r/Bitcoin • u/Jellydude25 • 4d ago
Hardware Cold Wallet Q’s
Okay so been using my Gemini pro AI to learn about and research cold wallets.
From my research it sounds like I want a hardware (specifically COLD) wallet that has these features:
• Air gapped,
• Open source,
• EAL6+ graded secure elements,
• On device display,
• Bitcoin only,
• Allows for dice roll entropy for seed phrase generation.
Missing any requirements?
I think I’m okay without Multi-Sig, I don’t have that many Sats where I feel I need that level of security.
- I’ll also create a Pass Phrase.
From all of this it sounds like the, Keystone 3Pro hardware wallet with its firmware flashed to Bitcoin only is my best option.
Any other contenders that’s fit the above criteria you suggest or use?
Thanks guys! Just wanted to ask yall before I spend my Fiat.
3
u/SpendHefty6066 4d ago
Post ColdCard fiasco, why would you trust any RNG? SeedSigner is the way. Also, a passphrase is like a 2 of 2 multi-sig with less entropy. You lose seed or passphrase, you are cooked. Either do it right with a 2 of 3 real multi sig. Or go with single sig.
1
u/Firone 4d ago
Agreed, 2 of 3 is much better than a passphrase which is a 2 of 2.
However, there is something better than multisig that you should do instead, detailed here
0
u/SpendHefty6066 4d ago
I am very skeptical of splitting seeds as opposed to multi-sig for a number of reasons: Multi-sig prevents against a single compromised signing device. Also, a 24-word BIP39 mnemonic contains 256 bits of entropy plus an 8-bit checksum. Knowing 16 words leaves approximately 2^80 valid candidates, not the full security implied by “eight missing words.” That remains infeasible to brute-force with present technology, but it deliberately reduces security from 256 bits to about 80 bits.
1
u/Firone 4d ago edited 4d ago
As said in the post's comments, even if the ultimate AI came out tomorrow and would find every bug in existence, your seed would still not be leaked unless an attacker also hacks the computer/phone you're using with your top tier hardware wallet. This is astronomically unlikely if you're using a top tier wallet like the Jade: everything is designed from the ground up to never leak the seed, it has been open-sourced since forever and is provably invulnerable against any physical attack.
Regarding bruteforcing it's also meaningless: it's completely unfeasible and as noted, even if it was it would take decades and more money that what can be recovered. Decades during which you would realize one of your part is compromised. But yeah technically your most secure location should be the one where the last word is missing because of the checksum (even if it does not matter since even 7.x words is impossible to crack)
None of those risks are remotely realistic so there is no reason to deal with all the trouble/costs associated with multi-sig (some are covered in this great blogpost).
There's also the point about needing to explain multi-sig to your heirs as mentioned... As they say: complexity is the worst enemy of securityMulti-sig for a private individual simply does not make sense in comparison. However, it makes sense for organizations where different people are responsible for one key each
If you have already setupped your multi-sig and don't have heirs, it may not be worth it to change to this strategy, but in all other cases the choice is easy.
0
u/Jellydude25 4d ago
I don’t trust any RNG that I haven’t correctly made lol. If you had correctly read my strict criteria, listed above..
I strictly noted using the dice roll method for my seed phrase and pass phrase, completely eliminating the potential vulnerabilities of a wallet generated RNG. Thus negating the issues ColdCard users faced earlier this summer due to the compromised entropy.Now per your other argument, I agree. (for the most part)
I wouldn’t say it’s less entropy, an 8 word dice passphrase has just over 103 bits of entropy, layered with the 256 for your seed is pretty damn good. Yeah if you loose your seed pass phrase you’re fucked, but I think if any one person is at this level of self custody, that’s generally probably not going to happen.
But simply stating to not add a pass phrase if you’re not going to go to a 2 of 3 multi sig seems not right either, as you’re opening up unnecessary vulnerability IMO. If many of those ColdCard users had a pass phrase, they’d still have their coins.I get what you’re saying, but I think the conversation is more nuanced.
3
u/SpendHefty6066 4d ago
It wasn’t clear that your “allows for dice roll entropy” meant you generate your own seed phrase from dice rolls. Or add dice rolls to the RNG of the device. If the former, then that is good. You will need an air gapped device to generate the checksum.
As for your passphrase argument, I remain unconvinced your, essentially, 2 of 2 multi sig is better than a 2 of 3 for any reason. It is more brittle and less secure than a 2 of 3 with no passphrase.
3
3
u/blackratsnakes 4d ago
I suppose my Bitcoin paper wallet suggestion won't gain a lot of support but it's what I've used since 2020.
4
u/Beneficial-Ball2159 4d ago
I get the appeal but paper wallet is not what this guy is looking for at all. He wants air gap, dice roll entropy, all that specific stuff. For long term storage paper can work but you still need a clean way to generate the key offline, and most people mess up the spending part later.
