Reddit Posts
SignerOS v1.2.0: Secure Boot, stricter PSBT checks, reproducible builds
[SERIOUS 2] Results of reproducing the MK3 weak-RNG search: 1157 weak wallet roots reconstructed and evidence the hack extended to ETH.
I'm making a crypto tycoon game called BAGHOLDER for a school assignment, would anyone play this?
[looking for feedback] I made a free retro RPG to orange pill beginners
I wanted to turn a regular PC into an air-gapped Bitcoin signer, so I built SignerOS
How can you sweep a paper wallet using Sparrow Wallet on an offline PC?
Me and my buddies started a small GPU store by bidding on bulk liquidation auctions. Need your honest feedback/support!
Me and my buddies started a small GPU store by bidding on bulk liquidation auctions. Need your honest feedback/support!
BigDice Mnemonic Seed Generator (llm slop, with details)
What site(s) should be considered the gold standard for generating Bitcoin mnemonics using dice?
Is it safe to use BitAddress.org to generate an offline wallet on an air-gapped PC?
Got paranoid after the Coldcard entropy thing, built a tiny dice→BIP39 tool for Pi Zero + Waveshare
I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step
DiceVault 7.0.0 – open offline dice rolls → BIP39 tool (nothing stored)
I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step
Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts.
I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step
YSK the most secure wallet is the Bitcoin Core Wallet especially air gapped with Tails OS
Can I am Which Cryptocurrency Should I Mine?
This guy was mining 1 Bitcoin every day in 2011. He built an $800 gaming PC, downloaded the mining software, ran it 24/7, and was earning Bitcoin like it was nothing. A true legend from the early days of Bitcoin
Do you feel a bit guilty for not buying BTC instead of something you desire?
We built an actual playable MMORPG on Solana. $ORBRYN just launched on pump.fun — under $100K mc.
Recovering a Schlidbach wallet (Cold Storage) hundreds of BTC
I made a fully decentralized cryptocurrency that runs completely in your browser.
Built an open-source crypto trading bot (QuantBot) — looking for honest feedback from the crypto community
Working on an open-source crypto trading bot — thoughts?
I built a CPU-only blockchain from scratch in Python. No ASIC, no pools, just fair mining for home PCs. Roast my project!
Satoshi's Coins: Freezing or Seizing? How do we respond to Quantum Supremacy in the coming years.
CryptoTab Farm is a whole new way of earning BTC. First, you can connect all of your computers for absolutely free or try the Pool Miner feature if you don't own a PC to get a steady income. And if you want to increase it — take advantage of the special referral system! Share your personal links wit
Xbox Game Pass May 2026 Lineup Revealed: Forza Horizon 6, Subnautica 2 And More Coming Soon
I built a PoW blockchain where your phone mines at the same rate as high-end hardware (no pooling advantage) — 200+ signed up to run a node
Bitcoin Breakthrough – The Simple Guide to Understanding & Profiting from Crypto
I’m super new to all things Crypto - I need help installing a wallet (please help)
I mass deleted every crypto app on my phone and built my own alert system instead. Here's what happened.
$fitgirl, organic growing and all trading fee go as donation for fitgirl continuity.
Brand new Trezor Safe 7 won’t connect to my PC (USB-C or Bluetooth). Anyone else?
WARNING: NEVER use SuperX (trysuper.co) on Hyperliquid. It’s a SCAM.
Accidentally Lost My BTC Backup in 2022 — Just Recovered It in 2025
[Technical Alert] BIP39 Entropy-Drain Vector & 2026-02-01 Incident Report (Translated)
Bitcoin v0.01 ALPHA — If you could go back to 2009 with this file, what would you do differently?
Hearing a rumor that Bitcoin could rise to $2.2 in the coming months would be my chance to buy a gaming PC 🤔
I built an alternative because math & staking haven’t stopped mining pool dominance, parallel mining, or capital/hardware advantages in blockchain. (MVP demo inside)
Found a PoW Blockchain that claims to END ASIC dominance, parallel mining & Sybil attacks (Phone = PC = ASIC) Seen?
Found a PoW Blockchain that claims to END ASIC dominance, parallel mining & Sybil attacks (Phone = PC = ASIC) Seen?
My Proof-of-Work Demo: Mining Faster No Longer Matters (Phone = PC = ASIC)
TradingView Premium Free Download v2.15 - PC & Mac Desktop App
Why it's so hard for people to wrap their heads around Bitcoin
When Hardware wallets are unavailable: Next Best Option?
10 years of crypto journey, but I am quitting.
I'm curious: approximately how long did it take you to buy into Bitcoin after discovering about it?
Is viable to build a node in my day to day PC?
Timeline of Technology, Computing, and Decentralized Value
Lost All Crypto After Running a Program — How to Stay Safe?
$DOGPU: The Meme Coin That's Ready to Compute to Mars 🚀
🪙 Bitcoin II (BC2) — A Second Chance to Be Early
Sparrow Wallet + Full Node : where should I install the wallet?
Have you already tried CryptoTab Farm? If You can not only connect all of your hardware to the farm for free but also use the Pool Miner feature if you don’t own a PC. Choose what suits you best! Promo code: QSJHDG9V
Mentions
Leaving your PC on 24/7 doesn't guarantee you'll manage to mine even a single block. It’s a war! Whoever has more computing power has a better chance, but there are no guarantees. It’s a completely different scenario. But just imagine—suppose you managed to mine every block in a full day: an average of 144 blocks per day times a 50 BTC reward per block. But that doesn't exist, and it never will. Back in 2010, the same guy from Pizza Day discovered that mining with a GPU was much easier... and the network scaled the difficulty. And so it goes.
Don't trust, verify applies to using BTC not obtaining it. In Satoshi's days anyone could mine easily on their home PC, or get it P2P, no one was buying from exchanges with KYC. ACIS miners have changed who is mining, but not how, and not how transactions work. No one is stuck on exchanges unless they choose to stay. There are more self custody options than ever (not necessarily all perfect)
You're totally right, and thanks for making me think deeper on this. To be clear, the government already knows 100% about my money, including my bitcoin. i don't keep anything on exchanges today, but every satoshi I own was bought through one. The OP’s post got me reflecting. I've read the whitepaper and Satoshi’s old Bitcointalk posts, and it feels like we've drifted far from the original blueprint. When ordinary people could mine on a PC, you had a truly decentralized on-ramp into digital cash. Satoshi foresaw industrial mining as soon as GPUs entered the game, then came ASICs... and what’s next? Today, the reality for everyday working people is choosing between government surveillance or trusting a random stranger. And that "trust" is my whole issue. The breakthrough of Bitcoin was solving double-spending to create a trustless system. Traditional finance needs heavy regulation precisely because humans can't be trusted, relying on centralized custody and clearing houses. If Bitcoin's essence is "don't trust, verify," why are we back to taking risks on human trust just to buy it? I'm just an everyday user trying to reconcile the original vision (a non-inflationary, trustless digital currency outside state control) with our current reality (a speculative asset where most people are stuck holding on exchanges). It's genuinely complex.
