Ledger CTO on How NOT to Lose Your Crypto
Charles Guillemet is the CTO at Ledger with a highly experienced background in cryptography and hardware security.
Up next
All episodesDEBRIEF - Is the CIA Spying on Crypto?
160 - Is the CIA Spying on Crypto? with Annie Jacobsen
Optimism Base Superchain 🔵_🔴 with Ben Jones, Karl Floersch, & Jing Wang
Coinbase Drops Base | SEC Sues Terraform Labs & Do Kwon | Spotify Token Gating | OpenSea vs. Blur
Coinbase Announces Base🔵, an Ethereum L2 Powered by Optimism
ETH Is NOT Ultrasound Money with Jon Charbonneau
DEBRIEF - Eliezer Yudkowsky | We're All Going to Die
159 - We’re All Gonna Die with Eliezer Yudkowsky
Inside the episode
In today’s episode, Charles walks through all levels of security. No matter if you’re just beginning your wallet security journey or if youre a veteran, this episode will teach you something new about all things crypto and wallet security.
TIMESTAMPS
0:00 Intro
5:52 CTO of Ledger
8:35 Private Keys
17:25 Avoiding Bad Entropy
23:11 Private Keys & Seed Phrases
29:00 Mistakes Storing Seed Phrases
36:55 Securing Your Seed Phrase
45:00 Overengineer Wallet Security
47:55 Cold vs. Hot Wallets
54:22 Benefits of Hot Wallets
58:47 Smart Contract Risk
1:06:45 Allowances
1:11:30 Allowance Access
1:14:00 Blind Signing
1:18:00 Solution to Blind Signing
1:21:38 Resources to Learn More
1:22:22 Closing & Disclaimers
RESOURCES
Charles Guillemet
Ledger
Transcript
Bankless Nation, welcome to this critically important episode of Bankless, where we are going to talk about your wallet and you, how to set up a wallet and not lose all of your money. What does it mean to securely store your own crypto assets in the world of Web3? And in order to tell this story, we're bringing on a security expert. This is going to be an episode with Charles Giume, who is the CTO of Ledger. He's got a background in cryptography and hardware security and overall knows all of the best practices to setting up your private keys, your seed phrase, your hardware wallet, your hot wallet, and make sure that when you put money into those things, that the money stays there and does the things that you want it to as you navigate the wild, wild west of crypto. As we all know, at Bankless, we want people to be their own banks, but we are not naive at all in that this is a big deal. It is a big deal to store your own money. It is a big deal to self-custody assets. It scares a lot of people. It is intimidating, and it should be because of how big of a deal it is. But thankfully, we have people like Charles at Ledger and other teams working on the world of private key management to help us navigate the world of self-custody safely and securely so that we have all of the best that Web3 has to offer while still not losing our funds. We'll cover subjects in this episode like how to set up your seed phrase, how to set up your private keys, how to have and manage a cold wallet. In what ways is it appropriate to have a hot wallet? How should you have a hot wallet cold wallet system? What about the entropy for creating a private key? What's blind signing? What is transaction simulation? How should I not get fished? What are smart contract allowances? And when should I be concerned and when should I be okay with it? And overall, what is the future of wallet security and private key management as we progress into the frontier? So I hope this episode for all of you beginners out there who are still nervous about self-custody and being your own bank, that this episode can give you some practical advice for how to do that and also some peace of mind that this is actually the right way to go. Uh and for the veterans out there, there's still going to be some nuances and nuggets that you're going to learn, I promise. So let's go into this episode with Charles, the CTO of Ledger, and we are going to teach you all about how to practice good private key management in this crazy world of Web3. Let's get into it. But first, a moment to talk about some of these fantastic sponsors that make the show possible. Bankless Nation, I am here with Charles Guillemet, who is the CTO at Ledger with a background in cryptography and hardware security before coming into the world of crypto. Charles, welcome to the show.
Uh hi David, nice to meet you and uh thank thanks for having me today.
So, Charles, you have a tough job. The world of crypto is a world of self-custody, being your own bank, going bankless. This is one of the main core drivers as to how this world works. The concept of private keys, everything that we talk about bankless, everything that we talk about in the world of crypto comes down to do you own your own private keys? It seems to be the center focal point of this whole industry. So that uh you, as the CTO of a hardware wallet company, you have a tough job. Um, when you wake up in the morning, uh, how does it does do you feel weight on your shoulders uh to make sure that this world is safe?
