Reddit Posts
does anyone uses a Duress PIN or decoy wallet?
Blockstream's Jade hardware wallet needs more attention!!
Actually test your seed backup before adding passphrase/multisig. I’m glad I did.
Retirement Attack: Many more details pointing straight to the CEO and CTO stealing the coins. This is more than enough evidence of probable cause to charge them and start a prosecution.
BIP-39 Passphrase Entropy & Hardware Wallet Passphrase Storage
Question about hardware wallets where you can't easily roll dice for the seedphrase
Post-Mortem: What Happened Between Samourai Wallet and Me
Sécuriser ses cryptos en 2026 : Pourquoi votre clé Ledger/Trezor n’est pas ce que vous croyez (Vulgarisation + Deep Dive)
Recovering a Schlidbach wallet (Cold Storage) hundreds of BTC
What actually happens to your crypto when you die? Has anyone dealt with this as an executor?
My hardware wallet PIN locked after I entered it wrong too many times. I still have my seed phrase. What do I do
NOCtura Wallet - Weekly Build Update #7
NOCtura Wallet — Weekly Build Update
NOCtura Wallet — Weekly Build Update #4
Moving your crypto off an exchange is the right call. But there's a problem nobody talks about.
Moving your crypto off an exchange is the right call. But there’s a problem nobody talks about
Hw wallet Blockstream Jade: initialised, but don’t see any difference
Has anyone actually used HYPNOSIS to recover a crypto cold wallet 12-word Seed Phrase? Need advice.
Your will becomes public record. Probably shouldn’t mention your Bitcoin in it.
Europeans! Are there any physical or virtual crypto cards that work for ATM cash withdrawals in Europe?
My plan for self custody against physical attacks.
For EU Users: How to Prove Wallet Ownership to OKX Using Sparrow + Hardware Wallet
Decoy wallets aren't useful. The only way to preserve your coins in a wrench atack is to be unable to access them.
Coldcard Delta PIN Bitcoin Private Key Recovery Vulnerability
I was tired of explaining multi-sig to friends keeping their sats on an exchange, so I wrote a post debunking the 4 big myths that always come up.
Why don't wallet softwares like Electrum and Sparrow support embedded secure elements?
If you securely create a Bitcoin seed phrase, then encrypt it using AES256 using a second seed phrase (or strong password), and store the cipher text online, and store the second seed phrase / password securely locally, could the first seed phrase be used securely as a factor in a multisig wallet?
PSA: Your crypto recovery phrase is not a password
Has anyone seen this NFT Machine? 👀 || it Requires a PIN code. Lmk
12 words? Boomers freeze, Gen X sighs… tutorial mode 4ever
Lost my second password on Blockchain wallet 8 years ago — any hope to recover my BTC?
Has anyone here actually tried AI PIn? What do you think?
What is the most secure mobile wallet?
New to cold storage - looking for coaching/feedback!
Hardware wallets: why doesn't Ledger or Trezor offer biometrics?
Urgent help needed I may have mistyped my pin number to prevent unauthorised sending of my bitcoin
I lost ALL my BTC yesterday, this is my story so it won't happen to you
TRIVIA for MOONS - Play Trivia for a chance to win from a pool of 1,000 MOONS. Tuesday December 19th 2023. 7 am EST (6.5 hours from this post). On Kahoot and YouTube Live!
Blockstream jade - what happens if you lose your SeedQR?
Self custody wallet planning for stacking (now) and spending (later)
Gigantix Wallet - The New Era OF Secured Cold Wallet
TRIVIA for MOONS - Play Trivia for a chance to win from a pool of 1,000 MOONS. Monday November 20th 2023. 9.30 pm EST. On Kahoot and YouTube Live!
Any open source, encryption based, 3/5 multi factor wallet already available? If not, can this be developed?
Please help me with this MetaMask/ Trezor problem.
How to Secure Your Crypto Wallet from Attack and Protect Your funds
Multi-Sig vs. Shamir Secret Sharing: Which Path Will You Choose to Safeguard Your Crypto?
TRIVIA for MOONS - Play Trivia for a chance to win from a pool of 1,000 MOONS. Monday 2 October 2023. EDT - 9.30 pm. On Kahoot and YouTube Live!
Is it possible for someone hack/steal from my hardware wallet?Or is it almost impossible?
Reminder to all the Celsius bankruptcy victims
A 96 yo woman’s letter to her bank. This is why we crypto.
$13,000,000 and victims of Sim Swap 2023
We're thrilled to introduce an innovative approach to secure seed phrase storage. Chaindeck, an entirely offline and analog solution that uses a unique deck of cards to encrypt information.
We're thrilled to introduce an innovative approach to secure seed phrase storage. Chaindeck, an entirely offline and analog solution that uses a unique deck of cards to encrypt information.
After almost 3 years of work, our small startup launched Chaindeck today! Introducing a new way to store and encrypt seed phrases using a unique deck of cards, completely offline and analog.
What's your self-custody strategy? Do you keep a backup hardware wallet on hand?
Blockstream Jade has new firmware. It looks like a nice improvement on an already great device.
Scam protection. It’s up to you and you only.
An Updated SUPER-Beginner’s Guide to Swapping, Bridging and Exchanging MOONs (the complicated way)
New user looking for a good hardware wallet, few questions
Only once you have paid for something with cryptocurrency do you realize how completely insanely insecure credit cards and bank transfers are
The BIP39 Passphrase, and how even the best hardware wallets let us down
The BIP39 Passphrase, and how even the best hardware wallets let us down
Bitbox02: A hardware wallet and it's solution to the open-source closed-source dilemma
How come no one ever mentions the Arculus cold wallet?
"If you opt-in for the service, as a user, you'll have to enter your PIN and consent to the backup process. Then the OS will encrypt and split the shards to send them to 3 different parties." - Ledger CTO
Set up your crypto-recovery plan with your spouse TODAY (STORY)
Everybody always recommends a hardware wallet like a silver bullet, and they're great until you realise that factory pre-sale tampering and fakes can leave you hugely exposed. It's even more plausible recent spate of wallet hacks
Exciting News - LocalMonero / AgoraDesk Free and Open Source Mobile Apps are Now Officially Out of Beta! Happy Birthday Monero!
Today is World Backup Day. Let's make sure your seed is secure and backed up.
How to avoid getting scammed and not lose your coin
Identity solution in Web3: What solution do you use?
what is happening with erc20 transactions ?
Mentions
> c) I think the costs aren't really small, they're just incorporated into the price. Often charged to the business which eats up profits which incentives the business to raise prices. For example, if you're selling your goods at a 20% margin and paying 3% in fees (on revenue) that's like 18% of your profit. I should clarify that it is negligible compared to the benefit of increased purchases. Cash makes people less likely to buy and they can always pay it "later". As a former business operator that dealt with a lot of that, it's not negligable and we by par prefer people pay with debit cards or even cash (despite the handling). > Also for the "sent and done" property. I don't think there's anything stopping networks from building this into a network. But I guess it either hasn't been asked for or networks that have built this haven't succeeded. It's a double edged sword for businesses too. It's not a technical challenge, but a business and operations challenge. Somebody has to decide if it's okay to cancel transactions. The whole idea of crypto is, nobody is in charge of that. So to implement something like that, we're suddenly no different than the existing systems ruled by the banks. It also means, the government can demand payments be stopped. > So definitely some pros and cons but the credit card model seems to be working pretty well in general. It works out of a necessity to strike the balance between convenience, oversight and profit for the middle men. For people like me, we take advantage of it, and try to profit by maximizing our cashback. The system doesn't care, it charges everyone else a high interest. Which to me at least means, everyone else is paying more than me. > It's a huge risk, not just for crypto. Agreed. It's also a relatively small risk right now, but who knows with AI. We're having huge breakthroughs in science and mathematics due to AI. > There's a ton of pros and cons for and against crypto but it hasn't proven itself as a global payments system i.e. It hasn't replaced Mastercard and Visa. It's great in third world countries. But that's mainly an access thing, rather than because it's a better technology. It likely never will replace MSC/VSA by the simple nature that the value addition that MSC/VSA adds is the real secret sauce of why consumers use them. It's not that it's electronic payments, because let's face it, there's debit cards with a PIN which is quite common in Europe. In fact, I rarely saw credit card transactions in my businesses. It was always, slip the card in, type in your pin and a receipt pops out approving it. Basically, crypto can't be a global payment system until there's some layer on top that solves the business and operational problems that MSC/VSA and the banks have solved. Until then, it's better as a money store and digital gold for those investing. > but I don't think it's necessary in their interest to make crypto payments better than Fiat payments. I think they're more just riding the wave. We'd probably need some big names like that to build more tech for crypto payments to gain more trust and adoption. Anything that tries to solve those issues, likely will need the same operational and business processes that MSC/VSA and banks have. Essentially we're back at the current system. The other aspect is the high cost (or should I say energy usage) of operating BTC. It's still a huge factor and yes, there are other crypto that is based on proof of stake that solves that, but we're in BTC sub. 😜 From a practical standpoint, I believe ETH is much better suited.
