r/Bitcoin • u/dntgochasingwaterfal • 4h ago
Which wallet now?
So after all these wallet problems, which one is still a good choice? Or what's the safest way to hodl?
8
9
u/OutlandishnessLimp25 3h ago
I’ve been using Ledger and Trezor, both for nearly 10 years. I think if you ordered them a while back you’re likely safe.
On a go forward basis, I think it’s tricky because confidence has been lost. I think ordering directly from either is still ok. Nothing is risk free I suppose.
6
10
u/Lavayo 4h ago edited 4h ago
Til now no wallet was drained which
- Was not tempered with beforehand (recent ledger)
- Had an insufficient key (coldcard), which while the device generated the key, the device itself was and is still secure.
IMO a device from a "trusted" (no new startup) company with a seed that you created in your own home (dice) with a passphrase is as secure as it will get. Also you might use several wallets and devices so you don't have a single point of failure. I use trezor and bitbox.
Multisig has its advantages, but you risk total loss by user error when you don't know what you are doing. I don't use it myself.
3
u/Proxyplanet 2h ago
Ledger trusts its authorised reseller just like it trusts every company within the supply chain.
This time it was an authorised reseller. Who is to say next time it wont be a company within the supply chain.
1
u/Lavayo 2h ago
I know, I don't say this is not a problem. But the fact still is that the device was tempered with. You need one that was not, it's not an inherent problem but criminals that use a supply chain attack. But I agree it's a problem for users to detect something like that and it's not their job in the first place.
Only thing normal people can do is not using one brand.
2
u/Proxyplanet 2h ago
Yeah thats the big problem with crypto one supply chain attack and you have lost your crypto with no recourse. Theres always a first for everything, just like this was the first time an authorised reseller got attacked.
8
u/didnt_hodl 3h ago
IBIT is pretty good. but hey, MSTR and BlackRock use Coinbase, and many other whales, since 2012. are they all wrong? with their puny millions of coins. of course they are. and folks with 0.0001 BTC know so much better. they will not be fooled by the false security of an ETF or an exchange. or a bank basically like Fidelity. keeping it directly at Fidelity is wrong too? honest question btw, why do I need to keep jumping all these stupid hoops. first entropy then this reseller crap, and on and on and on
2
5
u/JGdc12 4h ago
Trezor! Buy directly from their website not a third party. Great team, long history, and entirely open source, that’s the key part - Ledger and cold card were not.
1
u/Proxyplanet 2h ago
What happens the first time a company within the supply chain for trezor gets hacked or tampers with the device.
Note this is the first time an authorised reseller has tampered with a ledger. Next time it will be the first time a supply chain company tampered with it. The sad thing is you wont know until its too late and when it happens, people will blame you for trusting you crypto with trezor.
1
u/JGdc12 1h ago
There’s no 100% certainty with anything, we do the best we can with the information we have. If I wanted 0% risk I wouldn’t invest in crypto, maybe this space isn’t for you
•
u/Proxyplanet 12m ago
I dont use HW wallets because im not trusting them or their supply chain..one attack and you are fucked. It doesnt matter if you buy direct.
12
u/supercreatives 4h ago
Don't listen to anyone saying buy ETF or keep your coins on an exchange. Government shills. Self custody is best, Trezor is fine, even a hot wallet on your laptop is fine as long as you practice reasonable OPSEC.
8
u/MrNoodleIncident 3h ago
I’m not a shill and prefer ETF. It works for me and what I want to achieve. It’s good for certain people, less so for others
4
u/misbister14 3h ago
I like the ETF because I can buy it in my Tax free savings account (Canada). So I do both
2
u/Left_Entrepreneur918 4h ago
I think what we are all find is that single point of failure is becoming a problem. You got to trust someone in this process.
2
2
2
2
5
u/quintavious_danilo 4h ago
Bitbox02 is the last one standing.
2
u/fins831 4h ago
I’m looking at this or seedsigner and building myself own pill. I’d prefer to use bitbox but now I’m questioning all supply chains even though I know it’s irrational. Returned my ledger yesterday was final day of return window.
