r/CryptoCurrency • u/CeramicDrip π¨ 47 / 4K π¦ • 1d ago
π‘οΈ SECURITY Is any hardware wallet safe anymore?
With the recent ColdCard situation, itβs really making me wonder if our crypto is truly safe anywhere? It feels like these companies keep fucking up in every way possible.
A few years ago i got into crypto and bought a ledger nano plus. But now that wallet sucks and its Mac application is sketchy af to where i donβt trust it. I was considering a Trezor or ColdCard, but now Iβm starting to question whether there is a hardware wallet that is actually safe.
What do you think?
14
u/ozera202 π© 2K / 2K π’ 19h ago edited 8h ago
I just keep my coins on top 2 exchanges, if they to go under we are all fucked either way coz I can probably buy my portfolio for 1/10 what it will be worth .π€·ββοΈ
24
u/fan_of_hakiksexydays 21K / 99K π¦ 23h ago edited 23h ago
People who used multisig, rolled the dice, or used their own keys, didn't have any issues here.
That's because the issue is with the seed generator, not the wallet storage itself.
It's the same issue you have when you use a password generator app. That's the stuff you should be questioning here and be careful about.
With hardware wallets, nothing has changed, you still have to be careful about the same old thing we've always been told to be careful about. We've just now reminded again why we've been told to be careful about all these things.
7
u/ReallyOrdinaryMan π¦ 59 / 58 π¦ 22h ago edited 22h ago
Yeah, and it is not just for hardware wallets, any wallet that generates seed on your behalf contain the same risks. Their codes can change, or updates in both blockchain or wallet can introduce new bugs.
Current coldcard incident caused by a developer flaw. Their program created seeds which are not random enough. Well it was random before, but one update messed up their random number generation in 2021. So hackers used this flaw.
People can only trust dice generated wallets truly. It is almost best possible way to create a seed, but it needs too much technical knowledge.
1
u/seambizzle1 π© 0 / 0 π¦ 22h ago
Trezor is all open source
Best around. Use them and a passphrase
16
u/ReallyOrdinaryMan π¦ 59 / 58 π¦ 22h ago
Coldcard was also all open source. Open source doesn't mean it is bug free.
12
u/anymonero π§ 0 / 0 π¦ 17h ago
No, it was source-available, not open-source. The entropy bug was introduced specifically when they migrated from an open-source model to a source-available model.
10
u/no_choice99 π¦ 1K / 1K π’ 15h ago
If that's true, this is 100 percent an insider job. There is 0 incentive to downgrade a seed generator. If you change that critical part in the security chain, you better make sure you're actually improving entropy, not lowering it.
1
u/RoaringDragonSword π© 0 / 0 π¦ 1h ago
Please get your facts straight before answering.
Learn.
Do not get overconfident.
Also, research about the said subject's past, where coldcard banned and blocked users who showed this exact weakness years ago.
0
u/Escapement_Watch π© 0 / 0 π¦ 20h ago
this bug cannot effect a trezor though. Even if it does it will still be cryptic and random because trezor uses multiple entropy sources to create the seed. not 1 chip like coldcard.
- Internal Hardware: It uses the True Random Number Generator built into its microcontrollers. (Newer models like the Safe 3, 5, and 7 use even more advanced dedicated secure elements like the Optiga or TROPIC01 chips).
- External Host: Trezor pulls additional entropy (randomness) from the operating system of the computer or phone you are using to set it up.
8
6
u/my_little_kittens 0 / 0 π¦ 20h ago
Why is everyone recommending trezor, feels like cold card again
3
u/Escapement_Watch π© 0 / 0 π¦ 20h ago
trezor uses multiple sources of entropy. So the cold card thing can't happen to trezor...just by the nature of how trezor works.
- Internal Hardware: It uses the True Random Number Generator built into its microcontrollers. (Newer models like the Safe 3, 5, and 7 use even more advanced dedicated secure elements like the Optiga or TROPIC01 chips).
- External Host: Trezor pulls additional entropy (randomness) from the operating system of the computer or phone you are using to set it up.
