Build with CoinStats’ all-in-one API. Learn more

EnglishDeutsch日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçe포트폴리오 추적기스왑암호화폐가격Crypto API통합뉴스획득블로그NFT위젯DeFi 포트폴리오 추적기크립토 게이밍24시간 보고서홍보 자료API 문서
CoinStats

Reddit recommended Coldcard for years. Nobody asked these questions. Now $38 million is gone.

상승세:

0

하락세:

0

I lost nothing in this hack but I though I should write it down because I've seen people running away from the hardwork that actually makes you capable of self-custody. The idea of self-custody sounds like a major breakthrough in the beginning but isn't that what used to happen our civilizations were in early their infancy stages? You were responsible for everything you owned, if you lose it, that's your problem, societies evolved and banks and governments were there. Humans were happy that finally someone could take care of their funds and if something goes wrong, they can hold the institutions accountable. Finally crypto gave us a way to break out of this but we forgot why we opted out of that arrangement in the first place.

Moral of the story is that it's difficult, doesn't mean we should run away from it and leave our funds to exchanges that can end up as FTX or just freeze your funds.

I'm repeating this again, you can't buy a hardware wallet just because an influencer says its good or you read comments about it. Think of it this way, will a bank ever trust a technology just because they've heard good things about it?

The same parameters should now be used by HODLers like us because coldcard has been one of the most solid names for BTC maxis looking for cold wallets. And as much I hate to admit it, this might be one of the initial cases, we don't know what's about to unfold because if you understand what happened here was a firmware update that compromised the ability of the hardware of creating combinations during seedphrase generation. Basically cutting down the possibilities from trillions to just 4.2 Billion (a regular laptop can crack these many combinations in about 20-30 minutes)

So basically they bought a hardware wallet that looked safe, the firmware was open source but beneath their nose, they received a firmware update that introduced this bug.

And honestly speaking, I'm afraid this can happen with any wallet. Because regular people don't have the time and expertise to look into the source code and find out if there are serious issues.

Something interesting that I noticed was that coldcard had an open source firmware that was reproducible but this vulnerability didn't get exposed upto 4 years and that alarms us of something more dangerous.

And that is that they are running away from STRONG BUG BOUNTY PROGRAMS, had there been one. This vulnerability would have been exposed earlier. But there track record was not good as far bug bounties were considered.

Here's what I'd do myself moving onwards:-

1) I'm not installing any firmware updates in current wallet moving onwards
2) I'll stay away from wallets that are not open source (never to be trusted)

Also, before you buy a hardware wallet, ask your self what do you exactly need from your hardware wallet, some non-negotiables in my opinion are:-

1) EAL6+ chips or genuine equivalents
2) Open source reproducible firmware
3) Verifiable Entropy source

That being said, when I bought my hardware wallet, I took good 2 months to make the shift, I figured out what I need which was no single point of failure & inheritance support that was why I went with the X1 which supported shamir's secret sharing. And I read the entire documentation that is available on their website, only after that I opted for their wallet.

Any person, looking to buy a wallet should wait and figure out what they exactly want their wallets to do and not just pick up something which gets widely recommended. So take your time, understand what's the architecture you require and then get a wallet.

FUN FACT: If a user had used more than 50 or more dice rolls, they would have been safe but most users didn't even know about Dice rolls, the reason is they never read the docs of the hardware wallet they trusted their money with.

The bottomline is you can't be your own custodian if you're not ready to put in a lot of effort.

Most importantly, FAILURE OF ONE HW WALLET IS NOT EQUAL TO FAILURE OF SELF-CUSTODY AS A CONCEPT

Edit: Many people felt this was an AI slop because of the formatting, so I've just reverted the post to its raw form, might be a little difficult to read and I might not sound very precise with my language and choice of words since english isn't my first language. All disagreements are welcome and I see some comments about ETFs as the way forward or exchanges, well congratulations you are finally convincing everybody people to centralise the last hope of decentralisation we had. Why not just invest in the blackrock index fund and let them take care of your money?

submitted by /u/No-Wrap3568
[link] [comments]
상승세:

0

하락세:

0

한 곳에서 모든 암호화폐, NFT 및 DeFi 를 관리하세요

시작하는 데 사용하는 포트폴리오를 안전하게 연결하세요.