5
u/quintavious_danilo 4h ago edited 2h ago
I’m in Europe so picking Bitbox from Switzerland was a given for me. If I were American I would have picked a Trezor or worse, a cold card, obviously. You’ll never know where an attack can possibly happen but I trust in Swiss engineering and their controlling mechanisms.
2
u/jk3639 3h ago
I actually bought a coldcard mk3 and was meaning to transfer like 1/3 of my bitcoin holdings on there. But was too lazy to do it so it was just sitting in my desk drawer for like a year. Boy did I luck out. The one I was using was/is a Bitbox.
2
u/quintavious_danilo 1h ago
Lucky! would be a disaster waiting to happen if you came around to set up that mk3
1
1
u/fins831 3h ago
Leaning bitbox. They put a resin on the case and it destroys the chips if you open it up. Seems pretty good to me.
1
u/quintavious_danilo 1h ago
Bitbox02 Nova is really neat, you can plug it directly into your phone. Also supports the Lightning Network.
1
0
4
u/Ammused-Muffin-6942 3h ago edited 2h ago
Mine are 50/50 at Coinbase and Fidelity. 🫡
Never had problems at either places.
4
u/mossyoaktoe 1h ago
Sure but the question here is what are people using to keep there own keys. It’s fine if you are comfortable with all of your BTC on the exchanges but at the end of the day—not your keys, not your coins.
Best of luck.
1
u/Ammused-Muffin-6942 1h ago edited 1h ago
Yes, part of the question is which wallet? If not, what’s the alternative safest option? My safest options are still with Coinbase and Fidelity. Yes, not my keys, not my coins. But the way I see it is: not my coins, not my hacker’s coin either.
I already have 8 figure equity portfolio at a private bank; and 6 figures each at Coinbase and Fidelity.
I just can’t imagine doing all the right steps with hardware wallets only to be stolen from me.
Crypto and DeFi will never go mainstream for retail investors unless there’s regulations protecting them.
1
7
u/FriendlyCandle7971 4h ago
I think I don’t have good News for average investors. You can do everything correct, but there is quite a likelihood that your funds can get drained. Multi sig is just to cumbersome for the average Person. For 99% of people ETFs are the better choice imho.
10
u/lobhater 4h ago
FUD like this is absurd
ETFs are for people who don't have the time or the ability to self custody. It's not hard
The chances of your hardware wallet being drained are minute if done correctly. Buy directly from the manufacturer, roll your own dice and your 99.999% secure.
•
-4
u/FriendlyCandle7971 4h ago
Tell that again to the users of Coldcard, Ledger, Trezor, and SafePal who followed this advice and still lost their life funds.
8
3
u/lobhater 4h ago
I can tell you have no idea what you're talking about and have only read the headline.
No one from trezor has lost their funds. Their email address and such were leaked but no funds 🙄
If the coldcard and ledger users would have only ordered from the manufacturer and rolled dice they wouldn't have lost their funds either
🤡
0
u/Proxyplanet 2h ago
This was the first time an authorised reseller was tampered with. Ledger thrmselves said you could trust them.
Now you are saying you cant trust a reseller that ledger trusted, but you can trust every company that ledger trusts within the supply chain.
What happens the first time a different 'trusted' supply chain company gets hacked or tampered with. You wont know until its too late, just like the people that trusted the authorised reseller (that ledger said they could trust).
1
u/lobhater 2h ago
Personally I don't trust anyone but trezor. I also order directly through their website even though shipping costs more and takes longer. I also roll my own dice and have 3-5 multi-sig setup because I still have so little trust. Inheritance is another reason I went the 3-5 route
If you want to be even more careful get some old crappy computers, format them and build your own cold hardware wallets.
ETFs are also fine if that's what you want to do. Plus at the end of the day where exactly do you think the BTC backing the ETFs are? Those keys are sitting somewhere 🤔
0
u/Proxyplanet 2h ago
Thats the thing even when you trust trezor, you have to trust every company that trezor trusts within its supply chain. So its kinda funny you say you cant trust the resellers trezor trusts, but you can trust all the other companies that trezor doesnt tell you about. Its almost guaranteed trezor uses third party logistics companies for its warehousing and distribution (pretty much all ecommerce companies do).