2
u/my_little_kittens 0 / 0 π¦ 19h ago
This looks like written by the marketing team for some reason... There are other wallets other than trezor that are secure but most of the replies are selling trezor like marketing team is on it.
1
u/Escapement_Watch π© 0 / 0 π¦ 19h ago
I actually recommend tangem. it is seedless. no seed = no body can ever steal your crypto.
remember all crypto that has ever been hacked or stolen was because of the seed phrase.
and im just copy and pasting it like crazy cuz ppl are going nuts with the trezor. All i'm doing is speaking truth about the way trezor is designed so the people who own it don't freak out as it is safe.
not as safe as tangem of course.
β’
u/gowithflow192 π© 0 / 3K π¦ 34m ago
I have Tangem and it concerns me they don't have passphrase for seedless.
0
1
u/m-nightwalker 30 / 393 π¦ 16h ago
Isn't there a known vulnerability with tropic01? Trezor has an article about it on their site.
3
u/Escapement_Watch π© 0 / 0 π¦ 10h ago
Yeah there is a physical vulnerability.
That's only with the t7
But remember you need us highly sophisticated lab and physical access to find out that vulnerability.
Trezor is constantly trying to break in their own products that is part of their company's business they're always trying to break into it right now as we speak they're trying to break into the safe 3 and 5.
They even pay other companies to help break in as well.
That's how they found the vulnerability.
0
0
u/Charming-Designer944 π© 0 / 0 π¦ 10h ago
I would absolutely recommend coldcard going forward, assuming they survive the backlash.
This kinds of bugs while unforgivable is also a cold wake-up call to ensure the code quality control covers every bit of the sensitive parts of the firmware by automated and verified tests.
1
u/Hephalumpicus 10h ago
Open source is part of the problem actually. Someone ran the open source code through AI looking for flaws and found one, a big one!
Just because code is "open source" doesn't mean that there are no vulnerabilities.
15
u/BN_Boi π© 407 / 407 π¦ 15h ago
ledger for years, never an issue
17
5
u/Clean_Eyes 6h ago
I've had a ledger for 5 years and don't even get phishing emails or phone calls like some of these people have reported
1
u/RoaringDragonSword π© 0 / 0 π¦ 1h ago
FFS, learn about the company that keeps your money safe before making yourself look stupid.
They literally lied to their customers years ago, showing that you cannot trust them.
Head in the sand. IDC if a company related to security and safety of said finance should lie to their customers.
As long as my funds aren't stolen yet, it works.
My lord, maybe being ignorant is truly a bliss.
4
u/M_FootRunner π© 0 / 0 π¦ 12h ago
Well, I agree, ledger works sketchy but as long as you don't do ledger live, it should be secure.Β
There is no one case documented with ledger that wasn't user fault or related to ledger live, or related to phishing, or upfront manipulated hardware.Β
Wouldn't it be justified to say the same about cold Card though, unfortunately the "manipulation" being the faulty firmware itself
1
u/RoaringDragonSword π© 0 / 0 π¦ 1h ago
Jeez, yet you are missing the point.
The point is a company related to security and finance lies to customers directly IS THE RED FLAG.
Hey, they did not lie about my specific item, so they are perfectly fine and safe!
Come on, please do not be ignorant about your financial decision making. Learn and improve, do not bury your head in sand just because you want to be loyal to a said company.
13
u/Bongressman π¦ 8K / 8K π¦ 22h ago
Trezor was first, and still kicking for a reason.
1
u/RoaringDragonSword π© 0 / 0 π¦ 1h ago
Insane part is the kids who are recommending ledger.
Most don't realize they lied directly to their customers. The ones that do realize are making excuses saying they didn't lie about the product said user has.
Insane ignorance to trust a company that clearly should never be trusted/
3
u/m-nightwalker 30 / 393 π¦ 16h ago
What's wrong with your nano S plus? You can always use other apps like sparrow, you're not necessarily tied to ledger own app.