Disclosure: I’m on the support team at Ballet, a cold wallet brand. This is understandably unsettling. One useful distinction is that exposed customer information does not automatically mean the wallet or private keys were compromised. The official notice describes contact and shipping data exposure, not wallet backups or device secrets. The immediate risk is targeted social engineering. Treat unexpected wallet-related calls, emails, texts and letters as hostile—even when they know your name, address or device brand. A few practical steps: * Never provide recovery words, a PIN or remote access. * Reach support through a bookmarked official site, not a message link. * Secure your email and mobile account with unique passwords, strong 2FA and a carrier port-out PIN. * Avoid discussing holdings or recovery arrangements publicly. * Preserve evidence and contact local authorities if you receive a specific physical threat. Moving funds solely because contact data leaked may introduce transaction risk and won’t make the exposed identity information disappear.
Fair question, and it's the one that trips almost everybody up. The seed does get entered - just in exactly two situations, and never onto a screen. **Where.** Into a device, not into a website. On a hardware wallet you type the words on the device itself, using its own buttons and its own screen. The whole reason that little screen exists is so the words never touch a computer that a browser extension can watch. For a phone or desktop wallet, it goes into the wallet app on a clean device, and that's it. Never a web page, never a "verify your seed" tool, never support, never a wallet-connect popup, never anything that arrived by a link. **When.** Two moments, both of which you start yourself: 1. Your device dies, is lost, is wiped, or you forget the PIN. You buy a new one, choose *restore*, type the words into it. That's what it was always for. 2. Once, deliberately, right after you set it up, to prove your backup actually works. That second one is the part nobody does, and it's cheap. Withdraw a small amount to the wallet, then wipe the device and restore it from your written words before any real money goes near it. Checked on my own node just now: the next block is taking everything down to 0.44 sat/vB and an ordinary send is around 141 vB, so at today's price that test costs roughly 9 cents. People find out their backup was wrong years later, when 9 cents would have told them on day one. The rule that would have saved OP: **nothing legitimate ever asks for your seed.** Not Trezor, not a firmware update, not support, not a migration page. If a screen asks for it and *you* didn't just decide to restore a wallet, it's a theft, no exceptions. That's why it feels contradictory - the only person who should ever ask you for those words is you. Worth knowing what the seed actually is, too: it isn't a container with your coins inside. Your coins are entries on the blockchain and they never move. The words only regenerate the keys that let you sign, and the restored wallet then asks a node what those keys own. That's also why typing them into an online machine is permanent damage - the coins aren't in the phrase, but anyone who reads it can sign for you forever after.
As said in the thread I linked, the top tier hardware wallets can have multiple secure elements from different vendors in them. They're also open source and "organized" in such a way that even if the secure components were malicious, they couldn't do anything by themselves. You can read [this blogpost](https://blog.bitbox.swiss/en/best-of-both-worlds-using-a-secure-chip-with-open-source-firmware/) to understand. So no, it's impossible that "the wallet software can steal your keys". The fact that the seed is stored on one device is only a single point of failure in one scenario facing top tier attackers, and is defeated by the trick PIN feature. This is detailed in the comments of the post I linked. Your explanation of what is an M of N backup is not needed since the solution described in the post is also a M of N
This. What we generally call a passphrase is an extra bit of data that goes into the function to generate wallet keys; using different or no passphrase generates entirely different wallets. A passphrase is part of a wallet's *identity*, and thus can never be changed (one can, however, sweep the old wallet's funds into a different wallet, either existing or newly created with a different passphrase). A password or PIN, OTOH, is a protection on the local data of a wallet's software/firmware. It cannot protect the actual wallet, if someone else is able to generate its keys. A password can be changed, because it only affects the local storage. One can also have several wallet devices, or files, with keys for the same wallet, which can have different passwords/PINs.
I've been pondering this plan: \- 3 x yubikeys with pgp keys genenerated on device. be sure to get a strong PIN on each device \- sign and encrypt the seed words to all 3 devices ( single message or 1 message per device ) \- disperse the 2 of the 3 yubikeys to friends / family. they don't need to know its for BTC \- The encrypted message should be safe to store in multiple places, since it's already encrypted. This obviously doesn't solve succession planning as you are still the only one who can decrypt the message, but you can at least survive a total loss event of your home.
Yes. Loading a seed permeantly into the Jade is called "initializing" it. The seed isn't actually stored on the device because it doesn't have a secure element, but the seed is recreated with the help of the/a Blind Oracle via a PIN and the Blockstream App. If you don't initialize the Jade then it stays empty. When you power it up you simply select "scan QR", scan the QR seed you created when generating your seed, it loads in and functions as it would if you had gone the initialized route. Once you power off the device it automatically wipes itself. I've used the Jade and The Jade Plus this way for years. It's actually identical to the SeedSigner when used this way. There is a slight difference in how the SeedSigner deals with derivation path and multisigs so be aware of that if you have both devices and try to switch back and forth. The same seed loaded on a Jade will function instantly in a multisig, but the same seed loaded in a SeedSigner will require you to provide the derivation path before it can sign a transaction in the same multisig. That's not the Jade's fault, it's the way SeedSigners work.
\>blind PIN server (“blind oracle”) to encrypt your key material — the oracle never sees your actual seed, hence “blind" trust me bro
am a big fan of blockstreams jade few side facts: \- On setup, you choose a PIN. This PIN is combined with a **blind PIN server** (“blind oracle”) to encrypt your key material — the oracle never sees your actual seed, hence “blind" \- The decryption key is effectively **split in two**: one part lives on the device, the other is retrieved from the oracle (via blockstream mobile green wallet) each time you unlock \-> All communication between Jade and the Green app is encrypted end-to-end. Net result: if someone physically steals a **locked** Jade, there’s genuinely nothing of value to extract — no seed sits fully assembled on the device. \- Fully **open-source hardware and firmware** — you can literally build your own from the published GitHub repo if you’re into that. And for all Bitcoiners: it's BTC and LBTC only, with LBTC swapping features also for Jade
Going forward, you might want to get terminology right, otherwise you might get bad info or use features wrong. Your 12-24 words is the Seed Phrase (or Seed). Your Pass Phrase ("25th word") is an advanced feature to mask a wallet. A Password or PIN would unlock your device. Good luck on your journey!
https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/ check the section on how they generate a seed their firmware is also fully open source but if you still don't want to trust their entropy, you can roll dice for your seed and you can get a valid 12th/24th checksum word directly via the hardware/firmware easy to use for whichever route you prefer, and I like the user interface (touch based, but cleverly implemented via 3 touch zones on either size of the device - total of six - which makes entering PINs and passphrases, or restoring seeds, on a device with no keys or buttons relatively pain free) and the form factor (size of a thumb drive) I did not roll dice, but I use passphrase whether or not the device asks you for a passphrase after your PIN upon boot up is a simple option toggle, which is great for if you want to set up a dummy wallet -- if the device doesn't ask for a passphrase, why would an attacker assume you use one? when you need to access your passphrased wallet, simply enter the PIN and re-enable the prompt, then disable again when you're done I'd probably prefer if this could be implemented with a dummy PIN instead, maybe other wallets have such functionality, but this is the one that I have and those are the reasons I like it
I lost no funds. So I upgraded the firmware, changed my PIN and rolled the dice to generate new seed and pass phrases right before I nuked it and threw it in the trash
The Jade doesn't connect to Blockstream's website at all. The Jade has no network connectivity and is fully offline. Blockstream's Blind Oracle simple provides a key that is used to decrypt the seed stored on your device. It never receives that seed at all and it is also completely blind as to the PIN you use to retrieve the blind oracle key. Again, your seed phrase never leaves your airgapped device. One nice feature is that this process is fully open source and the Jade provides an option for you to host this blind oracle PIN server yourself. This means that you'll be in full control of the blind oracle and won't need to rely on Blockstream's server at all. It also means that if you were to ever lose your Jade, you could take your blind oracle server offline and effective remotely brick your HWW, which would prevent anyone from being able to steal your funds from it. You could also host your blind oracle server locally on your LAN without it exposed to the internet, which would make your Jade only usable within the confines of your home. Some neat features that are only available to the Jade HWW.
