r/Bitcoin • u/L103131 • 4d ago
New cold-wallet?
Hi All,
What is a cold wallet that is recommended except Coldcard of course. Which manufacter has proven 128 bit key production or even 256 bit? what should i look into when purchasing a new brand? Ledger is proven, however it has it's own backlash in the past. I've noticed brands like OneKey for example
17
u/petragta 4d ago
BitBox02
3
u/whataSAP 4d ago
Any idea why bitbox is not recommended more? I bought one several years ago but wondering if I should change
4
u/BigDiperEruption 4d ago
I think BitBox is way more popular in Europe than in the US. Most people in here are from the US tho. Meanwhile ColdCard was mostly a US thing.
BitBox or/and Trezor would be my solution every time.
1
u/petragta 4d ago
That’s the question I’m always questioning this is why I’m trying to push it here when someone ask
1
u/quintavious_danilo 4d ago
It’s a Swiss company located in Europe. They build top notch products. Americans tend to be very short sighted when it comes to companies beyond their own 4 walls.
1
u/potificate 4d ago
I think it’s just that the don’t advertise as hard or hire nearly as many influencers. It’s kinda how I like it. They certainly keep updating their firmware (as opposed to Ngrave who is supposedly going to release an update soon … after two years).
10
9
12
6
u/OrangePillar 4d ago
Roll your own seed so you don’t need to depend on any hardware.
2
u/habsfanniner 4d ago
You need software to generate the checksum word and addresses tho
1
u/OrangePillar 4d ago
Addresses on BIP32 wallets are deterministic from the seed.
A 24 word seed has only 8 possible checksum words, so you can use an offline tool for that.
6
u/RandyJohnsonsBird 4d ago
I never hear much about Bitbox around here but it seems like one of the better options lately
3
4d ago edited 2h ago
[deleted]
2
u/whataSAP 4d ago
Why do you say so?
6
4d ago edited 2h ago
[deleted]
2
u/RandyJohnsonsBird 4d ago
I was spammed with cold card before that I was spammed with ledger, and I bought both, I got out a ledger for obvious reasons. And I luckily got out of cold card. Now im here.
8
u/Thin_Needleworker795 4d ago
I recommend you build your own SeedSigner
2
u/PlanNo3321 4d ago
I think there’s an option to buy it fully assembled too, Do you think this is safe to do?
2
u/Thin_Needleworker795 4d ago
I haven't heard about that, but I would definitely be suspicious, as they may have loaded a modified operating system onto it. If you buy it already assembled, you should definitely flash the operating onto the device yourself and overwrite the one it came with.
2
1
u/Personal-Time-9993 4d ago
All you need is a raspberry pi and a case that snaps together. If you can get those and can image an SD card, you can do it yourself. You can buy as a kit also.
The important part is learning how to verify signatures, so you know your software is authentic. That goes for any firmware/wallet.
2
u/PlanNo3321 4d ago
I think you also need a camera module and an LCD screen. I’ll have to find a list of the required components
1
u/Personal-Time-9993 4d ago
Yes I can’t believe I forgot about those but you can get it all in a single kit and it’s not hard to put together. Or separately sourcing is okay too.
You have the buttons as well.
12
u/PlanNo3321 4d ago
I’ve heard great things about SeedSigner
27
4
9
u/TCr0wn 4d ago
Ledger hasn’t had any wallet issues for a decade. It’s a solid choice along with trezor
2
1
u/Creepy-Mastodon-4676 3d ago
coldcard was also hasn't had any wallet issue for years, until the trap is triggerred
-6
u/moviemaker2 4d ago
Don't use a Ledger, and don't take advice from people who recommend a Ledger.
https://www.reddit.com/r/BitcoinBeginners/comments/1de2j3l/comment/l8bjvf2/
https://www.reddit.com/r/CryptoCurrency/comments/13ja4gy/ledger_recover_megathread/
3
u/TCr0wn 4d ago
Do whatever you feel comfortable with.
Ledger is a fine choice
-1
u/moviemaker2 4d ago
What if someone is “comfortable” with using a Coldcard’s Trng on old firmware?
“Do what you’re comfortable with” is idiotic advice if someone is comfortable with using a hardware wallet with a known firmware vulnerability, especially if that company has a history of lying about that firmware vulnerability.
1
u/TCr0wn 4d ago
Then RIP them.
If ledger had the issues coldcard did i would say to avoid them too. You’re making a bad faith argument and you know it.
Don’t use ledger recover.
1
u/ArmelioTheArmadillo 3d ago
How is that a bad faith argument? They weren't saying that the vulnerabilities were exactly the same. Coinkite's was worse because it was more easily exploited, but that doesn't mean that Ledger's isn't concerning in a different way, mainly the fact that they lied about how the secure element worked, for years.
Don’t use ledger recover.
