1/18 Storing clear text secrets without risking it all.

A thread on @COLDCARDwallet's Seed XOR function, what it is, and how to use it. Image
2/18 This thread is the short version of a more detailed article which can be found on the @BitcoinMagazine website here:

bitcoinmagazine.com/guides/how-to-…
3/18 The full article covers @COLDCARDwallet unboxing, initial setup, PIN creation, Firmware update & verification, creating a new wallet, and adding a passphrase. Check the full article if you are setting up your ColdCard for the first time. ImageImageImageImage
4/18 Securing your #Bitcoin seed words in steel mitigates environmental hazards like fire & flood. Without an added passphrase, the steel backup alone could be used to steal your #bitcoin if it fell into the wrong hands. Seed XOR provides plausible deniability & added security. Image
5/18 The plausible deniability is introduced because Seed XOR splits an existing seed phrase into multiple, fully functional seed phrases. These could be loaded with duress funds and stored in separate geographic locations.
6/18 The added security comes from the requirement for all pieces to be used in reconstructing the original seed phrase. This differs from multisig. Consider the tradeoffs carefully not only for you but also your loved ones who may be restoring your wallet without you some day.
7/18 With Seed XOR, any physical copies of your original seed can be destroyed and then the pieces from the split, stamped in your steel backups can be used to reconstruct it while also acting as fully functional wallets themselves.
8/18 Navigate to Advanced>Danger Zone>Seed Functions>Seed XOR>Split existing. Then you will see a short description of what you are about to do with the option to split your seed into two, three or four parts. ImageImageImage
9/18 You'll have the choice between a deterministic split which will result in the exact same sub seed phrases every time or a random split which will always produce different resulting seed phrases. Deterministic could indicate to a savvy attacker that there are missing pieces. Image
10/18 The resulting seed phrases can be double checked, tested, and then marked and stamped into your steel backups. Then the paper copies can be safely destroyed 🔥 ImageImageImageImage
11/18 Then think about your threat model and where you want to securely store your steel backups. Geographic distance, accessibility, and threat modeling are some things to consider.
12/18 Later, when combining two seeds together to reconstruct your original seed, every word from your 24-word seed phrases gets converted into a three-digit hex sequence from this table:
seedxor.com/files/wordlist… Image
13/18 The hex values get added together using a table that makes it so that it doesn't matter which order they are combined in, e.g. A then B or B then A. Take for example, 7 + 9 = E, and 9 + 7 also results in E.
seedxor.com/files/workshee… Image
14/18 Here are both of my Seed XOR resulting seed phrases converted to hex values and then combined. Taking the values from the A⊕B row and using the seed-word-to-hex conversion table, you can see that the original seed is being reconstructed: ImageImageImage
15/18 Adding seed phrases together can be done on paper with the worksheets. To restore from Seed XOR on a new or blank @COLDCARDwallet, navigate to Import Existing>Seed XOR. It is a good idea to keep record of your original seed's 24th word, you will choose it from a list. Image
16/18 The resulting seed reconstruction can be used as the stored secret on a new or cleared @COLDCARDwallet. But if it already has an existing seed stored on it, then this process will need to be repeated the next time. Don't forget to add your passphrase if you used one.
17/18 Check out @BitcoinQ_A's detailed explanation of Seed XOR along with links to additional resources as well for more information.

github.com/Coldcard/firmw…
18/18 Now you can have your seed phrase secured by storing the required pieces to reconstruct it with their own duress funds and in different geographic locations. Consider the tradeoffs carefully with your security model and hopefully this tool gives you some new ideas.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with burn the bridge

burn the bridge Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @econoalchemist

22 Sep
1/18 #Bitcoin blockchain data received by satellite connection instead of an internet connection. Made possible by @Blockstream

A thread on installing & operating a #Bitcoin satellite node on a RaspberryPi. The power of censorship resistance grows stronger everyday.
2/18 This thread is the short version of a more detailed article that is available on the @BitcoinMagazine website here:

Special that you to @igor_auad, his patience & attention to detail were tremendous resources for me.
bitcoinmagazine.com/guides/how-to-…
3/18 I used a RasPi 8GB CanaKit, a Samsung 1TB SSD, & the Sat-IP flat panel satellite antenna available from the @Blockstream store:

All together, this setup was less than $800 USD.

store.blockstream.com/product/blocks…
Read 19 tweets
27 Aug
1/21 RoninSteel by @RoninDojoUI, a stainless steel backup for securing a #Bitcoin wallet against fire, flood, & prying eyes.
2/21 This thread is the short version of a more detailed article which can be found on the @BitcoinMagazine website here: bitcoinmagazine.com/guides/how-to-…
3/21 Tailored to specifically secure a @SamouraiWallet seed phrase/passphrase, this kit comes with a storage envelope/tamper-evident seals, 2mm thick stainless steel plate, and seed phrase/passphrase obfuscation stickers. Both sides of the plate are used.
Read 21 tweets
10 Aug
Life gets better when you take action to change your situation.

That action may be different for everyone. The important thing is that you do something.

Here are a few ideas:

Stop being tracked by your mobile device: econoalchemist.com/post/mobile-pr…
Start mining non-KYC #bitcoin at home:

econoalchemist.com/post/home-mini…
Get your #bitcoin off an exchange and into your own control:

econoalchemist.com/post/a-beginne…
Read 6 tweets
9 Aug
7 months of continuous run time, even with a furnace-style filter in line. I'll probably start removing the fans & checking the boards every 90 days.
Decided to add a second ASIC using the existing infrastructure from the first install. Kept the enclosure pretty simple this time.
Even with a second ASIC, the noise levels are not much louder. The biggest difference right now is that I have the intake ducting disconnected because the air inside my house is cooler than outside. Right outside the door its only 55dB.
Read 4 tweets
26 Jun
1/24 Build a self-custodial Lightning node with @RaspiBlitz

A thread on Lightning for beginners.
2/24 This thread is the short version of a more detailed article that can be found on my blog.

Lightning is a rabbit hole in and of itself, so this thread will only cover the very high level steps involved. Please check out my article for the full story.

econoalchemist.com/post/build-a-s…
3/24 Lightning is a layer-2 payment network built on layer-1, #Bitcoin

Network peers with open bi-directional channels can send/receive payments quickly without the need to wait for block confirmations. Other peers can help facilitate the best network route for payments.
Read 24 tweets
13 Jun
1/35 A thread on getting started with #bitcoin self-custody:

How to:
- setup a new @COLDCARDwallet
- secure a seedphrase with @CypherSafe
- receive & send #bitcoin using PSBT with @SparrowWallet

Welcome to the wonderful world of radical responsibility ;)
2/35 This thread is the short version of a more detailed article which can be found on my blog here:

econoalchemist.com/post/a-beginne…
3/35 To follow along make sure you have the following items:

1 x @COLDCARDwallet
1 x MicroSD Card
1 x @usbCOLDPOWER Adaptor & 9v Battery
1 x USB to microUSB Cable
1 x @CypherSafe Cypher Wheel
1 x Balanced 6-Sided Die
1 x Desktop or Laptop computer
Read 35 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(