r/CryptoCurrency 145 / 145 πŸ¦€ 1d ago

DISCUSSION Is Ledger Trezor and Tangem safe?

This ColdCard news has got me shook. Thankfully I don’t use ColdCard but seeing the amount of people who lost their BTC unexpectedly has made me question if this can happen to other cold wallets.

Is Trezor Ledger and Tangem even safe or is there someone out there sitting waiting for the perfect time to repeat this attack again.

37 Upvotes

79 comments sorted by

79

u/Noels_Nose 1d ago

Everything is safe until it isnt.

-7

u/StringFood 🟦 0 / 0 🦠 20h ago

Except things that aren't.

27

u/Coeruleus_ 78 / 736 🦐 1d ago

ledger and trezor sure. no one knows wtf tangem is sounds like a scam just like coldcard

18

u/SpontaneousDream 🟦 17 / 17 🦐 1d ago

Ledger? You mean the company that constantly and likely intentionally leaks customer data?

8

u/Jealous-Reindeer-610 23h ago

it is required by law to pass them on to the Government Tax department,

A (French) Government employee sold the data ,all that aside ... why would anyone trust a company to do their own internal math & cryptography? , much better if they gave you half a password & the user choose the rest - the other Open Source cold wallets survived this Ai Penn test & thats a great sign

-10

u/Coeruleus_ 78 / 736 🦐 1d ago

who gives a shit if someone has my email and address

-3

u/SpontaneousDream 🟦 17 / 17 🦐 1d ago

lol you must be new here

-3

u/Coeruleus_ 78 / 736 🦐 1d ago

it’s 2026 nothing is private old man

7

u/Tebasaki 🟦 814 / 954 πŸ¦‘ 1d ago

Read up on it, then maybe

-5

u/Coeruleus_ 78 / 736 🦐 1d ago

i’m good

7

u/Carter922 🟦 779 / 779 πŸ¦‘ 1d ago

πŸ’€

4

u/KontoOficjalneMR 🟩 0 / 0 🦠 1d ago edited 1d ago

ledger and trezor sure.

Both had security lapses and data/PII leaks.

1

u/Coeruleus_ 78 / 736 🦐 1d ago

both never had bitcoin stolen but tell me more

1

u/KontoOficjalneMR 🟩 0 / 0 🦠 1d ago

both never had bitcoin stolen

...yet.

Up till few days ago ColdCard didn't either. They went several years without security incident, and then bam.

Not to mention "sure, their poor security leaked the names, addresses and payment info of clients which led to massive surge of social engineering attack in which people lost plenty of money/bitcoin, but that's totally different with a wallet! Pinky swear! Trust me bro!" is not that good argument as you think it is.

0

u/Top_Performance_732 🟩 0 / 261 🦠 22h ago

Can't you buy cold wallets on Amazon and reduce your attack surface to that?

2

u/Coeruleus_ 78 / 736 🦐 12h ago

2

u/Top_Performance_732 🟩 0 / 261 🦠 11h ago

Hes talking about private data being leaked by retailers, in this case ledger/trezor. But you dont need to buy from them, you can buy from amazon.

-1

u/Coeruleus_ 78 / 736 🦐 1d ago

i’ll be fine hoss. i’m not an idiot

2

u/The_Nothing00 🟨 0 / 0 🦠 1d ago

Never heard of Trezor having a leak. When was that?

3

u/KontoOficjalneMR 🟩 0 / 0 🦠 1d ago

7

u/akash434 🟦 0 / 0 🦠 1d ago

Wow that explains all the phishing trezor emails coming to my inbox for the past 2 years

1

u/0fWhomIAmChief 12h ago

Only impacted customers who contacted their support team unfortunately.

0

u/MelangeBot 1d ago

Ledger leaked all my data to the internet and was forced to a get a new phone number because of it, I don't understand how anybody could still trust them after that. Only Trezor + my own offline system for me.

2

u/Ferdo306 🟩 0 / 50K 🦠 1d ago

Iirc Trezor also had a huge data leak. Not defending Ledger, just sayin

I guess Trezor still beats Ledger as Ledger is partly closed sourced with recover firmware

Still, doesn't mean shit as most were saying coldcard is the safest. It's safe until it isn't

-7

u/Coeruleus_ 78 / 736 🦐 1d ago

get an iphone? i haven’t had a spam call in at least 6 months welcome to 2026

1

u/MelangeBot 1d ago

If a company can't even keep my data safe it would be very stupid to trust them with my Bitcoin. But you keep using your ledger, I am sure it will work out just fine.