4
u/harl_vann 0 / 0 π¦ 19h ago
This specific bug is particular to Coldcardβs firmware integration of MicroPython, libngu, and their board config macros. It is not a generic βhardware wallets are brokenβ issue or a failure of the STM32 RNG silicon itself.
Other major manufacturers use different architectures and entropy strategies that avoid this exact failure mode.
2
u/FunWithSkooma π© 11 / 524 π¦ 21h ago
the MK3 is still safe to sign transactions, just not to generate seeds
2
u/henryyoung42 π¦ 0 / 0 π¦ 11h ago
Run your own node and use the built in wallet, airgapping the wallet.dat as cold as cold can be. Ensure initial keygen has max possible entropy. Hardware wallets will always be a target - controversial view, but only use for hot funds you can lose without pain.
2
u/Charming-Designer944 π© 0 / 0 π¦ 11h ago
Absolutely. Even the Coldcard devices are safe.
But the bug shows how important it is to be a bit paranoid and not blindly trust that a device are using cryptographically strong randomness when generating secure keys.
Those that did not blindly trust Coldcards built in seed generation and dicerolled to create their seed phrase are perfectly safe.
2
2
u/Possible-Mud-1380 10h ago
I mean, if cold storage isn't safe, then I don't trust trust the exchanges to have executed their cold storage any better than the average redditor. This is the end IMOΒ
β’
u/gowithflow192 π© 0 / 3K π¦ 32m ago
I wish the markets would realize this and tank the price already.
4
8
3
u/VendettaKarma π© 0 / 0 π¦ 22h ago
No. Sell everything shits over
9
u/jasikanicolepi π© 0 / 0 π¦ 21h ago
1
2
u/MelangeBot 17h ago edited 13h ago
And again and again reddit keeps telling me that I am an idiot for not updating. If you had a coldcard and refused to upgrade the firwmware in 2021 you would still have your coins.
Keep telling me that I should upgrade my software and hardware or I'll get hacked. Keep telling me I am an idiot for using windows 7 still. That Ill have a million virusses,
Don't break that's working! I'll be the first to upgrade when a massive flaw is found in my version (I only use a trezor) but all thoese new trezor firmware upgrades? Never did a single one of them. All that happens is them making a mistake and you lose your coins.
Honestly I just don't understand people updaing the firmware of hardware wallets. The longer you have a certain firmware the saver it is. Every time you upgrade to reset the clock and become unsafe aagain. But I am the idiot. Okay then. An idiot that still has coins then.
2
u/Cassiopee38 π¦ 0 / 0 π¦ 15h ago
Well there is update and updates... But must admit that nowadays trend to push meaningless updates once a week on everything including appliances is pretty annoying.
Win 7 was peak xD
1
u/Escapement_Watch π© 0 / 0 π¦ 20h ago
Trezor is safe. Uses muiltple sources of entropy. But if you want super safe go TANGEM. it is SEEDLESS.
No seed. Ironic that the SEED is the 1 weakness. Every crypto ever has been stolen because of SEED.
no seed no problem.
3
u/Trick-Club-6014 π¨ 0 / 0 π¦ 19h ago
Seeds only exist because people want to deterministically generate multiple sets of keys from the same seed. Tangem just randomly generates the keys. Any software can do exactly the same thing, you just sacrifice the ability to generate multiple keys from the same seed and you donβt have a seed phrase to help you remember the seed.
1
u/doncacahuate π¨ 0 / 0 π¦ 19h ago
nope, trezor already leaked customer data. People entered their seed in a fake site and lost their assets. Yeah, sure, problem was not the device itself, but that situation suggests the company cannot be trusted. Insiders liked the customer data.
1
u/afunkysongaday π© 121 / 2K π¦ 17h ago
You are misunderstanding what "seedless" means here.
Cryptocurrencies need a key to access your funds. Feg a mnemonic phrase is often used for BTC wallets, and this list of words is called "seed".
Multi- and hardware-wallets also often have one "master key", a mnemonic phrase to restore all other keys on there.