Left crypto on my Exodus on my PC; the PC died (PSU). I was so scared, thinking my SSD was fried and I lost everything. learnt a lot from that, thankfully didn't lose anything
Yeah the same rules, Wait until your setup comes Risk only 1% A Time Window Trade should be closed on the same day Close the PC After TP/SL Hit... No Emotions During Trade Only 1 Trade a Day Simple rules, For A Beginner...
A PC on average dies after 100.000 hours. GPUs may quit a bit earlier already. In 2009 you would not yield anything because there was no real money exchange for Bitcoin. Maybe a pizza for 20000 Bitcoin or something like that.
PC pool is a room with 40 computers. You can put multiple GPUs in a single machine. If it runs 24/7 it gets hot and uses lots of energy.
50000 BTC was mined every week by the entire network. It's unlikely that any one entity had a sprawling mining farm of PCs. Bitcoin was basically worthless and there was no incentive to set up hundreds of computers to mine. GPU mining was not big until late 2010 or so. It was a tinkerer hobby, with many people doing some mining here and there. Maybe some people abused their work owned hardware, or school PC labs to mine more than others. Most people did not have dedicated rooms full of GPUs mining because it was not worth doing. Not until later.
All hot wallets load keys in clear text to work with them. Using closed source wallets like Exodus is not recommended. That's an added risk on top of everything else. Hot wallets are pretty convenient and serve a secondary function as well. Why would you trust a PC/phone to do your social media, shopping, healthcare, banking, taxes, but not trust it with a few bucks in BTC? I have separate hot wallets on all my devices as somewhat enticing honeypots. None of them run Windows. None of them had anything stolen. If your hot wallet BTC disappears it can be a cheap (or expensive) indicator that you cannot trust that device for anything else.
50k BTC sounds insane now, but with a 50 BTC block reward that was “only” 1,000 blocks. For someone mining very early with a decent share of the network hash rate, it was possible — but definitely not something every random PC would just accumulate automatically.
The initial theft occurred because they got the victim to open a Remote Desktop client and then they stole his private keys from Bitcoin Core. Who the FUCK stores over 4000BTC in a hot wallet on a PC???
Fair point, 5% deserves an explanation. It funds pool infrastructure and operations, but also the Lab’s research, testing and development. Maintaining a mining research lab is expensive, and that work is a core part of what we’re building. The aim is to turn validated discoveries into practical improvements for the pool and its miners. We have demonstrated endtoend improvements for PC mining and are working to bring those gains to ASICs. **That could provide another form of value to miners over time, although it is nt a payout or a demonstrated ASIC advantage today.** Hybrid Solo also changes what miners get from participating. A small miner can mine for years without personally finding a block. Here, **85% goes to the finder and 10% goes to other eligible miners**, so your own block find isn’t your only opportunity for a reward. The fee still matters. But so does the community allocation, and the research that the Lab’s separate 5% helps fund. All payouts depend on actual block finds.
Not a PC repair subreddit. Get the drive and get the wallet.dat file, then you can ask here.
That's the weirdest 2009 PC mouse I've ever seen.
This hurts me spiritually. I had the PC to mine it back then too..
The United States is a big country. If you're a citizen or permanent resident you can simply be a nomad within it and always have a new place to move on to. If you're not a citizen or permanent resident, consider not entering the USA and enjoying the rest of the big planet, as a US border is a surrender your rights zone. A distinction needs to be made between Customs and Border Patrol (CBP) and the TSA. You've mentioned both but made no distinction. The policy posted is CBP, which applies when entering the USA. In the context of a domestic flight, you will only encounter the TSA and they are mainly concerned about aircraft safety. They are there to make sure only flight appropriate items end up in cargo hold and the cabin. They will involve other law enforcement when items unrelated to airplane safety catch their attention, but that's only for things that are big red flags and electronics is not one of those things as electronics are generally not a threat to aviation outside the context of lithium limits. When it comes to electronics, what they're looking for is to validate size of lithium cells and for the x-rays to align with electronics looking like electronics and not hiding something else (particularly) and there are also known sometimes to ask for power on tests as a way to demonstrate electronics are what they are. A power on test isn't necessarily invasive, and the reputation is that these are more for laptops than anything else and I'm not sure I've heard of smaller electronics getting much attention (can't hide much harmful to an airplane in them). Do more research on folk's specific experience with TSA power on tests -- even doing these with laptops may have become a thing of the past due to more sophisticated X-ray tech and explosive detection tech which makes power on tests obsolete per the TSA's aircraft safety mandate. This of course depends on the airport, bigger airports have better tech for faster screening throughput. Small airports will be 2002 era in their screening security. It is the CBP that is super invasive per the law and this policy. Their mandate, to prevent undesirable activity inside the USA by citizens and non-citizens alike by way of border control. That is a much bigger mandate. The border is a near-rightsless search heavy zone, even for returning US citizens. Though entry is a simple interview for most, as the article discloses things can get pretty invasive. The only counter measure when carrying a hardware wallet is to have it in a reset state. If questioned, you can honestly say you're not using it right now. To memorize a seed, use the memory palace technique, and consider generating a 12 word one which is plenty of entropy but half the memorization. Your palace is a super familiar place, hopefully there is something like "home" to you in your memory like a childhood home from before becoming a nomad. Put each group of three words in a room and create a colourful visual for those three words in that room. To build a strong long term memory, you have to re-enforce it, a of lot early repetition is critical (many, many times daily when starting out) but there has to be refresh down the line. Go for several walks on your first few days and in-between internal walks through the memory palace say to yourself "I am a sovreing citizen." Do not prepare a wipe code on any kind of device as a CPB countermeasure. A US citizen who was returning to the country is currently facing obstruction charges for refusing an invasive cell phone unlock request and giving a code that did a Graphene OS wipe request. BIP39 passphrases just add another layer where your memory can fail. If you can memorize a BIP39 passphrase that's not crackable (random words from this), then you can just memorize a BIP39 seed, no passphrase. A weak passphrase is crackable to a good adversary and finding a BIP39 seed on your person is a substantial starting port for a CBP agent giving you hell, way more than a hardware wallet in reset state. BIP39 passphrases only make sense for folks who have seeds in relatively secure places like their homes where they just need a little bit of search space as a thin defense layer against casual robbers and visitors. Consider pairing a memory approach with a distributed form of backups that can be distributed to insecure locations that you can turn to if your memory fails. The recently discovered Coldcard failure was a bad thing, but their device may be helpful for safe seed splitting. You don't need to trust it for seed generation, you can import one. They have a seed splitting scheme that uses the logic operation XOR, The output is BIP39 words. You could leave parts of the split with people you trust in your travels and/or open safe deposit boxes at banks / other safe keeping services. As these are built on the BIP39 wordlist you can use standard steel plates for encoding and for making things less subject to the "throw out that paper trash..." scenario. The point here is that the compromise of a single person or single physical location does not compromise the seed. After recovery with the XOR split scheme the Coldcard lets you see the original seed, handy if you had a memory failure and want to see what you forget after doing the recovery. There is a deterministic split and random splits. The deterministic split is helpful if you plan to bring a reset Coldcard mk4 through customs (looks like a calculator), as upon doing a recovery from memory you can regenerate that exact same split for your next deposit, for example if you already deposited deterministic part A and need to generate deterministic part B for your next drop off. If you use the random split you'll have to write down all parts down at the time of generation -- in that case you could bring one part at a time through customs and deal with any questions about it or bring all parts through unfunded. An alternatives: The SLIP39 scheme, which is well supported on device on the Trezor is also a key splitting scheme that using shamir secret sharing. BIP39 words are used, but in unusual lengths. There is also PC software available as an alternative to generating and recovering on Trezor. Generic shamir secret sharing can also be done on PCs, on Linux the command and package is "ssss". There are stories of this Winklevoss twins doing this and flying their shards around when they started building their crypto fortune.
