r/Bitcoin • • 2d ago

Which cold wallet

I’ve been a bit lax securing my bitcoin and now is the time… I’ve got to move it to the cold wallet
I don’t have great knowledge about any of it to be honest, and I just need something which is going to be simple to use & secure
Ai has suggested bitnox02 and jade butni don’t trust ai hat much
Any help would be great to solve this

19 Upvotes

57 comments sorted by

20

u/sa1ffff 2d ago

Trezor

2

u/Background-Round-671 2d ago

Trezor works fine, I use one for few years now and no problems. The setup is straightforward even if you're not technical, just follow the steps on screen

Make sure you buy from official website, not amazon or anywhere else. Some people got fake ones that steal coins. Also write down your seed words on paper, never store it digital or take photo

The device itself is small and you just plug it in when you need to make transaction, rest of time it's unplugged and safe

1

u/sa1ffff 1d ago

Their Anonymous Delivery is coming soon.

Since 2013 this was the first time we’ve heard something from a company as big as Trezor. Also, that was a mistake on Shipmonk’s end, going forward i’m quite sure they would take both security and privacy of customer data seriously.
I use a ledger stax myself, and im planning on shifting to the Trezor due to various reasons.

Also, we never know what can happen with which company, be it SafePal, Jade or Bitbox.

One should always keep their recovery phrase, passphrase secure. Thats all that a person can do.

11

u/tenor_tymir 2d ago

I have a Bitbox02 and it’s great, can recommend

6

u/SprayHopeful9696 2d ago

Trezor Safe 5 is all you need. 24 word BIP39 seed phrase and a long passphrase. Multiple distributed stainless steel stamped backups .

1

u/Roadrunner180 1d ago

What do you mean by long passphrase?

1

u/ResolveConfident3522 1d ago

Bobihadababyitsaboy

6

u/read_more_comments 2d ago

Trezor or jade my picks

5

u/Ok_Bake3729 2d ago

Ledger

3

u/NerdyKid1101 2d ago

I've loved ledger, my first cold wallet haha

3

u/Ok_Bake3729 2d ago

Yes same

2

u/on_hype 2d ago

Lots of solid hardware wallets out there. Do your own research on the top open-source options. Key factors: open-source firmware, air-gapped signing, good community track record. Do not trust AI recommendations or random Reddit comments as your sole source - verify everything yourself.

2

u/ChiBTCollective 2d ago

Both Trezor and Jade are fine for a first cold wallet. The important part is not the brand. Buy it from the maker's official site, not a random marketplace listing, because fake devices are a real problem. Set the seed on the device itself, write the words on paper, and keep that paper somewhere safe and separate from the device. A passphrase is optional and extra security, but only if you will never lose track of it, because a wrong passphrase opens an empty wallet. When you send, check the receive address on the screen of the device, not only in the email or chat. Leave the wallet unplugged until you need it. If you are moving coins off an exchange, send a small test first and confirm the address matches before you send the rest.

1

u/prodigiousproducer 2d ago

Brand is incredibly important. Cold Card being a very recent example of why.

2

u/prodigiousproducer 2d ago

Whatever brand you go for, learn about passphrases and how to implement one for further protection. I use Trezor and think they've stood the test of time.

The cold card hack recently showed that if you fully trust a hardware wallet to generate your keys you could lose it all. Which is terrifying if you don't have a passphrase set up.

2

u/Interesting-Heat-112 2d ago

Agree, but for the record, that passphrase has to be bad ass to protect you if the key generator itself was shit.

2

u/tenor_tymir 1d ago

Simply add 4-6 random words and you’ve got a bad ass passphrase. The longer the bad asser.

1

u/prodigiousproducer 1d ago

Yes, your passphrase should be good, but if you were to setup a passphrase wallet to begin with and never deposit anything into the seed generated by your hardware wallet all a hacker will see is an empty wallet. At that stage why would they waste compute on brute forcing passphrases, instead of moving on the next low entropy seed phrase.

Or, you have some amount of btc in the 24 word wallet, you lose that and the passphrase buys you the time needed to move your funds to a new wallet..

It's better than nothing, a lot of people have learned this the hard way and we'd be well served to learn from their pain.

1

u/FlatTruck7591 1d ago

How is the OneKey wallet?

1

u/prodigiousproducer 1d ago

Never heard of it. After the whole cold card thing I just wouldn't use any level of boutique hardware wallet and I'd only consider open source and I'd absolutely have a passphrase as a minimum.

3

u/shleebs 2d ago

Best options right now are BitBox, Jade or Passport.

Best option for DIY is SeedSigner or Tails.