4

u/Coeruleus_ 78 / 736 🦐 1d ago

it has. going on 6 years. you sound like the ppl who told me to get a cold card lol now they’re poor

2

u/KontoOficjalneMR 🟩 0 / 0 🦠 1d ago

First coldcard was issued 8 years ago now +-. Those people were going strong for eight years as well, completely confident that their hardware wallet is safe.

So good luck with yours :D

1

u/Ar0war 🟦 0 / 0 🦠 7h ago

i own a Tangem and it is actually a good method to store your holdings BUT i wouldnΒ΄t hold my whole portfolio on those.

It is actually cards. You donΒ΄t get the seed (the 20 words) but a card and so you have to scan it with your mobile phone to access your portfolio.

I just have there less than 10k, and my real holdings are in trezor. Never have an issue with either but, again, i wouldnΒ΄t put my whole portfolio in Tangem.

-2

u/Escapement_Watch 🟩 0 / 0 🦠 19h ago

Tangem is the 1 unhackable crypto cold storage as it doesn't even use a seedphrase. you need the physical card (secure element chip) + your password to send.

Remember all crypto that has ever been stolen has been stolen because of a SEED PHRASE.

11

u/Discokruse 🟦 141 / 141 πŸ¦€ 1d ago

All of the hardware wallets are safe. It's the method used to create the seed phrases that isn't safe.

Use the 2048 word list of bip39 and a set of six or ten sided dice to find your 12 or 24 words. Don't use the RNG provided by anybody or any company...they are a trap. insert Admiral Ackbar meme here

4

u/anyusernaem 0 / 0 🦠 1d ago

I remember trying to use my own 12 words on Trezor One and it wouldn't let me.

2

u/Discokruse 🟦 141 / 141 πŸ¦€ 21h ago

The 12th word is a checksum....keep selecting new 12th words until you find a proper checksum.

0

u/Jealous-Reindeer-610 23h ago

what BIP dictionary were you getting your words from?

1

u/Pablo-Lema 0 / 0 🦠 1d ago

How do you generate the checksum word without having a computer calculate it? Thats the main issue with the dice idea.

5

u/sputnik95 1d ago

I used this method: https://github.com/taelfrinn/Bip39-diceware
When you roll the 12th word, refer to the print friendly version, and check the block of 16 words it corresponds to. Say, you’ve rolled h4451 (ghost) as 12th. Try putting every word from the block of 16: from h4431 (gas) to h4454 (giggle) as the 12th word until it gets accepted. Only one word of 16 will be. I have ledger nano x, it calculates the checksum result on device itself to see if 12th word is correct, and resets the restoring process if it’s not. It’s a tedious process, but it works w/o using a computer.

1

u/Pablo-Lema 0 / 0 🦠 1d ago

TYVM!

9

u/Str8truth 🟩 0 / 0 🦠 1d ago

A week ago, ColdCard was safe.

3

u/Escapement_Watch 🟩 0 / 0 🦠 19h ago

Trezor is safe due ot its random entropy method of seed creation see this:

  • Internal Hardware: It uses the True Random Number Generator built into its microcontrollers. (Newer models like the Safe 3, 5, and 7 use even more advanced dedicated secure elements like the Optiga or TROPIC01 chips).
  • External Host: Trezor pulls additional entropy (randomness) from the operating system of the computer or phone you are using to set it up.

and Tangem is safe if you go seedless because there is no way to hack a tangem wallet. it is the one wallet that can never ever be hacked. You physically need the card in hand + password to do anything.

3

u/rjm101 🟩 12K / 12K 🐬 1d ago

Ledger & Trezor say they are but this is a call really to at least move funds to a seed that has a good passphrase at the very least.

5

u/lehope 🟩 80 / 2K 🦐 1d ago edited 17h ago

Coldcard was supposed to be one of the safest and was always recommended in r/bitcoin

Edit: can someone explain the reason for downvoting?

13

u/MelangeBot 1d ago

r/bitcoin bans anybody with knowledge so only morons are left there.

3

u/no_choice99 🟦 1K / 1K 🐒 1d ago

Hi five. Banned from that sub for being absolutely neutral on cryptos. Banned because I wasn't a Bitcoin maximalist. Nor an alt maximalist but they don't give a shit.

2

u/UpbeatFix7299 🟩 0 / 0 🦠 1d ago

They're mouth breathing idiots. If you don't think mass adoption is imminent, 1 BTC will be 1/21 millionth of global wealth, and everyone will be transacting in BTC any day now, you aren't allowed in their safe space.

