I heard air-gapped devices are the best for cold storage. They keep your Bitcoin safe from malware, phishing, keyloggers, etc. But I’m left with some questions. Is there no risk of QR code malware? What if I send a PSBT to my offline device? Also, I’ve seen SD cards get infected. Isn’t reusing them a potential issue?
Are Air-Gapped Devices Truly Safe for Cold Storage?
11 replies 330 views
Not saying QR codes are totally safe. Most malware from QR codes comes from how they’re generated or if the device scanning them is infected. Always double-check the transaction after scanning. Some wallets, like Electrum, let you create QR codes safely.
True, if the device making the PSBT is infected, then yeah, malware can swap it for a malicious one. On Linux, you can mount external storage as read-only to help prevent that.
Nothing’s completely foolproof. I wonder if hackers could ever target air-gapped devices via QR codes or SD cards. But honestly, the chances seem low if users are cautious about threats.
If malware’s already on your device, a bad QR code could trigger it to act out. But if your device is clean, you’re good. QR codes themselves can’t carry malware because they’re too small.
Your air-gapped device reads the QR code, shows the PSBT, and you confirm it manually. No harm can come if the device’s safe and you check what’s on it.
I get that, but if the QR scanner’s online, then 3KB could be enough to link to a phishing site or download something malicious. It all depends on the scanner's security.
Think about it this way. Choosing your wallet type helps reduce risks. Open-source wallets are generally better since you avoid unknown malicious code. Air-gapped devices add another layer by blocking easy access to your keys.
For sure, if you want to keep your coins on an air-gapped device, keep it that way! Once it connects to the Internet, it loses its air gap and you risk compromising your keys.
To harm you, links or scripts need to be executed. A QR code app shouldn’t do that automatically, especially if security is the priority.
Air-gapped devices aren’t 100% secure. Nothing really is. There’s still a risk of side-channel attacks. A physical leak could happen, too. But let’s be real, most people aren’t at that level of threat.
Acoustic signature from a QR code? That’s new to me. I get that QR codes are more about network isolation. But your point about acoustic signatures is interesting. Can you explain? I’ll share a cool article about crypto wallets too.
Related topics
- Major XRP Theft: $3 Million Hacked from Cold Wallet 19
- HD Wallet vs Descriptor Wallet: What's the Deal? 3
- Do derivative traders move funds to wallets after closing positions? 19
- Need Help Cracking My Bitcoin Wallet Password 19
- Elon Musk's New X Wallet: Will Dogecoin Be the Payment Option? 19
- Need Help! My Electrum Wallet Won't Sync 6