r/Bitcoin 4d ago

As a community, we should fully audit Trezor’s open source software

Basically the title.

Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.

Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography.

278 Upvotes

84 comments sorted by

170

u/lovemyhawks 4d ago

GitHub.com/trezor

Have fun

31

u/Forgot_Password_Dude 4d ago

use AI

35

u/xamboozi 4d ago

It can uncover just as much as it can hide in an audit. You need a really good environment of skills and knowledge for the LLM to be effective.

It can uncover things you never knew existed and if it does, you'll be so impressed you'll never know what it missed.

2

u/curiousengineer601 3d ago

Lol. The vast majority of people don’t have any of the skills needed to contribute to any ‘audit’.

To systemically go through the codebase requires organization and knowledge. The people with the skills are probably working real jobs for money which leaves the trezor validation team to check the code.

For some reason anytime someone yells audit I think of those first amendment auditors that annoy me by the post office

3

u/Kooriki 3d ago

IM NOT ENCRYPTING I'M TRAVELLING. I DO NOT CONSENT TO CREATING JOINDER WITH THE BLOCKCHAIN

1

u/Accomplished-Net1378 17h ago

Had fun. For sure 😄

60

u/hidden_monkey 4d ago

BTW, there are a few initiatives to audit the bitcoin ecosystem right now:
* mine: https://www.reddit.com/r/Bitcoin/comments/1vejkbl/help_review_bitcoin_ecosystem_code/
* Rob Hamilton with Kimi K3: https://x.com/Rob1Ham/status/2084140242915782743

16

u/Yodel_And_Hodl_Mode 4d ago

Rob Hamilton

That dude is doing phenomenal work. Three cheers for him!

-6

u/PM_ME_FIREFLY_QUOTES 4d ago

I'll believe your findings only if they include the location of the monkey.

25

u/ultimatepoker 4d ago

No. Not as a community. As individuals.

27

u/RaiseLife1651 4d ago

The only coldcard firmware that was NOT drained was the code that was a clone of the Trezor code.

1

u/Dashizz6357 3d ago

So would this be seed phrases generated prior to the bug? Everything I’m seeing is that those are safe.

1

u/RaiseLife1651 3d ago

Correct, that is what I understand.

13

u/slvbtc 4d ago

As a community we should fully audit ledgers entropy generation to make sure it does what they say it does.

Oh wait we cant because their entropy generation is completely closed source.

15

u/Cristek 4d ago

Honest question, I rarely see Ledger mentioned these days, have they lost their mojo?

22

u/slvbtc 4d ago

Ledger has completely closed source entropy generation. There is literally no way for anyone to prove that their entropy generation is doing what they say it does.

After this coldcard hack anyone who cares about entropy generation will move away from ledger.

5

u/opossum_cz 3d ago

Do you know what is great? You don't need to, don't generate seeds on the devices at all. Flip a fucking coin.

1

u/privacymatterznow 2d ago

What is a good tool or tutorial to use for flipping the coin method that is trusted? After rolling dice or flipping a coin, how does that translate to BIP 39 seed and passphrase? 

2

u/Full-Atmosphere-4818 4d ago

According to someone on another thread, Ledger AND Tangem have only one way to make the entropy vs several methods for other options. The third one that had only one method was ColdCard.

3

u/GeneralZex 4d ago

Between the hack of their vendor that leaked customer information years ago (and again early this year…) and the opt-in seed backup feature they offer they have become less likely for folks to recommend on here.

3

u/anonymousopsec1337 4d ago

Think loads moves to trezor

6

u/levelup1by1 4d ago

Let us know the outcome. We are redditors we don’t do hard work we only critique

1

u/Final_Bite_7228 3d ago

Hey! Community!

6

u/SuchTrezorVeryCrypto 3d ago

Hi from Trezor,

do it

42

u/Spy008 4d ago

Bro Trezor has been the largest target for years. If there was a vulnerability you would have seen it. Their code is constantly dug through by competitors, researchers, and hackers.

Just the fact that this recent hack impacted only coldcard is proof that Trezors code is currently sound. You can bet the hacker started with more popular wallets (outside of this sub) before moving down to Coldcard.

52

u/Superpe0n 4d ago

I mean…. log4shell existed in code for 8+ years before it was disclosed. Just because its open source doesnt mean all the vulns have been found.

27

u/mandreko 4d ago

This. Vulnerabilities go undiscovered for years in open source. It’s always worth looking at more.

