Ledger Nano X - The secure hardware wallet

How much safer is cold storage really, once you factor in the person using it?

Been chewing on this for two weeks and I want to hear where people actually land because I keep flip flopping.

Quick recap in case you missed either one. Coldcard: a build error in firmware from March 2021 meant some devices generated seeds using a software PRNG instead of the chip’s hardware RNG. Effective entropy dropped to around 40 bits on older models, which is brute forceable offline. Nobody got phished. Nobody’s device was stolen. Nobody typed their words into a fake site. Something like 1,800 BTC gone from 5,000+ addresses, and updating the firmware doesn’t fix a seed that was already generated weak.

Then Trezor’s fulfilment partner got breached. About 13,700 customers, and for most of them it was full name, email, phone number and home address. Credit where it’s due, Trezor’s own systems were never touched, and no keys were exposed, and their 90-day retention policy is the only reason it wasn’t every buyer in company history. But think about what that list is. It’s confirmed hardware wallet owners with the address the box was delivered to. Phishing by email, phone, and physical mail. Someone sends a letter on branded paper about an urgent recall or a mandatory firmware update, and I’d bet a decent number of people follow the instructions. Reports are already saying the data is being used to ask people for their 24 words.

Ok, so here’s the thing I want to argue about, and I want to say upfront I don’t think there’s a correct answer. I’m not saying cold wallets are unsafe. I’m not saying hot wallets are safe. I own hardware wallets, and I’m not getting rid of them.

Conceptually, cold is obviously better. That’s not in question. What I’m less sure about is how much of that advantage survives contact with a normal human being.

Take bad products out of it. There’s garbage on both sides, and there are wallets that used to be good and aren’t anymore. Assume the person picked well either way.

Good hot wallet, the chain is short. Most don’t ask for any personal info. You install the app, generate the wallet, and after that, it’s two questions. Is the seed handled properly, and is the phone clean. That’s basically the whole thing.

Good cold wallet, the logic after generation is identical. Seed safe, wallet safe. But now look at everything that has to go right before you even hold the device. Did you buy from the real site or a clone. A lot of manufacturers don’t ship everywhere so now you’re trusting a reseller, or a third-party seller on Amazon because that’s your only option. Was the package tampered with. And to buy it you hand over name, email, phone, home address and payment method, and that data then gets handed to fulfilment and courier companies you never picked and can’t audit. That’s the exact link that failed at Trezor.

That’s a lot of companies holding a file that proves you own crypto. Half this space cares about privacy above almost everything else, and buying a hardware wallet is one of the least private purchases you can make. Once it leaks, it’s also something a tax authority can cross-reference, which is a very different conversation for anyone whose declarations don’t line up.

And then there’s the part nobody wants to bring up. Loads of people buy a hardware wallet, generate the seed offline exactly like the manual says, and then save the 12 or 24 words into their password manager. Bitwarden, Proton Pass, a local KeePass file, whatever. They think it’s fine because it’s encrypted. What they actually did was turn a cold seed into a hot seed, and the device is now a paperweight with a screen.

I’m not laughing at anyone for that. Errors are the price of being your own bank. We have a long, very public list of people at the top of this industry who lost absurd amounts to small operational mistakes, so it’s clearly not a beginner thing. It’s a human thing. If you haven’t made your mistake yet, give it time.

Which gets me to the part I actually believe. People point at funds and custodians running cold storage as proof that cold is the answer. Sure, but those operations know how to handle a seed, they don’t go connecting their savings wallet to random contracts, they keep firmware current, and there are people whose entire job is that. Retail buyer has none of that. So when the standard advice is “buy a hardware wallet, or you’re doing it wrong,” two things happen that, I think, are worse than the alternative.

One, someone with a small stack gets intimidated by the whole ritual, decides self custody is above their level, and leaves the coins on an exchange. Which we all agree is the worst option available.

Two, someone spends 250 bucks on a device to protect 50 bucks of crypto because they were made to feel irresponsible for not buying the “safe” option.

So my position, and tell me where it’s wrong: a hardware wallet is a tool that quietly assumes a level of knowledge and paranoia that most of this market doesn’t have yet. For people who don’t have it, a good hot wallet with a couple of boring habits, like a cheap dedicated phone that does nothing else, might be the better real-world outcome than a hardware wallet used badly.

Anyway. If you’re advising a friend with a few hundred dollars and no technical background, what do you actually tell them and why? And does the purchase and shipping surface bother anyone else, or do you think anonymous delivery and paying in crypto solves it? Also, curious whether the Coldcard bug changed how anyone thinks about “it’s open source” as a security argument. Most of the people can’t read that code, and even the people who can have no way of knowing how many other qualified eyes actually looked. Open-source means auditable, not audited. Or do you file this one as a fluke and move on?

Not looking for a winner, I just think this sub gives better answers than “not your keys, buy a hardware wallet, done.” Sorry for the wall of text.

submitted by /u/EriksonThorsen
[link] [comments]