Start small, with a wallet on your phone is okay, so long as it is like less than 100K sats. Consider that a toy wallet, practise sending, receiving and recoery a few times before you move to put in any serious amount. Also, understand UTXOs and how tracing them can pose a threat to your privacy. This way, you do not end up revealing too much about your wallet (UTXOs and addresses you own) on the blockchain. Also important for privacy. If you choose to buy a BIP 39 words based recovery wallet, try one which does not even connect to a PC during set up. Remember, the coins are held in the chain, not in the wallet. The key to your coins is the wallet, OR the words+passphrase. Guard both. An attacker can get the coins he he has the words+passphrase without ever touching the wallet. Never ever put the words+passphrase anywhere except into the wallet itself (and an wallet that you have thoroughly researched). No website, no customer support, no _expert_ from the internet. Put the passphrase somewhere where your family can recover after you die, and at least one person in your family should be aware of how to use it. In general, how much you put in and your set up depends a lot on how much you understand. * Basic sending receiving...100K Sats * Wallet recovery and guarding seed+passphrase 10 million sats * 50 million sats and above...zpub for receiving, hardware multisig, smart UTXO management and use lightning for payment as much as possible and also you should have some basic understanding on what private key+public key, asymmetric key cryptography mean so that you don't end up making stupid decisions About lightning payment, if you use it regularly to pay (people or merchants), it is safe to keep some operational fund in a custodial wallet (I prefer CoinOS and Blockstream). But under no circumstances, you should put the keys of your hardware wallet into your mobile device. When I was starting out, I thought it is useful to have an on-chain address of my own handy to receive payments. But obviously, carrying my HWW around town is out of question. So I carried around the address and QR code in my phone. Silly and unnecessary, but fortunately not fatal. But I had no concept of zpub, hence. Then I learnt you can put the zpub in a mobile wallet to generate an address on the fly and also watch the transactions.
I was on PC and my keyboard was a foreign one lol.
There are three main steps to holding and using Bitcoin safely: * Creating the wallet * Protecting the seed phrase * Signing transactions to spend When creating a wallet, I think you should use at least two different hardware devices. We've seen that relying on a single hardware wallet isn't safe enough. You should use two separate devices, like a hardware wallet plus a PC, or hardware wallets from two different brands in a 2-of-2 multisig setup. People usually view multisig as protection against losing or stealing one seed phrase. But now, I think it has another important job: protecting against hardware vulnerabilities. A 2-of-2 setup is enough for this. To protect your seed phrase, never store it online in plain text. This prevents theft. Preventing loss is even more important, so keep physical copies in at least two separate locations. When you spend Bitcoin, the process should be completely air-gapped. Create the transaction on your online wallet, sign it on your offline device, and move the signed PSBT back online. Always review it before broadcasting. Double-check the addresses, and pay special attention to make sure the change address is correct.
Have you ever used PC with Intel chips? Or USB sticks, Waze, iPhone-s FaceID, VPN, Voice over IP or so on? All of those are based on tech developments done in Israel...
> and your IP address and password please My questions are reasonable and covered by many how-to on creating airgapped Bitcoin wallet using old PC/laptop. This will serve newbies, letting them know that they don't need to buy hardware wallet if they know what to do. Your comment is sarcastic and unnecessary. I am about to do the same as my ledger screen has died and currently weighing my options.
You do not mate. And you shouldn't think about that nonsense. Most people whom did what you were intended to do were the ones who sold BTC at 0,50€/btc and bought again at 2,00$/btc and sold at 2,50$/btc. This loop which did not make them rich. Bitcoin were only life changing for the ones who bought or mined it for the play and completely forgot about it... until one day searching their PC they find out about those old adresses for BTC and voi lá, rich!
Look up heurodeterministic wallets. That's the norm now, but back then, wallet software simply randomly generated a new bitcoin address every time one was needed. There was no seed words to regenerate deterministic addresses. This meant the ONLY place a private key existed was in that wallet.dat file on his local PC. And he wiped it for some reason.
I remember I mined in college and thought I was a big shot mining and having like 20 BTC when it was like $20 a coin and when it bumped up to $100-$200 a coin I sold I think everything to buy a nicer PC. Cashed out way too early, could've been sitting on a beach somewhere probably never having to work again. And I can't remember what I was doing in highschool because I was mining, but my god I must've had hundreds. Spent too long trying to track it down. At least the ride was fun right?
Ask ChatGPT and it will help you build your node. I recently bought an old mini PC (dell optiplex) off ebay and upgraded it with a 2TB SSD drive in order to store the whole blockchain. I installed linux mint and bitcoin core, and use this as a desktop PC now. It's a lot cheaper to go this way than to buy a pre-made unit like a start9. I learned linux and got a new computer out of the process too.
Start9 on a Raspberry Pi or an old small form factor PC / mini PC for the node. Electrum on TailsOS to set up the cold wallet. Initialize it, back up your recovery info, fully reboot the device, restore the recovery info and verify that you successfully restored a wallet with the correct fingerprint. Then export the extended public key and import it into BlueWallat, Sparrow, etc. to created a watch-only wallet.
buddy, I lost probably around 40 coins back when I used to play RuneScape. Remember buying some BTC using my mom's cc back in the day thinking she would never know what a BTC is on her transaction (yes I know that's not how it works, but as a kid that's how I thought) and lost my account info and PC was thrown away. So yeah, I feel the pain but at the same time I drill it in my head that I never had BTC.
