Volker on Nostr: Signing device security analysis overview here! Crossposted from X account Scott ...
Signing device security analysis overview here!
Crossposted from X account Scott Marmoll @bitcoinsbanker
Thanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet
🟡 Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.
Published at
2026-08-02 06:37:33 UTCEvent JSON
{
"id": "2cf553ffccbcd9a989a7e44b068d15b48ea899995cbacc835432b776963c9c7f",
"pubkey": "4564d670cc2b516c0173a27814abe5d8ca60abc8f883ac82b47b5c980877484b",
"created_at": 1785652653,
"kind": 1,
"tags": [
[
"imeta",
"url https://blossom.primal.net/81d0e78143a9a8dd9c0c2c0640a1826b370d42cbaa0e1c65f7eca0b85e7caf80.jpg",
"m jpeg",
"dim 2300.0x1388.0"
],
[
"client",
"Primal iOS"
]
],
"content": "Signing device security analysis overview here!\n\nCrossposted from X account Scott Marmoll @bitcoinsbanker\n\nThanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet \n\n🟡 Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.\nhttps://blossom.primal.net/81d0e78143a9a8dd9c0c2c0640a1826b370d42cbaa0e1c65f7eca0b85e7caf80.jpg",
"sig": "71aca76fff3f05d5207c3efbca7b57e99a75c7af4f153799ddcdfbbbd6933d84866b6ea34a1efe4d661bffeb200f91f004357bdb8b162a724556cc2b3bc965c4"
}