2026年8月9日 · 星期日
● 每日更新·改变自己
Eurekar·TOP
捕捉真实世界的英语信号
25信息来源
10,784精选文章
168单词卡片
18照片图片
全部7,175口语2,069免费826帖子3,249新闻1,599hackernews812tmz628techmeme542slashdot379随笔323techcrunch305arstechnica300外刊291Cards168simonwillison100动态69bloomberg60sethgodin50图片18youtube7

>use hardware wallet

>用硬件钱包

4chan /biz/ · Anonymous · 2026-08-01 08:25 · 92 帖 · 原文 ↗

← 上一篇返回列表下一篇 →
#1 >use hardware wallet / >用硬件钱包
Anonymous · 2026-08-01 08:25

>use hardware wallet

>用硬件钱包

>still get hacked

>照样被黑

So where exactly are you supposed to hold your buttcoins?

那你的屁股币到底该放哪儿?

图片: https://i.4cdn.org/biz/1785572746250720.jpg

#2 No.62549162
Anonymous · 2026-08-01 08:47

>>62549140

I keep mine offline in an encrypted file.

我放着离线加密文件里。

#3 No.62549194
Anonymous · 2026-08-01 09:32

Hardware wallets are bulletproof. It's dumbass humans that get hacked.

硬件钱包是坚不可摧的。被黑的都是蠢人。

#4 No.62549203
Anonymous · 2026-08-01 09:36

>>62549140

on an exchange

放在交易所里

#5 No.62549342
Anonymous · 2026-08-01 11:47

>>62549194

their seed generation had a bug, literally the wallets fault

他们的种子生成有bug,说白了就是钱包的锅

#6 No.62549696
Anonymous · 2026-08-01 15:02

>>62508806

图片: https://i.4cdn.org/biz/1785596524759742.jpg

#7 No.62549735
Anonymous · 2026-08-01 15:17

I'm very fucking glad I didn't trust any hardware and I generated my wallet with the 100 dice rolls method. So even though I have a Q, its basically just a signer for me and I never relied on its PRNG for my security.

我他妈太庆幸自己没信任何硬件,我用100次掷骰子的方式生成了钱包。所以就算我有个Q,对我来说它基本就是个签名器,我从来就没靠它的随机数发生器保安全。

#8 No.62549789
Anonymous · 2026-08-01 15:35

>>62549194

>bulletproof

but not wrench proof you moron

但扛不住扳手攻击,你个傻逼

#9 No.62549808
Anonymous · 2026-08-01 15:41

>>62549140

not all hardware wallets are made equally.

不是所有硬件钱包都一个水准。

don't use a cuckcard.

别用cuckcard。

#10 No.62549906
Anonymous · 2026-08-01 16:17

>>62549808

Brought to you by CoinKike

由CoinKike赞助

#11 No.62549911
Anonymous · 2026-08-01 16:22

i simply do not hold coins

我干脆不持币。

#12 No.62549921
Anonymous · 2026-08-01 16:26

I only remember this piece of shit from ads I saw years ago. no one ever talked about it. now we see why

我就是几年前从广告里记住这垃圾货的。从来没人讨论它。现在知道为啥了。

#13 No.62549938
Anonymous · 2026-08-01 16:33

Rolling for inside job. Thankfully, I rolled dice but I still transferred the funds off my Q this morning.

押注有内鬼。还好我掷了骰子,但今早我还是把资金从我的Q上转走了。

图片: https://i.4cdn.org/biz/1785602024793392.jpg

#14 No.62549947
Anonymous · 2026-08-01 16:36

>>62549735

It's funny how everyone preaches "don't trust, verify" but then trust all this complex code, RNG functions, secure chips, crypto libraries etc. Nobody can convince me there's a more secure and fool proof way of generating randomness for a BIP39 word than flipping a coin 11 times.

挺好笑的是,人人都喊“别信,要验证”,然后却信这些复杂代码、随机数函数、安全芯片、加密库之类的。没人能说服我,比扔11次硬币生成BIP39词组的随机性更安全更不会出错的方法存在。

>>62549789

There are timelocks, fake PINs, wipe PINs, multisigs, Shamir's secret sharing... so many different ways to prevent a wrench attack.

