First step for the ColdCard debacle: move your coins. Second step: learn to generate your own seed phrase with your own entropy.
jimbocoin 🃏's avatar jimbocoin 🃏
It’s not just “move your coins”. You need to generate seed material using your OWN ENTROPY. If all you do is move from ColdCard to a seed generated by SeedSigner or BitBox or Trezor, you haven’t changed your risk exposure to this class of vulnerability. You’ve gone from one straw hut to another.
View quoted note →

Replies (1)

All things considered, a relatively simple and highly secure choice is 2-of-3 multisig using different vendors. If you use Sparrow or Nunchuck to make a 2-of-3 with different vendors, it’s super unlikely that any two of them will have an active vulnerability exploited at the same time. I’d still recommend rolling your own seed material, but using multisig with a quorum of independent vendors is even better.