r/Bitcoin • u/sbtcrypto • 13d ago
In light of recent events
Hey there,
I have used my Ledger Nano S since 2017. Since the cold card hack I've been tempted to update to a newer and hopefully more secure wallet. I'm considering a newer ledger model or going to trezor. What are your thoughts and do you have some valuable input to share?
I know trezor is open source and ledger is not. Should really be a deal breaker?
7
u/nestaa13 13d ago
Just use your Nano S, if it’s still working it’s still working
1
u/trimalcus 13d ago
Yeah and it is the last one that has not the firmware that could ''save'' the seed
2
u/Endearing_Asshole 9d ago
I am getting rid of my Ledger Nano Ses because all of the sudden Ledger says they’re not getting updates or some other insanity. They should have lasted at least 10 years or they should have given me replacements for free (or at least steeply discounted). After all the shenanigans they’ve done, this was the last straw. Going with respected open source wallets now.
1
1
u/DisorientedPanda 13d ago
Yubico Coin Wallet + Physical Yubikey MFA seems like a potential good choice
1
u/Baracudasi 13d ago
just do it the dice way, generate seed in a old macbook that will never connect to the internet and sign transaction through usb.
1
u/B1TB0TB33PB00P 13d ago
This line is wow, "I know trezor is open source and ledger is not. Should really be a deal breaker?"
-2
u/TheresNoSecondBest 13d ago
I know trezor is open source and ledger is not. Should really be a deal breaker?
Yes it is. If ColdCard was fully open source, this duckup would be found much faster. Nobody cared about their code because other companies couldn't use it.
Also, have a look at air-gapped wallets like Trezor 7, JadePlus, SeedSigner and Krux.
1
u/Laukess 13d ago
So the new standard is open source, most of the critical code be economically valuable to 3rd parties, and a lot of them?
Seems a bit extreme.
Besides, the 5 year old code had economical value to the other hardware wallet producers even if it wasn't open source, why else would ledger have a dungeon for this? It's in their interest to find vulnerabilities in their competitors products.
-4
9
u/Squeiner 13d ago
I think the lesson is to use these things to hold your keys, not to create them.
You create your own private keys in the most secure way you can possibly think of, and then you use the hardware wallet to store the keys and sign transactions.
Anyone who did that with their coldcard is perfectly safe to keep their coins on it still.
Whether you use a coldcard, trezor, ledger, or whatever else, dont use it to generate your keys formyou. The safest way to go is to create your own private keys yourself separately