有时锁、假PIN、擦除PIN、多重签名、Shamir秘密分享……这么多办法都能防扳手攻击。

#15 No.62550131
Anonymous · 2026-08-01 17:38

>>62549194

Coldcard literally wasn't. Its RNG seed generation was flawed and now people can find working seeds in like 5-10 seconds with AI.

Coldcard显然不是。它的RNG种子生成有缺陷,现在人用AI大概5-10秒就能找出有效种子。

Ledger and trezor are probably safe though

Ledger和Trezor应该还是安全的

#16 No.62550270
Anonymous · 2026-08-01 18:28

>>62549938

>I rolled dice

>我掷了骰子

> I still transferred the funds off my Q this morning.

>今早我还是把资金从我的Q上转走了

I'm really not sure why you'd bother. If you rolled enough dice for a full 256 bits of entropy then the Q is doing nothing at all other than signing. I'm not sure why you'd "transfer" funds off a perfectly randomized wallet. If you distrust the hardware then run the nuke on the Q and just switch the same wallet onto a different hardware capable of doing signing.

我真不确定你为啥要折腾。如果你掷了足够多的骰子拿到完整的256位熵,那Q除了签名啥也没干。我不明白你为啥要把钱从完美随机的钱包里“转走”。如果你不信硬件,那就给Q跑个核爆,然后把同一钱包切到另一个能签名的硬件上就行。

#17 No.62550279
Anonymous · 2026-08-01 18:30

>>62549947

Yeah, at this point I think the ideal cold storage hardware wallet only has a secure element to optionally store your 24 words and a way to do signing.

是啊,到了这一步,我觉得理想的冷存储硬件钱包只需要有个安全元件可选存你的24个词,加上一个签名功能就够了。

Generating is a waste. You can never trust a hardware wallet to do the generation better than dice or coin throws.

生成就是个浪费。你永远没法信任硬件钱包生成的比骰子或掷硬币更好。

#18 No.62550296
Anonymous · 2026-08-01 18:35

Everyone preaching "generate your own with dice/coin throws"... how do you generate the 24th word which is a checksum?

人人都说“用骰子/掷硬币自己生成”……那第24个字是校验和,你咋生成?

#19 No.62550321
Anonymous · 2026-08-01 18:47

>>62550296

General consensus is to use a checksum generator on computer that is not connected to the internet and will be wiped later (Linux distro Tails is good for this).

一般共识是用一台不联网、以后会抹掉的电脑上的校验和生成器(Linux发行版Tails很适合干这个)。

#20 No.62550332
Anonymous · 2026-08-01 18:50

>>62549140

Coinbase

#21 No.62550354
Anonymous · 2026-08-01 18:57

>>62550296

some wallets give you the option to use dice and compute everything for you. You should still do a few test runs and compare them with an online tool like iancoleman. Then when you're sure it works you only use the hardware wallet.

有些钱包给你掷骰子的选项,帮你算所有东西。你还是应该先试几次,然后和Iancolman之类的在线工具比对一下。等你确定没问题了,再用硬件钱包。

other wallets compute the checksum for you and give you a list of valid words after entering the first 23. Blockstream Jade for example.

其他钱包会帮你算好校验和,输入前23个词后给你列出有效候选词。比如Blockstream Jade就是这样。

I also found a sh (I only use linux) file that lets me xor two seeds (even without valid checksum) and gives the XOR with a valid checksum (use option -s). So to get a valid checksum you can do. script.sh -s -24 words here- XOR -abandon x24-. Because abandon is just 11 zeros it does nothing when xor'ing. But the script will still return the correct checksum.

我也找到了一个sh脚本(我只用Linux),它可以让我对两个种子进行异或(即使没有有效校验和),并给出带有效校验和的异或结果(使用-s选项)。所以要得到有效校验和,你可以这样做:script.sh -s -24 words here- XOR -abandon x24-。因为abandon只是11个零,异或时它什么都不做。但脚本仍然会返回正确的校验和。

> https://github.com/GregTonoski/BIP39-XOR

XORing seed also allows you to mix entropy from two sources. So you could xor a computer generated seed together with a dice generated seed

异或种子还可以让你混合两个来源的熵。所以你可以把电脑生成的种子和骰子生成的种子异或在一起。

#22 No.62550440
Anonymous · 2026-08-01 19:42

>>62549938

Don't attribute to malice what can be attributed to incompetence.