By saying this, I now only need to check 1296 combinations rather than 10000 to find your PIN number
history doesn't always repeat itself, but it always rhymes. Same issue with before banks, people hoarded wealth at home in a safe, with a "secret" combo. If people knew you were "rich" they come to your home and attacked you to get the safe opened. Centralized banks, fixed that problem. (mostly) But Then the invention of ATM and debt cards... again... "secret" pin code... easily given to a criminal at gun point. Crypto, is the same cycle all over again. this time it is a passphrase rather than PIN or safe's combo at home.
Did you also have a PIN ? Was the ledger connected to the PC when the transaction was broadcast ? What address did the coins go to ?
Crypto isn't a being that is subject to laws but you most certainly are. If your neighbor kept their ledger on a desk and the PIN on a sticky note and records you on camera taking it, you bet your ass you're going to court. It's accurate to say that it's easier to commit anonymous financial crime with crypto, i.e. if a north Korean hacking group found your plaintext seed or convinced Grandma to buy crypto and send it to them then you're not going to get it back.
Here is how you handle the workflow so you don't lock yourself out: 1. Generate your new seed phrase using your chosen method (dice, offline tool, etc.). 2. Derive a receive address from that new seed phrase. If you have a second device or software wallet setup offline, grab it from there. If you used an offline BIP39 tool like Ian Coleman's, copy down 1 or 2 of the generated addresses (and the xpub/zpub if you want a watch-only setup). 3. Connect your Ledger (with your current/old seed) to your wallet software (Ledger Live, Electrum, Sparrow, etc.). 4. Send a small test transaction from your Ledger to the new receive address you generated in step 2. 5. Once confirmed, send the rest of your BTC to the new address. 6. Once everything is safely on-chain under the new address, wipe your Ledger (enter wrong PIN 3 times) and restore it using the new seed phrase. When you open your wallet software again, your funds will be right there. As for your specific questions: Adding a passphrase (25th word) creates a new wallet, but it still derives from the base 12 or 24 words. If the base seed itself lacks proper entropy, an attacker who breaks the base seed only needs to crack your passphrase next. If you genuinely suspect weak initial entropy, migrating to a clean base seed is much safer than just relying on a passphrase over a weak foundation. Should you act? Ledger uses dual hardware TRNGs on the chip and wasn't impacted by the MicroPython PRNG fallback issue that hit Coldcard. If you're paranoid or just want peace of mind, migrating via the steps above is safe. If you trust your current setup, staying put is fine too.
Seems like 6 is the standard “secure” length right now. I’m more talking about something secure into the future with advancing tech + weighing against this Coldcard incident, where one RNG bug means your passphrase is your only protection. More words = more time to react to a security incident. I think this only works if you can PIN protect your passphrase for day-to-day use though, which I’ve only seen offered by Ledger.
You do you, but this means the only thing standing between your coins and a person who comes across your stateful wallet is a PIN.
My idea around the 25th word and device PIN would be you release the 25th word and PIN upon death. Lawyer, will, etc. That way you can give your 24 to your family before you die and the lawyer can’t screw you over.
I don’t think I’ll do multi sig for various personal reasons, but 2 Trezor devices loaded with the same seed phrase you generate from dice rolling both setup with device PIN and 25th word seems to be the best thing you can do imo. Multi sig just makes things difficult as a person and not acting as a business entity. This way you can give one to a family member, don’t give them the pin or the 25th word, and just give that part as part of your will or something.
Banks and card networks usually refund clearly unauthorized transactions, but they can deny claims if they decide you were negligent (for example, willingly sharing card details or PIN). Idk why people think banks are so enthusiast about giving back the money you lose all by yourself, it doesn't work like that lol
Nah, I can walk into my local bank with ID and I can get money out even if I have lost my PIN and card for whatever reason.
Depends what you mean by hackable. If someone gets to your cold card and guesses your PIN, they can view the seed phrase on the display. But, it will nuke itself if you guess wrong a few times, and so far no one has found a way to bypass this pin even with specialized tools (unlike trezor)
The older model Trezor One had a flaw which allowed a determined hacker, WITH a physical access to the device, to figure out the PIN *if* you didn't use passphrase. So a flaw but a different order of magnitude, required your wallet to be physically stolen for starters.
Not meaning to inflame but you obviously seem knowledgeable. Wasn't there an issue with Trezors in the past where, if an attacker had physical access to your device, they could essentially try every PIN until they got in? I believe that having a passphrase defeated this problem but I remember being turned off by Trezor due to that.
No way, they are being exposed as incompetent devs, Just hours ago: COLDCARD FIRMWARE HOTFIX UPDATE CAN BRICK DEVICES A new bug has been identified in COLDCARD's emergency firmware hotfix. While the update fixes the original entropy vulnerability, researchers say a temporary hardware RNG error can leave the device stuck on a fatal error screen before the PIN prompt, preventing users from accessing the upgrade menu. Source: https://x.com/BitcoinNewsCom/status/2084264904370847761 ______ To be honest, using now a Cold Card is like "rolling a dice" hoping they do not mess around. If community do not make accountable stupid actors more like these will come. You have to fucking understand something. If you want to sell hardware devices you have to spend money on good team of software engineers. Those guys don't know what they are doing and is a ticking bomb to use a now exposed insecure hardaware wallet that has no serious devs with no basic security practices.
Thanks! People usually have a knee-jerk reaction to it, so your open-mindedness is appreciated. Previously, I considered my singleHW a single point of failure: if you were kidnapped with it and tortured you would give its password. But this can be solved with a trick PIN which resets the HW: you input it and then your kidnappers can't do anything: the seed is no longer there and they must obtain the 2/3 backups. (Though you'd probably want to work on the kidnapping not happening, lmao) The other possible issue is what we've seen with ColdCard, but I don't see how it could ever happen again. The (real) top tier hardware wallets already use multiple sources of randomness. Even if the ultimate AI came out tomorrow, I don't think it would be able to extract the seed from a top tier hardware wallet. Even if a bug allowing this would be found, the attacker would need to steal your HW or hack the PC/phone you're using with it too, so not really a single point of failure I would say
It's in a big city, did call their local PD and they pretty much told me "sorry dawg, you gotta ago through your local PD and they'll contact us if they see fit to do so." One of the things I did to protect myself is slap a PIN on my IRS filings so hopefully that helps prevent any of the fraudulent W2 stuff. Also reviewed my SSA file for anything suspicious and fortunately didn't find anything. In the meantime I am basically just keeping frantic track of everything that I possibly can right now and acting on any new ideas or items that come up as quickly as they do. Fortunately as of right now it has only been attemps, nothing successful. Still sucks to deal with.
I'm also a fan of it because of the added security beyond a simple PIN hardware wallets might rely on as protection against physical device theft
What about wrench/physical attacks, you have a gun pointed at your head, surrender your words, ledger PIN or whatever, the attacker uses it and finds a balance of zero :trollface:
You’re not logging into your wallet. Your hardware device PIN allows you to access your hardware device. The hardware device provides the secret required to authorize transactions via your signing on the device. You are not logging in anywhere.