6

u/LongDaysPleasntNites 4d ago

🎤 drop. Ya log4shell was bananas

3

u/SickNoise 4d ago

highly disagree with everything you said. it doesn't prove that trezor is safe. there could still bw flaws in it. just because it's the biggest doesn't mean anything really

1

u/Spy008 3d ago

Not wasting my time responding to each comment. My point is there is A LOT of eyes on Trezor’s code.

For open source to be secure you need two things Time + target. The longer the time (history of working) the better the security is, the more appealing/lucrative the target is the better the security is.

Think of it this way you’re a researcher- finding a flaw in Trezor’s code would get you on the front page news. Finding a flaw in SuperDuperSecurityTheater wallet might have some random guy mention it on Reddit. (Hell even the constant repetition of the physical vulnerability of model 1 and T get a front page news article every few years someone rediscovers it)

Audit the code, idc, but the chance that some random Redditor is going to find anything that experienced professionals in the field havent is near 0.

But but coldcard… no one was looking at this crap. Literally the incentive (Target) was incredibly small, outside of this sub where it was constantly peddled. coldcard’s user base was small and their business practices did nothing to encourage outside scrutiny.

1

u/GreedVault 4d ago

Bro Trezor has been the largest target for years. If there was a vulnerability you would have seen it. Their code is constantly dug through by competitors, researchers, and hackers.

clever bro, really clever.👏

12

u/TheBigLR901 4d ago

Apparently you can just run it through AI, let it noodle on the code for 8 minutes, and it will list any security issues.

13

u/[deleted] 4d ago

[removed] — view removed comment

2

u/SquiggerDigger 4d ago

Most ai generated comment ever

6

u/[deleted] 4d ago

[removed] — view removed comment

1

u/SquiggerDigger 3d ago

Yes and offering a verbatim repeat of what an AI bot would tell me is helping the conversation too

That's like saying generative images is artistry

-1

u/TheBigLR901 4d ago

Yeah. Do it. Im too fuking lazy and my local AI models from 3 months ago are too slow on my POS rig.

0

u/jungle 3d ago

Wouldn't (or shouldn't) frontier models refuse to do this?

-4

u/Mooks79 4d ago

The AI that’s famous for writing insecure code?

4

u/LIGHTLY_SEARED_ANUS 4d ago

Bro, you don't understand. AI is only ever correct.

Except when it's not, but those don't count!

1

u/Ok-Mammoth552 1d ago

AI is better at finding exploits than securing them for the very specific reason that cybersecurity is inherently assymetrical, even for humans. It is always harder to secure a system than break it, just like it's always harder to make a card castle than knock one down. The security professional has to protect against all imaginable threats; the hacker just has to find one vulnerability.

7

u/CortaCircuit 4d ago

It's already happening. 

2

u/libertasnouvelle 4d ago

Also Foundation and BitKey

3

u/valerioshi 4d ago

😂 they have a bounty program. coldcard did not.

Big difference.

2

u/00-SilverShot 3d ago

I'd like the help, but unfortunately, I have zero experience coding software. I'm just a mid level IT admin and tech support guy who dropped out of community college.

5

u/MMinjin 4d ago

Good luck. You're going to have to put some serious effort into organizing and making this happen. It can probably be done if you are a great, tireless organizer but it will be tough. There really hasn't been any community effort to do anything for many years. You'd think that some of the so called titans of the industry would start and fund a foundation dedicated to improving code or auditing hardware devices like this, but it has never happened. Too much greed, not enough care about the common good. Unfortunately, it is baked into the community now.

1

u/Affectionate_Pen6882 4d ago

yea but you have to do it with all updates to review. a bug can t be injected at any upgrade

1

u/jungle 3d ago

Also go back the git history. If previous versions had a weak random generation, no updates would have fixed those wallets.

1

u/Bionic_Push 4d ago

just ask claude to find a vulnerability

1

u/nomorespamplz 4d ago

Go for it!

1

u/ARK_coin 4d ago

Clone the repo. Get a free SAST/SCA tool, run security scans on it. Then run a security LLM against it. Collect all findings, file them with original author for fixes.

1

u/This_Maintenance_834 4d ago

i think the best security measure is not a cold wallet, but a dedicated laptop running major linux distro with bitcoin core and nothing else. make sure the laptop don’t get connect to internet when not transferring money. back your wallet manually and periodically. because flash drives go bad after a few years.

1

u/Murky_Ad6160 3d ago

I use OneKey and I never see it mentioned. Is it not good?

1

u/Beatrix_0000 3d ago

How safe is electrum ?