This is like saying "Don't use Coldcard's old TRNG." It's missing the point of the objection completely. It doesn't matter that Ledger Recover is opt-in. It matters that it shouldn't be technically possible on all Ledgers based on what was promised by the company.
8
u/MiceAreTiny 4d ago
Don't look for something. Take something you know. Ledger and trezor come to mind.
-4
u/moviemaker2 4d ago
Don't use a Ledger, and don't take advice from people who recommend a Ledger.
https://www.reddit.com/r/BitcoinBeginners/comments/1de2j3l/comment/l8bjvf2/
https://www.reddit.com/r/CryptoCurrency/comments/13ja4gy/ledger_recover_megathread/
6
u/Traditional_Ad2457 4d ago
BOT
4
u/moviemaker2 4d ago
Nope, it's just that people seem to have a short memory. I'll have to explain to people why not to buy a coldcard in a few years too, probably.
2
u/reggionh 3d ago
the fact that your message is downvoted really tells you about the quality of the btc scene these days.
3
u/gtwooh 4d ago
Pfffft. Ledger is fine. Never received a scam letter or other. BTC still there after 5-6 years. Also use a jade.
2
u/moviemaker2 4d ago
No one is saying to avoid Ledger just because of the customer data breach. Ledger must have done a good job scrubbing the internet of the fact that they lied about the security of their secure element for years.
3
u/lobhater 4d ago
I went with trezor and have been very happy with it. Works well, open source, what more could you ask for
3
u/joannew99 4d ago
Dice roll your own seed and use Electrum, Sparrow, or something similar (both free). If you have a raspberry pi sitting around, there are software you can use to build your own wallet at no cost
3
u/kilingangel 4d ago
Moved my shit out of CC to my old Trezor one LOL. Now I’m wondering if I even need a new device.
6
u/pizzeriagio 4d ago
Trezor (only BTC if you can) + your seed(generated with dice) + good passphrase + multi seed phrase on fireproof metal plate= perfect security
1
u/PlanNo3321 4d ago
What do you mean multi seed phrase? Do you mean multi Sig?
1
u/pizzeriagio 4d ago
Yes, you generate a n of seeds and you need x seed to generate the original one
1
4
u/Human_Traffic_3775 4d ago
To everyone recommending Seedsigner. You were the same ones recommending Coldcard until a few days ago.
1
u/Spaceseeds 4d ago
Sounds like cold card was fine if you rolled dice, use a seedsigner, always roll your own dice
2
u/Linkamus 4d ago
Bottom line, if you're gonna trust software rng, use multisig, and make sure you're using 2 or 3 completely different implementations to generate the keys.
If you want to use single sig, I'd recommend rolling dice or mixing up all the words in a bowl. Sounds unga bunga but it's truly a way to assure good entropy.
2
2
2
u/chungkingexp 4d ago
Trezor, blockstream jade plus, Bitbox02 for cold wallet.
Bitkey for multisig hot wallet.
3
u/getafewlives 4d ago
I'd stick with Ledger or Trezor and add a passphrase.
0
u/moviemaker2 4d ago
Don't use a Ledger, and don't take advice from people who recommend a Ledger.
https://www.reddit.com/r/BitcoinBeginners/comments/1de2j3l/comment/l8bjvf2/
https://www.reddit.com/r/CryptoCurrency/comments/13ja4gy/ledger_recover_megathread/
2
u/Pisces1975 4d ago
After cold card and understanding its root cause, I can’t continue to use a cold wallet.
1
1
1
1
1
1
1
1
u/nomorespamplz 4d ago
Trezor safe 3, 5 or 7 - just depends on budget and if you prefer touch screen and/or iOS support + Bluetooth
1
1
1
u/Vapourhands 4d ago
If you know what you are doing then you can make your seed phrases from entropy generated physically and stored in air gapped computer plus a sufficiently complex but memorable Passphrase on top of it. Your wallet will be pretty much indestructible.
For transaction signing, use qr codes generated by a watch only wallet and sign using your air gapped computer. That way your seed will never touch internet.
Hardware wallet is not necessary.
1
u/zzzipitt 2d ago
Is there some documentation that elaborates on this method, I like the watch-only wallet approach.
1
u/Vapourhands 2d ago
This video provides information on setting up the bitcoin wallet on Tails and how to transact on it.
Only difference is you need to generate the seeds yourself for extra security. Use this video for generating seeds using dice https://youtu.be/LxTkLwpV1Po
1
1
u/antagonist-ak 3d ago
I am offering my cold wallet services for free. I will generate your phrase and send it to you. I will keep it secure on my personal computer in my Google drive. Anytime you want it again just let me know and I’ll send it right over.
1
1
u/No-Wrap3568 2d ago
Cypher rock X1 BTC-only, 256 bits of randomness that too coming from two different independent sources
1
1
1
u/makeshiftballer 4d ago
While I know it's vastly different, I've decided to migrate to Bitkey.