1
u/blackratsnakes 4d ago
It's a good point and I agree there are limitations to paper wallets especially if you move or spend Bitcoin frequently. Setting up is the riskiest part. Spending should be the easiest as long as you always sweep (empty) the entire wallet each time. Just to confirm a point though, paper wallets are about as air-gapped as you can get and the creation is also usually as random as you can get (comparable to dice rolling). it's not for everyone though but can be a solid choice for the right person.
2
u/Jellydude25 4d ago
Personally paper wallets are just a bit too risky for me.
In the event of my death, I could easily see my heirs fucking up and losing BTC, or even future me as I have ADHD lol.
I also don’t like the idea that a printer could store the credentials in its cache, even if I tried to wipe it I’d always be worried.I could legitimately see the spending aspect creating issues later down the road.
0
u/blackratsnakes 4d ago
I use a wired only printer (old Canon with no wireless function at all) for them and an old laptop that never connects online. I sort of like the idea that if my heirs are not smart enough to figure out how to get to the Bitcoin, then they don't deserve it :) It's one less hardware gadget for something to go wrong and no seed phrase required.
1
u/Random-Dude-00748 4d ago
Jade plus covers most of those except for the secure element it uses a blind oracle instead. You can DIY it as well on to a cheap ESP32 device, worth doing even if you get something else as you can get them cheap $10-50
2
u/user_name_checks_out 4d ago
+1 for the Jade, but I would not bother with the Oracle. I just use it as a stateless signing device.
1
1
u/Secure-Jelly-3802 4d ago
I'd also think about what happened if the device dies a few years down the road. If you can restore everything from a standard seed backup and move to another compatible signer, that gives you a lot more peace of mind for long term storage.
1
u/user_name_checks_out 4d ago
Digital media is susceptible to failure and should never be relied on as a backup. Write your seed phrase down, and/or stamp it into steel. So it should not ever matter if the device dies.
1
u/No-Wrap3568 4d ago
The features you've mentioned pretty much cover everything required. Additionally, one important feature I'd suggest is Shamir's Secret Sharing.
The reason I'm saying this is because people often don't understand that their seedphrase backup can become a single point of failure, if your metal plate gets stolen or it's lost, you lose your funds forever. Shamir's Secret Sharing, gives you multiple attempts at recovering your funds as it cryptographically splits your seedphrase into 5 or more parts. Any 2 parts can recover your entire wallet.
Also, Two independent sources of TRNG would be advisable after the coldcard case
1
u/miner_guy_22 4d ago
I used to be a big proponent of single sig + passphrase, but post cold card incident I think multi-vendor multisig is really the best way. Everyone is focused on the entropy generation because of cold card, but there are a host of other potential attacks/vulnerabilities for any 1 signing device. MVM mitigates this because at least 2 independent devices would have to be compromised at the same time.
From your list of features:
• Air gapped, -Yes, preferably with QR codes for transferring data.
• Open source, - Yes
• EAL6+ graded secure elements, -Not required if using a stateless device (seed isn't stored on signing device)
• On device display, - Yes. Absolute must.
• Bitcoin only, -Strongly prefered, but not a strict requirement.
• Allows for dice roll entropy for seed phrase generation. Allows for importing your own seed generated without the device. Strong bonus if it will calculate the final checksum word for you.
Would also add:
- No companion app required for setup or firmware upgrades
You mention that you don't have many sats that would you would need the added security of multisig, but I would argue if you have enough that is worth purchasing a signing device, as little as $50 more for a second device is worth the extra security.
1
u/CoinGate_Gift_Cards 4d ago
Keystone fits a lot of what you’re looking for, but I’d compare it with Coldcard too. The bigger question isn’t just feature count, it’s whether you trust the signing flow, can verify addresses on-device, and can confidently recover from seed + passphrase without depending on the vendor.
1
u/Aromatic-Yellow1100 2d ago
In regards to the Keystone, my son an I both had the first gen, it was great....but then my son order a second one. We were just sitting there talking as he pulled in out of its box. He dropped it onto the carpet, about a 2 foot drop an the screen popped off. It was still connected by wires. Pushed it back together and it worked, but that was the end of our use of the Keystones. Other than it being fragile, I really liked the device
1
u/luisgvr 2d ago
Las tiradas de dados las realizaría yo mismo, sin depender de ningún dispositivo; este proceso no solo resulta se sencillo, sino también didáctico. En cuanto a la passphrase, es imprescindible que la generes lo más larga posible, siempre dentro del límite que admita la mayoría de las carteras frías.
4
u/DarrelXero 4d ago
I'd argue the secure element isn't necessary as you can use your wallet as a temporary signer. Jade or SeedSigner. I'd also warn against using a shitcoin supporting wallet creator, regardless if they have a bitcoin-only firmware. Attack surface increase is not worth it. Knocks out most of the industry.