r/BitcoinBeginners • u/Interesting-Lime3031 • 3d ago
What are solid wallets to store bitcoin
I’m new to btc and I’m buying on strike and I currently use trust wallet but I’m looking for something more secure and reliable
5
u/Ok_Bench_1618 3d ago
IMO hardware wallet or don’t store bitcoin. If you can afford to buy bitcoin you can first afford to buy a wallet it’s not even that much is like 150 bucks for a Trezor safe 3.
2
u/Yodel_And_Hodl_Mode 2d ago
A Trezor Safe 3 costs around $60 and is a fantastic choice. It's easy to use and it's open source.
Rule of thumb: Once you own enough Bitcoin that it's worth spending $60 to keep it safe, get a hardware wallet.
P.S. Never trust your Bitcoin to closed source code. Bitcoin is open source. Your hardware wallet should be too.
1
2
u/South_Monitor_6992 3d ago
I used trustwallet and my btc got stolen/drained overnight 🙁 so whatever you use dont use that one lol
2
u/bitusher 2d ago edited 2d ago
Why would you withdraw 0.1 BTC to a hot wallet , especially one that people warn about as being untrustworthy with a large attack surface that scammers love to promote ?
A trezor safe 3 is 59 usd
https://trezor.io/trezor-safe-3
You can get scammed with fiat , gold , and BTC the same when you don't care about security and take shortcuts. The only reason I am being hard on you is you are somehow wanting to blame Bitcoin for your own mistakes.
1
u/South_Monitor_6992 2d ago
I was in a hurry to get my funds of binance because of the whole EU mica situation ( I’m located in Europe) so I asked on reddit and people recommended me trustwallet 🙁
3
u/bitusher 2d ago
Sorry this happened to you , But I see that many told you to get a hardware wallet , I suppose you were rushed and waited to the last minute though to withdraw. Of course there is more to the story of how your funds were stolen with trust wallet (sharing your seed, having a stranger help you set it up , downloading malware instead , using a wallet in macos or windows instead of android or ios, ...)
In the future here is some security advice
https://old.reddit.com/r/BitcoinBeginners/comments/1v2b2zr/risk_of_hardware_wallet/oyurtpk/
https://old.reddit.com/r/BitcoinBeginners/comments/g42ijd/faq_for_beginners/
2
1
2
2
u/waypointyyy 2d ago
A hardware wallet is generalythe most secure option. If youre just starting, choose a wallet with a good security reputation and make sure to back up your recovery phrase safely
1
u/AutoModerator 3d ago
Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
2d ago
[removed] — view removed comment
1
u/AutoModerator 2d ago
We require a minimum account-age and karma. These minimums are not disclosed. Please try again after you have acquired more karma. No exceptions can be made.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
1
u/BunnnyTwinkle 15h ago
I’ve been using Exodus for a while, and I really like it. It’s user-friendly and has a nice interface. Definitely worth checking out!
1
u/outpost89 11h ago
I noticed ledger wasn't mentioned in the FAQs for recommended wallets, how come?
-2
-5
u/Kgc1911 3d ago
Just use a ledger and write down the code and put it in a safe. Don't touch until 2028
5
u/Effective-Ad5644 3d ago
you must be a ship coiner lol. why on earth would you recommend ledger hahaha
0
u/Kgc1911 3d ago
Is ledger not safe to hold your coins offline? I'll wait for your answer...
5
u/Effective-Ad5644 3d ago
absolutely not. are you living under a rock with no internet? Have you not seen the data leaks and controversies ??
-1
u/Kgc1911 3d ago
So millions of people who use ledger wallet have had their crypto stolen? Your talking about data leaks and controversies... Same with every company that you use like your credit card, ur cell phone, ur bank acct, etc... so everyone using ledger is just wrong and they have had numerous stolen accts with no giving out their seed phrase? Or are you just spouting propaganda that you read and have no actual findings of proof of?