别把能用无能解释的事归咎于恶意。

If you ever worked a day in software dev you would know how retard most devs are

如果你在软件开发上干过一天,你就会知道大多数开发者有多蠢。

#23 No.62550530
Anonymous · 2026-08-01 20:24

>>62549140

use open source software

用开源软件吧。

#24 No.62550562
Anonymous · 2026-08-01 20:36

Funds are safu

资金是安全的。

#25 No.62550574
Anonymous · 2026-08-01 20:42

>>62549938

Well, it is closed source so it probably was.

嗯,它是闭源的,所以很可能是那样。

#26 No.62550581
Anonymous · 2026-08-01 20:46

>>62549140

>Don't trust. Verify.

>别信任。要验证。

Oh how ironic.

哦,真讽刺。

#27 No.62550583
Anonymous · 2026-08-01 20:46

>>62550530

Coldcard literally was open source

Coldcard 字面上是开源的。

#28 No.62550597
Anonymous · 2026-08-01 20:56

>>62549140

Metamask

#29 No.62550615
Anonymous · 2026-08-01 21:04

>>62550583

Was until it wasn't, stop spreading bollocks mate

曾经是,直到它不是了,别瞎扯了兄弟。

#30 No.62550620
Anonymous · 2026-08-01 21:06

>>62549140

>Company called coldcard

>一家叫Coldcard的公司

>Isn't actually cold storage

>实际上不是冷存储

?????

#31 No.62550632
Anonymous · 2026-08-01 21:11

>>62550581

Not trusting Coldcard and using their own paranoid guide is actually what saved me here, thanks to doing 100 dice of entropy avoiding the firmware bug entirely.

不信任Coldcard并用了他们自己的偏执指南,实际上在这里救了我,多亏做了100次骰子熵,完全避开了固件漏洞。

#32 No.62550637
Anonymous · 2026-08-01 21:12

>>62550615

What the fuck are you talking about? The firmware source code has been completely open to anyone since 2018 until today, you fucking retard

你他妈在说什么?固件源代码从2018年到现在对任何人都是完全开放的,你个傻逼。

#33 No.62550660
Anonymous · 2026-08-01 21:28

>>62550637

I think you mean source available which is not the same as open source, that's like saying your website is open source because you published the code, you're just saying to people trust me bro

我觉得你说的是源码可获取,这和开源不一样,就像你说你的网站是开源的因为你发布了代码,你只是在跟人说“信我老哥”。

#34 No.62550672
Anonymous · 2026-08-01 21:34

>>62550660

>Yeah, the source code was publicly available, auditable and reproducible, but they restricted commercial resale by competitors so it's not truly open source

>是啊,源代码是公开可审计可复现的,但他们限制竞争对手商业转售,所以不算真正的开源。

Semantics and irrelevant to the discussion

语义问题,和讨论无关。

#35 No.62550685
Anonymous · 2026-08-01 21:41

I remember my phrase.

我记得我的话。

My mind is my hardware wallet.

我的头脑就是我的硬件钱包。

#36 No.62550714
Anonymous · 2026-08-01 21:52

Dice, paper and prayers

骰子、纸和祈祷。

#37 No.62550739
Anonymous · 2026-08-01 22:04

>>62550714

You do have backups in case you lose that little paper, correct?

万一那张小纸丢了,你确实有备份吧?

#38 No.62550747
Anonymous · 2026-08-01 22:07

>>62550660

Quit with your arbitrary and autistic definitions. If you can see the source code, its open source. So fucking stupid that fosstards think if they can't compile it it doesn't count. That is a mentally retarded and arbitrary line.

收起你那些武断又自闭的定义吧。如果你能看到源代码,那就是开源的。那些FOSS饭桶觉得不能编译就不算数,简直傻逼到家了。那是精神有问题的武断界限。

#39 No.62550772
Anonymous · 2026-08-01 22:23

All of this shit has just shown me that hardware wallets are mostly gimmicks of various sorts. The real way is to generate a wallet is 100 dice throws and then using that phrase. If you want more, throw a passphrase in there.

这一切只是让我看到,硬件钱包大多是各种噱头。真正的方式是掷100次骰子生成一个钱包,然后用那个助记词。如果你想要更多,就加个密码短语。

After that its just a matter of whether the hardware wallet stores the keys or if its a QR solution or a secured element card. Everything else is just simple ass signing or features like temporary wallets, indexes, whatever.

