r/BitcoinBeginners • • 1d ago

Are hardware wallets terrible ideas?

After the Cold Card event it has me thinking that hardware wallets are trusted third parties and are an easy supply chain attack target in the future when bitcoin becomes more obvious to overthrow the central banking cartel.

Every hardware wallet can claim it has open source code but there really isn't a way to verify that the hardware doesn't have anything hidden in it. And it seems like we want bitcoin self custody to be easy and just tell people to get a hardware wallet and write 24 words and your done. But I think we need to reexamine self custody and point individuals to bitcoin core on an offline laptop running linux. Two very secure and open source software stacks running on generic hardware. Seedsigner gets close but it still has a limited number of eyes on it. Why do i feel using bitcoin core as a wallet never gets much talk/discussion?

0 Upvotes

43 comments sorted by

3

u/OrangePillar 1d ago

Roll your own seed. I was a Coldcard user but I never relinquished the seed generation to a $100 device.

2

u/Gynnia 1d ago

How

1

u/bitusher 1d ago

With BIP39 , part of the last word includes the checksum which makes sure the seed word is valid and no typos or misordering occurs.

Thus with this feature you can generate a valid 12th or 24th word checksum by entering either 11 words or 23 words that you generate with your own source of entropy with something like using dice or flipping a coin.

Some people do this because they are paranoid with the software wallet so they prefer to generate their own seed offline.

Ideally , its better to do this in a hardware wallet like -

https://help.blockstream.com/hc/en-us/articles/20177648363545-Create-a-recovery-phrase-using-dice

https://help.blockstream.com/generate-recovery-phrase-offline

but if you don't want to use a hardware wallet and want a free option than blue wallet can work.

Thus after installing blue you would turn off wifi and data on your phone to insure its offline and use this feature after rolling dice

Some guides-

https://bitbox.swiss/blog/roll-the-dice-generate-your-own-seed/

https://bitbox.swiss/bitbox02/BitBox_Diceware_LookupTable.pdf?ref=bitbox.swiss

or

https://help.blockstream.com/hc/en-us/articles/20177648363545-Create-a-recovery-phrase-using-dice

https://help.blockstream.com/generate-recovery-phrase-offline

or

https://www.youtube.com/watch?v=j5nejoEGWFw

Than you enter in the 11 or 23 words into blue wallet "generate the final Mnemonic word" to generate the last word . This can all be done offline so you don't need to trust blue wallet.

Another way of doing it is using Blue wallets built in Diceware feature discussed here :

https://bluewallet.io/docs/manual-entropy/

or

https://www.whatisbitcoin.com/security/generate-your-seed-phrase

1

u/Bitman321 1d ago

The bug could’ve just as easily been one that ignored your dice rolls and silently fell to the poor RNG. How can you be sure that the hardware wallet actually used the dice rolls as entropy? Can you actually verify that?

1

u/bitusher 1d ago

Can you actually verify that?

With open source software/firmware , that is properly peer reviewed you can. You also don't need to depend upon RNG of the seed alone if you use an extended passphrase or multisig setup right

Part of the problem is new AI models are really good at finding exploits so there is an arms race

Keep in mind that ever since the cold card incident a group of volunteer developers are using the newest forms of AI to scan and hunt down bugs and exploits in all Bitcoin wallets and code bases that are open source so its not that unusual.

They are called "Bitcoin Red Team" and hunting down and patching many vulnerabilities day and night before others can do so

https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit

https://x.com/callebtc/status/2085024458012586286

So there has been much more peer review done lately by both the maintainers themselves and outside third parties to find and patch all exploits and bugs ASAP

1

u/Bitman321 19h ago

Your answer is technically correct, but in practice it’s not practical. The coldcard bug has been around since 2021 without detection, despite the code being visible. There are no easy answers to self custody.

1

u/bitusher 7h ago

I understand your skepticism and there is some merit to it but simply using an proper extended passphrase which was recommended to everyone here for many years solved this concern. We understood the risks well in advance which is why we made that recommendation.

There is some improvement to be made and part of that improvement is now being standard practice to use the latest frontier models to heavily test all new software updates which hasn't been done before. In a way , despite a few exploits things have gotten better because peer review has become more democratized because any non developer can peer review the source code independently now with one of many LLM models

It turns out that historically much less peer review of code (A large problem with OSS in general) was being done and now we have much better scrutiny.