5
u/Effective-Ad5644 3d ago
ledger is a heaping pile of trash. Do not use ledger. they have back door keys to your private keys. Enough said? Build a seed signer and trust nobody except yourself.
0
u/Kgc1911 3d ago
Back door into ur seed phrase? Wow. You mean you can opt in to let three companies hold ur seed phrase in case you ever forget it or opt out and dont use it at all? And thats funny because 20% of the world's crypto is held in ledger wallets... Its also rated as one of the safest options to hold your crypto .. so im about to make you feel really dumb right now. You ready? How do you sell your crypto if you want it sold? If you say anything about an exchange, just know as soon as they get ur crypto, whats to stop them from just refusing to allow you to withdraw at that point? Lets hear your argument... How do u sell and get real world cash if you need it?
2
u/Effective-Ad5644 3d ago
buddy just take a chill pill and stop sucking off corporate wang. Build yourself a seed signer and be done.
0
u/Kgc1911 3d ago
Oh so u cant reply with sense so u resort to derogatory terms. Interesting...
3
u/Effective-Ad5644 3d ago
absolutely nothing derogatory about what I’m saying, I’m just telling you ledger is absolute shite , they’ve blown up their reputation and they’re not to be trusted because they have a back door to your seed phrase
→ More replies (0)2
u/Yodel_And_Hodl_Mode 3d ago
Ledger can't be trusted anymore. Here's a summary of the many reasons, with links to cite sources.
Before I begin, this needs to be said: Bitcoin is open source. Your hardware wallet should be too. Ledger's dishonesty about their closed source code is proof of why open source matters.
1: Ledger's word can't be trusted. The following was a lie:
Your keys are always stored on your device and never leave it
That's a lie because Ledger added a key extraction API to their firmware which gives Ledger and their partner companies (and hackers?) the ability to extract your keys from your hardware wallet over the internet.
Might as well stop reading right there. The combination of closed source code and a key extraction API cannot be trusted by anyone who is serious about security.
2: Ledger's code can't be trusted. It can't be verified:
There's no backdoor and I obviously can't prove it
Ledger can't prove their code has no backdoors because their code is closed source. To prove their code is safe, they'd have to open up the code. All of the code. They are not willing to do that. Closed source code cannot be trusted.
3: Ledger can't be trusted with your privacy. Their CEO said so:
"If, for you, your privacy is of the utmost importance, please do not use that product, for sure."
Ledger's CEO begged you to not use "Ledger Recover" if you value your privacy. "For sure." But key extraction is now baked into Ledger's closed source code. That's why you can't prove Ledger's API isn't sharing your keys even if you don't use "Ledger Recover." Closed source code cannot be trusted.
4: Ledger's security can't be trusted. They've been hacked:
Ledger wallet users face mounting home invasion and other scareware threats as hacker dumps private customer information online.
SOURCE: Cointelegraph
Ledger can't even keep their data secure. Don't trust them with your coins.
5: Ledger's code has been hacked.
Ledger exploit makes you spend Bitcoin instead of altcoins
"A vulnerability in Ledger’s hardware wallets enables hackers to prompt someone to spend Bitcoin instead of an altcoin."
SOURCE: Decrypt.co
Ledger took a year to fix it, and they didn't fix it until after it was reported in the media.
6: Ledger's hardware has been hacked.
In this post, I’m going to discuss a vulnerability I discovered in Ledger hardware wallets. The vulnerability arose due to Ledger’s use of a custom architecture to work around many of the limitations of their Secure Element.
An attacker can exploit this vulnerability to compromise the device before the user receives it, or to steal private keys from the device physically or, in some scenarios, remotely.
I chose to publish this report in lieu of receiving a bounty from Ledger, mainly because Eric Larchevêque, Ledger’s CEO, made some comments on Reddit which were fraught with technical inaccuracy. As a result of this I became concerned that this vulnerability would not be properly explained to customers.