之后只是硬件钱包是否存储密钥、是否使用二维码方案或安全元素卡的问题。其他一切都是简单的签名或功能,比如临时钱包、索引什么的。

For 99% of hodlers, you do not give a shit about your wallet's capabilities beyond how secure the secure element is if its storing your keys. All you need is signing so you can move your coins.

对99%的囤币者来说,你不会关心钱包的能力,除了存储密钥时安全元素有多安全。你只需要签名来转移你的币。

>>62550685

Based, just don't get hit in the head.

有道理,只是别被打到头。

#40 No.62550818
Anonymous · 2026-08-01 22:39

>>62550747

that is an important distinction and it has a meaning, the amount of eyeballs in an actual (and important) open source project makes those kind of issues improbable, coldcard was not open source and the meaning was "let us handle the code", well here is the result

这是一个重要的区别,而且它有含义,在一个真正(且重要的)开源项目里,那么多的眼睛盯着,这类问题基本不可能发生。Coldcard 不是开源的,言下之意就是“代码我们来管”,结果呢,这就是下场。

this issue is clearly a consequence of human error from a very limited amount of people working on it

这个问题显然是极少数人参与工作导致的人为失误的直接后果。

#41 No.62550830
Anonymous · 2026-08-01 22:44

>>62550811

>fuck up the dice throws

>掷骰子掷砸了

easiest and fastest way to use dices is to put them in a clear box and shake it.

用骰子最简单最快的方法就是把它们放进一个透明盒子里摇。

>or the dice are biased

>或者骰子有偏差

you can throw dices and look at the distribution of the numbers.

你可以掷骰子然后观察数字的分布。

bitcoin only has 128 bits of security. Throwing some slightly biased dices for 256 bits is still overkill

比特币只有128位安全性。用有点偏差的骰子掷出256位,还是绰绰有余。

#42 No.62550861
Anonymous · 2026-08-01 22:57

Coldcard was not open source. Nobody is allowed to use the source code for new projects. There's no point for anyone to review the code. The bug literally got introduced and stayed there ever since they removed all GPL code dependencies.

Coldcard 不是开源的。没人可以用它的源码搞新项目。没人有必要去审查代码。这个漏洞就是被引入后一直留着,从他们移除所有 GPL 代码依赖开始就没动过。

Continuation of tweet:

推文续:

Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.

我们目前最好的理解是,熵漏洞是这次重大代码库重构的附带损伤。

To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

需要说清楚,这次重构不单纯是许可问题。Coldcard 也提到了技术目标,包括采用 Bitcoin Core 的 libsecp256k1、更快的 AES 和 SHA 实现,以及可重现构建。

But the timeline establishes two things:

但时间线证明了两件事:

(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and

(1)Foundation 的推出显然是 Coldcard 改许可的直接推动力,而且

(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

(2)移除剩余的 GPL 代码是后续 v4 重写的明确目标。

We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.

我们不知道许可压力对重写的范围和时间线影响了多少。我们能确定的只是,熵漏洞是在同一个移除旧 GPL 代码依赖的 120 文件提交里被引入的。

图片: https://i.4cdn.org/biz/1785625046454628.png

#43 No.62550865
Anonymous · 2026-08-01 22:58

>>62550620

it was cold storage you could have done everything right, but it only generated a few different seeds so anyone can guess them, and now people are guessing multi-sigs and 25th words which take more time to crack.

那是冷存储,你其他什么都做对了,但它只生成了少数几个不同的种子,所以任何人都能猜出来,而现在人们在猜多签和第25个词,那些破解起来更费时间。

It's a free for all 1,000s of BTC are being stolen right out of safety deposit boxes with zero access all because of a non random seed generator.

这就是一场混战,数千枚 BTC 正在从完全无法接触的保险箱里被偷走,全都因为一个非随机的种子生成器。

#44 No.62550890
Anonymous · 2026-08-01 23:10

>>62550861

>they removed all GPL code dependencies.

>他们移除了所有 GPL 代码依赖。

>the entropy bug was collateral damage from this major overhaul of the codebase.

>熵漏洞是这次重大代码库重构的附带损伤。

>adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

>采用 Bitcoin Core 的 libsecp256k1、更快的 AES 和 SHA 实现,以及可重现构建。

>removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

>移除剩余的 GPL 代码是后续 v4 重写的明确目标。

>120-file commit that removed the old GPL code dependencies.

