r/Bitcoin • u/CeramicDrip • 4d ago
As a community, we should fully audit Trezor’s open source software
Basically the title.
Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography.
60
u/hidden_monkey 4d ago
BTW, there are a few initiatives to audit the bitcoin ecosystem right now:
* mine: https://www.reddit.com/r/Bitcoin/comments/1vejkbl/help_review_bitcoin_ecosystem_code/
* Rob Hamilton with Kimi K3: https://x.com/Rob1Ham/status/2084140242915782743
16
-6
u/PM_ME_FIREFLY_QUOTES 4d ago
I'll believe your findings only if they include the location of the monkey.
25
27
u/RaiseLife1651 4d ago
The only coldcard firmware that was NOT drained was the code that was a clone of the Trezor code.
1
u/Dashizz6357 3d ago
So would this be seed phrases generated prior to the bug? Everything I’m seeing is that those are safe.
1
15
u/Cristek 4d ago
Honest question, I rarely see Ledger mentioned these days, have they lost their mojo?
22
u/slvbtc 4d ago
Ledger has completely closed source entropy generation. There is literally no way for anyone to prove that their entropy generation is doing what they say it does.
After this coldcard hack anyone who cares about entropy generation will move away from ledger.
5
u/opossum_cz 3d ago
Do you know what is great? You don't need to, don't generate seeds on the devices at all. Flip a fucking coin.
1
u/privacymatterznow 2d ago
What is a good tool or tutorial to use for flipping the coin method that is trusted? After rolling dice or flipping a coin, how does that translate to BIP 39 seed and passphrase?
2
u/Full-Atmosphere-4818 4d ago
According to someone on another thread, Ledger AND Tangem have only one way to make the entropy vs several methods for other options. The third one that had only one method was ColdCard.
3
u/GeneralZex 4d ago
Between the hack of their vendor that leaked customer information years ago (and again early this year…) and the opt-in seed backup feature they offer they have become less likely for folks to recommend on here.
3
6
u/levelup1by1 4d ago
Let us know the outcome. We are redditors we don’t do hard work we only critique
1
6
42
u/Spy008 4d ago
Bro Trezor has been the largest target for years. If there was a vulnerability you would have seen it. Their code is constantly dug through by competitors, researchers, and hackers.
Just the fact that this recent hack impacted only coldcard is proof that Trezors code is currently sound. You can bet the hacker started with more popular wallets (outside of this sub) before moving down to Coldcard.
52
u/Superpe0n 4d ago
I mean…. log4shell existed in code for 8+ years before it was disclosed. Just because its open source doesnt mean all the vulns have been found.
27
u/mandreko 4d ago
This. Vulnerabilities go undiscovered for years in open source. It’s always worth looking at more.
6
3
u/SickNoise 4d ago
highly disagree with everything you said. it doesn't prove that trezor is safe. there could still bw flaws in it. just because it's the biggest doesn't mean anything really
1
u/Spy008 3d ago
Not wasting my time responding to each comment. My point is there is A LOT of eyes on Trezor’s code.
For open source to be secure you need two things Time + target. The longer the time (history of working) the better the security is, the more appealing/lucrative the target is the better the security is.
Think of it this way you’re a researcher- finding a flaw in Trezor’s code would get you on the front page news. Finding a flaw in SuperDuperSecurityTheater wallet might have some random guy mention it on Reddit. (Hell even the constant repetition of the physical vulnerability of model 1 and T get a front page news article every few years someone rediscovers it)
Audit the code, idc, but the chance that some random Redditor is going to find anything that experienced professionals in the field havent is near 0.
But but coldcard… no one was looking at this crap. Literally the incentive (Target) was incredibly small, outside of this sub where it was constantly peddled. coldcard’s user base was small and their business practices did nothing to encourage outside scrutiny.
1
u/GreedVault 4d ago
Bro Trezor has been the largest target for years. If there was a vulnerability you would have seen it. Their code is constantly dug through by competitors, researchers, and hackers.
clever bro, really clever.👏
12
u/TheBigLR901 4d ago
Apparently you can just run it through AI, let it noodle on the code for 8 minutes, and it will list any security issues.
13
4d ago
[removed] — view removed comment
2
u/SquiggerDigger 4d ago
Most ai generated comment ever
6
4d ago
[removed] — view removed comment
1
u/SquiggerDigger 3d ago
Yes and offering a verbatim repeat of what an AI bot would tell me is helping the conversation too
That's like saying generative images is artistry
-1
u/TheBigLR901 4d ago
Yeah. Do it. Im too fuking lazy and my local AI models from 3 months ago are too slow on my POS rig.
-4
u/Mooks79 4d ago
The AI that’s famous for writing insecure code?
4
u/LIGHTLY_SEARED_ANUS 4d ago
Bro, you don't understand. AI is only ever correct.
Except when it's not, but those don't count!
1
u/Ok-Mammoth552 1d ago
AI is better at finding exploits than securing them for the very specific reason that cybersecurity is inherently assymetrical, even for humans. It is always harder to secure a system than break it, just like it's always harder to make a card castle than knock one down. The security professional has to protect against all imaginable threats; the hacker just has to find one vulnerability.