Not familiar with "Dcent" so I can't comment on that model *specifically*, but in *general* the whole point of a hardware wallet is that your private keys are *never* shared with your PC. That means that no hacker or malware can extract them through your PC, or interfere with transactions, since only the signed transaction is ever visible. There are always other opsec concerns of course, e.g.: The weakest link is usually the user. Scammers are always looking for new ways to trick you into revealing your seed phrase, often through fake emails (or phone calls or physical mail) claiming to be from exchanges or wallet manufacturers. Malware on your PC might display the wrong address, or switch an address in your clipboard during a copy/paste to trick you into sending funds to the wrong address.
You're already ahead of most people just by using a hardware wallet, the device is designed so your keys never touch the PC even if it’s fully compromised.
Welcome to markets. This is how almost every security or commodity works. Like 5-10 years ago RAM was one of the cheapest things you could buy for your PC, now its one of the most expensive.
Now everyone is an expert in entropy generation, is just a time waiting untill all wallets will got cracked, its the reality guys, the randomness comes from the devices makers, even If is a PC laptop cold wallet usb etc
Same I missed it, cuz unfortunately one of my PC's memory sticks died out of nowhere. I was busy cleaning it up with alcohol swabs, amd by the time I got back online, it had already touched $79k and reverted.
> What exactly is written into the blockchain when cold wallet is created? Absolutely nothing. > By checking the blockchain can you tell from which country/location is holder at? No. > Type of the platform (phone, PC) he used to create a wallet? No. > When moving crypto to/from cold wallet is it possible to tap into the mobile phone to see when and which transactions took place? What do you mean by "tap into the mobile phone"? If you're creating or broadcasting the transaction from your mobile phone, of course you can see when and which transactions took place. If a certain mobile phone wasn't involved in creating or broadcasting a transaction, "tapping into" that mobile phone doesn't tell you anything about it. > By checking a specific blockchain location/transaction is quantity and list of crypto sitting there visible to the third party? "Sitting there"? If you look at a specific transaction on the Bitcoin blockchain, obviously you can see the quantities of Bitcoin that were inputs and outputs for that transaction. There is no "list of crypto"; the Bitcoin blockchain is 100 Bitcoin.
The passphrase is not the seed phrase. For Trezor One there is no way to enter the passphrase on device. All newer Trezor models have capabilities to enter on device, but on Trezor 3 Safe it's really painful with the two buttons. On all Trezor devices you can also opt to enter the passphrase on the PC. You enter the seed on device only for most devices, although Trezor One still supports the "24 words in random order" method. But to be sure, use the advanced recovery that doesn't leak anything about your seed to the PC.
Aren’t you never supposed to enter any part of your seed phrase on a PC?
Both Trezor issues are fixed now. The first by displaying the passphrase in clear on the Trezor every time you enter it on the PC (with newer Trezor you can also enter the passphrase on the device, which is obviously more secure if you suspect malware on your PC). The second issue is basically a bug in BIP-143. For segwit transactions, the signature also signs the input amount, so that transactions don't have to check it. This was intended to be used by hardware wallets to avoid streaming the previous transaction to prove the amount. Unfortunately BIP-143 only signs for the single input. I found this problem in Feb 2017 and reported it to the BIP-143 authors; but segwit was already in shipped at that time. In retrospect, Trezor should probably not have used this new feature of Segwit and streamed the transaction anyway like it did before segwit (even though it can take minutes for people who received lots of batched payouts). On the other hand it seemed so unlikely to be exploited: it requires a malicious wallet, forcing the user to confirm the same transaction twice (which is already dangerous with a malicious wallet for obvious reasons) and the wallet manufacturer needs to collude with a mining pool, because the stolen money is sent to the miner. BTW, Taproot fixed the problem in the BIP.
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
Two questions worth separating, because they lead to different answers — and one thing below is time-sensitive. **Was it one wallet, or the seed?** If only this wallet went and your others (from a different seed) are untouched, the compromise is that one key. If everything sharing a seed went, the seed leaked, and the question becomes where it was ever typed, stored or photographed. Everything else depends on which of those two it is, so it's worth establishing first. **The timing points at the vector.** Drained within days of creating it points at where it was *generated* — a fake or backdoored app, a seed someone could predict. Drained long after, quiet in between, points at where it was *stored* — cloud photo backup, a notes app, a password manager entry, a screenshot you forgot about. People remember which app they installed. They forget they photographed the paper. **On moving your other funds, do this part carefully.** The advice to move anything sharing a key is right, but if you generate the new wallet on the same machine that may be compromised, you've just moved the coins to an address the same attacker will empty. Generate the new seed somewhere else. If the drained wallet was hot on your phone or PC, treat that device as untrusted until you know why this happened. **That address collecting from many wallets is your best clue — just not for getting anything back.** Recovery isn't happening, and that's the part nobody can soften. But one address draining many unrelated people means a common cause, and the fastest way to find it is to ask the other victims what they all used. If two or three of you installed the same wallet app or the same browser extension, that's the answer, and it's worth more to the next person than it is to you now. **The time-sensitive part.** You just posted publicly that you lost coins. You will get DMs within hours offering to recover them — "blockchain specialist", "certified recovery agent", someone claiming they already traced it. Every one of them is a second theft aimed at someone who just took a first loss. No stranger can reverse a Bitcoin transaction, so anyone offering to is telling you they want a fee, or your seed, or both. Nobody legitimate messages you first, and nobody legitimate ever needs your seed phrase to "verify ownership". Sorry about the coins. If you post the amount and which wallet software it was, people here can actually narrow the vector — right now the thread is guessing with almost nothing to go on.
💻 ¿BUSCAS SOFTWARE PARA WINDOWS? 🚀 Únete a nuestro canal de Telegram zonalerosoftware 📦 Programas y herramientas para PC 🛠️ Tutoriales y recomendaciones 💡 Consejos para Windows 📚 Recursos y novedades de software 🔔 Nuevas publicaciones directamente en Telegram 🔹 ZonaLeRoS — Software para Windows.
The coldcard hack wasnt about 'physical extraction from the device'. It was due to a change in the seed phrase generator portion of the software which greatly reduce entropy of the private key and allowed even a standard PC to crack thousands of addresses.
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
Find a better exchange. Almost all reasonable ones list all of their fees, including the exit tax, aka the withdrawal fee. Electrum is a good wallet. Test recovery from your backup, and keep the backup safe. Tails is a decent OS for browsing without leaving traces on your PC but it's not a cryptographic secrets management OS. It may come with older version of electrum and you should use the latest with bug fixes, depending on how old that version is. Your main OS has your life connected to it most likely with your banking and social media and whatever else. If $12 disappeared in your every day usage OS, that's a small price to pay to know that you can't trust it.
