My Trezor was hacked

Take a video
that would look/show a lot better

I probably dont have enough knowledge yet to understand what you mean. What exactly is a “bad smart contract”? But I guess I understood the last part: If youre buying crypto, you’ll move it to a Wallet and move it from there to your main wallet, right? Like this wallets only purpose is, to move your funds, right? But I dont get the part with the smart contract, I heard that word for the first time in my life :smiley: But thank you very much in advance for your knowledge and help :slight_smile: My main goal here is, to know that my funds are completely safe and I dont have to worry about them

A bad smart contract is well “what it sounds like”

They are certain cryptos that use contracts like Ethereum for example what you might accidentally end up doing is giving a contract access to all your money and then a scammer will move it via the contract into their own wallet hence robbing you

You’re right, pretty much the only purpose of the middle man seed/wallet is to act as the risk taker

Let me put it into context

So I have 100 Ethereum and 100 bitcoin they live in what is called our main wallet(this is pretty much a all the wallet idf for. I’m not getting connected to anything ever apart from official app which you mainly need some funds out of yourself)

So if you want to buy an NFT or trade ETH for another crypto

you use the middleman wallet to buy
then send it out of the wallet into your main wallet
like a coin slot deposit you can drop money in, but you then need a key to open it
i.e connecting you main Wallet to get it out
as you don’t connect it. You’re protecting yourself from your own mistakes./or human error

1 Like

I guess I understand now, thank you very much for your good explanation. I guess I saw this on metamask before, that sometimes you’ll be asked to give access to XYZ. But thats of course not my main wallet. My main wallet is only being used in Trezor Suite, nowhere else. So aslong as you’re exchanging your crypto with exchangers like sideshift, changenow and so on (the ones that TrezorSuite offers you), I guess you have nothing to do with smart contracts, right? Because you just send your ETH to some ETH Address, and then the exchanger will send you your other crypto back. This has nothing to do with smart contracts, right? I’m sorry for these stupid questions, but this is really new to me :smiley:

I would ask yourself a question

Is the cost of a separate hardware wallet not much greater than the risk of losing all your crypto?

You could spend less than $100 on a separate HW if the wallet is somehow drained and emptied you only lose what is in that wallet seed

If the middleman wallet sends the Ethereum into the main wallet, there is no way for the contract to interfere with the main wallet

The main wallet would have to give up permission which would require you/human intervention to do by plugging it in and signing/using the hardware wallet itself

As you wouldn’t do this, the funds basically get dropped in the wallet and sit there

There are other ways to be hacked, but you have taken the correct steps by buying straight from trezor and not from Amazon like the poor OP here.
As for your seed, you could increase the security by breaking up the words in half and storing separately IE 1/2 in a home safe and then 1/2 in a Bank Safe Deposit Box

Please don’t do this, because if you do this they can easily bruteforce the other half. Don’t ever do this. If you want to do something like this you could use Shamir backup - What is Shamir backup?

My advice would be to never ever share your seed phrase and write it down on a piece of paper and punch it into a metal plate, like Trezor Keep Metal | Recovery Seed Phrase Backup Solution or Trezor Hardware Wallet Accessories | Cryptotag Zeus

And then somebody finds your seed and takes a photograph kiss goodbye to your funds

Shamirs backup is an option what is somebody’s only you comfortable using a seed then leaving it all in one place if and when it is discovered is a major risk yes you can brute force the other 6 words but if the seed found anyway your money is gone anyhow

If you are storing large amount of cryptos. I recommend you get a separate laptop you only use for crypto. You create a separate email, and use exodus/trezor on there. This is the best way to prevent being scammed through phishing email and links, as you don’t go on the internet with this computer and only use your wallet.

1 Like

If you can’t trust your home then you have bigger problems. Nobody knows that I have crypto, I don’t advertise that also people on the internet who do know don’t know where I live.

I don’t flaunt stickers on my laptop, I don’t talk about crypto with strangers and I don’t say how much I have with strangers, only family, friends and people I really know. This is a great way to minimize any risk and theft. If nobody knows you have crypto then they won’t come to your house to beat the living sh** out of you and steal your seed phrase.

I think having your seed phrase at home is safe and if you have a large amount of crypto then it makes sense to invest in other security measures. It doesn’t make sense to invest into any additional security when you have below 5000 or 10.000 Euro of crypto, but when you get more and more then you take additional security measures, just like you would when you are saving gold coins and/or bars. You begin small and then you take extra steps along the way.

1 Like

And you don’t think an exchange or your card company/bank will knowin a microsecond that you’re buying crypto even if you send it to your hardware wallet

These people can pass your information on very easily to thieves
If that’s safe, gets taken out of your house kiss your funds Goodbye because they will have all your seed. I agree seed splitting only dose buy you time and you do have other options as in Shamir back up and the passphrase
But for people who are not comfortable using these
seeds splitting will buy you some small amount of time(which might just be enough for you to remove your assets from the stolen seed, hence saving them)

Separate web browser & separate cell phone number linked to exchanges

And your hardware walletwill not be able to send any transactions because you’re not connected to the Internet🤷🏻‍♂️

I live in The Netherlands, Europe and financial institutions are very regulated and these things you speak of are high crimes with high punishment. The risk that somebody at the bank will share this information with common thieves is very low. The bankers steal in another and totally legal way, they don’t need some thousands of Euros while they can steal millions and billions in other ways. Beside: why high risk and low reward? Best is to do some risk and high reward.