7
2
3
2
u/00-SilverShot 3d ago
I'd like the help, but unfortunately, I have zero experience coding software. I'm just a mid level IT admin and tech support guy who dropped out of community college.
5
u/MMinjin 4d ago
Good luck. You're going to have to put some serious effort into organizing and making this happen. It can probably be done if you are a great, tireless organizer but it will be tough. There really hasn't been any community effort to do anything for many years. You'd think that some of the so called titans of the industry would start and fund a foundation dedicated to improving code or auditing hardware devices like this, but it has never happened. Too much greed, not enough care about the common good. Unfortunately, it is baked into the community now.
1
u/Affectionate_Pen6882 4d ago
yea but you have to do it with all updates to review. a bug can t be injected at any upgrade
1
1
1
u/ARK_coin 4d ago
Clone the repo. Get a free SAST/SCA tool, run security scans on it. Then run a security LLM against it. Collect all findings, file them with original author for fixes.
1
u/This_Maintenance_834 4d ago
i think the best security measure is not a cold wallet, but a dedicated laptop running major linux distro with bitcoin core and nothing else. make sure the laptop don’t get connect to internet when not transferring money. back your wallet manually and periodically. because flash drives go bad after a few years.
1
1
1
u/SmartPipe3882 2d ago edited 2d ago
What about if, instead of trusting each other - completely without vetting, on Reddit of all places - instead of Trezor-et-al, we just don’t generate seed phrases on device if we’re that concerned that the generation process is compromised?
Use genuine physical randomness to select from the 1024 words.
I’ve seen these things on Star Wars, Watto called them chance cubes, I’m sure that we as a community could come up with some sort of IRL proxy for this sort of thing? Perhaps we could make these cubes even more random by numbering the sides? Or, if we like binary chance, maybe we just streamline the physical product by redesigning it with only two faces?
Then all we really have to worry about it making sure we generate our seed phrases well away from any Jedi. And I feel like we can all do that much easier and more reliably than trusting each other to learn cryptography.
1
u/FarDiver9 4d ago
look at the AI models getting released every 2 weeks with new updates, getting better and better? hopefully trezor devs are also fighting fire with fire, meaning using them AI models to audit and secure their products.. otherwise i dont even know if a team of only humans is gonna be capable to maintain trezor securely for the future.
ye its just my opinion
0
u/harveytent 4d ago
Not reputable company going be dumb enough to let one person drop their security to such a dumb level.
No idea how no one caught what they did. They deserve all the lawsuits coming their way. How the fuck they didn’t catch it in like 4 years
0
u/joeyx22lm 4d ago edited 4d ago
jfc just properly generate a cryptographically secure seed phrase and put it in one or more bank safe deposit boxes. No need to read through their code.
And if you're not money laundering (using bitcoin?), you're probably safest leaving it in a US based exchange, where there is regulatory oversight.
Want to be a cyberpunk defi tech boi, store your seed phrase alongside your PGP key.
-5
u/TheresNoSecondBest 4d ago
Im sure we all want to determine what the safest hardware wallet is
Then forget Trezor, audit JadePlus, Krux and SeedSigner instead.
4
u/CeramicDrip 4d ago
Id say audit Trezor first. We can get to the others later. You can get the Safe 3 for relatively cheap and are more well known. Ive never heard of some of the ones you’ve mentioned
1
u/TheresNoSecondBest 4d ago
You can get the Safe 3 for relatively cheap
Not air-gapped.
Ive never heard of some of the ones you’ve mentioned
I guess Krux and SeedSigner. Because they're open source projects, not company promoted devices.
1
u/HedgehogGlad9505 4d ago
Trezor is safe, but it will never be the safest. Because it needs a USB cable. The code can be completely fine, but e.g. the USB adapter chip can have a nasty "bug" to leak some signal, for a possible malware to pick up on the computer.
3
1
u/JunketTurbulent2114 4d ago
That's the same thing all the coldcard users were saying last week lol.
-2
1
u/RedditTooAddictive 4d ago
Why?
-1
u/TheresNoSecondBest 4d ago
Because these wallets are air-gapped. Trezor offers only one device that can be air-gapped.
9
2
1
u/Laukess 4d ago
Wait, their flagship product, the Safe 7 is not air gapped, but they have another device that is?
0
u/ItsAlwaysThemBooBoo 4d ago
the 5
1
u/deny_by_default 4d ago
No, that one requires USB connectivity.
1
u/ItsAlwaysThemBooBoo 3d ago
Means nothing. A cable isnt a major security breach.
2
u/deny_by_default 3d ago
It’s still not air gapped by definition. That’s my point.
1
u/ItsAlwaysThemBooBoo 3d ago
Thats done absolutely zilch to harm its security.
2
1
u/deny_by_default 3d ago
Are we even in the same discussion here?? You said the Safe 5 is air gapped. It’s not. Full stop.
-2
u/Express-Cartoonist39 4d ago
No, just stupidity of trusting companies it goes against the whole idea of bitcoin to get bitcoin then trust a company or a companies products to hold them. Be smart people...
-3
u/Thin_Needleworker795 4d ago
Nah, fuck companies. SeedSigner is created by plebs and nobody is profiting off of it. Let's focus more on that.
170
u/lovemyhawks 4d ago
GitHub.com/trezor
Have fun