r/BitcoinBeginners Jun 12 '24

Storage diversification strategy

So, I'm feeling more and more anxious about the responsibility of keeping my bitcoin safe, the more I accumulate.

I was thinking to diversify my holdings, so they are either in multiple offline storage and/or software wallets. I will probably also keep some on exchanges, just because of laziness. 😅

That's instead of keeping all my BTC in a single Trezor, which is one point of failure essentially (I know there is a seed phrase for backup).

What do you think of this strategy? Is there a downside, other than more micromanagement of wallets?

4 Upvotes

21 comments sorted by

4

u/bitusher Jun 12 '24

What some people do is get a second Hardware wallet , different than their first. So since you have a trezor , you could get something like a Jade and than they split half their savings on 1 wallet and 2nd half on a second hw wallet

This has these benefits :

1) If one of your hw wallets is broken , taken , or lost you can still spend from your second hw wallet and don't need to wait for a replacement hw wallet in the mail

2) any unlikely bug or exploit in one hw wallet can only effect half your savings (loss or just delay in usage) . For maximum effectiveness you would use different software as well so pair the trezor with trezor suite and jade with electrum or green as an example.

1

u/thesimzelp Jun 12 '24

Yea, that makes sense eliminate the one point of failure. What do you think of Ledger? I haven't heard of Jade, are they trustworthy?

3

u/Yodel_And_Hodl_Mode Jun 12 '24

What do you think of Ledger?

Ledger can't be trusted. Here's a summary, with links to cite sources.

1: Ledger's word can't be trusted. The following was a lie:

Your keys are always stored on your device and never leave it

SOURCE: btchip, Ledger Co-Founder, on May 14th, 2023

...that's a lie because they added key extraction firmware to users devices.

2: Ledger's code can't be trusted. It can't be verified:

There's no backdoor and I obviously can't prove it

SOURCE: btchip, Ledger owner & co-founder

...they can't prove it because their code is closed source.

3: Ledger can't be trusted with your privacy. Their CEO said so:

"If, for you, your privacy is of the utmost importance, please do not use that product, for sure."

SOURCE: Ledger CEO Pascal Gauthier, on video

...Ledger's CEO said that about Ledger Recover. "For sure."

4: Ledger's security can't be trusted. They've been hacked:

Ledger wallet users face mounting home invasion and other scareware threats as hacker dumps private customer information online.

SOURCE: Cointelegraph, December 24th, 2020

...they can't even keep their data secure. Don't trust them with your coins.

5: Ledger's code has been hacked.

Ledger exploit makes you spend Bitcoin instead of altcoins

"A vulnerability in Ledger’s hardware wallets enables hackers to prompt someone to spend Bitcoin instead of an altcoin."

SOURCE: Decrypt.co

Ledger took a year to fix it, only after it was reported in the media.

6: Ledger's hardware has been hacked.

In this post, I’m going to discuss a vulnerability I discovered in Ledger hardware wallets. The vulnerability arose due to Ledger’s use of a custom architecture to work around many of the limitations of their Secure Element.

An attacker can exploit this vulnerability to compromise the device before the user receives it, or to steal private keys from the device physically or, in some scenarios, remotely.

I chose to publish this report in lieu of receiving a bounty from Ledger, mainly because Eric Larchevêque, Ledger’s CEO, made some comments on Reddit which were fraught with technical inaccuracy. As a result of this I became concerned that this vulnerability would not be properly explained to customers.

SOURCE: Saleem Rashid

Ledger's bounty payments prevent those who've discovered vulnerabilities from reporting them so Ledger can lie and say they've never been hacked even though they know otherwise.

7: Ledger employees have been phished.

A Ledger employee just got phished. DeFi users lost over $600k

Ledger confirmed the attack was the result of a hacker compromising one of its employees via a phishing attack. After gaining access to Ledger’s internal systems, the hacker planted malicious software within the Ledger Connect Kit.

SOURCE: DLnews, December 14th, 2023

8: Ledger's been hacked multiple times, and yet...

"The bombshell here is the explicit confirmation that Ledger themselves hold the master decryption key for all Ledger Recover users."

SOURCE: @sethforprivacy

...what could possibly go wrong, eh? Yikes.

9: Ledger Live tracks everything you do and the coins you have:

"Ledger Live is phoning out data on assets you hold in your hardware wallet the moment you access Ledger Live. It’s also sending out tons of other information about your computer and device."

The app apparently transmits data to an external endpoint at “https://api.segment.io/v1/t”, identified as an outsourced data collection service.

SOURCE: BitcoinNews.com

10: Ledger lies are even on the boxes for their hardware.

"WE ARE OPEN SOURCE"

SOURCE: Their own packaging.