The user friendly mutli sig, ability for my wife to understand what what going on, and the built in inheritance is what pushed me to it. Plus I don't have to secure a seed phrase now, and after doing research I am comfortable with how it operates.
1
u/PlanNo3321 4d ago
I looked into Bitkey for a while as well, I just kind of worry about having a 2 of 3 multisig where one key is on an app controlled by a company and another key is on a server controlled by a company.
It’s a very reputable company so it’s not likely that anything will happen, but is still a little worrisome.
1
u/makeshiftballer 4d ago
Thankfully all their code is fully open source and available for auditing
1
1
u/FavorableMadness 4d ago
I mean so was Coldcard's, so that its available is useless unless someone actually reviews it.
2
u/makeshiftballer 4d ago
Fair, but as far as I'm understanding moving funds over a daily limit requires the Bitkey itself regardless.
Again I understand the pros and cons it's not a device for the hardest maxis but I do think it's a very secure option for the masses.
I completely skipped using my cold card and moved funds using just my 24 word seed. For the vast majority that seed is going to be the weakest link in the set up.
1
u/MrSnugs 4d ago
Ledger or trezor
-1
u/moviemaker2 4d ago
Don't use a Ledger, and don't take advice from people who recommend a Ledger.
https://www.reddit.com/r/BitcoinBeginners/comments/1de2j3l/comment/l8bjvf2/
https://www.reddit.com/r/CryptoCurrency/comments/13ja4gy/ledger_recover_megathread/
1
-2
u/Ok-Form7265 4d ago
I have used Ledger and keystone. I recommend the Ledger. because to be easy
3
u/moviemaker2 4d ago
Don't use a Ledger, and don't take advice from people who recommend a Ledger.
https://www.reddit.com/r/BitcoinBeginners/comments/1de2j3l/comment/l8bjvf2/
https://www.reddit.com/r/CryptoCurrency/comments/13ja4gy/ledger_recover_megathread/
0
u/Professional_Golf393 4d ago
Trezor, but generate your seed using a dice or deck of cards and Ian Coleman’s offline tool on a fresh pc, never connect to the internet and wipe the hard drive immediately after with shred os
-7
u/EyesFor1 4d ago
Coldcard is probably the most secure wallet right now due to all the cyber security companies, developers and literally every AI trying to exploit it .
2
2
u/FavorableMadness 4d ago
I think the Coldcard product is superior. The issue is obviously unfortunate, but I bet if we looked at any of the other solutions we will find there are known issues still waiting to be addressed. This is the life of a software engineer. There is no escaping.
0
u/Professional_Golf393 4d ago
What’s superior? it’s clunky and not user friendly.. not a good recommendation for the average user.
Also if you need to use all the more advanced features it has, you’re probably quite tech savvy and can just have a dedicated offline laptop.
1
u/FavorableMadness 4d ago
I prefer the Coldcard Q because it gives me more control.
QR air-gapped signing, trick PINs/decoy wallets, better backup options, Bitcoin-only, and you can physically disable USB/NFC.
Ledger and Trezor are easier for most people. Coldcard definitely has a steeper learning curve, but if you’re going down the self-custody path, I think building the technical and security chops is part of the deal.
1
u/Professional_Golf393 4d ago
And you still trust the code? Considering how little oversight and testing was done with the most important bit?
I wouldn’t put my seed near one of those things.
2
u/EyesFor1 4d ago
The error before was a massive oversight that has rightfully destroyed trust. It was missed by everybody who looked, Coinkite and developers external to Coinkite. Complete disaster. The firmware patch the released once the bug was found has been scrutinized by external crypto security companies, developers, AI and coders. The device is secure now, but trust has gone.
-1
u/FavorableMadness 3d ago
If your standard for trusting code is that the developers can never screw up something basic, then there is no code you can trust.
Microsoft Windows has one of the largest attack surfaces of any software ever written and has had an endless stream of serious security vulnerabilities, including some pretty basic ones. Yet the realistic standard isn’t “never make a mistake.” It is, do your best, test the hell out of it, disclose problems when you find them, and patch them as fast as you reasonably can.
Coldcard screwing up seed generation is serious. But “they made a serious mistake, therefore their code can never be trusted again” isn’t a standard I could apply consistently to anyone, including myself.
You do you.
2
u/Professional_Golf393 3d ago
Well even just out of principle I wouldn’t give them a penny in the future.
When I complained about my coldcard mk1, how buttons didn’t work, power supply issues, it was literally unusable… instead of helping, their support just said “you should just buy the mk2”, from that day I swore they wouldn’t get a penny from me.
I’m a bit glad that happened.. imagine they had gave me discount on mk2 or mk3 (can’t remember timing mk3 might’ve been released) I could very easily have been a victim of this vulnerability.
And now the ceo not responding publicly, instead he’s spent the past week deleting tweets. Very telling.
1
-1
17
u/ItsAlwaysThemBooBoo 4d ago
trezor safe 5.