Some other vulnerabilities sited by AI # Understanding the Most Common Attack Vectors on Bitcoin Hardware Wallets Hardware wallets (such as those from Trezor, Ledger, Coldcard, and BitBox) are widely considered the gold standard for self-custody. By isolating private keys inside dedicated, offline silicon—often secured by a Secure Element or microcontrollers with cryptographic sandboxing—hardware wallets shield user credentials from online malware. However, no security model is absolute. Hardware wallets mitigate remote network threats, but they introduce physical, operational, and supply-chain attack vectors. Below is an overview of the primary attack vectors targeted against Bitcoin hardware wallets. # 1. Social Engineering and Seed Phrase Extraction **Risk Level:** Critical (Most Common) **Mechanism:** Remote / Operational The weakest link in hardware wallet security is rarely the silicon itself—it is human operational security (OpSec). Attackers bypass hardware protections by tricking the user into exposing their BIP-39 recovery seed phrase. * **Phishing Sites & Fake Wallet Apps:** Attackers create replica wallet management interfaces (e.g., fake desktop companion apps or web portals) that prompt the user to "verify" or "back up" their 12- or 24-word seed phrase on a keyboard. Once typed into an internet-connected device, keyloggers or malicious sites instantly capture the seed. * **Fake Support Agents:** Attackers impersonate hardware vendor customer support or technical representatives via Telegram, X (formerly Twitter), or email, guiding victims to enter their seed phrase into online recovery tools. * **Unencrypted Cloud Backups:** Users who digitize their seed phrase (e.g., taking a photo, storing it in text files, or syncing to cloud storage) leave their keys vulnerable to automated web scrapers and credential stuffing. # 2. Host-Side Malware and Address Manipulation **Risk Level:** High **Mechanism:** Man-in-the-Middle (MitM) / Host-level Hardware wallets rely on host devices (computers or smartphones) to construct transactions and broadcast them to the Bitcoin network. If the host machine is compromised, malware can manipulate the data displayed on the computer monitor. * **Clipboard Hijacking / Address Swapping:** Clipboard malware monitors copy-paste buffers for Bitcoin address formats. When a user copies a recipient address, the malware swaps it with an attacker-controlled address. * **Change Address Tampering:** In Bitcoin's Unspent Transaction Output (UTXO) model, transactions typically send leftover funds back to a newly generated "change address" owned by the sender. Malicious wallet software on a host computer can replace the user’s legitimate change address with the attacker's address. If the user fails to verify all details on the device's hardware screen, the change output is diverted to the attacker. * **Blind Signing & Screen Discrepancies:** If the hardware device lacks a clear screen or if the user relies on "blind signing" without carefully verifying every output address and sat/vByte fee rate directly on the hardware screen, host malware can alter transaction parameters undetected. # 3. Supply Chain and Tampering Attacks **Risk Level:** Moderate to High **Mechanism:** Physical Interception Supply chain attacks occur before the hardware wallet reaches the end user. * **Pre-configured Recovery Phrases:** Fraudulent resellers or compromised shipping intermediaries generate a pre-seeded wallet with a known 24-word recovery phrase, leaving card inserts printed with the pre-determined words inside the box. Once the victim deposits funds into the generated addresses, the attacker sweeps the balance. * **Modified Hardware / Interdiction:** Advanced threat actors intercept packages in transit to flash rogue firmware or modify internal components (such as installing a hardware keylogger or replacing a legitimate Secure Element chip with a tampered microcontroller). * **Counterfeit Devices:** Attackers manufacture lookalike hardware casing containing malicious circuitry that records setup inputs or weak key generation routines. # 4. Physical Attacks and Side-Channel Analysis **Risk Level:** Moderate (Requires Physical Access) **Mechanism:** Non-Invasive & Invasive Hardware Analysis If an attacker gains physical possession of a hardware wallet, they may exploit hardware vulnerabilities to extract PINs or internal cryptographic keys. * **Voltage / Electromagnetic Fault Injection (Glitching):** By injecting precise voltage spikes or clock fluctuations during chip execution, attackers can disrupt logic checks (e.g., bypassing PIN entry counters or causing microcontrollers to dump internal flash memory). * **Side-Channel Analysis (Power & Timing Analysis):** Attackers measure micro-variations in power consumption or electromagnetic emissions during cryptographic operations (such as ECDSA or Schnorr signature generation). Statistical analysis of these traces can reveal secret keys. * **Physical Chip Probing & Decapsulation:** Attackers use acid to remove protective plastic encapsulation from integrated circuits, utilizing micro-probing needles or focused ion beams (FIB) to directly read memory traces on the silicon die. # 5. Malicious Firmware and Entropy Weaknesses **Risk Level:** Low to Moderate **Mechanism:** Software / Cryptographic * **Unsigned or Rogue Firmware Updates:** If a device fails to properly enforce cryptographic signature verification on incoming firmware binaries, an attacker could trick the user into flashing malicious firmware that exfiltrates keys over USB or bluetooth. * **Compromised Random Number Generators (RNG):** Key generation depends on high-quality entropy. If the hardware wallet's True Random Number Generator (TRNG) is flawed or deliberately backdoored, it may generate predictable seed phrases. Because the seed appears valid, the user will not suspect that the underlying private keys are deterministic and easily guessable via brute force. # Summary of Mitigation Best Practices 1. **Never digitize or type your seed phrase on a computer or phone:** Enter seed phrases strictly into the physical hardware wallet device itself. 2. **Verify on-device:** Always double-check recipient addresses, change addresses, and fee amounts on the hardware wallet's built-in screen before approving transactions. 3. **Buy directly from manufacturers:** Avoid third-party resellers or opened packaging to prevent supply-chain tampering. 4. **Use an optional BIP-39 Passphrase:** Adding a custom passphrase (sometimes called "the 25th word") creates an encrypted hidden wallet, protecting funds even if the 24-word physical seed backup is compromised. 5. **Verify cryptographic signatures:** Verify software companion downloads (GPG signatures) and hardware firmware authenticity upon initial setup.
I have a Cold Card Mk3, which is an affected device. Fortunately I didn't use it to generate my seed and used casino dice on a different vendors device instead. I bought into the hype that Cold Card was so amazing which is of course why I bought one. But I never even really used it for anything because I was so unimpressed with the usability and general design of the thing from the moment I got my hands on it. It really did strike me as style over substance. For example if you forget your PIN, you get something like 12 retries and then the device is BRICKED. Not wiped... Bricked. It cannot be factory reset. Why? I have no idea. I don't see why a device couldn't be factory reset and you can continue to use it. Bricking it just seems like security theatre, in a world where companies are competing to be the "most hardcore" about their security practices. That's just one example. There were at least half a dozen silly design choices that went into the device that made me roll my eyes, but it was years at this point and I can't remember them. I just know that all I had to remember was, this device is a poorly designed piece of shit. Looks like it really was the amateur hour that it appeared to be all along over at Coinkite.
Post is by: Intrepid-Honey and the url/text [ ](https://goo.gl/GP6ppk)is: /r/CryptoMarkets/comments/1vcj3l3/i_built_hodltight_a_clean_pwabased_holdings/ Hey everyone, I wanted a simple, secure app to track my holdings across my devices, so I built **HODL-Tight**. **What it does:** It lets you manually log your transactions (buys/sells) for different assets to track your average buy price, current portfolio value, and profit/loss in real-time. You can quickly log in using your Google account. I originally created this just for myself to keep things organized. Since it's working well for me, I figured I'd share it—if anyone else finds it useful, feel free to use it! **Key Features:** * **Progressive Web App (PWA):** Easily install and run it on any phone, tablet, or desktop browser. * **PIN-based Encryption:** Your portfolio data is encrypted directly using your custom PIN, keeping your holdings secure and private. * **Minimalist Dashboard:** Clean transaction logging and performance tracking. **Try it out:** [https://hodl-tight.web.app](https://hodl-tight.web.app/) Would love to hear your thoughts or feedback! *I am a bot, and this action was performed automatically. Please [contact the moderators of this subreddit](/message/compose/?to=/r/CryptoMarkets) if you have any questions or concerns.*
Imagine you buy a safe to keep your valuables in. However, for this particular brand of safe you can only set a 1 digit PIN number between 0-9.
Isn't it supposed to brick itself after too many attempts to guess the PIN? I forget.
Yes and no—as long as you **as soon as possible** move it to a safe device with **a new seed**. If your password has a high entropy (at least 128 bit) which is unlikely, then you would be totally safe. However, people are bad at generating entropy. We must therefore assume that many passwords have low entropy. It is extremely likely that, as a first step, either the original attacker or an imitator will try the pre-calculated seeds with combinations of numbers (e.g., 4- and 8-digit PIN codes, dates of birth) in an attempt to crack additional wallets.
I updated the firmware on my mk4 this morning and can't open it anymore. Keeps getting stuck on "Verifying..." or "Loading..." screens if I'm lucky enough to get past the PIN (happened once).
>Then you have your device's pin that has to be manually entered on the device itself before the wallet even opens up for any outgiong transactions. No accusation, just out of curiosity: what does the transactional PIN have to do with this story?