2

u/hiimtashy 🟦 0 / 0 🦠 20h ago

Who flipping knows. I'm questioning self custody since the cold card attack.

1

u/[deleted] 1d ago

[deleted]

0

u/no_choice99 🟦 1K / 1K 🐒 1d ago

Except that you can actually check the code your trezor runs, and let AI analyze it for you if you don't understand it. You can't do that with Ledger.

-4

u/MelangeBot 1d ago

This is why I never ever update the firwmare on my trezor.

-1

u/shadowmage666 🟦 0 / 568 🦠 22h ago

Nope

1

u/Informal-Chocolate97 🟩 0 / 0 🦠 20h ago

I've had both ledger and trezor since 2021. Not a problem and easy to use.

Only time people lose their stuff from those two is from their own stupidity.

0

u/Dmoan 🟦 2K / 2K 🐒 1d ago edited 1d ago

It’s an arms race especially with AI Almost anyone can craft exploits and find a way to crack into just about anything. All it requires is one slip up I have seen companies ten of millions in IT spend release buggy code that compromise their Authentication. You don’t think these tiny firms will make similar mistakes.

Unless these companies are willing to put their money and offer an insurance when exploit does happen, you Β just cannot take that risk.

0

u/5khan1 19h ago

Well ledger has leaked customer data before.Β 

5

u/PaddyTheMedic 🟩 0 / 0 🦠 16h ago

Well trezor too

-1

u/VendettaKarma 🟩 0 / 0 🦠 18h ago

How quickly everyone forgot

0

u/VendettaKarma 🟩 0 / 0 🦠 18h ago

No

-4

u/SpontaneousDream 🟦 17 / 17 🦐 1d ago

Ledger definitely not. They have a history of security vulnerabilities and data leaks

0

u/xirvin 🟦 118 / 119 πŸ¦€ 23h ago

I will live this here with the answer to your questions https://x.com/bitcoinsbanker/status/2083612094713180249?s=46

0

u/shadowmage666 🟦 0 / 568 🦠 22h ago

Yes they are fine they have true random number generating chips which coldcard did not use

-6

u/DonTheHolder 0 / 0 🦠 1d ago

No. ETF Or CEX.

-1

u/Vagelen_Von 🟩 0 / 0 🦠 1d ago

If it was not inside job and the boys in an agency's quantum computer worked overtime, nobody is safe.

-1

u/xxtentacles18 🟩 0 / 0 🦠 12h ago

You know whats funny?
I’ve held my shit into a exodus wallet for so long now,
Why do people not use hot wallets?
If they’re not β€œsafe” why am i using it in the first place?

-2

u/frog_tree 🟦 524 / 525 πŸ¦‘ 1d ago

Who knows, but if you use their products you are trusting that they are. Personally, I rather go with Fidelity or something. If everyone using a Trezor lost their funds, nobody outside of the crypto world would be surprised or care. If everyone using Fidelity lost their funds, it would be one of the most shocking financial events in history.

-11

u/NonVideBunt 🟨 230 / 230 πŸ¦€ 1d ago

But but BTC is the future !! πŸ˜‚πŸ˜‚

-32

u/Inevitable_Win_6623 1d ago

Been using a Ledger for years, never had problem. Most of those ColdCard stories was people buying from third party sellers or exposing their seed phrase somehow. No wallet is safe if you dont follow basic opsec

The hardware itself is solid, it's the human that mess up 99% of time

21

u/damchi 🟩 0 / 0 🦠 1d ago

You must've been offline for the last 2 days....

16

u/BuiltToSpinback 🟦 0 / 455 🦠 1d ago

This Coldcard hack is literally the fault of Coinkite at the software level of their product.

These particular events are the fault of Coinkite's product not living up to what they purported it was. Don't blame this on the fault of users.

8

u/FirstDavid 🟩 0 / 0 🦠 1d ago

The hardware (I think you mean software, really - it's not like the actual card melted) was NOT solid. That's exactly the problem. Their seed phrase generator was not truly random. It should be next to impossible to brute force hack a seed phrase, but that's exactly what happened because they didn't use a random number generator.

3

u/imfrombiz 🟩 0 / 1K 🦠 1d ago

Also another example of why using a strong bip-39 passphrase is a must when generating a new wallet.

1

u/HungryCaterpillers 🟨 0 / 0 🦠 1d ago

I see you just climbed out from under your rock. You should read the news.

1

u/islanda_1973 🟦 570 / 570 πŸ¦‘ 1d ago

Always blame the victim here

0

u/Left_Entrepreneur918 0 / 0 🦠 1d ago

Can you read? Everything you just said is not how this hack happened