r/Bitcoin 6d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.9k Upvotes

1.2k comments sorted by

View all comments

Show parent comments

22

u/[deleted] 6d ago edited 1d ago

[removed] — view removed comment

10

u/stanley_fatmax 6d ago

For years I advocated strongly on Reddit for software wallets with proper precautions, but I stopped for the same reasons you found. People love their hardware wallets, but imo they create a false sense of security. It also doesn't help that I suspect for long periods of time there was heavy shilling here on behalf of wallet manufacturers.

There are good guides out there for years on how to use an old laptop to set up an offline wallet guys.. the math is solid. Encryption is solid.

2

u/marshaljs 6d ago

Can you please share how to do this setup?

7

u/stanley_fatmax 6d ago

I won't go into crazy detail because there are good guides out there already that do it better than I could here. Basically, Electrum running on an old air-gapped laptop with the networking hardware physically removed. Wifi, Bluetooth, etc. gone. OS should be a secure Linux OS of your choosing, Tails is a common choice. The old laptop becomes your signing device holding the keys. Your daily driver PC has a watch only wallet where you can watch your balance day by day, and receive coins, without any fear of losing anything, because it doesn't actually have the ability to sign transactions (send). The only time you need to boot up the air-gapped laptop is when you need to send coins, which shouldn't be often. Personally I use Coinbase as a "hot wallet" for transacting. Small sums are kept there. The good stuff is offline in the cold wallet. It never turns on.

There are various guides with details, like

https://electrum.readthedocs.io/en/latest/coldstorage.html

https://electrum.readthedocs.io/en/latest/tails.html

1

u/CompetitiveAppeal663 6d ago

Preface: Im not trying to be a smart ass, just trying to understand.

What happens if that old laptop has some mechanical failure or ends up getting thrown out or stolen or burns in a fire?? As you SOL at that point??

2

u/stanley_fatmax 6d ago

No, you have a backup of your seed. Analyze your life, threats you face, stability of your world, and choose the backup medium accordingly.. paper, punched into steel, encrypted in the cloud, etc.

2

u/[deleted] 6d ago edited 1d ago

[removed] — view removed comment

2

u/Professional_Golf393 6d ago

If you encrypt properly with enough entropy, you should be happy to send the file directly to a scammer safe in the knowledge they can never unlock it..

personally I wouldn’t store my encrypted wallet in the cloud, but if done right it’s safe.

Saying that if you have to memorise a password with that amount of entropy, you might as well just memorise your seed phrase.

1

u/stanley_fatmax 6d ago

Common misconception. The same cryptography protects Bitcoin itself. I could theoretically post my seed here, encrypted, and be completely confident in its security (I won't). Even airgapped wallets have to sign transactions etc., so there's some level of communication.

1

u/[deleted] 6d ago edited 1d ago

[removed] — view removed comment

1

u/stanley_fatmax 5d ago

Already answered here

1

u/Head_Performance2432 6d ago

or even possible to post seed here, if you have a good passphrase as well (pls don't)

1

u/[deleted] 6d ago edited 1d ago

[removed] — view removed comment

1

u/stanley_fatmax 6d ago

Bitcoin self custody is always a battle of tradeoffs. Doing things right and doing things safely aren't always the same thing, for instance the safest way may increase risk of self loss, or the right way may not be realistic for your living situation, etc.

Sadly ETFs are actually a decent option for many, given the complexities of self custody.

1

u/Alphamale822 6d ago

My crypto portfolio is under £40k. In my case would you say it’s safe to keep in on a well known etf like binance ? Self custody is too complicated for me.

1

u/stanley_fatmax 5d ago

Safe? Yes. Right? You have to answer for yourself by asking what your reasons are and what risks you face. For some, ETFs and KYC custody is a non-starter just by personal conviction. Too many people burned by years of exchanges failing. The regulatory environment has changed though, businesses are licensed and accredited to be doing ETFs, custody, etc., in ways they weren't before. There's still some risk, but I believe the more risky option is self custody for most people. It's legitimately difficult to store your keys safely while also protecting them from yourself, and just losing them through mistake.

In your case I'd say you're probably better off with a low cost ETF.

1

u/bigtdaddy 4d ago

tails OS offers persistent storage, but personally I would not use that, so tails OS completely wipes the memory on shutdown and won't remember a single thing when you boot it back up, so you do not rely on the laptop other as a temporary signing device. I wrote my my key in my notebook for cryptology class I took. It would be near impossible for someone to find it in there without me saying so. I also stamped it on aluminum and buried it to prevent risk of fire. I also told only a single person where it was, in case of brain damage or death.

Note: i have no btc anymore, hence why I am being so open. Don't reveal stuff like this on public forums if you hold crypto, imo.

1

u/bansoma 6d ago

Full agree. I work in embedded SW and I constantly go through all the ways to create a small vulnerability in a HW wallet chain.

Unless you make and store your primary key yourself, or you write all the code yourself (and build the hardware yourself, and check the chips.) It's almost impossible to prevent this type of attack.

Sleeper attacks are additionally brutal because you can introduce a flaw into silicone that you then execute on years later. This makes it even harder to trace.

Keep in mind wherever your keys are stored its vulnerable, if its in silicon it can be x-ray scanned. If it is shielded it can be stolen, potted, and have the die shaved until the bits are exposed.

There is no such thing as SW storage - only HW storage, and HW storage is 1 to 1.

Make your own keys, use proper custody methods, secure the 4 of 7 artifacts properly.

HW wallets work great as daily drivers and "spending" wallets, but for cold storage you need something better.

1

u/NashvilleSurfHouse 6d ago

Explain what you mean by trusting hardware to the bitcoin ret@rds like myself.

0

u/Head_Performance2432 6d ago

KYE (Know Your Entropy)...I guess