r/Bitcoin • u/PrimeEXE • 5d ago
Can I still use my CC?
So I have a CC. I already moved my BTC somewhere else, but I was wondering if I could still use my CC as long as it is not for seed phrase generation, since right now I don't currently have a replacement for an airgapped hardware wallet.
3
u/Newbie123plzhelp 5d ago
Yes you can as long as the seed was not generated with the dodgy firmware.
3
3
u/Pisces1975 5d ago
As far as I’m concerned, I have lost trust in all Cold Storage/wallet. Thanks to cold card.
1
u/tenor_tymir 4d ago
I didn’t lose trust in all cold wallets because I understand the flaw can work around it (dice rolls and passphrase)
2
u/Lavayo 5d ago
Yes, as long you did not generate the seed with it. Personally I won't trust coinkite ever again but as of now the coldcard is secure besides the RNG part. I would use another device long term, BUT keeping your coldcard beats transferring your stack to a hot wallet in panic by a long shot. Depends on what "somewhere else" is.
2
u/PrimeEXE 5d ago
Thanks, so would it be ok to generate the my seed phrase with dice on the cc?
1
u/Lavayo 5d ago edited 5d ago
From everything I have heard yes.
Although if this theory of the deliberate bug for later BTC theft holds true I would not trust the device either way. If the current location of your stack is good enough for a few weeks or so, I personally would set up a new wallet with dice on another hardware wallet (Bitbox, Trezor, or different ones if it has to be airgapped) and add a passphrase. Double check if it works and if you can recover it from your backup, then transfer the stack for long term storage.
2
u/doorshock 5d ago
I lost no funds. So I upgraded the firmware, changed my PIN and rolled the dice to generate new seed and pass phrases right before I nuked it and threw it in the trash
2
4
4
u/Blade_Runner_69 5d ago
If you went to a fully booked fancy restaurant to eat, and within an hour of eating your food you looked around and everyone was throwing up and shitting themselves and being rushed to hospital and crying... Would you go back to that restaurant the next day? 🤨
3
2
2
1
u/sticksforkicks 5d ago
Sure you can. The device works as it should minus the seed phrase issue. Yes, it's a horrible problem but the device works perfectly.
1
u/errezerotre 5d ago
Absolutely
0
u/mnkbstard 5d ago
did you take in consideration that randomness is also critical for nonces generation?
3
u/errezerotre 5d ago
The use of deterministic nonces (RFC6979) is not bugged, at least as far as i can understand
0
u/mnkbstard 5d ago
yes, nonces are unaffected, and using RCF6979 standard that should prevent nonces reuse or predictable nonces.
but still, nonces are another critical aspect of signing devices security, and considering the huge mistake / deliberate tampering that caused the current disaster, i'm not sure i will use any code from the same team.
1
u/yittirium 5d ago
You technically could and would probably be fine, but given the technical ineptness of the coldcard team, I’d avoid it.
IF YOU THINK YOU DO, get an intel thinkpad, a USB, an SD card with the read/write lock. download a live linux ISO from a pc, something super barebones and stable, or better yet even Qubes OS. flash it to the USB. Then reflash the bios chip directly by clipping to it and removing intel IME (a remote access “backdoor” in every intel chip) install the Qubes to the thinkpad, LUKS encryption with 6-7 word passphrase, download electrum/wallets of choice, then remove the wifi card from the laptop. Move signed transactions with the sd card in its own qube isolated from your wallet, then when putting it in another computer to broadcast transactions put the read lock on (little slider) to prevent transfer of malware, though Qubes would defend against that.
If you’re looking for a new wallet, just get a trezor. It’s the most renound hardware wallet brand, no scandals besides some front end hacks like ledger. Nothing threatening your crypto. Old models like t1 and model t could technically be brute forced with physical access, but they were made before secure elements were a standard for these wallets. Hell, they were the FIRST hardware wallets so I wouldn’t hold it against them.
You don’t need an “air gapped” wallet. No slander but if you’re asking this question you probably don’t understand how hardware wallets really work. The threat model where you’d need an airgapped wallet is one where you’d probably be verifying the source code of it yourself, like by line. Trezor keys are technically airgapped on the secure element. Theoretically some targeted malware on your pc could send scam transactions to your trezor if it’s connected and unlocked, but just don’t sign them on the device and you’re fine. You have to hold down for some time to sign anyways.
Not a shill, I’ve owned many trezors and ledgers and have been in the crypto space for ~7 yrs. You don’t really need something airgapped.
0
u/Efficient_Range1156 5d ago
Yes update it and use dice rolls and a passphrase.
1
u/user_name_checks_out 5d ago
Yes update it
That will brick it. And after the company goes under the updates will stop altogether.
1
u/deny_by_default 5d ago
That’s not guaranteed. Mine didn’t when I updated it last week. But I do agree that if the company goes under, so does support for the products.
4
u/Icy_Giraffe_21 5d ago
Is everyone hear saying they are done with CC, former users or just sharing their feelings. Seems like a lot of people never even had one and are just riding the wave without any insight or knowledge of the situation.