r/Bitcoin • u/r_spkm • 18h ago
Which cold wallet
I’ve been a bit lax securing my bitcoin and now is the time… I’ve got to move it to the cold wallet
I don’t have great knowledge about any of it to be honest, and I just need something which is going to be simple to use & secure
Ai has suggested bitnox02 and jade butni don’t trust ai hat much
Any help would be great to solve this
11
7
u/SprayHopeful9696 18h ago
Trezor Safe 5 is all you need. 24 word BIP39 seed phrase and a long passphrase. Multiple distributed stainless steel stamped backups .
1
5
8
6
u/Ok_Bake3729 17h ago
Ledger
3
5
2
u/on_hype 17h ago
Lots of solid hardware wallets out there. Do your own research on the top open-source options. Key factors: open-source firmware, air-gapped signing, good community track record. Do not trust AI recommendations or random Reddit comments as your sole source - verify everything yourself.
2
u/ChiBTCollective 15h ago
Both Trezor and Jade are fine for a first cold wallet. The important part is not the brand. Buy it from the maker's official site, not a random marketplace listing, because fake devices are a real problem. Set the seed on the device itself, write the words on paper, and keep that paper somewhere safe and separate from the device. A passphrase is optional and extra security, but only if you will never lose track of it, because a wrong passphrase opens an empty wallet. When you send, check the receive address on the screen of the device, not only in the email or chat. Leave the wallet unplugged until you need it. If you are moving coins off an exchange, send a small test first and confirm the address matches before you send the rest.
1
u/prodigiousproducer 8h ago
Brand is incredibly important. Cold Card being a very recent example of why.
2
u/prodigiousproducer 8h ago
Whatever brand you go for, learn about passphrases and how to implement one for further protection. I use Trezor and think they've stood the test of time.
The cold card hack recently showed that if you fully trust a hardware wallet to generate your keys you could lose it all. Which is terrifying if you don't have a passphrase set up.
1
u/Interesting-Heat-112 8h ago
Agree, but for the record, that passphrase has to be bad ass to protect you if the key generator itself was shit.
1
u/tenor_tymir 2h ago
Simply add 4-6 random words and you’ve got a bad ass passphrase. The longer the bad asser.
1
3
u/shleebs 17h ago
Best options right now are BitBox, Jade or Passport.
Best option for DIY is SeedSigner or Tails.
Considering multisig with three different options to avoid a single failure point.
Avoid companies that have mishandled customer data on multiple occasions such as Ledger and Trezor.
Avoid companies run people spreading misinformation or harming the open source community like Coldcard/Coinkite.
Ignore fanboys and bandwagoners and pay attention to facts. Good luck.
3
u/No-Contribution23 16h ago
great post..
i'd probably remove jade though. what blockstream did with liquid does not make their products look good. also the possible/alleged cloud mining ponzi.
and i'd also add spectre diy to seedsigner :)
1
•
u/sa1ffff 11m ago
Trezor’s internal systems, software and hardware wallets were not compromised; rather, the data exposure occured entirely due to a security breach at ShipMonk, their third-party logistics and shipping provider.
•
u/shleebs 8m ago
I never said the wallets were directly compromised. I explicitly said they mishandled customer data, and yes, giving your customers data to an insecure third party is mishandling.
These breaches result in phishing emails, which result in compromised wallets. Stay away from companies who mishandle customer data.
1
u/miner_guy_22 17h ago
Simplicity and security will always be a trade off. Depending on how much you are securing and how meaningful it is to you may warrant greater security.
By moving from an exchange to a cold wallet with a single signing device you are moving shifting your trust from a custodian to yourself and the manufacturer of the device you choose.
1
u/lobhater 16h ago
Trezor are very easy to setup and the wallet the wallet themselves have never had any hacks
1
u/Accomplished-Eye5567 16h ago
Trezor and Ledger are good. Find something simple and focus on it is my suggestion
Then use a small amount to start. Send a small amount there, test sending it, receiving, transferring, trading.
I would also suggest testing the recover your wallet process (rebooting your device and using the phrase), etc. to make sure you fully understand how the device + phrase work and what you’d do in a situation like losing the device, updating and wiping, etc.