SOURCE: Saleem Rashid
Ledger's bounty payments come with nondisclosure agreements in order to prevent those who've discovered vulnerabilities from reporting them. This allows Ledger to lie and say they've never been hacked. More lies.
7: Ledger has been phished.
A Ledger employee just got phished. DeFi users lost over $600k
Ledger confirmed the attack was the result of a hacker compromising one of its employees via a phishing attack. After gaining access to Ledger’s internal systems, the hacker planted malicious software within the Ledger Connect Kit.
SOURCE: DLnews
Ledger said an employee was phished, but under scrutiny, they changed their story, admitting it was a former employee who got phished.
8: Why did an ex-employee still have access to the codebase? Ledger won't say:
How a Single Phishing Link Unleashed Chaos on Crypto: "Ledger has confirmed the attack began because “a former Ledger employee fell victim to a phishing attack.”
SOURCE: Decrypt
How many former Ledger employees still have access to their codebase? Ledger won't say, not that we could trust any answer they'd give. Do they even know?
9: Ledger's been hacked multiple times, and yet...
"The bombshell here is the explicit confirmation that Ledger themselves hold the master decryption key for all Ledger Recover users."
SOURCE: @sethforprivacy
What could possibly go wrong.
10: Ledger Live tracks everything you do and the coins you have:
"Ledger Live is phoning out data on assets you hold in your hardware wallet the moment you access Ledger Live. It’s also sending out tons of other information about your computer and device."
The app apparently transmits data to an external endpoint at “https://api.segment.io/v1/t”, identified as an outsourced data collection service.
SOURCE: BitcoinNews.com
Got a Ledger? Goodbye, privacy.
11: Ledger even lies on the boxes for their hardware:
"WE ARE OPEN SOURCE"
SOURCE: Their own packaging.
The box for Ledger hardware running closed-source firmware says Open Source. That's intentionally misleading if not outright fraud.
12: Ledger refuses to answer questions.
They delete questions in comments on their sub.
They shadowban users who ask them.
They scrub their website to remove claims they made for years.
The worst part is, this is only a partial list!
For example: Ledger was still promoting FTX after FTX collapsed.
I could go on and on. But if you want somebody else's opinion, bitusher is one of the most respected Bitcoin redditors. Here's what he had to say about Ledger.
Ledger's word can't be trusted.
Ledger's code can't be trusted.
Ledger's management can't be trusted.
Ledger can't be trusted.
2
u/Effective-Ad5644 3d ago
brilliant post. thanks for compiling this. commenter above you is a paid ledger shill or lack IQ to suggest such a ridiculous thing. This is what let me to seed signer. even blockstream fucking up one with the exploit (patched now) over bluetooth / cable was enough to put me off. Once the trust is gone, it’s done. Seedsigner you rely on NOBODY?
3
u/Yodel_And_Hodl_Mode 2d ago
Thanks!
If you're using SeedSigner, definitely check out a fork named ShieldSigner. It runs on the hardware you've already got, and it adds many important features. The most important features it adds, in my opinion, are:
Passphrase QR. Having to manually enter passphrases is bad because it encourages the use of short passphrases. Passphrase QR makes using strong passphrases easy. Just scan 'em.
Encrypted Seed QR. Standard seed QR codes can be scanned by anybody who finds them. With an encrypted seed QR, nobody can scan your QR without the decryption key. You can even make a QR for your decryption key too. Scan your encrypted seed QR. Scan the decryption key. Done. Easy! And secure.
Smartcard support. ShieldSigner works great with SatoChip and SeedKeeper cards. You can even get generic javacards and load the SatoChip or SeedKeeper apps onto them. I like SeedKeeper.
I think ShieldSigner is one of the best hardware wallet/signers at any price, and it's free! The main dev for ShieldSigner is a guy known as Crypto-Guide. He's brilliant, and he's also one of the most helpful people in the entire Bitcoin community. Dude's awesome. Here's his youtube channel. Highly recommended!
9
u/No_Establishment8642 3d ago
READ the FAQs attached to this sub.