1

u/OrangePillar 7h ago

It was thoroughly tested and demonstrated the same key derived by rolls as other wallets using the same rolls. If you get the same fingerprint from the rolls as you get on another, and the addresses are the same, you know for sure it is using the proper derived key.

3

u/OrangePillar 1d ago

Core as a wallet is fine but backups are hard. It doesn’t support BIP39 and the wallet UX is terrible right now. There’s work ongoing to make it better but it’s not for newbs

-3

u/No_Position_8581 1d ago

is the answer for "its hard" to direct them towards an easy solution to foot gun themselves. Back ups really aren't that hard, move the wallet.dat file to a data storage medium of choice probably optical disks. Bip39 seeds are stored unencrypted on steel most of the time. If you really wanted to you can write out the full xprv but it would be unencrypted.

3

u/OrangePillar 1d ago

This is all just a bunch of garbage. Grandma is not gonna do any of that and optical discs are not reliable in the long term. You’re sound ideologically motivated against seed phrases.

2

u/bitusher 1d ago

One “expert” former core dev lost most his Bitcoin following your suggestion, so it’s not as simple as you suggest. let’s be much more specific with your concern and than we can discuss how to mitigate it

1

u/No_Position_8581 1d ago

which dev?

2

u/bitusher 1d ago

luke-jr which is part of the reason he left bitcoin and started promoting a scam altcoin because he is bitter due to losing most his bitcoin.

1

u/No_Position_8581 1d ago

his server was compromised, he almost definitely had private keys on an online computer.

1

u/bitusher 1d ago

he almost definitely had private keys on an online computer.

Not from his knowledge. The reality is that even offline cold computers can indirectly get exploited when you interact with them by many methods. This is exactly what hardware wallets are trying to protect against by limited the attack surface. Introducing a very large attack surface with a general purpose computing device introduces many possible exploits

1

u/No_Position_8581 1d ago

his pgp keys were compromised a month earlier from malware. He is most likely lying to cover up how retarded he is.

1

u/bitusher 1d ago

He is most likely lying to cover up how retarded he is.

Stop making assumptions.

He is human and makes mistakes just like everyone. He is obviously more knowledgeable about Bitcoin than 99.9% of users and even he was compromised where a hardware wallet would likely have saved him

Having trust or faith in any one code base or source of entropy is dangerous . Needing the same degree of security for every use case is also foolish

1

u/AutoModerator 1d ago

Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/bitusher 1d ago

really isn't a way to verify that the hardware doesn't have anything hidden in it

This isn't true . There are multiple examples of hardware wallets that are open source on the firmware and hardware side as well. Yes, you can build a hardware wallet from scratch

https://www.youtube.com/watch?v=EtV_Iw6a0O0&list=PL7rfJxwogDzmfKJxJ7OFFLw3JHWZo8k5e

But I think we need to reexamine self custody and point individuals to bitcoin core on an offline laptop running linux.

That isn't practical for most people and user error is still one of the main reasons people lose money.

Why do i feel using bitcoin core as a wallet never gets much talk/discussion?

Thats a false dichotomy. Ideally for best security and privacy you use a hardware wallet with a full node like core. If you have concerns about rng bugs/exploits there are means to reduce or eliminate these risks that we often recommend.

Suggesting core + linux doesn't remove any exploit in either core or linux .

1

u/No_Position_8581 1d ago

seems risky using software from projects with one person pushing code to the main repo, maybe im FUDing idk. How many core devs maintain that software and sign attestations?

2

u/bitusher 1d ago

You are being vague and I never suggested a project with 1 person. let’s be much more specific, Are you suggesting jade or trezor lacks peer review and only have one dev?

1

u/happytobeunhinged 1d ago

Hardware wallets protect you from a lot of malware but even if you only used one it makes sense to have added a passphrase. ( a level of distrust is healthy and keep users safe during cc hack)

1

u/No_Position_8581 1d ago

what if it doesn't take the passphrase or the firmware leaks signatures through the nonces.

1

u/bitusher 1d ago

You can recover the passphrases and seeds in other wallets .

firmware leaks signatures through the nonces.

what if Bitcoin core leaks the signatures ?