Yes you can add an additional passphrase (25word) with ledger. And linked it to a new PIN. You will need to transfer your assez ti the new adress (hence new private key). A passphrase is like a password you add to the seed. Actually you can and should store the vanilla 24 words offline. And you can store the additionnal passphrase online in a password manager . Lots of video online and ledger website explains it
It depends on the wallet. But a common method is to prompt for an optional passphrase once you’ve entered your PIN/password. No passphrase = base wallet, passphrase = completely different wallet. As far as risky, it depends on your OpSec. Personally, while I have my seed on a metal backup, my passphrase only exists in my head. I boot up my wallet every few months to make sure I remember. But if I have a head injury or lose my marbles, my stack becomes a contribution to the scarcity of bitcoin.
Summary for us smooth brained folks: This is one of the **most serious hardware wallet security advisories in years.** It affects the fundamental randomness used to generate Bitcoin private keys, meaning some wallets may have significantly less security than users believed. # What happened * Coinkite disclosed a flaw in the random number generation used when creating seeds on several COLDCARD hardware wallets. * **Most affected:** Mk3 devices running firmware **4.0.1 or later**, where the issue has existed since **March 2021**. * **Also affected (to a lesser extent):** * Mk4 before **v5.6.0** * Mk5 before **v5.6.0** * Q before **v1.5.0Q** * Existing wallets **cannot be repaired with a firmware update**. If your seed was generated using affected firmware, the recommended solution is to **create a new seed and move your funds**. # Why it matters * **This is a cryptographic entropy failure.** Hardware wallets rely on high-quality randomness when generating seed phrases. If the randomness is reduced, an attacker's search space becomes much smaller, making it theoretically more feasible to recover private keys than intended. * **Severity varies by device.** * **Mk3:** Potentially severe enough that Coinkite is advising essentially **all affected users to migrate immediately.** * **Mk4/Mk5/Q:** The advisory states these seeds have roughly **72 bits of entropy instead of the intended 128 bits.** While **72 bits is still an enormous key space** and not practically brute-forceable with today's publicly known computing capabilities, it represents a substantial reduction from the intended security margin. Coinkite is therefore recommending migration as a precaution. # Bottom line The real story isn't that COLDCARD wallets have been "hacked"—there is **no evidence that anyone's funds have been stolen because of this bug**. Rather, Coinkite discovered that some devices generated wallets with **less cryptographic randomness than designed**, undermining one of the core security assumptions of a hardware wallet. Out of caution, they are recommending users generate entirely new wallets on fixed firmware (or via the dice-roll method) and transfer funds. **What to watch:** * Coinkite's forthcoming **technical postmortem**, which should explain exactly how much entropy was lost and under what conditions. * Whether independent cryptographers confirm the practical impact and whether any feasible attack emerges. * Whether any thefts are linked to this vulnerability. At present, the advisory appears **preventive rather than reactive**. # Practical advice If you own a COLDCARD: |Device|Action| |:-|:-| |**Mk3 (firmware 4.0.1+)**|**High priority:** Generate a new wallet and migrate funds as soon as practical.| |**Mk4 / Mk5 (<5.6.0)**|Update firmware, generate a new seed, and migrate funds.| |**Q (<1.5.0Q)**|Update firmware, generate a new seed, and migrate funds.| |**TAPSIGNER / SATSCARD / OPENDIME**|**Not affected.**| If you were using a **strong, unique BIP-39 passphrase** (the optional "25th word," **not** your device PIN), your immediate risk is lower because the passphrase adds an independent secret. Even so, Coinkite still recommends migrating to a newly generated seed when feasible.
you don't get your money back anywhere if it's your fault... your fault means willingfully, grossly neglect, etc... In MOST cases you get all your money back, you got phish through a phone call, you get your few hundreds back. Thiefs just can't start to withdraw/transfers several thousands all that easily, lol, even if they have your PIN/Passwords. Someone attempt to transfer 45000$, there are security checks to slowdown the transfer, pause the transfer or stop the transfer entirely. In crypto? you can lose 50millions dollar on a heartbeat. This isn't an argument, it's straight common sens. Crypto is incredibly unsafe against fraud for the common user, hence you'll never ever fucking see "mass adoption".
💯— Bitcoin = 12-24 seed phrase - plus other ways to secure it vs. Bank = 4 digit PIN code + constant hackers and security breaches but your banker will say “trust me bro your money is fdic insured.” Meanwhile banks hold fractional reserves.
My favorite is when people say quantum computing will crack bitcoin. But don’t mention the fear of it cracking their 4 digit ATM PIN code
Legend. If you currently use a software wallet, that is okay, but make sure to purchase a hardware wallet soon (this is a large amount of Bitcoin). I recommend the BitBox02. Get the Nova if you want to use it with iOS, for Windows the regular BitBox02 is enough. Buy it directly from bitbox.swiss, not Amazon or another seller. Generate a fresh 12 word seed phrase with that hardware wallet, write down the words with a pencil (more durable than a pen) & store it in a safe location. Those 12 words are your Bitcoin essentially, NO ONE should ever get them, otherwise your Bitcoin WILL be gone in no time. Anyone who asks for those words is a scammer, no exceptions. Not the police, not tech support, no one. The hardware wallet itself is not critical, as it's secured by a PIN you choose when you set it up. After 10 unsuccessful attempts it will factory reset & wipe out the keys stored inside the wallet. So you can pretty much keep that thing in your desk drawer.
Ah, you mean the mobile app or the desktop app? I had troubles around the oracle+PIN which is a PITA especially if at any point Blockstream server goes bust.
I suppose the stage where it is supposed to show the correct BTC balance instead of 0 in the Blockstream app? After entering the PIN to unlock the Blockstream jade, and using the Blockstream app on my phone in conjunction with the jade plus to access the wallet using QR codes, the wallet that was generated on my phone said 0 BTC, and I tried it over and over again. I was using it in watch-only mode.
This is an AI generated response from Brave’s Leo. Sorry if any of this is redundant Recovering Bitcoin from old Android phones without a PIN, password, or seed phrase is extremely difficult and often impossible, especially if the device cannot be accessed or rooted safely. Since Schildbach Bitcoin Wallet (now known as Bitcoin Wallet) stored private keys locally on the device, your only chance lies in successfully extracting the wallet data file (wallet.protobuff or similar) from the phone’s internal storage without wiping it. Step-by-step instructions Prerequisites The original Android phone(s) with the wallet still intact. A computer (preferably running an older OS like Windows 7 or Linux, due to driver compatibility). USB debugging enabled (if previously activated). Knowledge of ADB (Android Debug Bridge) and fastboot tools. Potentially, a working battery and functional USB port on the old device. Recovery Steps Try enabling USB debugging (if not already): If the phone boots normally and you can access settings, go to Settings > Developer options and enable USB debugging. If Developer Options is locked or inaccessible, this path may not be available. Connect the phone to a compatible PC: Use a original or high-quality USB cable. Try multiple USB ports and PCs if possible. Install legacy Android USB drivers (e.g., from Google or the phone manufacturer for 2010-era devices). Use ADB to pull wallet data (if USB debugging is on): Install Android SDK Platform Tools. Run: adb devices adb pull /data/data/de.schildbach.wallet/files/wallet.protobuff (Path may vary slightly depending on wallet version.) If successful, import this file into a modern Bitcoin wallet that supports legacy formats. If USB debugging is off and the phone is locked: Your only option is to gain root or recovery access without wiping data. Look for device-specific exploits from 2010–2013 that allow temporary root or recovery mode without data loss (e.g., via unrevoked, SuperOneClick, or GingerBreak). Try booting into custom recovery (like ClockworkMod) if previously installed. Use Android Studio or ADB in recovery mode (advanced): Boot into recovery (usually Volume Up + Power). If ADB works in recovery, try pulling the /data partition. Note: Most stock recoveries do not support ADB; custom ones do. Consider professional data recovery services: Some specialists focus on mobile forensic recovery and may extract chip data directly (e.g., via JTAG or chip-off methods), though this is costly and not guaranteed. Once wallet file is retrieved: Use the original Bitcoin Wallet app or compatible software to open the file. Transfer funds to a new, secure wallet immediately. ⚠️ Warning: Any attempt that involves flashing, factory resetting, or improper rooting may permanently erase your wallet data. Proceed with extreme caution.