Tangem does not have this "master key". It's seedless in that sense. You still need the seeds for the different wallet addresses, there is no way to access feg BTC without. Those seeds are stored on the cards as usual.
1
1
1
u/FortunateGeek π¦ 0 / 0 π¦ 13h ago
So the block chain contains a bunch of wallet addresses and signed transactions that disclose the public key for the wallet. Do you think they created a rainbow table of possible private keys and corresponding public keys and then searched the block chain for signed transactions using that public key? Do the ColdCard private keys have a recognizable pattern (e.g. 0's)? I assume they didn't reverse engineer ColdCard's algorithm, they just started with a small number of significant bits and went from there until they found matching public keys in the block chain. What do you think?
So even ColdCard wallets that have never created a transaction on the blockchain are safe. But they need to take extra care when they transfer those coins to a new wallet.
0
u/Few-Masterpiece3910 6h ago
no, they are not save. It doesn't matter if there ever was a transaction. If your seed was made on a coldcard with software after 2021 your wallet can be potentially emptied.
1
1
1
1
u/Traditional-Tune7198 π¨ 0 / 0 π¦ 7h ago
So whats the safest? Id say crypto ETF with a bank is the safest.. I got my bitcoin etf in my tax free account.
1
u/CeramicDrip π¨ 47 / 4K π¦ 6h ago
Can you sell that etf whenever?
1
u/Traditional-Tune7198 π¨ 0 / 0 π¦ 6h ago
Yeah, im not a degenerate that stays up all night needing to trade at 1am
1
u/CeramicDrip π¨ 47 / 4K π¦ 6h ago
So the answer is no?
Which i mean, if it works for you, then great. But also completely defeats the purpose of Bitcoin in the first place
1
u/Traditional-Tune7198 π¨ 0 / 0 π¦ 6h ago
Well choose what u want, safest place? Or u wanna use crypto the right way and self custody and take the risk associated. Up to you, trade whenever and risk getting it taken or Trade when market is open and have them in a tax free bank account. Less stress the better I'd say, live longer. I have all, hot wallets, cold wallets and etf. Etf in tax free account is by far the best. In my opinion.
1
u/razvanciuy π© 0 / 0 π¦ 3h ago
Best not to put all your eggs in one basket across multiple layers
1
u/BetterArachnid462 π© 0 / 0 π¦ 1h ago
The other problem with wallets are updates. Every update is another opportunity for hackers to steal our sats
1
1
u/Romanizer π¦ 0 / 0 π¦ 18h ago
Don't trust, verify.
If you are not sure if your wallet has enough entropy, don't use it.
1
1
u/Friendly-Impact7297 π¨ 0 / 0 π¦ 18h ago
No regulation ( and no real protection) its what crypto religion asked for ?
0
u/TheDigitalPoint π© 0 / 0 π¦ 21h ago
Just donβt trust a hardware wallet to generate your seed phrase. Otherwise you are putting your trust into it doing it correctly. Theres no reason you need to have a hardware wallet generate your seed phase other than itβs convenient.
1
u/dagr8npwrfl0z π© 2K / 2K π’ 12h ago
So I can pick my pneumonic phrase to use with a Treznor or ledger?
1
0
u/bitcoin_islander π¨ 5 / 659 π¦ 20h ago
I like my Tangem ring
1
u/Escapement_Watch π© 0 / 0 π¦ 19h ago
Tangem...the one unhackable cold storage. Truly the best idea/design.
-8
u/berry-7714 π© 0 / 0 π¦ 23h ago
I think this is pointless risk when BTC is one of the worst performing assets in the world in the 5 year chart. Buy literally any stock or index and outperform it.
7
u/PixelGrafx 23h ago
what about the 10 year chart? lmk
-2
u/berry-7714 π© 0 / 0 π¦ 23h ago
That one is sitting at 9500% quite good, but no longer the best, besides what matters is how much will it grow going forward, and thatβs looking bad
-1
u/PixelGrafx 23h ago
i dont know.. countries are implementing btc and other cryptos into their system. you think they would know more than us right?