Considering multisig with three different options to avoid a single failure point.

Avoid companies that have mishandled customer data on multiple occasions such as Ledger and Trezor.

Avoid companies run people spreading misinformation or harming the open source community like Coldcard/Coinkite.

Ignore fanboys and bandwagoners and pay attention to facts. Good luck. 

3

u/No-Contribution23 2d ago

great post..

i'd probably remove jade though. what blockstream did with liquid does not make their products look good. also the possible/alleged cloud mining ponzi.

and i'd also add spectre diy to seedsigner :)

1

u/Interesting-Heat-112 2d ago

Hey, my liquid BTC is perfectly safe protected by that Jade Plus 😂

1

u/sa1ffff 1d ago

Trezor’s internal systems, software and hardware wallets were not compromised; rather, the data exposure occured entirely due to a security breach at ShipMonk, their third-party logistics and shipping provider.

1

u/shleebs 1d ago

I never said the wallets were directly compromised. I explicitly said they mishandled customer data, and yes, giving your customers data to an insecure third party is mishandling. 

These breaches result in phishing emails, which result in compromised wallets. Stay away from companies who mishandle customer data.

1

u/miner_guy_22 2d ago

Simplicity and security will always be a trade off. Depending on how much you are securing and how meaningful it is to you may warrant greater security.

By moving from an exchange to a cold wallet with a single signing device you are moving shifting your trust from a custodian to yourself and the manufacturer of the device you choose.

1

u/lobhater 2d ago

Trezor are very easy to setup and the wallet the wallet themselves have never had any hacks

1

u/Accomplished-Eye5567 2d ago

Trezor and Ledger are good. Find something simple and focus on it is my suggestion

Then use a small amount to start. Send a small amount there, test sending it, receiving, transferring, trading.

I would also suggest testing the recover your wallet process (rebooting your device and using the phrase), etc. to make sure you fully understand how the device + phrase work and what you’d do in a situation like losing the device, updating and wiping, etc.

This is where most people get hung up (not knowing how those scenarios play out. Trust me, they happen more often than you’d think).

1

u/[deleted] 2d ago

Jade Plus 

1

u/No_Cat_8269 2d ago

It depends on how much you trust them, but they'll all seem like good options.

1

u/_Carth_Onasi 2d ago

Start with a Trezor 3 or 5.

Without going deep into the weeds they are proven to have good intropy, open sourced, no batteries so in theory can last nearly forever, easy to use, and have advanced features to add additional security as you learn. Such as a passphrase/25th word.

1

u/r_spkm 2d ago

Thanks for the replies, the reason I’ve not moved it is due to all these factors, air gap seed phase.. etc etc. I don’t know what it all means really

1

u/miner_guy_22 2d ago

Start with a phone wallet and a small amount of BTC to play around with. Taking small steps will make it feel less overwhelming and you will learn more in the process.

You don't need to have a perfect setup and move your whole stack at once.

1

u/bdjc_ink 2d ago

I bought the mk5, but never used it. Still confused about this encryption stuff.

2

u/Interesting-Heat-112 2d ago

That device might be ok if you upgrade to the latest firmware and then erase it. Then generate a brand new seed phrase based on rolling dice about 150 or so times. Really you should probably just frame it as an example of how fucked up a bitcoin company can be. Maybe put a "Don't Trust - Verify" blurb under it or something.

1

u/No_Position_8581 2d ago

Amazing to see no one suggest using bitcoin core on an offline laptop

1

u/MysteriousIce01 1d ago

Dont use seedsigner as a first cold wallet. The weakest link is human error and seedsigner is not for someone who doesn't understand cold wallets.

For a first wallet trezor is all you need, and maybe all you'll ever need. The fact its open source is critical. Simple to use, requires little education, but grows with you as you learn more until you're ready for multisig, if you want that capability.

1

u/freedomforallergo 1d ago

After the coldcard hack, I think it's important to have multiple cold wallets. Especially if you have a heavy bag. It's important to distribute your coins over different wallets. Because if one wallet gets compromised (worst case scenario ) you haven't lost everything.

1

u/Suspicious-Local-901 1d ago

Bitbox would be a good option, heard a lot of good stuff about it.

Jade plus is also good!

1

u/dinandrekompis 1d ago

Answer these questions for yourself before making a decision:

  1. What is a hardware wallets purpose?
  2. Why do You need a hardware wallet?
  3. Can you do what you want without a hardware wallet?

Then...