Yes, it installs anything I don't feel like installing and does research on how to install it on its own. Also moves around files and organizes PC on its own. And it basically creates better versions of personal apps I used to have to download... which is nice as well. I hate to say it but it's kind of like having a robot slave that has to do whatever I want (mostly).
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
Using any hardware or software wallet isn’t a good move. You’re placing trust in someone else. My advice is to literally roll 1000 literal dice and then write out the sum of the numbers, sort them in alphanumerical order, add the numbers up, divide them by the sequence’s prime number allocation, then use a python script to generate the address. After you’re done, destroy the PC piece by piece, preferably burning it, then smashing it with your car. After that, put the leftover ashes and pieces into a garbage compactor and run it over again in your car, burn it again. Rinse and repeat until the ashes have ashes. Then write down your phrase on a piece of paper and place the paper in a vault. Dig a hole in the ground 20 feet deep in the woods using rented equipment (which you’ll burn after use), and place the vault at the very bottom of the hole. Create a map to the vault on another piece of paper using exclusively cryptographic lettering which was also generated from a python script and manual dice rolls. Then you’ll use that lettering and its corresponding key to create the map in such a way that it’s only readable with the key. Memorize the maps key phrase and burn the map. At least that’s what I did.
Under a minute on a normal PC if the master seed is already known
Apparently this is hard for many people, but I agree. An old laptop with the wireless chipset taken out, Linux, Electrum, a watch-only wallet on your main PC to receive, create, and broadcast transactions. If it's too difficult, you may be better off just using an ETF or custodian. Being your own bank isn't designed to be easy, it's designed to be secure.
Trezor already combines multiple enthropy sources including from your PC.
This is exactly what I do I boot into tails is then do what I do then reboot PC no worries.
On Q1: the cost of running a node is capped by consensus, not by what people choose to put in blocks. Three things I measured on my own node this morning. **Blocks are already full.** Last 1,008 blocks (one week): average weight 3,929,788 out of the 4,000,000 limit. That's 98.2%. Junk doesn't create new space, it competes for space that was already being paid for. **The growth rate is bounded.** At last week's actual block sizes, the chain grows 86 GB/year. The absolute ceiling, if every block were maximally witness-heavy, is 210 GB/year. That ceiling is a consensus rule and nothing in this debate changes it. **How much of it is OP_RETURN?** Last 20 blocks, 95,539 transactions: 64,260 OP_RETURN outputs totalling 1,389,828 bytes = 4.44% of the block bytes, averaging 21 bytes each. Twelve of those 64,260 were over 83 bytes. Twelve. Being fair to your worry: the genuinely big payloads ride in witness data, not in OP_RETURN, so don't take 4.44% as a measure of all "spam" - but it does mean the OP_RETURN limit was never where the volume was. What regular people should do is the practical part. My archival node is 899 GB (blocks 809, chainstate 11, indexes 80) - but that's a choice, not a requirement. The part that actually enforces every rule is the 11 GB chainstate. My second node is pruned, on a used mini PC behind Tor, and it validates exactly the same rules as the big one. Pruning has been there since 2016 and it's the honest answer to "can normal people still afford this". On 1.1, the factual half: a pruned node validates that data and then deletes it, it never keeps it. The legal half I'm not qualified to answer. Q2 I'll pass on. I don't have an opinion to offer on the governance, only what my node measures.
I can’t speak for all wallet manufacturers but the wallet I have, you can either setup your passphrase using the device OR you can set it up by typing it into the app on your PC. I opted to type it into my device for extra security. I used to not be this paranoid if you wanna know the truth but after this whole cold card hack and seeing people lose a combined $130 million it makes you realize we have to be extra safe and take security seriously. When you get hacked your funds don’t come back like a bank or credit card.
Oh boohoo poor me i live in the richest country on earth. Try living in indonesia with average monthly salary is less than 300 usd while living cost is more or less adjusted by the economic parity will left almost any average Indonesian with literally nothing. Mind you we still pay international price for electronics, even more due to low exchange rate and high “luxury” tax, because apparently anything but food is luxury in indonesia Oh did i forget to mention the average house price in indonesia is 50k usd, good luck buying one with 300 usd salaries You know what? You can tru visit the indonesian subreddit and see for yourself, what you crackers consider a “normal” life is considered a upper-middle class in indonesia like owning car, AC and a PC, The car price here is almost double that in the us because the car tax aline is almost the same price with the car Hurray for communism, i meant pancasila ideology
Building the hardware yourself… you must have missed the part where I said “air gapped PC”
Some years ago, I had a hard time using an old PC to calculate the last word, and I drilled its hard drive afterwards. No regrets haha. That experience led me to start developing an offline BIP39 calculator. After the CC incident, I was kind of forced to come clean and make it public. [https://www.seedmate.net/seedmateblog/what-is-seedmate](https://www.seedmate.net/seedmateblog/what-is-seedmate)
Your point is very good, thanks for clarifying your position. Rolling the 11/23 words manually with dice, and then guess-and-checking the 12th/24th word with the hardware wallet (as you propose) does seem like it would be a more secure solution for generating a checksum word than the 2nd link solution I propose above. However, generating the receiving addresses using the hardware wallet from the seed phrase is another issue altogether. Using a hardware wallet, you are trusting that the custom and niche hardware/firmware/software layers have all been implemented correctly. Whereas if you use a permanently air-gapped PC running audited JavaScript code in the browser, you need only trust that the general purpose computer and the browser running the code are behaving normally. While its true that a thief could compromise the cryptographic SHA-256 primitive in the Firefox browser to generate deterministic keys, the number of developers relying upon the cryptographic integrity of Firefox is massive compared to the relatively few developers who are looking at the code running on a hardware wallet. Case in point: the ColdCard fiasco. I know of no such similar attack on cryptographic primitives that has occurred on general purpose computers that has lost people bitcoin. Is it possible? Yes. But I believe the Cold Card attack shows that it's much easier to compromise these custom hardware devices than general purpose computers. That being said, generating identical receiving addresses using identical derivation paths on two (or more) different devices would probably be pretty secure, but is arguably more difficult to accomplish than using a general purpose computer. Thanks for your thoughtful input.
I wrote my own python codes to generate mnemonics using dice rolled bits, then used the 3rd website above to verify my codes via testing inputs. Once all done, I put my python codes in an air-gaped PC and ran mnemonics generations there.
No, a hot wallet means it was connected to the internet. A permanently air-gapped PC is not connected to the internet at the time of seed generation, nor is it ever connected to the internet again. Thus, there's no hot, only cold, because there is no connection to any online interface, not now, or ever again, on the device. I've described this multiple times, but there seems to be a communication gap in my description of "air-gapped". Why was/is this unclear to you?
In case you're unfamiliar with the term "air-gapped", it means a computer that is not connected to the internet. I tried to clarify in my post that not should this be run on an air-gapped PC, but that the PC should be permanently air-gapped (i.e. no Internet connection today, tomorrow, or ever again).
