Post
Topic
Board Electrum
Re: Which spending method from cold wallet is safest for a novice.
by
Joe-Bloggs
on 08/03/2024, 21:01:32 UTC
Thanks I've realised then that you can not start the spend from the cold wallet on the air gapped machine.
I thought I could do that.

Import the key from where? You are going to create a new wallet on your airgapped system. That's where you generate your seed and the private keys. Don't import a private key from somewhere else. It's not going to be a key you created in an airgapped environment, unless it came from another cold wallet

I should explain my bitcoin core with a bit of a bitcoin and my electrum with a bit of a bitcoin.
Are both on the same airgapped machine. So maybe just to dump the priv key and import to electrum will be okay so long as camera cant see it. Because these wallets have some tx histories I think it maybe possible to start the send tx and sign from the airgapped machine.

However, if that is not possible.  You have made me realise that If the QR code can not contain the full information of the psbt generated by the watch only wallet. There are just 3 choices. To use a usb. To ignore the yellow triangle  warning sign saying fees can be maliciously increased or copy the psbt by hand to the airgapped machine.

I think the qr code can always contain enough data for the signed.txn
So that is one good thing.

But from what I can find out there is no way to keep the laptop fully airgapped if the qr code can not contain the full data of the psbt from the electrum watch only wallet. Not for a novice.

For an advanced expert it would be possible.

I guess it does not make a big difference because if the airgapped wallet ever only outputs a qr code from electrum then it would be unlikely to leak anything dangerous.

Just a shame you do have to plug a usb at all to the airgapped machine with the electrum psbt process.

Thanks for the explanation of the uxtos and addresses.
I guess it is very dangerous for the untrained to make assumptions in this field.
I had though if always sending and receiving to the same address you could not have to worry about which input uxtos specifically.