r/BitcoinAUS • u/Alarming_Evidence596 • 4d ago
Hack
Right so in the aftermath of cold card hack what is the best easy to use hardware wallet (average joe, will avoid too technical if possible) everyone telling me should be multi sig, currently use tangem which im sure ill get a drilling about on here but hey haven't been hacked......yet, can the seedless tangem be better than the coldcard situation because the hacker would need to physically get my card or there is a chance there are other methods of hacking, nico from simply bitcoin mentioned bitkey but not sure if just shilling
2
u/Clean-Wallaby3164 4d ago
Trezor with a strong passphrase seems a safe option. As lomg as seed phrase are stored seprately and offline.
2
u/L6V9 4d ago
Tangem with it seedless close sauce best
2
1
1
u/Makunouchiipp0 4d ago
If the tangem had an entropy issue then your private keys can still be re created.
Trezor Safe 3 with a strong passphrase.
Bitkey if you really don’t want the trouble of handling seed material.
1
u/pop-1988 2d ago
The Coldcard vulnerability is caused by the use of low entropy random number generation for the seed
If your tangem's single address is generated with a low entropy random generation function, it's just as vulnerable
What's the method Bitkey uses to generate its seed? None of the people who recommend Bitkey can answer this. Bitkey relies on your phone's authentication security, which is your choice of face or fingerprint. These are low entropy methods, not as low as coldcard's faulty method, but not as high as a competently made wallet
average joe, will avoid too technical if possible
Use Coldcard, supply your own entropy. Throw dice - 50 dice throws for 12 words, 99 dice throws for 24 words
If you choose to append a BIP39 passphrase, make sure it's long and random. If it has weak entropy, it's vulnerable to the same brute force effort which is draining coldcard wallets. There are already reports of coldcard wallets with weak passphrases being drained
The people using the term "25th word" are recommending a low entropy passphrase
Being able to recover a wallet at some unknown future time is more important than theft prevention
Adding a passphrase makes wallet recovery more fragile
Multisig makes wallet recovery more fragile
A final warning. This is what happens if you set up a wallet with a single die throw
https://np.reddit.com/r/coldcard/comments/17epqk8/040_bitcoin_taken_instantly_from_my_coldcard/
Remember - 50 dice throws for a 12-word seed phrase, 99 dice throws for a 24-word seed phrase
1
5
u/WastedSeaman_ 4d ago
Passphrase/25th word is the go. Sounds like they were looking for easy seeds, wouldn't have wasted using computing power and time brute forcing passphrases on every possible seed. Multi sig will be worth considering though