I know I had hundreds of btc based upon pictures and screen shots on my phones I had after the one in question. There is no PIN or password. It's also been a long time since I used Linux, Which I'm aware is the best OS to try to recover the BTC
Thanks for the advice. Yeah, alot of DM'S alredy. Anyway, The device in question is an: Android Incredible model number: ADR6300VW I belive the android version is 2.3.4 (the device is dead, I need to charge it to give further info. *side note: google stopped supporting this OS awhile ago. Which makes this harder to recover. The Schlidbach app is not on the phone. But i believe once I access super user I can access the protected files. (My other apps, wallpaper etc are still there, so no. It hasn't been factory reset or anything. It does have an SD card. To my knowledge and as far as I can recall, there was no PIN, password or anything about a backup. It would just prompt " The amount in your wallet is quite high for carrying in your pocket. Please move some to a safer place" As far as I've researched the phone NEEDS to be rooted to gain access to the protected files. But as you said, rooting the phone like whiching the OS the clock work recovery mod may or in most cases WILL delete all data.
If the recovery phrase is correct and complete, the assets should be recoverable because they are on-chain, not stored inside the hardware device. Before resetting anything, slow down and verify the phrase privately, never type it into a website, never share it with support or DMs, and follow the manufacturer’s official recovery instructions only. Most losses in this situation come from panic or phishing, not from the locked PIN itself.
The problem with being this level of delusional is that the internet in 2000 was useful and crypto is still useless. Do people even talk about Web 3.0 anymore? Decentralized social media, ID, PIN, media, etc? Web 3.0 got replaced by DeFi, NFTs, RWA and a bunch of other useless shit that only serves to keep the scam going. At this point smart contracts from ETH SOL ADA or whatever are no different than any of the promises of bitconnect. More than a decade and nobody knows what the hell crypto does or what it will do. At the same time AI has revolutionized the world. AI is doing it all. War, cybersecurity, hacking, your homework, etc. We don't need a delusional conversation. If you have anything to say, use coherent arguments rather than aspirational commentary.
Before you wipe anything, treat the recovery words as the source of truth and keep the process boring. A Ledger reset after too many bad PIN attempts is a normal safety path. It does not delete coins from the chain. What matters is restoring the same recovery phrase, and the big rule is: enter those words only on the hardware wallet itself. Do not type them into Ledger Live, a browser page, a phone note, a support chat, or any DM. The order I would follow: 1. Check that your paper backup has the full word count and the words are in exact order. Do not photograph it or run it through any online checker. 2. Use Ledger Live only from Ledger's official download/app source, then choose the restore-from-existing-phrase path on the device. 3. Enter the words on the Ledger screen/buttons, not on the computer keyboard. 4. Reinstall the apps and add the accounts again in Ledger Live. Balances may look empty until the relevant accounts are added and synced. 5. Once restored, do a tiny test transaction before moving anything large. If you are genuinely unsure the written phrase is correct, do not test it in a software wallet or random seed checker. The safer route is Ledger's official recovery-check flow on a trusted Ledger device, or official support instructions that never require you to reveal the phrase.
Post is by: dantey_korir and the url/text [ ](https://goo.gl/GP6ppk)is: /r/CryptoMarkets/comments/1tnhtk8/my_hardware_wallet_pin_locked_after_i_entered_it/ I’m kind of stressing right now and hoping someone here has gone through this before. I was setting up my Ledger on a new laptop earlier today and somehow completely blanked on the PIN I usually use. I tried a couple combinations that I thought were right but after too many failed attempts the device locked itself and now it says it has to be reset before I can use it again. The part that’s making me nervous is that I still have my recovery seed phrase written down on paper and stored safely. I checked it and I’m pretty sure it’s correct, but the idea of doing a factory reset on the wallet still feels risky for some reason. I keep thinking “what if I reset it and then something goes wrong during recovery” or “what if I copied one word wrong years ago and never noticed.” From what I understand, the crypto itself is not actually stored on the Ledger device and the seed phrase is what really matters, but I’ve never had to fully recover a wallet before so this is new territory for me. I also saw mixed comments online where some people say the process is simple while others talk about recovery failures caused by mistakes in the phrase order or spelling. I haven’t reset the device yet because I wanted to ask people who have actually done this before. Is the reset process completely normal in situations like this? Did your balances and accounts come back normally after restoring from the seed phrase? Also is there anything important I should double check before starting the recovery process? Would appreciate advice from anyone who has dealt with this firsthand because right now I’m honestly nervous about touching anything further. *I am a bot, and this action was performed automatically. Please [contact the moderators of this subreddit](/message/compose/?to=/r/CryptoMarkets) if you have any questions or concerns.*
Post is by: AdGlass6838 and the url/text [ ](https://goo.gl/GP6ppk)is: /r/CryptoMarkets/comments/1tnayd9/my_hardware_wallet_pin_locked_after_i_entered_it/ I got a new laptop and was setting up my Ledger again. Kept entering what I thought was the PIN and it locked after too many attempts. The device now says it needs to be reset. I have the seed phrase written down and I know it's correct but I'm scared to do the factory reset in case it somehow goes wrong. Is the reset completely safe if I have the seed phrase *I am a bot, and this action was performed automatically. Please [contact the moderators of this subreddit](/message/compose/?to=/r/CryptoMarkets) if you have any questions or concerns.*
Great questions, let me break this down. **Seed phrase vs. private key** Your steel seed backup is enough. The seed phrase *generates* all your private keys deterministically (BIP32/BIP44), so you never need to write down individual private keys separately. Just the 24 words, correctly backed up, is the standard approach. **The passphrase (25th word) problem** This is the real challenge. The passphrase is powerful but if your friend loses it, the funds are gone forever. Options: \- **Another steel plate** stored in a completely separate location (bank safe, trusted family member) \- **A hardware secrets manager** like Seedkeeper: stores the passphrase encrypted in a secure chip, PIN-protected. Even if someone finds the card, they can't extract the passphrase without the PIN. It's essentially a hardware password manager that works offline \- **A sealed envelope with a notary**: low-tech but works **For your friend specifically** Since he's bad at remembering passwords and doesn't use a password manager, I'd actually lean toward [Seedkeeper](https://satochip.io/product/seedkeeper) here. It stores sensitive info in hardware without requiring him to memorize anything - just keep the card safe and remember a PIN. The [Satochip Academy has a good explainer on passphrases](https://satochip.io/passphrase/) if he wants to go deeper. Bottom line: steel plate for the seed, separate secure location for the passphrase, and never store them together.
“Brute force successful, please enter your 4-digit PIN”
That works for people comfortable with the setup, the backup cards plus PIN approach removes a lot of the complexity. Main thing is making sure they actually know what the cards are and what to do with them.
Why wipe the Trezors if they're PIN protected? They're arguably safer than plaintext seedphrases. Another option would be to properly encrypt your seedphrase with a memorable but secure password. Upload to secure online storage. Take two wiped/new Trezors. On arrival immediately restore your old wallet and create a new one. Move funds from old to new. There is minimal risk there as the seedphrase is protected by two security systems and only for a day or two.
A bitcoin private key is usually generated by a *wallet*. It is usually backed up with 12, 20, or 24 words (the "seed phrase") which can be used to backup/recover all private keys generated by the wallet. If you have a hardware wallet (e.g. Trezor, ColdCard, Ledger, etc.), a PIN (& the device) may also be enough to access the funds. If you have a wallet on a phone or PC, access to the phone/device/account may be enough. If you have funds on an exchange, login credentials may be enough.
If you'd just cut out most of the fluff then most people wouldn't have cared that you used an LLM to help form your thoughts into words - but instead it took a whole page to say this: *Self-custody solved the "exchange risk" problem, but it created an inheritance risk most people ignore. If your heirs don't have not just the seed phrase but also the passphrase, wallet details, PIN, and recovery instructions, your crypto can effectively die with you - regardless of wills or legal ownership.* And then you could've ended with something like "What're the best options we currently have for dealing with crypto inheritances, what do you use?" 🤷
Hi, I saw your post regarding the lost PIN on your Trezor from 2017. Since you have a significant amount (50,000€+), please be very careful with people offering "hacks" in your DMs. I work as a partner with KeychainX. They are a legally registered recovery firm that specializes in high-value hardware wallets. They have the computational power to recover PINs and passwords without risking your funds. They work on a "No Cure, No Pay" basis (20% fee only upon success). If you’re interested, let me know your email, and I’ll introduce you directly to Peter at KeychainX via a CC email to ensure your case is prioritized. Best regards, my email husseinjunior90@gmail.com
If UK has done that 20 years ago with Blackberry PIN they could have avoided the entire country burning that summer.