Did you do it on a PC that is occasionally connected to the internet?
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
You could type the code directly into the calculator's keypad, but that would be a nightmare, right? Instead, you write the Python code on a PC, connect the calculator via a USB cable so it shows up as an external drive, copy the code file over, and then load and run it directly on the calculator.
That's assuming your PC started out clean with zero malware or anything. A seed phrase should never be on a computer that will be connected to the internet ever again (at least not prior to being completely formatted fist maybe), for even a microsecond.
You're completely wrong. Using a PC is a terrible idea, as the attack surface is much larger. You should use something like a SeedSigner instead.
The 24 word seed phrase is just a replacement for an actual number between 1 and 2\^256. That is more atoms in the knowable universe. No one can guess it. All encryption is based on this type of “improbability”, not just bitcoin. The Coldcard “hack” - if that’s even the right word - was the discovery that the wallet did NOT generate a random number up to 2\^256, instead if fell in a specific range of 2\^40 - approx 1 trillion. That is a very easy number of combinations for machines today. You can guarantee a random number guess of 2\^256 using a well documented method of dice rolls, card draws or even coin flips. Also, cryptographic libraries for every programming language running on a standard desktop PC can do it reliably. Coldcard is an embedded device suffering from a serious human coding error, nothing more.
Right? I see people here with a couple hundred in crypto insisting that everyone should take responsibility for their seed phrase integrity while advocating hardware wallets or even steel plates. Etc. this is fine if you plan on taking your crypto to the grave but for anyone with a family, being your own bank carries tremendous responsibility that most family members are not prepared for. I still have deep anxiety issues whenever I connect my wallet to my PC for transactions. I don’t wish that on any of my family. Perhaps in some third world country this is indeed the best approach. But the day the US takes away my crypto holdings then we clearly have much bigger problems.
This may not help but many years back I too suffered a loss. Nearly 12 BTC gone to someone who installed a key logger on my PC. It was an $11k loss at the time. Instead of resigning myself to Bitcoin I got a hardware wallet and repurchased the lost coins as soon as I was able. Those coins ended up costing me nearly 2x what the lost batch did. But the years passed and my investment went on to eclipse the loss. Today I would advise the same except I would suggest you consider an ETF or custody at Fidelity. Those options did not exist for me back then.
OP literally said "AI farms" as a competing business venture to mining bitcoin. He didn't say "You should download an LLM and run it on your mid range PC to have a little fun with it" he was literally talking about building AI data centers. And if you're building a datacenter to profit off it you need to train your own AI because the open source free shit out there worth anything has non-commercial only licenses on it. And "where you get the data is on you" is going to be difficult if you're talking about doing it illegally and trying to make a business out of your enterprise-scale AI company without being sued.
They can both be true. People try to use Tails Linux, for example, which is a really neat and useful platform, and hold their keys in persistent storage, and one bad update or USB thumb drive failure lose it. Same issue with RPi/SD card implementations. Worse if they try to VM it (dumped memory state attacks, vulnerable hosts). Folks rolling their own on stuff they barely understand and won’t keep up to date, or build using out of date YT walkthroughs instead of current official instructions, caries different but similar consequence risks. Then it becomes how do they backup the key. Too many are going to type it on their phone or PC or photograph it, or not back it up at all.
After all of this nonsense recently I feel like an airgapped PC with a high entropy dice roll key and a very well secured physical back up of the seed is the safest possible way. Apart from a trustworthy-proof of reserve exchange.
I know this is hard to swallow but you need a PC that is set up for one task. And that is connecting your hardware wallet. Everything else from emails, to gaming has to be done on your main PC and never mixed between the two. A PC like that is very inexpensive as well, as it is simply your banking terminal. Almost all of your problems are solved, only physical access would be a huge threat as always. But having the keys used only on one trusted service is your best bet. It's not bullet proof, but no plan is. It simply is like not washing your hands before preparing food, it will probably be ok but you also might get salmonella poisoning. People want to takes risks and they can, that's the nature of critical thinking and not the fault of cryptocurrencies. A stringent security protocol is essential for all things on life.
Dude I mined 5 BTC or something when I was a kid on my PC. Ended up wiping it several times for video game space. This shit has happened and will happen over and over. That's the thing about volatile assets, no one knows shit about shit and anyone who says they do are either scamming you or just talking shit.
I think all hardware wallets should offer the option to create your own entropy (dice rolls etc), determine your own seed words, and then allow you to wnter the forst 23 seed words and let you choose the 24th word checksum. This way you can create a seed with your own entropy while never letting your seed words touch anything but a hardware wallet. Most hardware wallets make you use a seed generation file or 24th word checksum generator on an offline PC. This introduces risk for example if the file is malicious. A hardware wallet that generates your 24th word checksum for you should be an industry standard feature.
And to think that bitcoin when it started was worth cents and could be mined with the cpu, i kmew about it when it was worth 25$ each but i had no PC back them
Trezor XORs the output of the TRNGs from the PC it is connected to plus the one in its main CPU and the one(s) from its secure element(s).
I ordered an N100 16GB mini PC to use as Linux server. Might put a node in there as well.
Did you leave your PC on reposting Reddit comments?
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
The great thing about using a hardware wallet is that your key is never exposed to your computer, so if your computer is hacked (now or in the future) the hacker doesn't get to see your keys. If you generate your own entropy, you then still need a way to find out what address(es) you should be sending your coins to. So with all the best entropy in the world, if you then type the seed words into your PC to find out your address, then your security posture is (potentially) worse than just using a hardware wallet on default settings.
in 2010, my son was 4 years old and my daughter was a baby. No risk for either of them not to get conceived. I could buy a PC with a state-of-the-art graphics card, and mine 50 non-KYC bitcoins. Sell 10 of them in 2025, and still have 40 left by now.
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
Malware. If you know what you downloaded on PC, so no worries could be. And no antivirus needed at first, just firewall with proactive security. I mean storing crypto on a hot wallets it's not a problem, for me.
