The Coldcard incident made me go back and relearn a few things. In a way, that’s a good thing. We all need reminders like this from time to time. When it comes to Bitcoin security, I think the fundamentals are still pretty simple: generate your seed properly using strong, independent entropy - dice, coin flips, or something like SeedSigner - and keep that seed completely secret. If you’re generating it yourself, do it offline. Don’t use a device connected to Wi-Fi or the internet. Make secure backups and store them in separate locations. The bigger lesson for me is don’t trust, verify. We shouldn’t blindly assume a device is generating our entropy correctly just because it’s a popular hardware wallet. Multisig can make a lot of sense when you’re securing significant amounts of Bitcoin, but it also introduces more complexity and more things to get wrong. Ultimately, the right setup depends on your situation and how much Bitcoin you’re protecting. Sometimes the best security is simply getting the fundamentals right.
Horszt's avatar Horszt
What are your current thoughts about security and are you using multi sig ?
View quoted note →

Replies (9)

Some HWW and those behind them can be trusted and some imho increasingly can not
I would say roll physical dice then input to a device you trust offline.
@Oshi tails being amnesic is the part doing the heavy lifting there, nothing about the seed survives the reboot. the usb stick is the last surface left, which is why sd card or qr transfer beats it.
Simple, robust fundamentals, just like a diet based on animal products.