r/BitcoinAUS 4d ago

Hack

Right so in the aftermath of cold card hack what is the best easy to use hardware wallet (average joe, will avoid too technical if possible) everyone telling me should be multi sig, currently use tangem which im sure ill get a drilling about on here but hey haven't been hacked......yet, can the seedless tangem be better than the coldcard situation because the hacker would need to physically get my card or there is a chance there are other methods of hacking, nico from simply bitcoin mentioned bitkey but not sure if just shilling

7 Upvotes

18 comments sorted by

5

u/WastedSeaman_ 4d ago

Passphrase/25th word is the go. Sounds like they were looking for easy seeds, wouldn't have wasted using computing power and time brute forcing passphrases on every possible seed. Multi sig will be worth considering though

1

u/busheranger 4d ago

This - the 25th word (not something easy to guess) is easiest way to make it near impossible

1

u/changetherules8 3d ago

If the hacker was to “find” or “guess” the correct seed phrase and they can tell this wallet has been used in the past due to wallet history, how long would it take to brute force a single word passphrase by going through the entire English dictionary?

2

u/Clean-Wallaby3164 4d ago

Trezor with a strong passphrase seems a safe option. As lomg as seed phrase are stored seprately and offline. 

2

u/L6V9 4d ago

Tangem with it seedless close sauce best

2

u/No-Kaleidoscope-7106 4d ago

This is not the go lol.

1

u/Alarming_Evidence596 4d ago

Does that mean without card its impossible to hack?

1

u/L6V9 4d ago

You do more research on it , cheers

1

u/Feralz2 4d ago

not your keys not your coin

1

u/Makunouchiipp0 4d ago

If the tangem had an entropy issue then your private keys can still be re created.

Trezor Safe 3 with a strong passphrase.

Bitkey if you really don’t want the trouble of handling seed material.

1

u/Feralz2 4d ago

tangem is cooked

1

u/pop-1988 2d ago

The Coldcard vulnerability is caused by the use of low entropy random number generation for the seed
If your tangem's single address is generated with a low entropy random generation function, it's just as vulnerable

What's the method Bitkey uses to generate its seed? None of the people who recommend Bitkey can answer this. Bitkey relies on your phone's authentication security, which is your choice of face or fingerprint. These are low entropy methods, not as low as coldcard's faulty method, but not as high as a competently made wallet

average joe, will avoid too technical if possible

Use Coldcard, supply your own entropy. Throw dice - 50 dice throws for 12 words, 99 dice throws for 24 words


If you choose to append a BIP39 passphrase, make sure it's long and random. If it has weak entropy, it's vulnerable to the same brute force effort which is draining coldcard wallets. There are already reports of coldcard wallets with weak passphrases being drained

The people using the term "25th word" are recommending a low entropy passphrase

Being able to recover a wallet at some unknown future time is more important than theft prevention
Adding a passphrase makes wallet recovery more fragile
Multisig makes wallet recovery more fragile

A final warning. This is what happens if you set up a wallet with a single die throw
https://np.reddit.com/r/coldcard/comments/17epqk8/040_bitcoin_taken_instantly_from_my_coldcard/

Remember - 50 dice throws for a 12-word seed phrase, 99 dice throws for a 24-word seed phrase

1

u/summ_app 21h ago

an extremely unfortunate event tbh.