>120 文件提交,移除了旧 GPL 代码依赖。

lol NERDS

哈哈哈 书呆子

#45 No.62550934
Anonymous · 2026-08-01 23:33

You fucking retards thought you could be your own bank KEK

你们这帮傻逼以为自己能当自己的银行,乐了。

#46 No.62550937
Anonymous · 2026-08-01 23:34

>>62549140

>So where exactly are you supposed to hold your buttcoins

>那你的币到底该放哪?

In your butt

放你屁眼里。

#47 No.62550938
Anonymous · 2026-08-01 23:34

>>62550321

>>62550296

All this cuck work just to lose money KEK

折腾半天结果还是亏钱,乐了。

#48 No.62550950
Anonymous · 2026-08-01 23:41

>>62549342

Not to sound like a massive faggot but if you just rolled the dice instead of using their shit rng. You would be fine.

别说得像傻逼似的,你要是自己掷骰子而不是用他们的破随机数,完全没事。

#49 No.62551062
Anonymous · 2026-08-02 00:38

>>62550934

OY VEY COINKIKE WILL TEACH YOU ABOUT BEING YOUR OWN BANK GOY

YOU CAN TRUST NVK HE'S A NICE JEWISH BOY

#50 No.62551093
Anonymous · 2026-08-02 01:06

>>62550672

it's not semantics. you are stupid

这不是咬文嚼字,你就是蠢。

#51 No.62552068
Anonymous · 2026-08-02 11:44

There's people dumping their coins over this and I dont blame them. You lose 40, 50k and get ready to sign divorce papers or live with the shades drawn all your life out of embarrassmentand and fear. Its literally the same story, guy wakes up to find his life savings gone and nothing he can do about it, asks for help, gets scammed some more lol.

有人因为这事在抛币,我不怪他们。你亏了4、5万刀,准备签离婚协议,或者这辈子拉上窗帘过活,又尴尬又恐惧。说白了就是老套路:一觉醒来发现积蓄没了,啥也做不了,找人帮忙反而被再骗一轮,哈哈。

#52 No.62552097
Anonymous · 2026-08-02 12:03

more like aladdincard cause that rug flew

更像阿拉丁卡,因为那张地毯直接飞了。

#53 No.62552254
Anonymous · 2026-08-02 13:10

>>62549140

multisign

#54 No.62552417
Anonymous · 2026-08-02 14:33

>>62549203

>exchange goes bankrupt when oil is 300 dollars a barrel because of drumpf's war for chosenites and they can't afford to keep the lights on

>油价300美元一桶时交易所破产,因为川普为犹太人的战争,连电费都付不起了。

>sorry no refunds

>抱歉,不退款。

Genius move.

天才操作。

#55 No.62552433
Anonymous · 2026-08-02 14:39

>>62550685

Your memory goes to shit as you age. Good luck.

年纪大了记忆就烂了,祝你好运。

#56 No.62552638
Anonymous · 2026-08-02 16:00

>>62549947

>so many different ways to prevent a wrench attack.

>防扳手攻击的方法多了去了。

yes

图片: https://i.4cdn.org/biz/1785686407757273.jpg

#57 No.62552656
Anonymous · 2026-08-02 16:07

i make 30k/yr in dividends at 2.6%. i don't even know what's happening. the device looks like a bargain bin overstock lot of blackberries that some autist figured out to sell to retards on the Internet.

我靠2.6%利息一年拿3万刀分红。我都不知道发生了啥。那设备看起来就像清仓甩卖的黑莓堆,被某个自闭症患者拿来忽悠网上的傻逼。

#58 No.62552666
Anonymous · 2026-08-02 16:11

>>62550739

How many times have you lost your passport anon? your social security number or your birth certificate?

哥们,你丢过几次护照?丢过几次社保号或者出生证明?

#59 No.62552710
Anonymous · 2026-08-02 16:27

>>62549140

So how did no one catch this for so long? Wasn't this vulnerability around since 2022? And even AI models running the code could tell you about the vulnerability. So no one thought to check openly available code at all? Not even their own devs?

那为啥这么久没人发现?这漏洞不是2022年就存在了吗?连跑代码的AI模型都能告诉你漏洞在哪。所以压根没人想着检查公开代码?连他们自己的开发都没查?

