I have had multiple people in my personal life say that they are seriously considering moving to a custodian after this coldcard scare. This seems like a perfectly reasonable reaction considering the last few days, but is it actually logical?
First of all, this post is not meant to come across as a victim blame, I had coins at risk.
When you pressed the button on the cold card to create a wallet and chose not to add any entropy or light entropy, you were in effect trusting the coldcard and the makers of the coldcard. That's not what it seemed like at the time, but that is in fact what was happening. So fast forward to today, sending your bitcoin to a custodian feels like a stress free thing after all they are the experts! Unfortunately if you decide to do this you are only adding a layer of trust to your original coldcard setup. You are trusting the custodian wont just steal from you and or rehypothecate your money and you are trusting that the custodian will not lose your bitcoin.
So what was the lesson?
Don't trust, verify!
No singular person/device/company/etc. should be able to screw you over.
No single points of failure!
Don't add points of failure because of this, get rid of them!
Been thinking of dumping all hardware wallets. Might go deep into Darthcoin mode. Get some dice and create a seed
I got some dice last weekend lol
go ask the onceler, he knows! I agree with you, but to challenge it anyway:
what if a person knows that they won't be able to get rid of trusted single points of failure? For instance, they may know that they are not going to be able to do a good job of auditing hardware signer code and they may also know that they aren't going to be able to do a good job of evaluating the financial wherewithal of a given custodian (eg Prime Trust was a shit show). But they may still one over the other because they think they will be slightly better at the one than the other.
The real question though: did the custodian review the code to their HSM?
Satoshi seems to be doing alright. Let's get whatever hardware wallet he's on!
Satoshi's wallet doesn't have a seed.
Seems to have sufficient entropy
Yeah, /dev/random is enough. Using hardware rnd is enough. Using insecure pseudorandom generator or cryptographycaly secure, but predictably seeded pseudorandom number generator is not.
he literally just created a hot wallet on a windows machine lol!
Damn skippy 🙂
It was the most secure wallet on the market; nobody saw this coming. You're right in what you say: the more layers of security we add, the safer your BTC are. I hope this serves as a learning experience for all BTC lovers.
The Coldcard attack is a watershed moment, making us constantly reflect on the issue of security and self-custody. Study Bitcoin!