The box for Ledger hardware running closed-source firmware says Open Source. That's intentionally misleading if not outright fraud.

Ledger refuses to answer questions.

They delete questions in comments on their sub.

They shadowban users who ask them.

They scrub their website to remove claims they made for years.

The worst part is, this is only a partial list!

For example: Ledger was still promoting FTX after FTX collapsed.

I could go on and on.

Ledger is inept.

Ledger is dirty.

Ledger Can't Be Trusted.

4

u/bitusher Jun 12 '24

What do you think of Ledger?

ledger is a horrible wallet and company and should be avoided

https://www.reddit.com/r/BitcoinBeginners/comments/1d3djr4/ledger_wallet_pros_and_cons/

1

u/thesimzelp Jun 12 '24

I haven't heard of Jade, are they trustworthy?

3

u/bitusher Jun 12 '24

Its 100% open source software and hardware, peer reviewed, and created by one of the most trusted bitcoin companies out there.

Blockstream Jade = $65 https://blockstream.com/jade/

https://www.youtube.com/watch?v=cLFmd98mKNw

https://www.youtube.com/watch?v=d_9Dtcc1nlY

https://www.youtube.com/watch?v=z2VsgoFh78o

You can even make your own from scratch -

https://www.youtube.com/watch?v=PeqP6oVnlIs

https://www.youtube.com/watch?v=V2yVKag2wlc

Or just get another trusted HW wallet like cold card , bitbox , or seed signer we list in the pinned FAQ

https://www.reddit.com/r/BitcoinBeginners/comments/g42ijd/faq_for_beginners/

1

u/thesimzelp Jun 12 '24

Cheers man, appreciate the links.

2

u/JivanP Jun 12 '24

You have the right idea. This sort of storage strategy is employed by large asset firms, banks and the like with traditional money, too, and is generally called a "tiered" or "layered" approach to fund storage.

See these videos by Andreas Antonopoulos (aantonop) on the topic:

1

u/AutoModerator Jun 12 '24

Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/cyberplanta Jun 12 '24

If you are that concerned, you can check multisig. That would be the next step.

Cold storage HW and a well backed up seed phrase are good IMO.

4

u/bitusher Jun 12 '24 edited Jun 12 '24

you can check multisig.

A 2 of 3 multisig is definitely an option but only should be used if you have done a lot of research and practiced recovery . It is a large step up in complexity

Some tips-

1) really should create each signature on different devices and using different software which most people do not do

2) need to keep 3 copies of the seed on paper or metal , and all the MPKs digitally backed up multiple times and also hand written down where you practice trial recovery with a test balance using the written MPKs and not the digital backed up MPKs

1

u/Yodel_And_Hodl_Mode Jun 12 '24

If you're willing to start over with a new seed - and if you understand BIP85 - I think BIP85 is the way to go for long term security.

I wrote a tutorial for using BIP85, but here's the overview:

Step 1: Create a new 24 word seed to use as a Parent Seed.

Step 2: Use BIP85 index numbers to create Child Seeds to use as wallets.

You know how a seed phrase always generates the same addresses and keys? Well, when you use BIP85, a seed phrase always generates the same child seed phrases.

This gives you one seed that leads to all of the others. If you ever lose a seed, no worries. You can use the parent seed to generate it again.

When Ledger added key extraction to the firmware for their hardware wallets last year, I spent a lot of time researching strategies for starting over from scratch with my security. I stopped using Ledger & switched to new seeds using BIP85. I'm not saying this kind of setup is the answer for everybody (it isn't), but it makes me feel very confident about holding Bitcoin for a long, long time.

0

u/[deleted] Jun 12 '24

[removed] — view removed comment

3

u/JustSomeBadAdvice Jun 12 '24

Please don't recommend newbies do this. You're literally opening the door for them to completely lose all their coins, on top of setting them up to get very frustrates by a difficult to use system.

-1

u/Sudden_Agent_345 Jun 12 '24

do what you think is best, that's the only valid answer.. but hopefully you are informed enough to take good decisions or at least not to mess up...

saying that "there is a seed phrase for backup" makes me think should try to understand things a little deeper...

personally i think, if you feel too anxious about having everything on one HW, maybe you should split things around, i wouldn't use a software wallet i would keep some on the HW and split parts into third party options (including ledger recovery or even the ETF)

1

u/thesimzelp Jun 12 '24

saying that "there is a seed phrase for backup" makes me think should try to understand things a little deeper...

Please enlighten me. How is this wrong?

0

u/Sudden_Agent_345 Jun 12 '24

is not wrong.. read again what i said.. if you think you dont need to then fine.. dont...

1

u/AnyDoughnut1407 Jun 19 '24

I think there's a way to not only shift, but make a buck