Also is something like Keystone still safe? Kind of starting to think this whole "be your own bank" larp is becoming laughably absurd if you start having to talk about doing 100 fucking dice rolls to secure your stack. "Future of finance." Yeah, imagine any of this becoming mainstream.

还有,像Keystone这类东西还安全吗?我开始觉得这整套“当自己的银行”的戏码越来越搞笑荒谬了,要是你开始说要掷一百次骰子才能保护好你的资产。“金融的未来。”是啊,想象这玩意儿变成主流吧。

#60 No.62552733
Anonymous · 2026-08-02 16:37

>>62552710

That's not even the real problem. Even if you were using a regular bank, you could still fuckup and leak your password/pin/whatever and get drained. The real problem is that with bitcoin or any crypto, if it happens, there's nothing you can do about it. Poof, gone forever with no help. With regular banking you have a good chance of getting it back or potentially having the transaction caught and stopped before it even occurs. The danger of crypto is having literally 0 backstop. Well, that and also the fact that nearly everyone in the space is trying to scam you.

那其实还不是真正的问题。就算你用的是普通银行,你还是可能搞砸,泄露密码、PIN码什么的然后被掏空。真正的问题是,用比特币或任何加密货币,一旦发生这种事,你一点办法都没有。嗖的一下,永远消失,没人能帮你。普通银行的话,你有很大机会把钱拿回来,或者交易可能在被执行之前就被拦截和阻止。加密货币的危险在于完全没有兜底。还有一个事实是,这个圈子里几乎人人都在想骗你。

#61 No.62552748
Anonymous · 2026-08-02 16:40

>>62549140

future of finance! no refunds

金融的未来!无退款

#62 No.62553112
Anonymous · 2026-08-02 19:01

>>62552666

I lost all of it in a housefire.

我全在一场房子火灾里丢了。

#63 No.62553130
Anonymous · 2026-08-02 19:07

>>62553112

Damn, that's a shame. I hope you are doing alright anon.

操,真可惜。希望你还好,匿名老哥。

#64 No.62553185
Anonymous · 2026-08-02 19:30

>>62553130

Happened a long time ago. Point in making this is that you can lose the seed on paper through factors outside of your control. At least get a titanium plate and dremel the seed on it so you can dig for it if your house burns down.

那是很久以前的事了。发这个帖子的重点是,你可以通过自己控制不了的因素在纸上丢掉种子。至少搞个钛合金板,用打磨机把种子刻上去,这样就算房子烧了也能挖出来。

#65 No.62553297
Anonymous · 2026-08-02 20:26

>>62550296

You don't. You generate the private key directly with dice throws and generate your seed phrase from that

你不需要。你直接用掷骰子生成私钥,然后从那里推导出助记词。

#66 No.62553570
Anonymous · 2026-08-02 22:08

sars your coins are in veryvery trouble

严重警告,你的币现在麻烦大了

图片: https://i.4cdn.org/biz/1785708489617891.png

#67 No.62553725
Anonymous · 2026-08-02 22:53

>>62549947

> muh mitigation and muh self-soveriengty

> 我的缓解措施和我的自我主权

Torture enters the chat.

酷刑上线了。

图片: https://i.4cdn.org/biz/1785711181949429.png

#68 No.62553785
Anonymous · 2026-08-02 23:19

>>62550296

Okay I was wrong about fool proof because the checksum makes it complicated, but the main point is to generate entropy in a way where you can guarantee it's random.

好吧,我说绝对安全是错了,因为校验和让它复杂了,但关键是用一种你能保证随机性的方式生成熵。

>how do you generate the 24th word which is a checksum?

> 你怎么生成第24个词,也就是校验和?

Easy mode with a dedicated tool: get offline version of iancoleman BIP39 tool and use that on an airgapped pc.

简单模式用专门工具:拿离线版iancoleman BIP39工具,在一台完全断网的电脑上用。

Medium mode with basic tools: convert your 256 bits of dice/coin generated entropy to hex, run that through SHA256 (make sure to use hex encoding and not UTF-8 or whatever else), take the first 8 bits of the hash (2 hex characters), convert those to binary and add them to the end of the last 3 bits of your entropy, and walla those 3+8=11 bits are your 24th word.