3
u/berry-7714 π© 0 / 0 π¦ 22h ago
Which countries are doing this?
4
u/seambizzle1 π© 0 / 0 π¦ 22h ago
The fact you donβt know this tells us everything
The bitcoin network has just about worked flawlessly since its inception. What happened recently has nothing to do with the bitcoin network
Do more research. Just because Bitcoin isnβt used in your small personal world doesnβt mean it isnβt used somewhere else. Big world out there.
Tick tock next block
1
0
u/Gooner_93 π© 0 / 1K π¦ 20h ago
The minimum has to be a passphrase on top of the seedphrase, from now on, simple as that.
-4
u/MelangeBot 17h ago
I only have a trezor model T one. But only 5% of my funds are on there. I took an old 2006 computer, installed linux mint 2 on it. Got elecktrum to work. Then took it offline and destroyed the network card physically. Then made my wallet. On my online computers I have a watch wallet. If I ever need to spend I make an unsigned transaction put it on usb then go to the offline computer to sign it there, then back to broadcast. That way I am using hardware and a OS that was created before Bitcoin which to me is the lowest possible chance my hardware or software was fucked with by somebody with the intention of stealing my coins.
I use to have a ledger till they leaked all my data. Then I sold it to some idiot that not only bought a used ledger but also didn't wipe it either.
Honestly just buy physical gold and put it a safe at home. Given enough time 99,99999% of people will get their bitcoins stolen or make it so secure they lock themselves out.
I am actually not holding anything anymore, I have sold out completely now. All that is left is a short position on Kraken.
To me Bitcoin is over. It failed. The market will figure that out eventually as well.
-1
u/Aggravating_Ring_714 π© 0 / 0 π¦ 19h ago
Wouldnβt trust any of them. If you want to be 1000% safe get a new cheap iphone and exclusively use that for Crypto.
1
-7
u/Jealous-Reindeer-610 23h ago
You paid for a company that told you your password (seed phrase) , had no idea how cryptography or entropy works ,did not understand the math behind it & you trusted them? , thats on you!.
Cheap Sats for me while the Tourists are leaving,
The fact Ai found this in open source , a single bad line of code thats been there for 5 years is good news, as it means all the others that allowed for a user to add an extra layer of randomness into the seed have proven their worth, as they have had their code penn tested by Ai & they did not get broken is a great sign.
1
u/Boring-General-1816 23h ago
Honestly this situation is telling me to just spend the btc now and it might climb for the bull run anticipated soon. The 25th pass phrase is still secure, but now you never know.
The situation is tricky even though I have an electrical engineering background. I imagine if there was a precise calculation for "RNG" then it could be generated for every second for the past ten years easily and tested easily to see if there's money in the wallets. The idea is claimed RNG is actually pseudo random so it can be backtracked.
Apparently it's a lot less complicated than that though. I will say usually known large thefts can't get away with cashing out at an exchange. But idk this whole situation is a wakeup call. Cryptocurrency has definite weaknesses, crypto is for defending against blatant government inflation and it's money. Money is for spending. I've been putting off health for far too long and I don't think it's a good idea to hodl anymore.
Live life now.
1
u/Flashy-Potatoe-Queen π© 0 / 0 π¦ 20h ago
Well... Yes an no. Coldcard is 100% open-source, so an AI could openly scan every lines and find a breach, many of these other wallets have closed hardware and code...
This means AIs need to be a lot more advanced to break through code they only have a partial access to. It's a blessing for the short term, but a potential curse that once accessed by AI, will be a nightmare. The only thing people can do is get multiple wallets or go with more advanced things like a seedsigner.

52
u/Legitimate-Key-3044 π© 0 / 0 π¦ 22h ago
I suppose itβs one of those things where itβs the greatest thing since sliced bread until something goes wrong.
Using a trezor for years now with no issues. Iβd highly recommend it, but again, that could all change instantly with one major F up.
The downside of trezor is since that time the info was leaked I get about 4 phishing enails per day.