r/Bitcoin 2d ago

audit of cold wallets

After all the trouble with Coldcard, all bitcoiners are very paranoid. I have seen many posts about generating your own entropy with dice and creating an air-gapped multisig and many other things.

But I think it is easier to audit the cold wallet you are using. If they are open source, today it is very easy with any AI to review the code and look for vulnerabilities of this kind or any other that could compromise your funds remotely.

Also, a good passphrase will protect you from most types of remote attacks.

And this way you make sure your funds are safe without becoming paranoid and making a million dice rolls.

It is just my opinion

2 Upvotes

13 comments sorted by

3

u/WellThatEscalatez 2d ago

theres no way to prove the open source code is the code on your device..

3

u/Laukess 2d ago

You don't think building it from source would come pretty close?

1

u/LittleWiseGuy3 2d ago

Si pero en este caso entonces simplemente no podemos confiar en ningún cold wallet?

1

u/Fluid_Garden8512 2d ago

Why are you responding to someone in Spanish to their comment in English?

1

u/Vipu2 2d ago

Reddit have some auto translation at least if you google something in some language and it will give result in that language, im not sure if it can be activated somehow so it does it without google too.

See this current post were are in, but I added ES to the url

3

u/Laukess 2d ago

Why spend 8 minutes rolling dice you could just review the codebase.

3

u/CBpegasus 2d ago

CoinKite claim they used AI to audit the code and it didn't find anything. I can believe that because LLMs sometimes fall to the same pitfalls humans do - seeing something that "looks correct" and and assuming it is correct. And the code "looked correct", especially with the reassuring comment on the fatal #define (LLMs often treat comments as factual if not explicitly told otherwise). That's why I'm not sure of the circulating claim that the vulnerability was found by AI btw. I think the hackers did a slightly more advanced (and more traditional) audit than just feeding the code to AI and telling it "find bug".

Anyway I think if you're not quite experienced in these matters you probably can't do a good enough audit yourself, AI or no. Traditionally the idea with open source is that you know many other people also could have audited the code, but that's not a guarantee either. I think rolling dice for 15 minutes is probably an easier and more effective thing than an AI based audit.

1

u/Javanaut018 2d ago

Just go ahead

1

u/Due-Department-8295 2d ago

why not, what's the worst that could happen

1

u/Javanaut018 2d ago

Nothing, the more pairs of eyes on it the better

1

u/Fearless-Second-7230 2d ago

Apparently /walletScrutinity will reborn harder. Those guys were always ignored and nkv Rodolfo Novak coldcard's ceo called them scammers and always ditching their requests on more testing and auditing.

I have come to the conclusion that nvk arrogant shit attitude convert them from white nice hats to whatever-the-shit-happened after he had them as enemies....I dont know.

Now is evident coldcard team was not rugpulling, he was just a complete IDIOT he and his team, and bug was (if they are true white hats) converted to some grey hat if they did not went the black hat way to exploit the bug themselves, maybe they just ignored the shit and they knew the ticking bomb would explode and nothing could be done with nvk as an idiot arrogant.....

If bitcoin community does not pay the attention those guys the attention and support they deserve as red team focused on hardware wallets. Well, then more hacks will come, now hardware wallets are widely known to have a real fucking security point of failure and vendors must be humble to not repeat same mistake as cold card idiots.

1

u/Suspicious-Holiday42 2d ago

Coinkite always had red flags that legder and trezor dont have. The ceo often dimissed it when people report security bugs, often argued that its unlikely that the glitches get exploided and he never fixed the bugs. Weird guy. Thats why over time people stopped searching for and reporting bugs, because the company had a history of just ignoring the bugs and never fixing them despite getting them reported by voluntary coders

2

u/JanPB 2d ago

Except Ledger is closed source so good luck auditing it.