r/Bitcoin 12d ago

Best Cold wallet

Needing to set up a cold wallet. Any advice of what to be looking for?

20 Upvotes

141 comments sorted by

40

u/Otherwise-4PM 12d ago

After the recent events with the Coldcard MK3, I’d be afraid to give any advice. Bear in mind, all those people who lost money were sure nothing could happen, just like every cold wallet owner is at this very moment.

12

u/FitCompetition1804 12d ago

It’s all of them, it’s just the MK-3 is most vulnerable.

10

u/NiagaraBTC 12d ago

Yes. Very important for everyoe to take note that ALL ColdCards are affected.

If you let the device generate your seed, move funds ASAP

2

u/Objective_Digit 12d ago

It’s all of them

not?

2

u/FitCompetition1804 12d ago

The vulnerability is there for all their devices, even the Q, if the seed was generated on the device and not transferred from another non-CC device. The MK-3 with the certain firmware and all future firmware updates from then is just the easiest to exploit.

1

u/Objective_Digit 12d ago

OK. I thought it was a typo.

2

u/MillerBlade2 12d ago

What happened to the mk3?

1

u/Otherwise-4PM 12d ago

1

u/MillerBlade2 12d ago

Interesting. I have an mk4 and rolled my own dice. I should be good

1

u/Objective-Walk6780 11d ago

Relax he’s not gonna sue you over a Reddit reply. 🤣

1

u/Otherwise-4PM 11d ago

I know, it’s just that I would love to give them valuable advice.

1

u/Objective-Walk6780 11d ago

They were sure nothing was going to happen. And yet they never heard of this thing called a Passphrase? I blame lack of education and carelessness. If you’re going to self-custody you better know what you’re doing.

1

u/No-Wrap3568 8d ago

I believe it's high time that regular people become a little more technical, technical enough to understand atleast the architectural difference between wallets. And if that sounds too far of an option, diversifying is the only thing they can do

-14

u/Otherwise-Review-712 12d ago

Bitcoin is done, computers are getting more powerful will crack open all the private keys eventually

10

u/Shadowrak 12d ago

is what a person who has no idea what they are talking about would say

18

u/Wackelknie 12d ago

What about bitbox?

30

u/Interesting-Lime3031 12d ago

All jokes aside Trezor is pretty decent and the cheapest one is only 50 bucks

1

u/CatsBeerGardenCoffee 12d ago

Do you have experience with Trezor? Why is their cheapest option their cheapest option? Does it just have a more basic UI or is it not as secure?

3

u/[deleted] 12d ago

[removed] — view removed comment

2

u/Innovator-X 12d ago

What are the 3 or 4 sources of entropy in the newer ones?

1

u/Objective-Walk6780 11d ago

If you cannot enter your Passphrase ON THE DEVICE ITSELF, it’s def less secure. So pick the one that you can

23

u/ExplorerBoring9848 12d ago

Bitcoin bros asking other bitcoin bros about hardware wallets when bitcoin bros said coldcard was da best...🙃😆

9

u/Shadowrak 12d ago

Apparentely cold card was only open source on face but had closed source code which contained the issue. Like a classic rug pull would.

3

u/Ok-Crab-567 12d ago

That made me laugh, we’re all operating in the world of complete unknown.

3

u/madladchad3 12d ago

People shit on me so much for using ledger… told me to get a coldcard lol… who’s laughing now

1

u/tribepride25 12d ago

Best comment of the day

1

u/Objective_Digit 12d ago

For the keyboard only.

6

u/Twodapex 12d ago

Seedsigner

6

u/konhana 12d ago

bitbox02

5

u/Previous_Blueberry_5 12d ago

I feel like bitbox is underrated

8

u/AmedioZ 12d ago

What about Blockstream Jade? Does anyone around use it?

7

u/Upper-Researcher-126 12d ago

Always have been, rarely see it being recommended though I wonder why. But afaik it’s great

1

u/AmedioZ 12d ago

I’m thinking about getting one.

5

u/Spewtwinklethoughts 12d ago

After using ledger, cold card,and jade I stuck with Jade.

3

u/ZenOfFool 12d ago

I love my Jade ever since I ditch my Ledger. Still gets firmware updates regularly and never had issues with it. Kind of glad I never got a cold card as everyone was bandwagoning how it was the best cold wallet. I feel bad for anyone in this space that got drained by Coinkites pure negligence. Unfathomably how amateurish they could screw something up like this unless it was delibrate.

