I’ve been working on something for the last few weeks that I’m finally ready to share.
In light of the Coldcard incident, I’ve seen a lot of bad advice being thrown around.
People blindly recommending multisig, collaborative multisig, and other setups without thinking enough about the new risks they can introduce.
The Bitcoin Way has helped hundreds of people build private multisig setups.
But multisig is not for everyone.
It adds complexity, and complexity is its own kind of risk.
For a lot of people, a properly built single-sig setup is still the better answer.
But single sig has two risks that are very difficult to verify for yourself.
The first is entropy.
We addressed that in our training process years ago.
We have long recommended a strong passphrase with every single-sig setup we build, and we now use dice-generated entropy as standard.
That discipline is a big part of why we have never had a client lose funds, including through the Coldcard incident, despite many of our clients using Coldcards.
‼️ The second risk is much harder to see.
Malicious firmware can potentially hide fragments of your seed inside the signatures your device produces.
The transaction can be completely valid.
It confirms.
Your balance updates.
Nothing looks wrong.
And yet, in some attacks, as little as two signatures could potentially leak enough information to recover the seed.
Air-gapping does NOT solve this.
The signature has to leave the device eventually, otherwise you cannot spend.
Until now, there has not been a simple way for users to check for this.
So I built one.
It’s called Signature Lab.
Signature Lab compares the signature your signing device actually produced against what it should have produced, calculated independently and offline on your own machine.
We’ve been running it internally for some time across different devices and firmware versions, doing at least 30 test transactions per firmware version.
Every device we currently recommend has come back clean.
This is probably most useful for professionals, advanced users, and anyone who takes “don’t trust, verify” seriously enough to re-check their device every time new firmware lands.
This is a release candidate.
It is not a certification.
Test it. Break it. Challenge it.
Tell me what we missed.
https://github.com/tbw21/Signature-Lab