Damus
Juraj🏴💛🌘 profile picture
Juraj🏴💛🌘
@Juraj
Three questions to ask about any hardware wallet

Most comparisons argue about chips. Three duller questions tell you more:

Does an outside firm test it, and can you read the report? Anyone can claim their device is secure. Paying researchers to attack it and then publishing what they found, including the unflattering parts, costs money and stings.

Do they pay for bugs? A bounty gives someone who finds a flaw a reason to report it rather than sell it, and gives skilled researchers a reason to go looking at all.

Can those researchers see the code? Closed firmware still gets attacked. Fuzzing over USB or QR is routine, and reverse engineering has got cheaper as models have got better at reading disassembly. Source code does not make an audit possible, it makes it cheaper, so more people attempt more of it. Open source beats source available too, because code under a real licence gets reused, and the developers reusing it (sometimes) read it.

All three

Passport publishes firmware under GPL and hardware under CERN-OHL-S v2, complete enough to build one from the files. Outside audits are online with the fixes. The bounty covers the device, though the amount is decided case by case.

Keystone also has all three, with the best evidence that its bounty works: outside researchers found a real firmware flaw and got paid. Audits from two firms, reproducible builds, schematics and secure element firmware published. One catch is theirs alone: researchers are asked not to disclose without written approval, with no time limit.

Two of three

Trezor publishes firmware and hardware and runs the best funded bounty, up to $100,000. No commissioned audit report, but the secure element in its newest device was tested externally and the flaw disclosed publicly.

Ledger pays well and its in house team does serious offensive work, including on rivals. Firmware and OS are closed, so every finding costs more effort. The chips are lab certified, but you only see the certificate.

Open and nothing else

Jade and Bitkey publish firmware, Bitkey with reproducible builds. No audits or bounties, so the code waits for volunteers. Sometimes they turn up: Jade's serious 2025 flaw was found and reported for free.

SeedSigner is as open as anything here and built from off the shelf parts, but there is no company; an audit or bounty was never on offer.

This measures how a company behaves, not how the device is built. Still, between two similar devices, take the one that publishes its code and pays people to break it.
349❤️14❤️3👍2🤙21🌻1
murmur · 1d
Want to hear this note? I'll turn it into audio for the thread once 500 sats land here. One zap or many.
bootlace · 1d
audit this https://blossom.primal.net/65000d63ce1ac35720e00e7d260581032811c3907c0879faf899124d6298ef77.png
m4d4m · 1d
The SeedSigner - they have no stash to put the bounty up. So there is that. And an audit is maybe hard, as the parts vary in source and manufacturing quality. (I get the point, and according to the rules, they need to fit in somehow.)
Financial Parasites · 1d
Ledger is the only one among those who provides custody solutions to institutions.
zoomoutpls · 1d
Non-binding Code of Conduct
Imaginaero · 1d
Independent penetration tests are rarely comprehensive; a significant number rely solely on the manufacturer’s own internal validation, which demonstrably favors positive outcomes.
Cody · 1d
What do you know about nostr:nprofile1qqsy3hc9jy28npuqzmc908td6cmx6dtaf36llel2adch6kynwksywecprpmhxue69uhhqunfd46hxtnwdaehgu339e3k7mf0qyghwumn8ghj7mn0wd68ytnhd9hx2tcpy9mhxue69uhkzun5d93kcetn9ekxz7t9wgejumn9waej76n4d35k2aqkes3l7 ?
Neo ⚡️ · 21h
“but the secure element in its newest device was tested externally and the flaw disclosed publicly” so the trezor 7 is compromised?
Anita · 20h
Did you look how the BitBox compares?
NaKojnu · 20h
BitBox ticks all boxes, we. believe. nostr:nprofile1qqs9500z3l7sn46sdnls5fnjm0d3lqmrq7707qshes2y7j8pnm4rllcfc0kcc
cryptowolf · 15h
“Ľudia idú ako ovce, kam ich baran vedie…” - J.Z.
John Satsman · 15h
A big enough bug is worth sitting on for 4 years & exploiting on a random Sunday evening nostr:nevent1qqs2p8g0u2aslm4vd67addmlmnp6ydksp74k4uxztlnafwmdmsy4gvgjfhjrp
cryptowolf · 15h
https://blossom.primal.net/d3204ed4b2411c1bb126f98606390e727304de4e579f5f4f9f657f24cd7a0f72.png
cryptowolf · 15h
Jonáš Záborský 's approach can be summarized in four principles: 1. Historical claims must be supported by evidence He repeatedly attacks chroniclers who rely on legend or patriotic embellishment. 2. National myths are dangerous He believed that nations deceive themselves ...
cryptowolf · 14h
“Illusions are cheap, evidence is expensive — that is why it is true.” https://blossom.primal.net/d44850318dc943277cf48eaf81ecd2a6d3f58527de0a39f6d7e405c89885af62.png
Chris · 12h
So many thoughts here…. But mostly…. In the time it takes one to go through all these mental gymnastics as to whose hardware DEVICE is least likely spit out a piece of compromised/insufficient entropy, one can generate their OWN entropy. Myself, I use these hardware devices for their most ba...
The Stacker Monster · 3h
I see nostr:nprofile1qyv8wue69uhnsvfwxcuzuvfhxqhrzv3j8gmnzvf59uq3vamnwvaz7tm9v3jkutnwdaehgu3wd3skuep0qqsdg2ufsmn9t0fkal4jsd7pmx3370uwaa5gerf385ju0xmussygn3q0zvh6l has one audit from 2020 in their github. I don't know how often code should be audited to be considered current? Do you think that is suf...
The Stacker Monster · 3h
I think we should apply these same standards to wallet coordination/management software. Sparrow Wallet (by the brilliant nostr:nprofile1qy2hwumn8ghj7etyv4hzumn0wd68ytnvv9hxgqguwaehxw309ahx7um5wgkhyetvv9ujuamvweejuumsv93k2qpqhea99yd4xt5tjx8jmjvpfz2g5v7nurdqw7ydwst0ww6vw520prnq70qrf6 ) has been widel...