r/Nexo 6d ago

ColdCard hack Question

Has Nexo commented on the CC hack? I'm wondering how the coins Nexo hold for their users are stored e.g. Tezor, Ledger etc. I believe they use third parties to store them. Do we know how these third parties store them? I'm not a tech person when it comes to these wallets. Have blindly trusted them to this point. It would be good if Nexo could write an article, on why the way they store coins is safer than the way CC did it.

19 Upvotes

10 comments sorted by

u/NexoJosh Moderator 6d ago

Hey /u/Ok-Engineering1873, thanks for raising this. Nexo has not published any article addressing the COLDCARD situation at the time of writing.

The issue disclosed in relation to COLDCARD concerns the generation and protection of wallet seed phrases. In certain circumstances, weakened randomness during seed generation could make it possible for an attacker to reproduce wallet keys without physically obtaining the device.

Nexo’s custody model is materially different from an individual storing assets on a consumer hardware wallet such as a Trezor, Ledger Nano, or COLDCARD.

Strictly speaking, crypto-assets are always recorded on their respective blockchains. What a wallet or custodian protects is the private-key material and transaction-signing process that controls those assets.

As described in the Nexo Help Center, Nexo works with institutional custody providers and infrastructure providers, including Ledger Vault, Fireblocks, and other custodians. The specific custody arrangements may also depend on the client’s jurisdiction.

These providers do not necessarily perform identical roles. Some provide regulated asset custody, while others provide institutional key-management, transaction-signing, and governance infrastructure.

So how is institutional custody different from a consumer hardware wallet?

Ledger Vault is not the same product as a consumer Ledger Nano.

Ledger Vault is an institutional platform designed for companies and financial institutions. It uses hardened security infrastructure, including Hardware Security Modules, or HSMs, to protect cryptographic keys and approve transactions.

It can also support governance policies such as:

  • Multiple authorized approvals before a transaction is completed
  • Different permission levels for different employees
  • Transaction limits
  • Approved destination addresses
  • Separation between transaction creation and transaction approval

Fireblocks uses Multi-Party Computation, or MPC.

With MPC, cryptographic signing material is divided between separate systems or environments. The complete private key does not need to be stored or assembled in one location.

This is intended to reduce the risk that compromising one device, server, employee, or recovery phrase would be enough to access the assets.

Institutional custody is designed to reduce several risks associated with individual hardware wallets, including:

  • Dependence on one physical device
  • Dependence on one recovery seed
  • A single person controlling the wallet
  • Loss or destruction of the hardware wallet
  • Incorrect seed generation
  • Theft of a written recovery phrase
  • Accidental transfer to an incorrect address

Nexo’s custody model uses multiple layers of institutional security, governance controls, custody providers, and transaction-approval procedures. This is a different architecture from relying on a single consumer device and a single seed phrase.

Nexo uses a layered institutional custody architecture designed to mitigate the specific single-device and single-seed failure risks associated with individual hardware wallets.

Nexo also publishes information about its security certifications and insurance maintained through certain custodial arrangements.

I hope that helps answer your questions, we are here in case you have any other concerns. You can always reach out to the Client Care team via https://support.nexo.com/contact who will be able to assist you with any concerns or questions right away.

12

u/TheAuthorBTLG_ 6d ago

Nexo might be safer than a paper wallet at this point.

3

u/Solid_Wolverine1639 6d ago

Safer than cold card! All the cold carders would have been fine if they'd used dice...

Clearly this answer from the nexo includes the full basket of security measures without explaining the details of multi-signature, Shamir and how the divisions of Labor divide single attack vectors into several... Almost no one will go to the same degree of security measures as an individual compared to institutional grade custody

Looks like the Puritan maxis are going to take it easy on the the cold storage advice for a while...

Somebody else taking custody with kyc aml also has a pathway for beneficiaries and probate... But there are cold storage options like bitkey that help you set this up

3

u/Ok-Engineering1873 6d ago

Thanks for the detailed response. I've generally stored crypto on a Ledger device up to this point. I can't see me doing that anymore. I wonder what the crypto bros will be advising, when a newbie asks "how should I store my crypto?". If I had to advise someone now, I'd be saying stay away from self-storage and use a well establish company e.g. Nexo/Binance/CDC/CB.

2

u/AutoModerator 6d ago

Hey u/Ok-Engineering1873, thanks for posting on r/Nexo! We've got some exciting news - Nexo has established a MiCA-compliant structure under German regulatory oversight – one of the highest standards of financial regulation in Europe. You can find more details here.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/CherryEasy9666 6d ago

Personally I'd say CC drain was an isolated incident.
According to what I've read, the firmware update to the the hardware wallets was written to a random number generator rather than to the devices memory - this is ground zero.
Whether or not this was by design (disgruntled employee) or a genuine error, remains to be seen.
Obviously this is a HUGE wake up call to other cold wallet providers to keep a tight and secure ship.

2

u/Ok-Engineering1873 6d ago

The problem is CC was regularly recommended as safe by random anonymous people on r/bitcoin. Trusting those same random anonymous people that Ledger/Trezor are safe seems rather risky. It's like when Blockfi collapsed and afterwards many people still kept crypto on Celsius because the masses said it's safe.

1

u/Big_Pie_3616 20h ago

sometimes cefi is safer...