Dylan
· 4d
My thought is that since these wallets haven’t fallen yet, is switching a foolish move. With coldcard getting wrecked, one can assume they will make sure it never happens again. With other ones who ...
the idea with multi-vendor multisig is that you’re protected against any one of the vendors going down at one time. it is much more complicated though and introduces a lot of ways you can mess up yourself and lose your own funds because you don’t remember how you set things up. i wouldnt trust coldcard with any funds ever again because 1) they had an egregious error in their security code that people are arguing either represents extreme incompetence or intentional malice (which would mean a long jail sentence for the creators, 2) the code is still not open source (like most of the other HWW options i listed) so you can’t verify that there are not other vulnerabilities, 3) CC will likely be sued and their company will not be able to make it financially, this means that the wallet firmware won’t be maintained and any new security issues can’t be patched and any updates to bitcoin in the future won’t be supported, 4) there are a lot of people in the bitcoin space working together right now auditing the codebases of all the open source wallets and disclosing any vulnerabilities. it doesnt seem like the other HWW’s had any vulnerabilities that could have resulted in loss of user funds like this one, but they are nonetheless strengthening their security and hardening their codebases. At the end of the day, CC failed at the most basic of security tasks, so they are dead to me. If you just had your bitcoin in one of the other single sig wallets it’s possible that they would have never fallen because their security code is not flawed, but this episode taught me that unless I personally have verified the code, I am risking losing all my funds at some point in the future. So for me, personally, I want to mitigate that risk with multisig. But the final decision is up to you. If you are not technical and feel the risks of losing your own funds with multisig are higher than the risks of being rugged with single sig by one of the HWW companies, then don’t do multisig. One other option that is sort of unique is the bitkey which is a collaborative custody multisig which would protect you from compromise of one of the keys but you are also putting sole trust in Block to secure your funds. They do make it much easier for non-technical people though and would help with backups and wallet recovery