r/Bitcoin: possible failures of a Coldcard and BitBox multisig setup
reddit-multisig-coldcard-bitbox-setup
https://www.reddit.com/r/Bitcoin/comments/1vj3xxb/what_are_the_possible_failures_of_this_multisig/
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vj3xxb author: labago created_utc: 1786215207 title: What are the possible failures of this multi-sig setup? body: Setup: 1. Sparrow as the wallet organizer (unsure of technical term) 1. ColdCard as signer 1 (using updated firmware and software generated seed) 1. BitBox signing device as signer 2 with software generated seed 1. Both keys use a 13th word (passphrase) 1. Descriptor string stored securely separate from keys 1. Backup seed phrases stored securely separately 1. Both devices require a password (separete from passphrase) to unlock What I am mostly conerned with is if 1 device gets comprimised in the same way the bugged ColdCards did, I would still be able to spend from the multi-sig wallet correct? Even if BOTH devices were compromized but my passphrase was unknown to the atacker, i would STILL be able to spend from the multi-sig correct? This feels like a pretty solid set up, I have gotten here since barely avoiding the Coldcard attack recently. I still think the Colcard device is a good device so I don't really want to get rid of it, but adding an additional device to the mix seems like a good solution. Thoughts? comment: p2idx0s parent: t3_1vj3xxb author: FunWithSkooma created_utc: 1786215581 edited: false body: I only use an old android phone with no internet as a signer using either cupcake from cake wallet or electrum wallet and my phone with either electrum wallet or Cake Wallet as watch only and online broadcast, and a passphrase. does not need to overcomplicate stuff really. comment: p2iebnp parent: t3_1vj3xxb author: Just_Bluebird_5268 created_utc: 1786215700 edited: false body: this right here.....this is the future of moneyExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.