1] https://www.reddit.com/r/Bitcoin/comments/1vckbbr/coldcard_is_not_open_source/If you follow up you the activities of your wallet providers, you should be able to spot red flags before they even manifest. I think it's just waaaay better to stick with Trezor and old crypto hardware wallet that are open source fully, few new players are coming into this space introducing new hardware wallet while Bitcoin is on its way to 1 million dollars some years in the future, don't bother telling me that this is a joke..
I don't think you should vouch for Trezor or older wallets either. They may still fall under thesame category. Since people trust them so much now, they seem to be the best actors to execute such scene. What is most important is always make sure to monitor recent activities relating your hardware manufacturers. That they are good today does not make them automatically good tomorrow.
|
|
|
|
|
Zaguru12
Legendary
Online
Activity: 1540
Merit: 1286
Instant Crypto Withdrawals
|
 |
September 10, 2026, 01:49:10 PM |
|
I don't want to sound like dullard, this is all for learning sake. Is AI capable of detecting a vulnerability on a chip itself? Because I believe there is limit to what AI can detect, probably software based.
The thing is with AI you’re exposed to more information in a short period of time than you can actually detect or find yourself. AI cannot just simply detect vulnerability like that but an hacker can do that with help of AI by using it to scan codes and the hacker can even prompt it to detect certain vulnerabilities. We have heard of hardware using AI to check for vulnerability so that they can correct it, imagine AI can do this then if the vulnerability flaws were discovered first by a scammer it can be use to exploit such hardware wallet just similar to what happened with cold card wallet. Few hardware wallets are not even completely open source, if you know what I am getting at.
This particular piece you wrote on OP is the major reason why you shouldn’t trusts wallets like that. Just once the source code of a wallet is not verified mostly by the public there could be room for errors or even room for exploits. Imagine a wallet which has always been open source right from the start simply chooses to be closed or just source verifiable then its best to abandon that wallet because who knows maybe they are taking the direction of what you just described up there.
|
|
|
|
letteredhub
Sr. Member
  

Activity: 1316
Merit: 342
Never breaking the rules isn't weakness.
|
 |
September 10, 2026, 02:05:23 PM |
|
Then one day I just pull the rug on them all, putting the blame on some North Korea hackers or glitches in the system, like tell me how this isn't even possible? It's possible that you may succeed and it's also possible that you may not succeed at it. . I think it's just waaaay better to stick with Trezor and old crypto hardware wallet that are open source fully, few new players are coming into this space introducing new hardware wallet while Bitcoin is on its way to 1 million dollars some years in the future, don't bother telling me that this is a joke.
Even the old hardware wallet companies can't be completely exempted from the risk of a heist if all the fears you're raising is anything possible to be a thing in the future, because bitcoin at $1m+ in years from now is a huge figure when like 4,000 bitcoins are moved. Although the most risk lies with using newly developed hardware wallets that ain't open source.
|
|
|
|
Dreadboost
Sr. Member
  

Activity: 364
Merit: 254
What words best describe a man? (Most natural)
|
 |
September 10, 2026, 02:07:19 PM |
|
It's beyond thought. Very possible that the plan works from A to Z. Trezor remains the one hardware wallet to use in this generation. Any other wallet, whether open source or closed source, is not recommended. This pattern you exposed is the same pattern fake wallet developers use to keep taking money, blaming it on some random hackers. What if you plan it, but AI helped other hackers to know the vulnerability earlier and exploit it?  Some balance will be left untouched. Then there will be no option but to wipe everything out immediately when the hack commences.
|
|
|
|
|
macson
|
 |
September 10, 2026, 02:07:23 PM |
|
Then one day I just pull the rug on them all, putting the blame on some North Korea hackers or glitches in the system, like tell me how this isn't even possible?
It might sound like it's that easy. Like you just need to set everything up and then let people use it, and then you immediately do a rug pull. Let’s say you actually pull that off, but how do you launder all that Bitcoin? Right now, it’s really hard to convert the stolen Bitcoin into cash without creating a trail that can be traced back to you. Especially with the tighter supervision from blockchain security firms and investigators who constantly monitor your activity, it makes it really hard to move because even one small mistake can get you traced.
|
|
|
|
|