# Trezor Safe 3 — How the BIP-39 recovery words are generated After tracing the firmware and PC-side code, the recovery words appear to be generated from **two separate sources of entropy**: one from the Safe 3 itself and one from the PC/host software. The overall chain is: PC / HOST │ │ generateEntropy(32) ▼ PC CSPRNG │ │ 32 bytes host entropy ▼ EntropyAck.entropy │ │ USB / protocol ▼ TREZOR SAFE 3 │ ├─────────────────────────────────────┐ │ │ ▼ ▼ STM32 hardware RNG Host entropy │ │ │ 32 bytes │ 32 bytes ▼ │ int_entropy │ │ │ └──────────────┬──────────────────────┘ ▼ SHA-256(int_entropy || ext_entropy) │ ▼ 32-byte hash │ ▼ mnemonic_from_data() │ ▼ BIP-39 checksum + 11-bit word indexes │ ▼ BIP39 English wordlist │ ▼ 12 / 18 / 24 recovery words # 1. The PC generates 32 bytes of host entropy In the PC-side Trezor Connect code, `resetDevice (1).ts`, lines 61–65, the host calls: generateEntropy(32) and then sends the result as: EntropyAck { entropy } So the PC contributes **32 bytes of entropy** to the reset process. `generateEntropy()` is implemented in the PC-side entropy code, lines 9–24. It calls `randomBytes(len)` and requires a cryptographically secure random source. So: PC ↓ generateEntropy(32) ↓ randomBytes(32) ↓ 32 bytes host entropy ↓ EntropyAck.entropy The same `generateEntropy(32)` mechanism is used again during the entropy-check workflow (`resetDevice (1).ts`, lines 91–100 and 127–130). # 2. The host entropy travels to the Safe 3 The protocol contains two relevant messages: EntropyRequest ├── entropy_commitment └── prev_entropy EntropyAck └── entropy The important value for seed generation is `EntropyAck.entropy`. This becomes the firmware's `ext_entropy`. # 3. The Safe 3 generates its own entropy On the Safe 3, `reset.c` generates internal entropy with: random_buffer(int_entropy, sizeof(int_entropy)); The relevant code is around lines 288–304. `int_entropy` is **32 bytes**. The `random_buffer()` implementation for the STM32 build eventually calls the STM32 RNG peripheral. In the STM32 `rng.c`, the hardware RNG is read through: RNG->DR and `rng_get_u32()` / `rng_fill_buffer()` use those values to fill the requested buffer (STM32 `rng.c`, around lines 336–375). The generic `random_buffer()` wrapper is also shown in the STM32 RNG implementation around lines 66–85. So the device-side path is: STM32 hardware RNG ↓ RNG->DR ↓ rng_get_u32() ↓ rng_fill_buffer() ↓ random_buffer() ↓ 32-byte int_entropy # 4. The two entropy sources are combined This is the most important part. In `reset.c`, around lines 307–320, the firmware performs: SHA-256( int_entropy || ext_entropy ) In other words: 32 bytes from STM32 RNG + 32 bytes from PC CSPRNG ↓ SHA-256 ↓ final entropy The resulting SHA-256 output is stored as `secret`. So the final BIP-39 entropy is **not simply the raw STM32 RNG output** and it is **not simply the PC entropy**. It is the cryptographic combination of both. # 5. The SHA-256 result is passed to BIP-39 Immediately afterward, `reset.c`, around lines 314–321, does: mnemonic_from_data(secret, strength / 8) For the normal 256-bit case: STM32 entropy = 32 bytes PC entropy = 32 bytes ↓ SHA-256 ↓ 32-byte result ↓ BIP-39 entropy For the supported strengths: 128-bit → 16 bytes → 12 words 192-bit → 24 bytes → 18 words 256-bit → 32 bytes → 24 words # 6. BIP-39 converts the entropy into words Inside `bip39.c`, around lines 66–94, `mnemonic_from_data()`: 1. Takes the entropy. 2. Calculates SHA-256 of the entropy. 3. Takes the required checksum bits. 4. Appends the checksum to the entropy bits. 5. Splits the resulting bitstream into **11-bit groups**. 6. Each 11-bit value produces an index from `0` to `2047`. 7. That index selects a word from the 2048-word English BIP-39 word list. Conceptually: Final entropy ↓ SHA-256 ↓ checksum bits ↓ entropy + checksum ↓ 11-bit groups ↓ 0–2047 indexes ↓ BIP39_WORDLIST_ENGLISH ↓ recovery words For 256-bit entropy: 256 entropy bits + 8 checksum bits = 264 bits 264 / 11 = 24 words # Final conclusion Based on the source files traced above, the Safe 3 reset/new-wallet process uses **two entropy inputs**: 1. 32 bytes from the Safe 3's STM32 hardware RNG 2. 32 bytes from the PC-side cryptographically secure RNG (generateEntropy(32) → randomBytes(32)) Those are combined inside the Safe 3 firmware: SHA-256( STM32 hardware entropy || PC host entropy ) The resulting hash is then used as the BIP-39 entropy, which is converted into the 12/18/24 recovery words. So, in short: PC CSPRNG ───────────────┐ │ ▼ SHA-256 ▲ │ STM32 hardware RNG ──────┘ │ ▼ BIP-39 entropy │ ▼ BIP-39 encoding │ ▼ 12 / 18 / 24 words One important clarification: the **firmware hash is not the host entropy** in this chain. The host entropy is generated explicitly with `generateEntropy(32)` and sent as `EntropyAck.entropy`.
I'm doing the same thing. I upgraded from the Trezor Model T to a Safe 5. Just got it a couple days ago and planned on setting it up this weekend. Make sure there are no cameras around. Use SLIP-39 for the seed. I'll make my own random passphrase on paper (not using anything on PC to generate the passphrase). Store the seed and passphrase on metal backup. I have an older PC that I only use for Bitcoin and financial transactions. No normal web browsing. I'll only plug the wallet into this PC. Also, I'll load the xpub into Sparrow wallet so I can receive bitcoin without having to bust out the wallet itself (you need to do this with the Trezor app and it annoys me). A SLIP-39 generated seed, with a strong passphrase of random characters, and only transact using a super secure PC; that's enough for me.
Doing this in an offline air-gapped PC running a Linux live CD and then securely formatting it. It is also extremely low risk.
While I don’t disagree gambling insurance is bad, buying random shit like clothes or a PC is just as bad.
