Replies (14)

No system is immune. The difference is that hardware and mobile wallets have different attack surfaces. The Coldcard discussion is about a very specific attack scenario. It doesn't automatically mean mobile wallets are more or less vulnerable, just vulnerable in different ways I believe.
Bond008's avatar
Bond008 4 days ago
Any amount that would devastate you if you lost it should be kept on a hardware wallet where you use dice or something similar to generate the first 23 words. Then you type them in and let the hardware wallet generate the last word. Otherwise if you rely on electronics to generate randomness for you you are taking a risk with your funds. There are guides for this online. Each person has to decide for themselves at what point an amount of money becomes significant.
Hofer99's avatar
Hofer99 4 days ago
If you would've asked the likely hood of a cold card attack 3 days ago most people would've said your funds are 100 percent secure. We dont know what we dont. Your best bet going forward is probably make your own keys. Not your entropy not your keys. Had those cold cards made there own keys the funds would still be secure.
this attack was allowed by a coding error that mistakenly generated much weaker than intended entropy for seed generation. bottom line: any wallet developer is capable of making a similar mistake. This can be mitigated by not relying on any wallet to generate your seed words for you. Instead, you can generate your own near-perfect entropy offline simply by letting 11 coin flips choose each of your seed words from the list of 2048 BIP-39 words. Then tell your mobile wallet what your seed words are rather than the other way around.
Great instruction videos come from Ben on BTC Sessions. But before you decide your route remember these options: - Multisig is best with wallets from 3 different manufacturers. Do Bitcoin only wallets or install the Bitcoin only firmware for the ones you get. Do Trezor, BitBox02, Blockstream Jade, and Passport Core by Foundation Devices. - Single Sig + Passphrase is more robust than singlesig, but less complicated and less expensive than multisig. But you MUST MUST MUST do all the homework to fully understand the Passphrase, what it is, that you need it to access your funds at all, and how it works and how it can trip you up. - A blend of the two would be the Passkey by Block (make sure you use the one with a screen).
sedited's avatar
sedited 4 days ago
There have been similar attacks on mobile wallets.
If this is something you still might be interested in, this aid may help.
Judge Hardcase's avatar Judge Hardcase
Hello Friends! All of the entropy generation talk has inspired me to put together what I hope is a useful aid for generating seed words from coin flips. I suspect something similar already exists; but, I wanted to make my own exactly as I wanted it; and I thought I'd share it. If you think you might be interested in doing this, but it's not exactly clear to you what this process entails, I highly recommend reading the note at the start of the instructions section before going any further. It may easily turn out that this process is not for you. If you already know what you're getting into, I hope to have made the rest of it intuitive enough so that you should be fine to skip the instructions. Instructions: https://drive.google.com/file/d/1esU_VnMGXjNQrY7FcehDZlcFqMKW999V/view Small print (more compact) version: Worksheet: https://drive.google.com/file/d/1oTrz6Dd0DtLznozeH0JVljUsGOTcYkFx/view Lookup Table: https://drive.google.com/file/d/1zrQwBR5781qwr2luXI29RBBo8PgqnZNT/view Larger print version (for those of us with less than supernatural vision): Worksheet: https://drive.google.com/file/d/1rrczg6roAEO88UzLXwtrVrcSy68Sagln/view Lookup Table https://drive.google.com/file/d/1jHII0iqJVu2UPUCA6RnmvKt26F-_KAAu/view If you find this aid useful or know someone you think might, feel free to share, download, improve, or do whatever else you want to with it.
View quoted note →