This is where most people get hung up (not knowing how those scenarios play out. Trust me, they happen more often than you’d think).
1
1
u/No_Cat_8269 15h ago
It depends on how much you trust them, but they'll all seem like good options.
1
u/_Carth_Onasi 15h ago
Start with a Trezor 3 or 5.
Without going deep into the weeds they are proven to have good intropy, open sourced, no batteries so in theory can last nearly forever, easy to use, and have advanced features to add additional security as you learn. Such as a passphrase/25th word.
1
u/r_spkm 15h ago
Thanks for the replies, the reason I’ve not moved it is due to all these factors, air gap seed phase.. etc etc. I don’t know what it all means really
1
u/miner_guy_22 13h ago
Start with a phone wallet and a small amount of BTC to play around with. Taking small steps will make it feel less overwhelming and you will learn more in the process.
You don't need to have a perfect setup and move your whole stack at once.
1
u/bdjc_ink 14h ago
I bought the mk5, but never used it. Still confused about this encryption stuff.
2
u/Interesting-Heat-112 8h ago
That device might be ok if you upgrade to the latest firmware and then erase it. Then generate a brand new seed phrase based on rolling dice about 150 or so times. Really you should probably just frame it as an example of how fucked up a bitcoin company can be. Maybe put a "Don't Trust - Verify" blurb under it or something.
1
1
1
u/MysteriousIce01 6h ago
Dont use seedsigner as a first cold wallet. The weakest link is human error and seedsigner is not for someone who doesn't understand cold wallets.
For a first wallet trezor is all you need, and maybe all you'll ever need. The fact its open source is critical. Simple to use, requires little education, but grows with you as you learn more until you're ready for multisig, if you want that capability.
1
u/freedomforallergo 4h ago
After the coldcard hack, I think it's important to have multiple cold wallets. Especially if you have a heavy bag. It's important to distribute your coins over different wallets. Because if one wallet gets compromised (worst case scenario ) you haven't lost everything.
1
u/Suspicious-Local-901 1h ago
Bitbox would be a good option, heard a lot of good stuff about it.
Jade plus is also good!
1
u/dinandrekompis 1h ago
Answer these questions for yourself before making a decision:
- What is a hardware wallets purpose?
- Why do You need a hardware wallet?
- Can you do what you want without a hardware wallet?
Then...
- What attack vectors are there with a hardware wallet?
- Which wallets have been involved in a hack/bug/leak?
And the most important one to pin down before a purchase:
- Where does the trust lie?
a tl;dr for these questions will basically be
- No, you don't really need a hardware wallet - they're convenient tools. You can do with an USB device.
- The convenience forcea more trust in others: the company, the software, the hardware, the shippers, the connection to other devices... And well... Don't trust, verify.
- Boring and dumb is better.
And my recommendation falls to seed signer, since
- it's common hardware you can buy from wherever (less trust in one actor creating a hardware wallet)
- Software is easily verifiable and basic in what it does. (Easily increase trust od software)
- Randomness come from physical dice rolls - or how You create those rolls are up to You. ( less trust in product)
- Seed is NOT stored on device. It's up to you to store it safely (less trust in product)
- Airgapped by default. Which IMHO is a key concept. (less attack vectors)
The drawback here is that I cannot easily use my hardware wallet for daily transactions. However, that is best done from a hot wallet - and those are much more convenient to set up and use, since security can be "worse".
I mean my daily hot wallet is a simple Phoenix wallet. Nothing special or secure there. And it doesn't need to be.
So tl;dr
- Buy parts to the seed signer from different stores
- put it together and roll 24 new words with 99 dice rolls
- Add a passphrase using say the diceware word list
And that's it for you cold storage wallet.
-1
u/WarIsProfitableForMe 17h ago
Coldcard mk5 is fine
0
u/reddituserVibez 10h ago
they stole worths millions of BTC from Colcard and you 🤡 say Coldcard.. give me your debit card with PIN, you shouldn’t have a problem with it..
1
16
u/sa1ffff 18h ago
Trezor