Here is a complete, ready-to-copy Markdown summary tailored for a Reddit post. It provides an objective breakdown of using the Schildbach wallet in today's threat landscape, emphasizing critical architectural realities. ------------------------------ ## Title: The Original 2011 "Schildbach" Bitcoin Wallet in 2026: An Open-Source Alternative or a Security Risk? With recent supply chain and firmware security concerns surrounding popular hardware wallets like Coldcard, many in the community are looking backward at classic, purely open-source software architectures. One fascinating option still running today is the Schildbach Wallet (the original "Bitcoin Wallet" for Android, first released in 2011). Because it is completely decentralized and peer-to-peer, it bypasses corporate servers entirely. But is it actually viable as a hot or cold storage setup today? Here is a breakdown of how it works, where to get it, and the serious architectural trade-offs you need to know. ------------------------------ ## 🌐 Where to Find It Safely Because it was removed from the official Google Play Store due to evolving API policies, you must use verified, audited open-source repositories to avoid phishing clones: * The Source Code: Accessible on the official [bitcoin-wallet/bitcoin-wallet GitHub](https://github.com/bitcoin-wallet/bitcoin-wallet). * The Compiled App: Downloadable via F-Droid under the package identifier de.schildbach.wallet. F-Droid compiles the binary directly from the public source code, guaranteeing no hidden developer modifications. ------------------------------ ## 🛡️ Why It Appeals to Sovereign Users * True Peer-to-Peer Routing: Unlike modern wallets (which query centralized API servers like Blockstream, ElectrumX, or Alchemy to fetch your balance), Schildbach connects directly to the live Bitcoin network via SPV (Simplified Payment Verification). No middleman logs your IP address or XPUB. * No Corporate Dependency: There is no company infrastructure to go bankrupt, get hacked, or push a malicious remote firmware update. * Zero Altcoins: It is strictly Bitcoin-only, drastically limiting the application's attack surface and eliminating smart-contract logic bugs. ------------------------------ ## ⚠️ The Hidden Architectural Catch (Read Before Using!) While it sounds like an ideal sovereign wallet, its ancient codebase presents severe security and operational challenges in the modern threat landscape: ## 1. No Seed Phrase (Protobuf Backups Only) Modern wallets use a BIP-39 mnemonic seed phrase (12 or 24 words) that you can write on paper. Schildbach does not. It stores keys in a local database file called a Protobuf. * To back it up, you must export an encrypted file (bitcoin-wallet-backup-...) and set a manual password. * If your phone experiences hardware failure or water damage and you don't have that exact file and its matching password, your funds are permanently gone. ## 2. Network Sync Issues (SPV Vulnerabilities) Because it relies on mobile SPV syncing, your phone must crawl through the blockchain block-by-block over peer-to-peer connections. * If the app has been offline for months, it can take hours or days to sync. * In a hot wallet scenario where you need to make a fast transaction, the app may lag or temporarily show a zero balance while catching up. ## 3. Mobile OS Vulnerabilities Using a mobile phone as a "cold wallet" is highly discouraged. Even if the phone is kept completely offline, Android OS vulnerabilities, memory exploits, or physical device tampering present risks that dedicated, air-gapped hardware chips (Secure Elements) are specifically designed to prevent. ------------------------------ ## 📋 The Verdict: Hot or Cold? * As a Cold Wallet? ❌ Not recommended. Air-gapped hardware or dedicated multi-signature setups remain vastly superior. Relying on an old Android operating system and a single Protobuf backup file for long-term storage introduces too many physical and digital points of failure. * As a Hot Wallet / Hobby Project? Viable, but use caution. It is an incredible tool for learning about early Bitcoin P2P mechanics and running a sovereign mobile wallet. Just ensure you rigorously maintain off-device copies of your password-encrypted Protobuf backups. ------------------------------ If you post this to Reddit, the community will likely emphasize testing your Protobuf decryption workflow on a desktop PC before trusting it with significant funds. Let me know if you want to modify any specific section! ---- I used Googles AI Search Engine Assistant, after having it help me find the original Bitcoin Wallet Mobile App.
Did you also have a PIN ? Was the ledger connected to the PC when the transaction was broadcast ? What address did the coins go to ?
We really have no idea who is using what wallet. For sure many Bitcoins are in the Core Wallet, especially from the early days and so far there really has not been any big theft outside of bad opsec. if you are are an air gapped PC with the core wallet and your wallet.dat is never in a internet accessible machine via PSBT, history has shown it is a very safe option. No guarantees of course and to your point, more eyes are on the Full Node than the wallet, but that does not mean the core developers want to avoid a cold wallet situation with the core wallet as it would be devastating for Bitcoin’s reputation as it is as close to core as you can get with a wallet. The general wisdom is that hardware wallets are the safest, but so far history is favouring the core wallet and it almost certainly has more eyes on its code than cold wallet do and likely other hardware wallets too. With good opsec, both are great options, but one is tied directly to Bitcoin and has a lot more to loose than a corporate reputation.
For me, I am trusting HW wallet entropy (example trezor,ledger etc) to generate 24 word seed phrase. On top of that i am using 6 to 8 word completely offline generated passphrase from Diceware list (passphrase don't have checksum issue) so you don't need PC to generate that. That passphrase over 256 bit TRNG Seed is very high security. Even if we assume HW TRNG fails to generate high entropy wallet, we are combining it with 8 word random passphrase that restore back the overall entropy.
It was bound to happen. Better now than later. Who enters their "secret 24 words" for an update? Was your brain on "fartmode" for 10 minutes straight. Get up from PC, get passphrase, return to PC, enter 24 words. Not at anytime did you think this is weird?
Same shit for me. I left PC on and went to a bar. After lots of beers I checked amount and concluded that whatever I get in BTC would show up on my elctricity bill at the end of month. Then deleted app without backing up wallet. Wasnt worth it because I would have to explain to parents whats the deal with electric bill and bigger issue was to replace PC after some time. Btc was maybe $1 back then.
Same shit for me. I left PC on and went to a bar. After lots of beers I checked amount and concluded that whatever I get in BTC would show up on my elctricity bill at the end of month. Then deleted app without backing up wallet. Wasnt worth it because I would have to explain to parents whats the deal with electric bill and bigger issue was to replace PC after some time. Btc was maybe $1 back then.
Same shit for me. I left PC on and went to a bar. After lots of beers I checked amount and concluded that whatever I get in BTC would show up on my elctricity bill at the end of month. Then deleted app without backing up wallet. Wasnt worth it because I would have to explain to parents whats the deal with electric bill and bigger issue was to replace PC after some time. Btc was maybe $1 back then.
Same for me with btc, i have mined it on my Dad's powerful PC he used for work and after a few days it was like 0.3 btc so i deleted all with the wallet it was practically worthless. This is what time machines are for I guess 🥲
The guarantee that standard computers are able to generate entropy for encryption is that every single piece of encrypted data online has remained fine. Every SSL certificate for every website is not generated with a Coldcard-like device but just a regular ol’ PC. Anyone can generate a secure seed without a hardware wallet and just use the wallet for signing. They can roll dice or use battle-tested .SecureRandom methods in decade old crypto libs for any language. This is why Coldcard is the bum in this case - it failed to do what every other general purpose device has done fine for decades, because of one awful bit of code that said “if true rng fails, do it silently, and use this pseudo rng process instead.” Show me any encryption software anywhere for general purpose PCs that does this. Ask an LLM to go find it.
No you don't need HW wallet, you can easily use e.g. Electrum in cold mode on the offline PC. But it has to bo offline 100% of time, always, forever.
Avoid websites unless they're open source and have been for years. And even then, download the code to your own PC. The one OP provides is good. Others are questionable.
An air gapped (no Wi-Fi card, no Bluetooth, Ethernet cable never plugged in) PC running Sparrow for offline signing is a pretty good solution. Only real attack vector is using a USB drive to transfer the transaction to be signed. A cheap web cam and QR codes can fix that.