So this coldcard attack…what’s the likely hood of a similar attack on mobile wallets?!
Login to reply
Replies (14)
#asknostr
🤷 don't keep much money there has always seemed like good enough advice, but not for everyone
No system is immune. The difference is that hardware and mobile wallets have different attack surfaces.
The Coldcard discussion is about a very specific attack scenario. It doesn't automatically mean mobile wallets are more or less vulnerable, just vulnerable in different ways I believe.
Any amount that would devastate you if you lost it should be kept on a hardware wallet where you use dice or something similar to generate the first 23 words. Then you type them in and let the hardware wallet generate the last word.
Otherwise if you rely on electronics to generate randomness for you you are taking a risk with your funds.
There are guides for this online.
Each person has to decide for themselves at what point an amount of money becomes significant.
If you would've asked the likely hood of a cold card attack 3 days ago most people would've said your funds are 100 percent secure.
We dont know what we dont. Your best bet going forward is probably make your own keys. Not your entropy not your keys. Had those cold cards made there own keys the funds would still be secure.
If you’re going to use mobile, use a multisig setup such as Bitkey.
I need help with multisig setup. What’s the best video?
I'd look into Bitkey. It's multi-sig by default. Your phone, the bitkey device and block server acts each as a key. You need 2 of 3 sign and you have access to a mobile app to check on your stack. In that case you just follow their setup, its multi-sig by default. 

Bitkey
Bitcoin Self-Custody Wallet, App & Hardware
Bitkey is a bitcoin self-custody wallet with an app, hardware device, and built-in recovery, so you keep your private keys without losing access.
this attack was allowed by a coding error that mistakenly generated much weaker than intended entropy for seed generation.
bottom line: any wallet developer is capable of making a similar mistake.
This can be mitigated by not relying on any wallet to generate your seed words for you. Instead, you can generate your own near-perfect entropy offline simply by letting 11 coin flips choose each of your seed words from the list of 2048 BIP-39 words. Then tell your mobile wallet what your seed words are rather than the other way around.
Great instruction videos come from Ben on BTC Sessions. But before you decide your route remember these options:
- Multisig is best with wallets from 3 different manufacturers. Do Bitcoin only wallets or install the Bitcoin only firmware for the ones you get. Do Trezor, BitBox02, Blockstream Jade, and Passport Core by Foundation Devices.
- Single Sig + Passphrase is more robust than singlesig, but less complicated and less expensive than multisig. But you MUST MUST MUST do all the homework to fully understand the Passphrase, what it is, that you need it to access your funds at all, and how it works and how it can trip you up.
- A blend of the two would be the Passkey by Block (make sure you use the one with a screen).
Different threat vector than weak hardware generated entropy
There have been similar attacks on mobile wallets.
I don’t understand the process of coin flips. I didn’t realize I can generate my own seed words
If this is something you still might be interested in, this aid may help.
Hello Friends!
All of the entropy generation talk has inspired me to put together what I hope is a useful aid for generating seed words from coin flips. I suspect something similar already exists; but, I wanted to make my own exactly as I wanted it; and I thought I'd share it.
If you think you might be interested in doing this, but it's not exactly clear to you what this process entails, I highly recommend reading the note at the start of the instructions section before going any further. It may easily turn out that this process is not for you.
If you already know what you're getting into, I hope to have made the rest of it intuitive enough so that you should be fine to skip the instructions.
Instructions:
https://drive.google.com/file/d/1esU_VnMGXjNQrY7FcehDZlcFqMKW999V/view
Small print (more compact) version:
Worksheet:
https://drive.google.com/file/d/1oTrz6Dd0DtLznozeH0JVljUsGOTcYkFx/view
Lookup Table:
https://drive.google.com/file/d/1zrQwBR5781qwr2luXI29RBBo8PgqnZNT/view
Larger print version (for those of us with less than supernatural vision):
Worksheet:
https://drive.google.com/file/d/1rrczg6roAEO88UzLXwtrVrcSy68Sagln/view
Lookup Table
https://drive.google.com/file/d/1jHII0iqJVu2UPUCA6RnmvKt26F-_KAAu/view
If you find this aid useful or know someone you think might, feel free to share, download, improve, or do whatever else you want to with it.
View quoted note →