Then it is most likely a Nano S. If you have the 4-digit unlocking PIN code, you can recover your funds (even if you list the 24-word recovery seed phrase). Connect the ledger on a USB plug, jnlock it, go in the Settings, the General, then look at the firmware version and post it here.
Jade is a solid choice, open source and Bitcoin-friendly. The one thing to know is it requires a connection to a Blockstream server for the blind oracle PIN model unless you run your own node — worth understanding before you rely on it.
As long as you have your 24-word recovery seed phrase, there is no issue at all, as you can enter it in a newer ledger device (or update the firmware of your old ledger). If you lost your seed phrase, there are ways to recover access to all cryptos secured by your old ledger without having to update the firmware (updating the firmware is not recommended is you lost your seed phrase). As long as your ledger device works and that you have the unlocking PIN, all cryptos secured by your ledger are recoverable. The tools to use and the efforts / difficulty depends on the type of cryptos that are secured by your ledger device. For example, BTC can generally be recovered by using Electrum, connected to your ledger device. Other cryptos may require using older versions of existing front-ends, or in some cases, custom low-level front-ends. Note: It is not recommended to update the device firmware if you lost the seed phrase, because if the update goes bad, you would permanently lose access to all your crypto. So, for safety, the recovery has to be done using the older firmware that is on your device.
HAHAAHAHAH PIN THIS, u have to be mental to think btc is not going below 50, ww3 is around the corner, countries are financially on the edge. Hell it will be bullish if we stay above 40. Not hating but if you say this then you are new in crypto.
If you lost the PIN to unlock the hardware wallet, you need to enter the SEED (24 mnemonic words) into another hardware wallet and if you also lost the SEED, it's a real problem since after three failed attempts to enter the PIN the Ledger wallet erases everything.
Hopefully you have your seed phrase. If you do you can just setup another wallet with a new PIN using your seed phrase. Pin is for the physical device but the seed phrase is to access your BTC balance
You can, but what does that have to do with this discussion of cold wallets? A hardware wallet with a secure element encrypts the stored secret, but it also DECRYPTS the secret for any user who's able to authenticate to the device. If authentication is simply a PIN, the fact that the secret is encrypted is largely irrelevant. Stop deflecting and just answer my question: What makes you think a hardware wallet plus PIN is more secure than a mnemonic sentence plus passphrase? What cold storage attack vectors does it mitigate that a zero-device setup doesn't mitigate?
I know what a hardware wallet is. It's a secure signing device. OP's question wasn't about signing transactions or moving Bitcoin. It was about **cold wallets**. A device that, if found by an unauthorized person, has only a PIN protecting you from losing your Bitcoin is LESS SECURE than a mnemonic sentence stamped in stainless steel with a complex passphrase stored elsewhere.
If someone comes across your hardware wallet, can they access it and take your Bitcoin? Or would they need another secret - a PIN, for example - to do that? Do you keep the PIN with the hardware wallet, or do you store it elsewhere because your storage of the hardware wallet is insecure? How is a hardware wallet plus PIN more secure than a mnemonic sentence plus passphrase?
One thing most people overlook: your wallet is only as secure as the device it's on. Doesn't matter if you have a hardware wallet if your computer has malware logging your keystrokes when you enter your PIN. Use a clean machine for crypto, keep your OS updated, and never install browser extensions from unverified sources. I've seen more people lose funds to compromised browsers than to actual blockchain exploits.
I'm not. Explain to me why you think a PIN-protected hardware wallet is more secure than a mnemonic sentence on stainless steel with a passphrase stored in a separate location.
Yeah it’s a bit different from the daily-use apps. Most crypto wallets don’t really use usernames/passwords. Your “login” is basically your private key or seed phrase. That’s the real access. Apps just put a PIN, Face ID, or fingerprint on top for convenience, but that’s just local security on your device. So yeah, losing access is still a risk. If you lose your seed phrase and your device, there’s no reset option like email/password apps. Biometrics and passkeys are starting to come in with newer wallets, but under the hood it still comes down to key ownership. The UX is improving, but the responsibility is still on you for now.
Weird that you're not getting this. He didn't have the mnemonic, the kids messed it up. He did, however, still have the device, presumably with a PIN to use it. So he created another wallet somewhere (maybe on the same device and switched back and forth, maybe somewhere completely separate), and then he used the devices and PIN to send funds to this new wallet. You only need the mnemonic in the case of losing the device or device PIN.
Physical security matters just as much as digital security. If someone can watch you input your seed phrase or private keys, all the hardware wallets in the world won't help. This case highlights why operational security (OPSEC) is critical: private spaces for crypto operations, secure storage of recovery materials, and never letting anyone observe your access methods. For anyone managing significant holdings: treat your crypto activities like banking. You wouldn't let someone watch you enter your PIN at an ATM.
Copy Bluewallet. Having biometrics or a PIN is good if you lose your phone or someone has access to it, it doesn't do jack shit if the phone is compromised. The reason why I mention Bluewallet is because it's the only mobile software wallet in existence with an encryption feature (AES 256 standard) that, when enabled via a strong password, encrypts the entire file containing all your wallet data. Meaning that on top of Android/iOS device encryption, you've got Bluewallet's file encryption. Also mitigate risk as much as possible by lowering the attack surface -> Bitcoin-only. And make it 100% open-source so the code is fully verifiable.
Checked out the security features, and it's the same deal as with the other dozens out there, with the exception of Bluewallet. They rely on your phone's OS-level encryption + biometrics/PIN for app access. The reason why i mention Bluewallet is because it's the only mobile software wallet that allows you to encrypt the entire app's storage (including your wallet data, seeds, etc.) on top of your phone's built-in encryption, by enabling the "Encrypted Storage" option via a strong password. Meaning, that on top of the OS encryption, you've got Bluewallet's encryption (AES-256), ***and*** the biometrics/PIN. No other wallet does that. And that's the reason why it's the best on mobile. Sparrow being the best on desktop.
If someone is beating you with a wrench, it doesn’t matter if they’re asking for your bank PIN or your 24 word key
Use cold wallet and make sure your PC does not have keyloggers or other malicious software. Generally it is safe to use exchanges for trading but it's not recommended to leave crypto on these platforms, instead of it transfer your funds onto your cold wallet as soon as possible. Actually your crypto remains on blockchain but private keys are stored in cold wallet's security chip, so in this case access to your account transactions are granted only through your cold wallet (user must to verify addresses and confirm (sign) manually the transaction). While using cold aka Hardware wallet then there is much less risk that input has been tracked or compromised (for additional security purposes HW wallet can be accessed with PIN and this input is done only on HW wallet and that input never leaves HW wallet, technically be tracked or logged from outside (PC). While using hot (online) wallet there is always risk that your computer is infected with malicious software and so all your keyboard keystrokes can be logged and sent to the host who then can see and guess your passwords. Bear in mind that you should never enter your seed phrase anywhere (for short term you can use paper but most secure is stamp seed phrases to the metal plate. If you use hot wallet and their seed input then these words can be too be tracked because you never know what's actually running in background on your PC.
Everything that Schrezberatina said. I use Trezor One now. However, I'd like to upgrade it to a Trezor Safe 5. For the seedwords, it defaults to SLIP-39 instead of BIP-39. I'd recommend looking at [Trezor's description of seedwords](https://trezor.io/learn/security-privacy/personal-security-standards/understanding-trezor-wallet-backups-12-20-or-24-words). The 20 word backup gives you a lot more flexibility on how that's set up. During setup, put a good PIN on your Trezor to avoid easy cracking if it falls into the wrong hands. **Do Not Ever** put your seeds on computer. That means no photo. No password file or database. No printer. *Be paranoid!* Don't speak them near a phone or microphone. Don't let a video or security camera observe you while you are recording and saving the seedwords. But you need to save the seedwords. That's the only thing that you do actually need to save. I'd recommend a technique called the [SAFU Ninja](https://youtu.be/3Aj_EHOu9WE) which is basically hand stamping the words into a series of washers. The nice thing about this technique is that it is just a valid regardless of the number of seedwords. So it doesn't matter if you are doing 12, 20, or 24 words. Plus with some of the more advanced options of SLIP-39, you have the option of doing multiple sets (or shards) of seeds and setting a restore option to require, say, any 2 out of 3 sets, etc. So with the SAFU Ninja, you may have (a relatively modest) upfront cost of a stamp set, but then the per use price is very affordable.