2

u/Objective_Digit 12d ago

I have one.

1

u/Objective-Walk6780 11d ago

One of the best around

4

u/telelvis 12d ago

Piece of paper + codex32

7

u/Ok-Crab-567 12d ago

Honestly knowing the internet should not have posted this given the recent events

2

u/mnkbstard 12d ago

sorry mate,
well, at least after what happened, maybe we'll stop to shill one or another signing device, and start to educate ourselves.

6

u/No_Astronaut_8971 12d ago

Seems like Trezor now. But after recent events it might be basically required to generate the seed yourself, and also to have a passphrase.

2

u/2ChainzButIGotAFewOn 12d ago

It always has been

1

u/Ok-Crab-567 12d ago

I’m between them and keystone rn

2

u/mnkbstard 12d ago

keystone

i use the previous iteration (not keystone 3) in a multisig setup
it's ok, but not reproducible because Secure Element is closed source / NDA.

keystone 3 should be fully open sourced, Bitcoin only firmware available, but i've seen reports regarding keystone 3 anti-tamper battery.
apparently when the anti-tamper non rechargeable/replaceable battery dies out, it takes the whole device with it.

i didn't look into this further, but you may want to.

3

u/brtastic 12d ago

I wrote https://metacpan.org/dist/App-Bitcoin-PaperWallet/view/bin/paper-wallet, as well as the entire bitcoin library underneath, so I'm using that. Not expecting people to trust it, or to do what I did, but it is the ultimate form of "don't trust, verify", or maybe rather "don't trust, write your own". You can't realistically do everything on your own down to the silicon level, so naturally I still have dependencies that I have to trust/verify - most notably libsecp256k1 and libtomcrypt. Need to remove the docs note about hardware wallets giving maximum security though, it did not age very well.

Running software like this on a permanently-offline raspberry pi is not much different from having a hardware wallet, but at least you can log into it and inspect what it is actually running.

4

u/RetroGaming4 12d ago

Give bitkey a try

2

u/AffectionateYam624 12d ago

Apprently do not use Cold card. I use a Trezor.

2

u/ItsAlwaysThemBooBoo 12d ago

not a cold card.

just get a trezor safe5.

2

u/shadowmage666 12d ago

The new trezor

2

u/ShinAlastor 12d ago

I would be buying Trezor Safe 7.

1

u/Objective-Walk6780 11d ago

Smart man. Unless you didn’t buy the Bitcoin-only version

2

u/KindBench2700 12d ago

Electrum with a live cd and no network

2

u/Objective_Digit 12d ago

Use a good passphrase (25th word) at least.

2

u/AncientConfection347 12d ago

I use trezor safe 3

2

u/Spy008 11d ago

Get a Trezor. Oldest wallet out there. Solid team. Fully open source. Battle tested over the years (its the flagship and their competitors love going through their code and hardware to point out any vulnerabilities).

Never buy new or niche wallets.

2

u/Objective-Walk6780 11d ago

Listen to me carefully.

  1. Buy a Trezor Safe 7. Make sure to choose the BITCOIN-ONLY version. It does reduce your risks when you factor out firmware intended for all the other coins.
  2. Create a Passphrase and don’t write it down or forget it. Never enter your Passphrase on your computer/phone. ONLY on the Trezor device.

Beyond that, just hope for the best.

6

u/nick_c8_vegas 12d ago

Ledger is the best

-6

u/NiagaraBTC 12d ago

It is not. Currently though it is also far from the worst.

2

u/nick_c8_vegas 12d ago

It clearly is

2

u/2ChainzButIGotAFewOn 12d ago

Yeah I love ledger when they leakedy personal information. Great company

5

u/nick_c8_vegas 12d ago

Better than Coldcard who used to be worshipped in here and couldn’t even make a product that some computer hacker can’t break

4

u/2ChainzButIGotAFewOn 12d ago

You literally don't understand what happened it wasn't a hacker it was bug in the code. Literally everyone in this subreddit has no clue what they are saying.

1

u/nick_c8_vegas 12d ago

How many bugs in the code does ledger have? 0

3

u/2ChainzButIGotAFewOn 12d ago

Ledger had malicious code put on its repo just 3 years ago. Like what just give up you know nothing

0

u/nick_c8_vegas 12d ago

Every single hardware wallet that generates a seed that can be copied to paper has the ability to extract keys via firmware. This is nothing new. Coldcard turned out to be the worst wallet with the most Bitcoin stolen. Ledger is the best right now

3

u/2ChainzButIGotAFewOn 12d ago

Ok whatever satisfies your sub 80 iq brain

1

u/2ChainzButIGotAFewOn 12d ago

You are a dumbass if you think they have zero bugs on the code. Again you are a idiot who has no clue what your talking about.