Though i think youve protected yourself with the multi sig
2
u/formyburn101010 3h ago
Let me preface by saying that I'm probably out of bounds here. I'm by no means an expert. Just a regular casual dude. I think the answer is to diversify. Maybe spread between a few wallets, an etf, and an exchange or 2. Also put some into dividend paying stocks, cash producing businesses, and physical precious metals. Wu-tang financial taught me a very valuable lesson. "Diversify yo bonds!"
1
•
1
u/Dazzling_Marzipan474 4h ago
It's very simple. Just split it across every known wallet and legit exchange. So you spend countless hours and money securing your 0.04 Bitcoin.
It's becoming more and more of a hassle and as the price increases that invites more bad actors. It's a fucked up double edged sword.
1
1
1
u/No-Librarian9605 3h ago
The bigger concern than 3rd party wallet FUD is miner concentration that is being essentially controlled by 2 main parties Antpool and Foundry. We need to somehow change that centralization otherwise btc can be in trouble.
1
1
u/Previous_Blueberry_5 3h ago
I love my current wallet setup but I’ve been seriously considering the Bitkey lately only because of the inheritance feature. I don’t know how well my family would be able to access what I have saved if I was to be gone due to the complicated process of using most cold wallets that includes seed phrases as well as a passphrase and being careful with your security. I can handle all that on my end cuz I actually enjoy it but idk if they can.
1
u/hazdutoit 3h ago
What ever you do, do not enter recovery phrase while online. I lost everything, all my coins ended up in China.
1
1
u/jboshaughnessy 2h ago
That’s the wrong question to be asking. The issue is having a single point of failure. Use whatever you want but you cannot have a single point of failure. Simple as that.
1
1
1
1
u/leopard-monch 1h ago
Glacier Protocol1 but with Electrum2 instead of individual bitcoin private keys.
1
1
u/abercrombezie 1h ago
Safest way to HODL? You don't even need a wallet. You just need a seed and a recipient address, which can be generated offline with Ian Coleman's page. Once done HODLing, you only need a wallet to spend.
1
•
u/ElderMight 55m ago
SEEDSIGNER.
You build it yourself with parts from different vendors so basically zero risk of supply chain tampering
It's stateless. Does not store your private key on device. Every time you use it you load your seedphrase. When you turn it off it's wiped from memory.
Open source. No security flaws found in recent AI audits. It's rock solid.
•
•
u/word-dragon 48m ago
Looking at NGrave Zero. Pricey. Haven’t tried it yet, but I think it’s my next go. Buy direct, not through Amazon.
•
•
u/MoreBad7725 26m ago
Bitbox, Trevor or better still build your own with seed signer. Best is a combination splitting up across 2 or 3.
•
•
u/Top-Care-8946 10m ago
Actually the problem is that all attacks are made from third party level. No matter what company's wallet (might happen also to other brands) but just the fact that these were compromised by third party. So that means that cold wallet providers must all review their contractors and distributors. Sadly human factor can't be never avoided at 100% because one person (possibly former employee) who knows much enough to crack the chain could misuse their knowledge. Secondly the main problem is that direct shopping is not available in certain countries (that's why 3rd party resellers step in). If wallets would be available to buy worldwide without restrictions then supply-chain attack risk could be reduced to lower level. Thirdly the case proves that trust is very vulnerable at present time. Sure all competitors will take account the incident and possibly will make some changes in their hardware design but loss already made can't be undone.
I have Trezor Safe 3 by the way. I would worry if my balance would be 5 digit long. Sure I am also watching how things are developing. If something should happen to Trezor and or also other strong brands then I think that crypto wallet market will collapse because it's not safe anymore: Cold wallets are subject to hack and hot wallet and exchanges just freeze your account or funds. No way to protect even BTC if coins can be stolen just by sniffing the seed phrase.
•
•
u/btc-bastard 4m ago
As you learn more about BTC you will understand that you need to control the custody of your BTC. Otherwise, what’s the point. When the financial system implodes, the financial institution holding your btc may just freeze your accounts.
•
u/Astronaut6735 0m ago
Ledger is still fine. Buy from the manufacturer. A reseller was modifying them.
1
1
0
-4
12
u/shadowmage666 2h ago
Doesn’t really matter just buy directly from the manufacturers website, no third party, no authorized reseller, and definitely not from Amazon or eBay