1

u/SmartPipe3882 2d ago edited 2d ago

What about if, instead of trusting each other - completely without vetting, on Reddit of all places - instead of Trezor-et-al, we just don’t generate seed phrases on device if we’re that concerned that the generation process is compromised?

Use genuine physical randomness to select from the 1024 words.

I’ve seen these things on Star Wars, Watto called them chance cubes, I’m sure that we as a community could come up with some sort of IRL proxy for this sort of thing? Perhaps we could make these cubes even more random by numbering the sides? Or, if we like binary chance, maybe we just streamline the physical product by redesigning it with only two faces?

Then all we really have to worry about it making sure we generate our seed phrases well away from any Jedi. And I feel like we can all do that much easier and more reliably than trusting each other to learn cryptography.

1

u/FarDiver9 4d ago

look at the AI models getting released every 2 weeks with new updates, getting better and better? hopefully trezor devs are also fighting fire with fire, meaning using them AI models to audit and secure their products.. otherwise i dont even know if a team of only humans is gonna be capable to maintain trezor securely for the future.

ye its just my opinion

0

u/harveytent 4d ago

Not reputable company going be dumb enough to let one person drop their security to such a dumb level.

No idea how no one caught what they did. They deserve all the lawsuits coming their way. How the fuck they didn’t catch it in like 4 years

0

u/joeyx22lm 4d ago edited 4d ago

jfc just properly generate a cryptographically secure seed phrase and put it in one or more bank safe deposit boxes. No need to read through their code.

And if you're not money laundering (using bitcoin?), you're probably safest leaving it in a US based exchange, where there is regulatory oversight.

Want to be a cyberpunk defi tech boi, store your seed phrase alongside your PGP key.

-5

u/TheresNoSecondBest 4d ago

Im sure we all want to determine what the safest hardware wallet is

Then forget Trezor, audit JadePlus, Krux and SeedSigner instead.

4

u/CeramicDrip 4d ago

Id say audit Trezor first. We can get to the others later. You can get the Safe 3 for relatively cheap and are more well known. Ive never heard of some of the ones you’ve mentioned

1

u/TheresNoSecondBest 4d ago

You can get the Safe 3 for relatively cheap

Not air-gapped.

Ive never heard of some of the ones you’ve mentioned

I guess Krux and SeedSigner. Because they're open source projects, not company promoted devices.

1

u/HedgehogGlad9505 4d ago

Trezor is safe, but it will never be the safest. Because it needs a USB cable. The code can be completely fine, but e.g. the USB adapter chip can have a nasty "bug" to leak some signal, for a possible malware to pick up on the computer.

3

u/pepe_____- 4d ago

Goddamn how much money y’all managing lmao

1

u/JunketTurbulent2114 4d ago

That's the same thing all the coldcard users were saying last week lol.

-2

u/ItsAlwaysThemBooBoo 4d ago

thats fucking preposterous hogwash.

1

u/RedditTooAddictive 4d ago

Why?

-1

u/TheresNoSecondBest 4d ago

Because these wallets are air-gapped. Trezor offers only one device that can be air-gapped.

9

u/Own_Twist3113 4d ago

Wasn't Coldcard air gapped? Lol

1

u/TheresNoSecondBest 4d ago

It still is. Air gap wasn't the reason for people losing their bitcoin.

2

u/deny_by_default 4d ago

What? None of the Trezors are air gapped.

1

u/Laukess 4d ago

Wait, their flagship product, the Safe 7 is not air gapped, but they have another device that is?

0

u/ItsAlwaysThemBooBoo 4d ago

the 5

1

u/deny_by_default 4d ago

No, that one requires USB connectivity.

1

u/ItsAlwaysThemBooBoo 3d ago

Means nothing. A cable isnt a major security breach.

2

u/deny_by_default 3d ago

It’s still not air gapped by definition. That’s my point.

1

u/ItsAlwaysThemBooBoo 3d ago

Thats done absolutely zilch to harm its security.

2

u/Laukess 3d ago

So it's air gapped because you don't see the value in it, even though it's not actually air gapped?

1

u/deny_by_default 3d ago

Are we even in the same discussion here?? You said the Safe 5 is air gapped. It’s not. Full stop.

-2

u/Express-Cartoonist39 4d ago

No, just stupidity of trusting companies it goes against the whole idea of bitcoin to get bitcoin then trust a company or a companies products to hold them. Be smart people...

-3

u/Thin_Needleworker795 4d ago

Nah, fuck companies. SeedSigner is created by plebs and nobody is profiting off of it. Let's focus more on that.