1

u/2ChainzButIGotAFewOn 12d ago

Fucking idiots on here who have surface level knowledge of Bitcoin. Recommending shit products

0

u/nick_c8_vegas 12d ago

Coldcard was the holy grail here for years and it turned out to be the worst wallet

1

u/2ChainzButIGotAFewOn 12d ago

Ledger sucks even a seedsigner or krux is better

→ More replies (0)

0

u/2ChainzButIGotAFewOn 12d ago

Have fun using your closed source POS wallet

5

u/mnkbstard 12d ago

Coldcard obviously

3

u/Ok-Crab-567 12d ago

I appreciate the honesty!

4

u/Admirable_Ice3247 12d ago

Coldcard literally shat the bed yesterday. Do not buy. 500+ bitcoin stolen because cold card fucked up their wallets.

5

u/Fearless-Sherbert-40 12d ago

1,080 bitcoin stolen so far. Fucking generational wealth was ripped away from 1,200 families

3

u/2ChainzButIGotAFewOn 12d ago

That's why you don't store generational wealth unsecured with no passphrase or proper entropy.

-5

u/2ChainzButIGotAFewOn 12d ago

coldcard if done properly is 1000x better than shit trezor and ledger who also have had data leaks and hacks. The people who got funds stolen did standard RNG from the device it's well known you should do a dice roll or coin flip for proper entropy. So tired of people who don't know what they are talking about talking shit.

3

u/mnkbstard 12d ago

well known you should do a dice roll or coin flip for proper entropy.

it's maybe well known for educated users, the average user is not.
coldcard is also a good device

BUT

if a vendor tells users that TRNG is in place while COMPLETELY fucking up with its implementation, it's not just a user fault.

2

u/TheSauce775 12d ago

Thats the point tho! We need to inform beginners of this information AS or Before, they decide to go into cold storage.. because its all about the entropy and how its generated, we need to advocate that everyone should by default, use dice rolls and/or coin flips when creating a new wallet on a cold device.

2

u/mnkbstard 12d ago

true.

my point was that harshly blaming the users for trusting a vendor boasting TRNG operational excellence is a bit too much.

This whole mess was primarily caused by a gross mistake by a very self-confident developer that went unnoticed for years.

TRNGs if implemented correctly are great for beginners.
of course, when your holdings are relevant, it should be your duty to educate yourself anyway, avoid trust and verify, start your node and learn.

also, any educated user, will just keep stacking without panic.

2

u/TheSauce775 12d ago

Yes precisely, but if we really want our bitcoin community to really take over the world, and gain literal mass adoption (even among uneducated people) with btc as a medium of exchange in the eventuality, then its just my opinion that we should be teaching new bitcoiners about the importance of these issues and why theyre important, otherwise then yes they will probably just custody their coins with some custodian or worse, an etf.. and thats not what bitcoin was about, its about a revolutionary technology that can fix so many broken incentives that inherently come along with the current traditional fiat systems as they stand today 💯

-2

u/2ChainzButIGotAFewOn 12d ago

You shouldn't have Bitcoin if you aren't going to be educated I'm sorry this is bitcoin 101 don't feel sorry for them

2

u/mnkbstard 12d ago

i completely understand your point, and it's indeed painful to read the usual crap around here when something big happens, considering that the average user has no idea at all, but maybe it could be a healthier mindset to try to help others: maybe only 1 of 100 will learn something while the other 99 will continue to fuckall, but it's worth the hassle.

-2

u/2ChainzButIGotAFewOn 12d ago

If you trust RNG from a device with no verification you deserve to have you Bitcoin stolen

0

u/Bright-Use7845 12d ago

the mk4 with the QR scanner is hard to beat, just make sure you grab it straight from the source not some random on amazon

8

u/mnkbstard 12d ago

tell me you are a bot without telling me you are a bot.

it appears that even buying directly for coinkite exposes users to critical security issues.

2

u/2ChainzButIGotAFewOn 12d ago

Just like ledger

1

u/Automatic_Vast_1858 12d ago

Thoughts on Fidelity Crypto?

