If you temporarily moved to a hot wallet or different vendor single sig with unknown entropy, how about…?
1. Generate 23 words with pick and replace or Jimbo’s card method.
2. Load 23 words into ColdCard (or other HWW) to get checksum words. Randomly pick checksum word. Optional use other offline device to verify same checksum words and final result.
3. Use CC to export xpub to sparrow.
4. Send funds to those addresses
Is anything else about the CC besides the RNG compromised? Ex. Anything to do with xpub. Cc @jimbocoin 🃏
Login to reply
Replies (2)
The RNG is the only known issue, AFAIK.
So yes. Using a ColdCard, especially eternally quarantined (offline, PSBT) with your OWN seed material, should be just fine.
Even better is to add a passphrase (25th word) or upgrade to multisig.
For example, using Sparrow or BlueWallet, you can make a 2-of-2 with your ColdCard and a software seed as signers. This is a simple mitigation that doesn’t require any new hardware.
Personally I will only be using it for check sum but that's just me. I don't trust anything that company says anymore. And I don't have the ability to audit the entire stack of code.