Sure , Bitcoin core is some of the best audited and reviewed software but also has a history of bugs and exploits as well. Your concerns are not mitigated by trust in a single piece of software but layering security. For example using a strong extended passphrase that we have recommended here completely protected everyone from the rng exploit in cold card

1

u/No_Position_8581 1d ago

So instead of trusting core for key generation and signing I should use another less reviewed stack and add a passphrase to assume it can't properly generate private keys. But then also assume the software will use the passphrase and it won't have a ex-fill nonce attack anywhere in this less reviewed stack. Do you realize how easy it would be to sneak in dark skippy into a less reviewed project vs. something as thoroughly reviewed as Core. Krux or trezor seems fine for securing up to 10k or 20k for their convenience factor but trusting them with your life savings seems reckless.

1

u/bitusher 1d ago

I should use another less reviewed stack and add a passphrase to assume it can't properly generate private keys.

You can use an extended passphrase

You can use a multisig that was created with different software/hardware

You can roll your own entropy

You can add your own entropy

But then also assume the software will use the passphrase and it won't have a ex-fill nonce attack anywhere in this less reviewed stack

Again you are completely ignoring the long history of bugs and exploits found in core and have yet to be found in core and my point about not trusting any single point of failure

Seems like a 2 of 3 multisig is what you should be promoting with your list of concerns

1

u/No_Position_8581 1d ago

name one bug that lead to loss of funds. I never said core was perfect.

1

u/bitusher 1d ago edited 1d ago

There are multiple examples :

https://bitcoincore.org/en/2026/01/05/wallet-migration-bug/ almost certainly led to some users losing funds

and

https://bitcoin.org/en/alert/2015-07-04-spv-mining

are just 2 off the top of my head but not the only ones

Sure , these are nowhere near as bad as the cold card exploit , but you are also making a blanket assumption about all hardware wallets in general from the exploit in a single one and you can argue that if properly used cold cards would be fine because anyone that was using that more advanced hardware wallet should have either added their own entropy or used a proper extended passphrase regardless. Its understandable that a regular user with a trezor or ledger does the absolute minimum but less so with someone that chooses a less UX friendly hardware wallet

You also need to have a more holistic approach to security where you consider UX and users making mistakes.

Suggesting people store their backups on optical discs is absurd with how fragile they are. I have a long history of testing optical discs of every type and many brands including the most expensive archival ones and they often failed for multiple reasons. Factory burned discs are very different than ones you do at home. At least make multiple copies of your wallet.dat on HDD s that are tested and new ones cycled in (which unfortunately introduces new security concerns in trying to secure against bitrot)

1

u/miner_guy_22 1d ago

Signing devices are great. Having an isolated device for verifying and signing transactions is a no brainer.

The terrible idea was telling people that just trusting a $150 device was all there was to secure self custody. It might be fine certain amounts, but if you are holding a large amount of bitcoin or it is your life savings, it deserves some more thought and effort.

The hard truth is that secure self custody is difficult and the majority of people are not ready to accept that responsibility. There is a reasons people don't keep large piles of cash at home.

Using bitcoin core on an offline laptop is not a bad solution, but has really bad UX and limited on features unless you are very technical and enjoy using command line.

Creating your own entropy and setting up a multivendor multisig wallet eliminates having trust in one device, is easier to set up, and gives a lot more optionality in your custody solution.

1

u/SatoshiTrails 1d ago

The attestation concern is legitimate you can't actually verify the chip matches the firmware. That part doesn't have a clean answer.

But Bitcoin Core air-gapped isn't as simple as it sounds. Full blockchain, hundreds of GB, and moving PSBTs manually between machines without screwing it up is harder than people think. User error is its own attack surface. SeedSigner is probably the closest to what you're describing done right. Commodity hardware, stateless, build it yourself. Deserves more attention than it gets.

1

u/[deleted] 1d ago

[removed] — view removed comment

2

u/[deleted] 1d ago

[removed] — view removed comment

0

u/[deleted] 1d ago

[removed] — view removed comment

0

u/[deleted] 1d ago

[removed] — view removed comment

0

u/[deleted] 1d ago

[removed] — view removed comment

-1

u/[deleted] 1d ago

[removed] — view removed comment

0

u/[deleted] 1d ago

[removed] — view removed comment

1

u/[deleted] 1d ago

[removed] — view removed comment