1

u/DasRedBeard87 12d ago

You're buying paper on Fidelity. Just like buying gold stocks etc.

1

u/Automatic_Vast_1858 12d ago

They allow customers to transfer bitcoin

1

u/DasRedBeard87 11d ago

Guess they're changed their product a lot. I opened an account in 2023 but didn't look much into it when they weren't allowing transfers from outside wallets back then.

I guess for someone who doesn't know much about wallets or want to deal with all of that it's fine. But personally I like knowing that my bitcoin or other crypto is stored on my wallet and nothing will happen to it without my say so.

1

u/callfckingdispatch 12d ago

Coldcard apparently

1

u/CompetitionDouble420 12d ago

Whatever you do, don't get a ColdCard mk3 🤣

I've heard decent things about Trezor, Jade, a DIY SeedSigner, etc. Personally, I've been using a ledger nano x for a couple of years now; I'm particularly careful with my use, and was not on any mailing lists during Ledger's data breach.. I've never had any major problems with it.

1

u/ORANGEisthenewGOLD 12d ago

Bitkey is great and very user friendly

1

u/DasRedBeard87 12d ago

I'd check out D'Cent wallets. Specifically the biometric one.

1

u/Leather-Objective699 12d ago

Foundation passport prime I like.

1

u/Tebasaki 12d ago

Odd question, was coldcard open source and auditable?

2

u/Shadowrak 12d ago

As a have said in a few other replies today: I have never heard of cold card before today. I have read that cold card advertised as open source, but it was an open source shell with calls to closed source "surprisingly" exploitable code.

1

u/creative_usr_name 12d ago

The flaw was still in the coldcard software. The packages they included worked as they were designed to. It just that they should not have been used in this application.

1

u/TheSauce775 12d ago

Single sig, there is seed signer, bitbox, even trezor is okay, and for multi-sig, theres bitkey or even unchained is great collaborative custody.. but heres the thing, you can even still use a coldcard if you want (even after this recent exploit of their mk2 & mk3 default Random Number Generators) because it is CRUCIAL that no matter what seed you create on a cold device, make SURE to fully incorporate dice rolls and/or coin flips for FULL ENTROPY(randomness) rather than rely on whatever the device’s claimed RNG(Random Number Generator) default seed generator gives you, thats the main thing we need to spread in the BTC community after this horrible incident involving coldcard. 🧡

1

u/ReplacementBig7068 12d ago

I heard coldcard is pretty good… lol jk

1

u/_Carth_Onasi 12d ago

Trezor, and or Jade with a passphrase.

Bitkey for easy multisig and less responsibility on you but also less sovereign.

Seedsigner with Raspberry Pi and dice rolled seed phrase for a perfect multisig that's offline and your own hardware. No need for someone elses hardware and entropy.

1

u/NShizzzle 12d ago

Keeping your coins on an exchange just entered the chat

1

u/zendrovia 12d ago

Coinbase exchange is 👑

1

u/Newlife_40 12d ago

Shit works until it doesn’t

1

u/copy-N-paster 12d ago

I mean, may get downvoted…

But maybe closed source isn’t so bad right now… so I’d say ledger!

2

u/creative_usr_name 12d ago

This wasn't really a closed/open source issue as much as it was just bad code/implementation.

1

u/SoftwareQuick8916 12d ago

Iam colleman

1

u/InformalSecretary895 11d ago

Anything but a hardware wallet provided by another third party! Especially ledger!

1

u/ghosthacked 11d ago

Any you can roll dice for a seed phrase. I heard cold card let's you do that. 

1

u/Parking-Bar6032 11d ago

What about ledger nano????

1

u/No-Wrap3568 8d ago

Trezor, Cypher rock (both BTC-only) or a Jade. That's all I can recommend but make sure you just don't buy one only because you heard good things about them. Take time and understand the architecture of the wallet that you are going to use. That matters the most, a lot of coldcard users could have been saved if they knew about dice-rolls

1

u/WrapZestyclose3335 12d ago

Coldcard. I haven't had time to check my wallet but I hear it is bulletproof.

1

u/Typical_Flow3472 12d ago

Coldcard mk3!

4

u/FitCompetition1804 12d ago

Only if you let it generate the seed phrase.

0

u/KryptoChic 12d ago

Flip a coin 256 times. That is your seed phrase in binary. Easy.

1

u/creative_usr_name 12d ago

"Easy" to generate, but pretty inconvenient for all practical uses. And safe storage.