中等模式用基本工具:把你用骰子或硬币生成的256位熵转成十六进制,跑一遍SHA256(确保用十六进制编码,别用UTF-8或其他),取哈希的前8位(2个十六进制字符),转成二进制加到熵最后3位后面,好了,那3+8=11位就是你的第24个词。

Schizo mode with zero computer tools: medium method but convert bin<->hex by hand and hash SHA256 on paper. You will need software for deriving keys and signing transactions anyway so going this far is pure schizo.

精神分裂模式零电脑工具:中等方法但手工转二进制<->十六进制,然后在纸上算SHA256。反正你最后还得用软件来派生密钥和签名交易,搞到这一步纯属脑子有病。

>>62552638

Based, but having crypto logos visible anywhere can only reduce your security.

有道理,但任何地方出现加密货币logo只会降低你的安全性。

>>62553725

>torture

Your picrel is right. It doesn't matter if the torturer gets your crypto or not because anyone willing to go that far will just kill you in the end. If a smart robber knows there might be all these crypto security setups that make it impossible or extremely hard to access the money, they might choose a different target like a gold hoarding boomer or a watchfag.

你贴的图是对的。折磨你的人能不能拿到你的币根本不重要,因为愿意走那一步的人最后反正会弄死你。如果聪明的强盗知道可能有这些加密货币安全设置导致钱几乎拿不到或极难拿到,他们可能会选别的目标,比如囤金的老年人或玩表的家伙。

#69 No.62554499
Anonymous · 2026-08-03 04:17

>>62549194

/thread

>>62549342

>>62549789

>>62550131

Hardware wallets store your crypto offline

硬件钱包把的加密资产离线存储。

They probably had it

他们八成是这么丢的:

A) Either connected to the internet

A) 要么连过网

B) Wrote down their seed phrase someplace and hackers found it

B) 要么把助记词写在某个地方,被黑客找到了

Rule 1 in crypto:

加密圈第一定律:

- Don't believe everything you see on the internet

- 别信网上看到的一切

#70 No.62554517
Anonymous · 2026-08-03 04:24

>>62554499

no dude that's not at all happened. the hardware wallet generated shitty seed phrases that were easy to predict. It was a bug in the code of the hardware wallet

哥们儿,根本不是那么回事。硬件钱包生成的助记词烂得一批,太好猜了。是硬件钱包代码里的一个bug。

#71 No.62556059
Anonymous · 2026-08-03 15:06

>>62549194

>Hardware wallets are bulletproof. It's dumbass humans that get hacked.

>硬件钱包固若金汤。被黑的是那些傻逼人类。

no, it had bug in firmware.

不,是固件里有bug。

>>62554499

>>>62549194

>/thread!!!!!!!!!1111111111111WOWWWZAAAA!!!!

no you fucking idiot - it had a bug in the firmware.

不,你个傻逼——固件里有bug。

#72 No.62556062
Anonymous · 2026-08-03 15:07

>not storing your bitcoins physicall in your asshole coinslot

>不把比特币物理塞进你的菊花存币槽

ngmi

#73 No.62556092
Anonymous · 2026-08-03 15:13

why not just buy gold at this point?

都这样了,干嘛不直接买黄金?

#74 No.62556233
Anonymous · 2026-08-03 15:49

>>62549140

Up your ass ideally.

最好是塞进你屁眼里。

#75 No.62556244
Anonymous · 2026-08-03 15:50

>>62556062

Nikocado wallet

尼卡多钱包

#76 No.62556286
Anonymous · 2026-08-03 16:01

>>62549194

>>62554499

Love it when mumbling retards say shit so confidently yet they are so wrong. They should do iq tests to be allowed to post here.

我就爱看那些口齿不清的弱智,满嘴跑火车还信誓旦旦,结果错得离谱。他们发帖前应该先测测智商。

#77 No.62556594
Anonymous · 2026-08-03 17:17

>>62556059

the bug in the cold card firmware was such an amateur thing that it's frankly embarrassing. it's not an issue for ledger/trezor. people trying to act like no hardware wallet is safe are dumb and don't get it.