Stateless mode is amazing BUT y'all are sleeping on what the blind oracle really does. Even after you've set up your Jade, the blind oracle keeps it effectively stateless. There's still nothing stored on the device for someone to extract. That's the whole security model. What makes this great: you can travel with an initialized Jade and just use your PIN. No seed words written down, no QR codes to carry, nothing physical to secure except the device itself. And if it gets stolen or confiscated? There's literally nothing on it to compromise your funds. The server never sees your PIN or keys, open-source code. No secure element on Jade means it's fully open-source, so you can verify this yourself. If you don't trust the oracle at all? Yes, run it air-gapped via QR or use temporary signer mode. Or run your own!! But for traveling? Initialized Jade with PIN unlock is unmatched. Stateless security with hot wallet convenience.
Any security question needs to weigh the cost/benefits and also consider the threat model. Just as you wouldn’t buy a $700,000 bank vault to protect a $70 watch, you need proportional costing BTC storage too. It works the other way too. Nobody is going to crack the chip on your Trezor model 3 for 0.1 BTC. Have more? Is your adversary going to buy a scanning tunneling microscope or an $8 pipe wrench to hit you with until you spit out your PIN?
I started with Trezor Safe3 as beginner. All is still OK. I think that main difference between TS7 and TS3 is that TS7 is more comfortable to handle as well as TS5 because these HW wallets have a touch screen while TS7 has biggest touch screen in the product line. For me the only downside is that navigating and confirming/selecting with two buttons simultaneously is not good and does not always succeeds. Mistyping for an example the PIN code initiates time-delay countdown by doubling the power of two each time the wrong PIN is entered. But I personally decided to start with crypto by using TS3 because it is available at very affordable price and has good security/manageability/price ratio. No overthinking just double checks of everything and I like that it is also very lightweight. And generally I think that having USB-only device increases also security because without Bluetooth connection it's not discoverable by nearby bluetooth devices , so less risks to get too much attention even if it is promised that it is safe to use HW wallet over bluetooth. TS3 is fully offline that only gives and option to sign transactions or settings made/changed in suite. I know that TS7 has advanced security features but currently I don't need that level of security.
Sooooo anyone can steal your money by getting near your hand with an nfc device and you wouldn't even know it happened? I hope he did some authorization step on his phone before this. Id rather tap to pay BTC with a phone that requires a PIN/biometric to send BTC
You're already ahead of most executors because you found both the device AND the recovery phrase. Here's the simple version: \*\*To find out what she owned:\*\* 1. Download Trezor Suite (the official app) on your computer 2. Plug in the Trezor Safe 3 3. Enter the PIN you found 4. It'll show you all the Bitcoin (and any other crypto) on that wallet 5. You can see the current value and generate a transaction history I wont get into probate and time-stamping valuations but I'm sure you're on this. I actually built a tool (Evoke Schedule) specifically for this situation - it helps executors and families document crypto holdings properly for probate and ultimately recovery. But honestly, for a single Trezor wallet with $1000, you can probably handle it yourself with the steps above. This is literally what I do. DM me if you get stuck. Also: \*\*Keep that recovery phrase somewhere very secure.\*\* That's literally the keys to the Bitcoin. If someone gets that phrase, they can take the Bitcoin. Don't photograph it, don't email it, don't store it digitally.
You just plug it in, put in the PIN or the words and there you go You download the trezor suite on your computer to look at it
Just to be sure: do not give anyone that PIN or these words. Ignore any direct messages.
With multi-share the passphrase only provides the benefits of plausible deniability, should someone force you to PIN unlock the device. Because of this, it doesn't have to be greatly complex. This situation should be considered by each individual and their resistance to torture...but I digress. I should mention that if you get comfortable recovering with the multi-shares, DESTROY the single share because that single share creates a single source of failure, should someone find it.
When you send bitcoin to a self hosted wallet (idealy a properly set up hardware wallet = cold wallet), each time you send an amount of bitcoin you create a new UTXO. Therefore if your wallet software can handle UTXO management (which should typically be the case), it would technically be possible to separate UTXOs that belong to different persons. BUT I would not recommend that practice because: \- It might get pretty cumbersome from a tax calculation perspective (who owns which UTXOs and how to prove?). \- Anyone who has access to the wallet (either through the physical device + PIN or through the SEED phrase) has automatically access to all UTXOs. So all participants must trust all participants 100 % and all time.
1. Do not answer DMs or take any advice, help, follow links etc from private chats 2. If you plug the Nano in does it power up? Do you remember the PIN that you set on your Ledger? If NO, you'll have to go through a recovery process with the 24 words. Post a comment and someone will tell you how to go about that. 3. If YES then * Download the official Ledger Live app from https://www.ledger.com/ledger-live. * Connect your Ledger Nano device via USB. * Pass the genuine check (device verifies it’s authentic). * Enter your **PIN** to unlock the device. * Once unlocked, Ledger Live will **automatically detect your accounts** and display your balances — no seed phrase required. * ✅ **Important**: Never enter your seed phrase on your computer. If any app asks for it, it’s a scam. The seed phrase should **only** be entered directly on your Ledger device during setup or recovery.
I see….that sucks. How did they know you had a wallet??? Did your wallet have a pass phrase? PIN?
Here's the thing no talking about: This is not just about making money.. it's about investing in the future economic infrastructure you want for the entire globe. When you put your money into something like XMR or any kind of truly decentralized piracy-focused chain, you are placing a vote for privacy-based transactions. Same goes for truly decentralized AMMs and all kinds of DeFI and PIN solutions. If a public and decentralized system does not take off in the mainstream, then the alternative is exactly what we have now.. except a level of control over the entire economic and financial infrastructure that the world has never seen before. CBDC's are coming like a storm. Read the patents. Read the research. Look into the trials. You are going to have the elite of the elites issue you a *programmable currency*. They are selling all of the solutions it will create, but addressing none of the truly terrifying concerns. Digital IDs combined with CBDC's mean that you are 100% tracked and traced across your entire digital footprint. This will all be handled on PRIVATE blockchains. Businesses will be incentivized to join/connect directly into these private chains because it will automate everything for them and handle all reporting and tax obligations. Once you are on THE network... that's full control. I urge people to continue investing in the technology that is going to move us way from this so that at the very least there is SOME kind of meaningful resistance or alternative. Putting your money in these chains developing these alternatives means that developers and other talent will be attracted to move into these spaces. Stop thinking only of how you are going to profit in the moment. It's so much bigger than that. If you're the type of person that only sees and values "Crypto" as an asset to make money from and doesn't even care to move their coins off of the central exchange you bought them on... pick up your game, or you are part of the problem.
I really don't think about it at all. A hardware wallet is a signing tool (and seed phrase generating tool). If it fails, I get another. No biggie. It's really that simple, and I do fear too many think of their hardware wallets logically more like wallets than signers. That is unfortunate naming. Your seed phrase backup strategy really should be everything you're depending on. You can add a passphrase (BIP-39, part of the Bitcoin spec, not to be confused with a password or PIN number) for security to your strategy.
Gaining access to a Google or Coinbase account or even personal data does not give anyone access to a hardware wallet. 1. The only way use a hardware wallet is to have physical access to the device and know it's PIN (or whatever security it has). 2. The only way is to send the crypto protected by a hardware wallet without having physical access to the device is to gain access to the seed phrase. One likely possibility is that your friend obtained the Trezor from the scammers (perhaps they posed as legitimate sellers), and he used the seed phrase that *they* installed on the device. They told your friend that the Coinbase account was compromised in order to get him to send his coins to the device. Since they knew the seed phrase for the device, they were able to take the coins.
Pretty strange. From what you describe, your device does not currently contain the same recovery seed phrase that was in it when you created your accounts. Updating the firmware cannot normally cause that to happen, event if interrupted as you describe. If the device still has its unlocking PIN, it shoukd still have the same recovery seed phrase stored in it. It the device had reset, id wouldd lose bothe the unlicking PIN and the seed phrase, and it woukd display "welcome" when plugged in. In the past, did you ever reset your device and generated a new seed phrase with it?