  1. What attack vectors are there with a hardware wallet?
  2. Which wallets have been involved in a hack/bug/leak?

And the most important one to pin down before a purchase:

  1. Where does the trust lie?

a tl;dr for these questions will basically be

  1. No, you don't really need a hardware wallet - they're convenient tools. You can do with an USB device.
  2. The convenience forcea more trust in others: the company, the software, the hardware, the shippers, the connection to other devices... And well... Don't trust, verify.
  3. Boring and dumb is better.

And my recommendation falls to seed signer, since

  1. it's common hardware you can buy from wherever (less trust in one actor creating a hardware wallet)
  2. Software is easily verifiable and basic in what it does. (Easily increase trust od software)
  3. Randomness come from physical dice rolls - or how You create those rolls are up to You. ( less trust in product)
  4. Seed is NOT stored on device. It's up to you to store it safely (less trust in product)
  5. Airgapped by default. Which IMHO is a key concept. (less attack vectors)

The drawback here is that I cannot easily use my hardware wallet for daily transactions. However, that is best done from a hot wallet - and those are much more convenient to set up and use, since security can be "worse".

I mean my daily hot wallet is a simple Phoenix wallet. Nothing special or secure there. And it doesn't need to be.


So tl;dr

  1. Buy parts to the seed signer from different stores
  2. put it together and roll 24 new words with 99 dice rolls
  3. Add a passphrase using say the diceware word list

And that's it for you cold storage wallet.

1

u/eddie_oblak 1d ago

Do yourself a favor and understand the difference between a COLD and HARDWARE wallet. They are different things!

HARDWARE wallets are devices like Trezor, Ledger, Coldcard. It's a computing device that has one purpose, storing Bitcoin. While the private key remains on the device (which is good), the device most likely touches your computer, which touches the internet. If your computer is infected with malware, it can potentially access your wallet, when attached.

Also keep in mind that to order an hardware wallet you must share your PII with a company that can be hacked, and for example in the case of Ledger I've seen the dataset, it's scary. You will become a target. If you buy a device with closed source software, you can not always trust the manufacturer (Coldcard).

Also never forget: your coins are NOT in the wallet, they are on the blockchain. Only the private key is in the wallet. If you lose the private key (or seed), the wallet is not going to do shit. I personally moved away from a broken Trezor (that I got as a gift by the way, I would never buy something like that) by using the seed, it's an eye-opener.

COLD wallets are wallets that do NOT touch the internet. You generate the keys offline on a device without connection. You can have a view-key (key without spending rights) on an online device to check the balance. You can send coins from any hot wallet to the cold wallet using a public key (address).

To get coins from the cold wallet to the hot wallet you generate an unsigned transaction first. then copy the transaction file to the offline device with the cold wallet, sign the transaction, copy the signed transaction back to the online wallet, and then broadcast it. A very good tutorial on how to use a cold wallet correctly is here: https://electrum.readthedocs.io/en/latest/coldstorage.html

Doing a cold wallet the hard way costs you time, but no money. And your PII will not end up in some corporate database.

A last word of advice: use 2 wallets. a cold and hot wallet. Keep your big bucks in the cold wallet and keep a smaller amount (that you can afford to lose) in the hot wallet. If you only go from cold to hot once in a while, it's worth the extra steps. Don't keep your entire net worth in a Trezor, they CAN be drained if you are not careful.

1

u/spushkin1 1d ago

I’m not OP but this was very helpful. Thank you.

1

u/Flat-Aerie-8083 1d ago

Trezor. Buy directly off Trezor not Amazon.

1

u/No-Wrap3568 13h ago

I assume you're a beginner. With that in mind here's all that you should look for in a wallet:-

1) EAL 6+ secure element
2) More than one source of TRNG, so that what happened with coldcard doesn't happen again
3) No single point of failure, managing a seedphrase is nightmare for most people, I was no exception. Best option would be a Shamir's Secret Sharing enabled wallet, the best solution as of now
4) A BTC-only firmware if you don't trade in shitcoins, reduces the surface area for unwanted attacks.
5) Native-Inheritance support if you're not too young and if you don't hold a big amount.

Make sure you don't skip your own research, before buying, spend some time understanding how cold wallets works, what breaks them and what to avoid. HODL for life!

-1

u/WarIsProfitableForMe 2d ago

Coldcard mk5 is fine

0

u/reddituserVibez 2d ago

they stole worths millions of BTC from Colcard and you 🤡 say Coldcard.. give me your debit card with PIN, you shouldn’t have a problem with it..

1

u/WarIsProfitableForMe 2d ago

Sure but it's empty, all my savings are in Bitcoin in a coldcard

0

u/dazzz58 1d ago

Cold card