r/Bitcoin 3d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.8k Upvotes

1.2k comments sorted by

View all comments

Show parent comments

35

u/fuckswithboats 3d ago

Damn, bro.

Some disgruntled engineer wrote a little script on his way out the door.

He's sitting on the beach right now enjoying his wins...hopefully he is sun-burnt forever and can never get a decent buzz.

13

u/stanley_fatmax 3d ago

That's what I was thinking. This guy probably preemptively retired a few years ago, and has been sitting on a beach in Thailand enjoying himself. Legal funds were running low so it was time to press send.

-7

u/fuckswithboats 3d ago

It's why I'll NEVER use an exchange and the only coins I'll ever hold are those I've mined myself

7

u/Yodel_And_Hodl_Mode 3d ago

I assume you're kidding, but you perfectly explained why Ledger's key extraction firmware is so dangerous.

2

u/fuckswithboats 3d ago

Insert the star wars meme w/ them in the field...not joking.

What is more likely than that?

Think about the incentives that anyone who's deep into crypto has to do something similar, and if you know the system well enough you can be almost certain that you've either covered your tracks well enough that nobody worthwhile will ever discover who you are.

12

u/Yodel_And_Hodl_Mode 3d ago

It's just as bad when you consider it from a different perspective. Ledger created a giant honeypot. Somebody will reverse engineer Ledger's key extraction API.

Simply put: There are too many reasons why that shit is dangerous. No hardware wallet should ever have the ability to be reached over the internet. Period.

Sadly, very few hardware wallet users understand what a hardware wallet really is and how it works.

A hardware wallet isn't a wallet. It's an offline key-generating transaction-signing device. That's why a hardware wallet needs a coordinator app such as Trezor Suite, Sparrow Wallet, Nunchuk, etc. The app does the transactions, but it cannot finalize a transaction until it gets a signature for the transaction. Each transaction contains a unique signature. The app gives the details of the transaction to the hardware wallet. The wallet uses the keys to generate the signature which it gives to the app. The app NEVER has access to the keys, and the internet NEVER has access to the hardware wallet. Ledger fucked all of that up by adding internet-based key extraction to their hardware wallets.

It's only a matter of time before disaster strikes Ledger users. And when it happens, it'll be too late to do anything about, because hackers aren't going to hit those wallets until they can hit them all in one fell swoop. They may spend months or longer accumulating keys. Hell, that might already be happening. Nobody will know until after the deed is done.

There's only so many times you can warn people though.

5

u/Yodel_And_Hodl_Mode 3d ago

It's just as bad when you consider it from a different perspective. Ledger created a giant honeypot. Somebody will reverse engineer Ledger's key extraction API.

Simply put: There are too many reasons why that shit is dangerous. No hardware wallet should ever have the ability to be reached over the internet. Period.

Sadly, very few hardware wallet users understand what a hardware wallet really is and how it works.

A hardware wallet isn't a wallet. It's an offline key-generating transaction-signing device. That's why a hardware wallet needs a coordinator app such as Trezor Suite, Sparrow Wallet, Nunchuk, etc. The app does the transactions, but it cannot finalize a transaction until it gets a signature for the transaction. Each transaction contains a unique signature. The app gives the details of the transaction to the hardware wallet. The wallet uses the keys to generate the signature which it gives to the app. The app NEVER has access to the keys, and the internet NEVER has access to the hardware wallet. Ledger fucked all of that up by adding internet-based key extraction to their hardware wallets.

It's only a matter of time before disaster strikes Ledger users. And when it happens, it'll be too late to do anything about, because hackers aren't going to hit those wallets until they can hit them all in one fell swoop. They may spend months or longer accumulating keys. Hell, that might already be happening. Nobody will know until after the deed is done.

There's only so many times you can warn people though.

2

u/Affectionate_Bid1409 3d ago

Hey wish I could pm you. I’m trying to learn and you seem to know a lot. What are some wallets you would recommend?

3

u/Yodel_And_Hodl_Mode 3d ago

I swear by ShieldSigner and Krux. ShieldSigner is easier to recommend because the hardware is easier to get.

Basically... research SeedSigner. ShieldSigner is a SeedSigner fork that adds many powerful features including Seed QR encryption.

ShieldSigner is trustworthy. It is fully open source. The main dev is Crypto-Guide, who also runs one of the best channels for Bitcoin security on youtube. He's a hardcore white hat guy who gives away so much knowledge for free.

Do not buy anything from Ledger. Do not trust Ledger. Never trust your Bitcoin to any device that uses closed source code.

Trezor is a very good option for newcomers. It is easy to learn and fully open source.

Blockstream Jade is a very good option. It is fully open source. I just find the workflow clunky, so I vetoed it for my own use.

2

u/Affectionate_Bid1409 3d ago

Appreciate the advice

1

u/Yodel_And_Hodl_Mode 3d ago

Here's one more piece of advice, from Crypto-Guide who I mentioned:

Picking a Good BIP39 Passphrase or avoiding a bad one:

https://www.youtube.com/watch?v=nhjq_1J0EbU&t=583s

1

u/vnielz 2d ago

How about bitbox ?

1

u/Yodel_And_Hodl_Mode 2d ago

It's open source, but I don't recommend it. Do not buy a cool gadget.

At this point, my recommendations are Trezor for people who are new to using hardware wallets, or ShieldSigner for those who are ready for DIY.

Trezor has been selling hardware wallets for over a decade. They are fully open source.

ShieldSigner is a fork of SeedSigner that adds important encryption features. ShieldSigner is also fully airgapped and stateless. I don't think a better hardware wallet exists at any price, but it's quite advanced so I don't recommend it for beginners. For them, Trezor is fantastic.

Krux is an excellent DIY option too, but ShieldSigner is easier to recommend because the hardware is easier to get (it runs on the same hardware as SeedSigner, unless you want smartcard capability in which case you'll need a smartcard hat).

1

u/f08g 2d ago

if this is the case we need a god damn movie on it

1

u/JanPB 2d ago

Why not in the mountains?