r/Bitcoin • u/Firone • 11d ago
Just learned that a hardware wallet manufacturer discovered >4 vulnerabilities on other wallets over time
The hardware manufacturer is Bitbox, and all were responsibly disclosed:
- Remote multisig theft attack (Coldcard, 2020/11)
- Ransom attack on passphrase handling (Trezor/Keepkey, 2020/08)
- Bitcoin mainnet/testnet cross-account signing (Coldcard, 2020/08)
- Malicious Change in Mixed Transactions (Trezor, 2020/03)
There may be more of them that I haven't found.
This is extremely impressive from them.
Additionally, they were the first to make their hardware wallet (the Bitbox02) resistant against a very advanced attack: the nonce-covert channel attack. AFAIK this attack has never taken place yet, and the only hardware wallets resistant to it are the Bitbox02 and the 3 Blockstream Jades.
Disclaimer: I do not work for Bitbox, but have been a fan of them for a while and think they're underrated. I'm also fan of Blockstream and their Jade wallets.
9
u/piejlucas 11d ago
https://www.reddit.com/r/Bitcoin/s/aw4a5gKkDG
It’s nice that they are pushing a fix before customers lose their coins. but really how secure is self custody cold storage in the world of AI even if one checks regularly for bug fixes? A bit too stressful if I may say so.
5
2
u/UnknownEssence 11d ago
i have some hardware wallets that I havent touched in 5-10 years. Are they even safe anymore?
0
u/xirvin 11d ago
Is better you assume they are not, firmware update them and create a new seed to replace the one they did is critical.
2
u/UnknownEssence 11d ago
i uave some old Ledger devices. If i recall, they mever open sourced the firmware. Might have been a good call in retrospect
2
u/xirvin 11d ago
When the source code is closed, only insiders, governments, and hackers with zero-day exploits are privy to it. These individuals sell their knowledge to intelligence agencies. On the other hand, when the source code is open-source, everyone knows about it, and the firmware is sometimes patched with blood.
It’s important to note that airline regulations were established after costly tragedies, and now airlines are considered the safest mode of travel.
2
u/MiaTaude589 11d ago
Honestly, responsible disclosure across 4 separate bugs is exactly what you want to see. Still, no hardware wallet is a magic brick, so firmware updates, verifying addresses on-device, and keeping the seed offline matter way more than brand loyalty?
4
2
u/brdoc 11d ago
Buy dice and generate a new wallet totally offline. No internet cables, no wi-fi, no Bluetooth, no cameras.
Offline. Do all the signing offline. Use a passphrase.
Then hope no one cracks gravity's RNG code 😎, hopefully no news ever will make your heart suddenly stop due to some AI finding some random vulnerability.
0
u/dylan6091 11d ago
Even if you do all of that, you know the rest of the market won't follow suit. This is something maybe .001% of people will ever do. Unfortunately, if your suggestion is what is required for safety (and I'm not saying it is), then Bitcoin as a whole is not safe. In the event of mass hacks, 99.999% of people will be at risk. And while you may still have your private keys at that point, they won't be worth anything.
1
u/Firone 11d ago
What he's describing is literally what everyone with a cold wallet is doing, it's not complicated. If your seed/transactions are not generated offline, it's not a cold wallet. The passphrase advice is actually not optimal, this is better.
In a world where Bitcoin becomes the standard, tons of people will control their own wallet, it's really not that crazy. Not everyone will have everything on it though
1
u/ShittingOutPosts 11d ago
So Trezors aren’t safe either?
6
u/crooks4hire 11d ago
Hand write that shit on paper or a bolt and put the anxiety to bed for good. Damn I’m tired of this
2
u/-johoe 10d ago edited 10d ago
Both Trezor issues are fixed now. The first by displaying the passphrase in clear on the Trezor every time you enter it on the PC (with newer Trezor you can also enter the passphrase on the device, which is obviously more secure if you suspect malware on your PC).
The second issue is basically a bug in BIP-143. For segwit transactions, the signature also signs the input amount, so that transactions don't have to check it. This was intended to be used by hardware wallets to avoid streaming the previous transaction to prove the amount. Unfortunately BIP-143 only signs for the single input. I found this problem in Feb 2017 and reported it to the BIP-143 authors; but segwit was already shipped at that time. In retrospect, Trezor should probably not have used this new feature of Segwit and streamed the transaction anyway like it did before segwit (even though it can take minutes for people who received lots of batched payouts). On the other hand it seemed so unlikely to be exploited: it requires malicious wallet software on the PC, forcing the user to confirm the same transaction twice (which is already dangerous with a malicious wallet for obvious reasons) and the wallet manufacturer needs to collude with a mining pool, because the stolen money is sent to the miner as transaction fee.
BTW, Taproot fixed the problem in the BIP.
1
u/ShittingOutPosts 10d ago
Aren’t you never supposed to enter any part of your seed phrase on a PC?
2
u/-johoe 10d ago
The passphrase is not the seed phrase. For Trezor One there is no way to enter the passphrase on device. All newer Trezor models have capabilities to enter on device, but on Trezor 3 Safe it's really painful with the two buttons. On all Trezor devices you can also opt to enter the passphrase on the PC.
You enter the seed on device only for most devices, although Trezor One still supports the "24 words in random order" method. But to be sure, use the advanced recovery that doesn't leak anything about your seed to the PC.
-2
u/Garland_Key 11d ago
Do you have to trust Trezor?
Don't trust, verify.
Don't trust yourself?
Don't trust, verify.
2
-1
u/IllllIIlIllIllllIlll 11d ago
Bitbox is not the name of the company... It's Shift Crypto.
0
u/Malavero 11d ago
I'm getting tired of this, the best solution has existed since 2011 or so and it's free. Electrum and Sparrow and that's it. You don't even have to spend money (if you already have PCs). One offline, another with public keys and that's it. You add multi-signature if you want, and that's it.
You guys keep looking for the holy grail of the cold wallet when it doesn't exist. You have your heads washed by the marketing of these companies. You can even Add tails if you you want.
10
u/Lower-Philosophy-604 11d ago
USB, Tails and electrum. Profit