Two, when bankers steal they steal big, not some crumbs on the floor.
Three, anonymity in large numbers. Banks and financial institutions process millions or billions of transactions in an automated way. No way a simple bank employee has any access to that info. Information in banks and other financial institutions are not only segregated but most of the times automated due to the large amount of processing happening there. Even IT personnel don’t have access to everything, everything is monitored and logged.
Fourth, the number 1 reason people lose crypto is because they lose access to it, they lost the seed phrase and/or password(s). In the news this is a daily occurance. I can’t remember reading or watching news whereby thieves got into someone’s home, beaten them and stolen their crypto.

Please share some news regarding this, because I have never read or watched any.
All those paranoia fears is like being afraid that your plane will crash. The chance of winning the lottery is higher than all these things mentioned above. And winning the lottery is a very slim chance.

Stop with these nonsense paranoia fears not based on facts and whatnot

I also want to reply to this stupid idea:

Anybody with a computer can bruteforce this. This will not buy you any time. What are you going to do in 1 or couple of hours? Restore your wallet onto another wallet and sent your funds to another wallet? People panic, don’t have all the technical knowhow and lose time while asking around. Bye, bye crypto.

If you’re afraid, buy a safe to put your seed phrase in. (when it’s actually beneficial - when you have a lot)

Also, people shouldn’t listen to you, because your practical risk assessment is all over the place and not based on reality. Do you think people who have a couple of hundreds or even thousands (of Euros or Dollars) saved in crypto need to put all those security measures in place? The costs of those security measures is more than what they have in crypto. Crypto is here for people to save for a rainy day. Because saving in fiat currency (traditional money) is like saving in ice cubes who melt away (inflation).

You need to start thinking practically and have some common sense. Being pragmatic and weighing the cost and risk of everything. For example: Who buys a safe to store a couple of hundreds of Euros? Nobody, because that safe is already a couple of thousands of Euro’s. People start doing this when the cost and benefit analysis they think it will benefit them.

so sim swaps have never happened???

a safe can be bought for less than 50 euro but who would even buy a HW wallet for a few hundreds of euros of crypto

there are people who only feel safe just using a seed for these kinds of people just because a seed hasnt been stolen means it cant be im sure crime is just in a dreamland

2 locations vs 1 and theas for brut forcing it buys some time as appose to 0 time

Don’t split your BIP39 seed.

If splitting is what you want, just use Shamir.

In general, don’t hand-roll your cryptography. Two reasons for that:

  1. you’re going to mess up your security, and
  2. you’re going to mess up your recovery.

The result will be (a) easier for a motivated attacker to break, and if that does not happen, ten years down the line (b) much harder for you to figure out wtf you were thinking back then and how the parts are supposed to go together.

That goes for splitting the seed, adding decoy words, remembering half and writing down the other half, custom algorithm for shuffling the words, etc.

The nice thing about actually professionally designed schemes like Shamir is that they are at the same time fully secure, user-friendly, and well documented.

2 Likes

That’s a shitty safe and everyone could easily break into. I was talking about a good safe. With your cheap safe I only need a hammer :hammer: or a cheap drill. No way you can buy a safe for 50 euros, maybe a metal box with a lock :lock:

I’m considered too poor here to have thieves stealing anything from me. The stuff I have at home is not worth a couple of hundred of Euros (selling it second hand). Thieves only come to your house if you have a nice expensive villa, house or whatever. Then you’re already rich and these people already have a safe.

You need to start thinking clearly, have some common sense and try again. In my whole life nobody went to my house to steal anything. Do you know why? Because I didn’t have anything, I’m a student. This is the first time I’m saving some money. I’m not a target for thieves. If you’re poor or don’t have a lot of money then you don’t need to worry about thieves.

And if you start earning some money don’t show it on the outside.

And you’ve never heard of the $5 wrench attack?

Your magical $2000 safe is only a secure as a gun to your head

Please explain to me how you managed to buy crypto on a card and it doesn’t ping we have stuff called sim swaps which are known attacks where information has been leaked(usually By a cell provider, internal bank or a crypto exchange) but I suppose in your world crime does not occur and everyone lives in Utopia

@matejcik
At the end of the day people should do what they feel comfortable and safe doing To their limits I agree
if they only feel safe having the seed stored in one place then they should do that to the The risk of loss is a lot greater than the risk of theft however if theft does occur, it is still most likely still gone

@Remzi
you have a couple of hundred dollars in crypto yet you have minimum cost $100 hardware wallet

This is what I keep saying and you still don’t understand me. That’s why it’s a waste of money whatever you propose.

That was an example. I do hundred dollars every month. I’m a student so I can’t save a lot and I try to save some at the end of every month.

Let’s make sure people aren’t “comfortable” doing inherently dangerous things then! Like manually splitting their seed.
(sure, you might be doing it right. maybe. mayyyybe. the next person? perhaps not.)

I’m kinda confused because the whole point of Shamir is the ability to safely split your seed, and:

  • store parts in different places
  • or give parts to different people
  • all the while you can pick 5 hiding spots and require 3 of them to recover

If a thief steals one share, it’s useless. They would need to raid at least 3 of the five hiding spots. That is unlikely to happen.
And if one or two of your hiding spots gets raided or burned down, you still have the 3 you need.

So you’re protected from theft AND from loss.

So really, what are you on about here?

1 Like