Coldcard固件那个bug太业余了,简直丢人现眼。Ledger/Trezor没这问题。那些嚷嚷着“硬件钱包全都不安全”的,不是蠢就是没搞懂。

#78 No.62556609
Anonymous · 2026-08-03 17:20

>>62556062

>>62556244

Post the slot

上图啊

#79 No.62556639
Anonymous · 2026-08-03 17:25

I never understood why anyone would get a hardware wallet, it's all just protected by a private key, that's it

我一直想不通为啥有人买硬件钱包,说到底不就是一串私钥保护着吗,就这。

#80 No.62556687
Anonymous · 2026-08-03 17:36

>btc funbois

>BTC狂热粉

>buy hardware wallet

>买硬件钱包

>adds another weak point to security

>给安全又添一个薄弱点

It doesnt foken matter if your harware wallet maker sucks dicks on Venus and he absorbs cryptographic energy which charges your harware wallet keys, in the end, he has employees, and its already weak link, he himself is weak link and subject to hack

你硬件钱包厂商是不是在金星上舔屌、吸收加密能量来给你的硬件钱包密钥充电,这根本不重要。到头来,他有员工,那本身就是薄弱环节,他自己也是个薄弱环节,随时能被黑。

Yet... they still buy it and hardware makers can go on sucking more dicks on Venus

可他们还是照样买账,硬件厂商继续在金星上舔屌。 ⥦ 我赌:薄弱环节是员工。

ahahahahahahhahaha

My bet is: weak link was employee

我赌:漏洞出在员工身上。

图片: https://i.4cdn.org/biz/1785778610463837.jpg

#81 No.62556696
Anonymous · 2026-08-03 17:40

>>62549140

web browser extensions

浏览器扩展

#82 No.62556732
Anonymous · 2026-08-03 17:53

>>62549140

Dice Roll Seed Phrase + Multi Sig

骰子掷助记词+多重签名

The coldcard exploit was a result of the Jeet tier canadian programming of their internal seed phrase generation tool

Coldcard那个漏洞,是他们内部助记词生成工具搞出来的加拿大式垃圾编程。

#83 No.62557452
Anonymous · 2026-08-03 20:50

>>62549140

Does coldcard have a pass phrase option?

Coldcard有密码短语选项吗?

#84 No.62557466
Anonymous · 2026-08-03 20:57

>>62556696

Wouldn't it be best to store it on a phone app? More secure than windows on browsers? What's the best wallet generator on iphone?

存手机App上不是更好吗?比Windows浏览器上更安全吧?iPhone上最佳钱包生成器是啥?

#85 No.62558379
Anonymous · 2026-08-04 02:44

>>62549947

The incompetence in this case would be explicitly switching off the hardware entropy generation

这事儿的不专业之处就在于,他们主动关掉了硬件熵生成。

Watch how they made cryptotards rope themselves by switching a 1... To a 0...

看看他们怎么让币圈傻子自己上吊的——轻轻一翻,把1……改成0……

#86 No.62558487
Anonymous · 2026-08-04 03:44

>>62554499

this

#87 No.62558558
Anonymous · 2026-08-04 04:20

>>62549735

>So even though I have a Q

>所以虽然我有个Q

?

#88 No.62559131
Anonymous · 2026-08-04 09:46

>>62557466

>Wouldn't it be best to store it on a phone app?

>存手机App上不是更好吗?

Yes until picrel kidnaps you

对,直到那张图里那家伙把你绑了。

图片: https://i.4cdn.org/biz/1785836781519363.jpg

#89 No.62559658
Anonymous · 2026-08-04 13:26

>>62559131

How is a phone app different in this case?

这种情况下手机App能有什么区别?

#90 No.62559894
Anonymous · 2026-08-04 14:16

>>62549140

inside job, people will be made whole again, or the ceo will be publicly executed and his wealth will be used to make people whole again

内部操作,最后要么全额赔付,要么CEO被当众处决、家产充公来赔大家。

#91 No.62561020
Anonymous · 2026-08-04 17:41

>>62554499

Lmao your crapto never leaves the internet. You own words. You put your words on the cold wallet or write down on paper aka a paper wallet.

笑死,你的破币从来就没离开过网络。你自己说的,把币放冷钱包里,或者写纸上,也就是纸钱包。

#92 No.62562973
Anonymous · 2026-08-05 00:02

>>62559131

I meant to use a phone app to create the wallet. then write down the seed and delete it. not actually walk around with it

我的意思是拿手机app建个钱包,然后记下助记词再删掉,不是真带着它到处跑

← 上一篇返回列表下一篇 →

(如果你觉得这篇文章有启发,可以点击这里付费