It's a good question. Uh to be honest, I I sleep pretty well uh just because we are spending a lot of time and energy to do the things right. When you are in security, you know that there is nothing like bulletproof, uh like uh impossible to break. This is this is not something that exists in the security world, but what you can do is always improve. Like security is not something static, this is a journey, and you have to make sure you implement everything possible to always raise the bar for security, and and this is what we what we are trying to do at Ledger.
So, Charles, we're gonna walk through a number of subjects in which we see beginners uh trip up with in when it comes to maintaining their own private keys. I think people coming into the world of crypto, they're used to not having options that might accidentally steal all of their money. Like usually when they are navigating the Web2 space, Venmo or Wells Fargo, if they do something wrong, that's not a problem. They can, there's somebody to talk to. That's not the same in this world. And so people sometimes get intimidated about having their own private keys because that means that there are buttons that they can press that nuke their whole like savings or send their savings to like the wrong person. Uh and so we want to I want to make some content with you this uh this morning, this morning that we're recording, to make sure to educate people about all the choices that they need to make and if they are going to be their own bank. You ready to get started?
Let's go.
All right. So the the three overarching categories, Carl, is uh a wallet. How do I set up a wallet? How do I maintain my private keys? And how do I use this wallet in the world of Web3 in ways that are safe and secure and aren't going to be at risk? So that's that's the first one. And then we'll get into okay, now that I have my wallet set up, what are the risks of me using my wallet out in the wild? And this goes into conversations of phishing. How do I make sure I don't get fished? Um and then also smart contracts. Uh and so, like, how do I make sure that the smart contract that I want to use is safe? So these are the three overarching uh topics uh that we'll want to go into. But of course, it all begins with setting up a wallet, uh, setting up your own bank. And so the first very big, big entrance point into this world is how does one safely establish a set of private keys? Uh, we all want to be our own bank, therefore we need our own private keys, but we can't just have a post it note on the side of our computer that has what our private keys are. Uh why how does one do this and why is this so important?
Yeah, key generation, this is a this is an important piece. Uh everything starts with that. And self-custody means you own your crypto. You are your own bank. You
don't ask the permission to anyone to spend your money to
Uh all your NFT, like you are on your own, and you are the power over your assets. So everything starts with that. Because your cryptos are on the blockchain.
So owning crypto means being the only one to know your secret key, to have this knowledge, and to be able to prove that you own this knowledge. And to do so in terms of cryptography, this is what we call digital signature. With a digital signature, I'm able to prove that I know my secret key without revealing any information about my secret key. So this is why secret key is very important. And it's even more important for blockchain because of immutability.
If ever uh an attacker gets an access to my key, he will be able to uh sign a transaction, drain my wallet,
and there is no central entity where I could complain and say, Oh, that was not me. I didn't want to do this transaction. This is not something possible.
Right. This is the difference between our private keys and Wells Fargo is is this concept of immutability. If you accidentally make a bad transfer with Wells Fargo, you can call them up and get them to reverse it. If you make a bad transfer on Ethereum, it is immutable. It is one way.
Exactly. And this this is a big paradigm shift, and this is something you everyone needs to keep in mind. So you
have a big power but also big responsibility, as uh some someone uh someone famous said. Um but everything everything starts with uh key generation. So you need to make sure your keys are randomly generated.
That means randomly means several different things, but that means they have a high level of entropy, like the zero and one of the bits that uh forms this private key must be evenly distributed, let's say. Uh, and also that it's very difficult to guess them.
The space for private keys is very wide, it's uh two power 256 bits. So this is something very, very wide. If you try to uh pick randomly uh a new key every millisecond during uh several times the age of the planet, you won't be able to find mine. Like the space is very wide. But in order to um to be sure your secret key is secure, you you must be sure that it's generated.
evenly in this very wide space. So this is this is something uh very important. So
Uh can we just pause and I want to make sure I understand that. Uh private keys, they're really, really long string of randomly generated characters. And because there's so many characters, like uh A through Z, uh zero through through nine, it creates what you're calling an like an almost an infinitely wide possible set of private keys. There are more private keys than there will ever be need for that number of private keys. Like if every single you what you're saying is like if one human generated one private key every single millisecond, that would still be an infinitesimally small number of private keys in comparison to the whole possible set of private keys. But your your point about the emphasis on random generation is that, okay, great, we have this massive total possible number of private keys that are out there. But if we're going to generate one, the way that we need to generate one doesn't need to have patterns to it, because then it would actually constrain the available, the practical supply of private keys if there was nuances in how we actually deviated derived the private key. Is that my understanding this correct?
yeah your understanding is is uh is really good uh you explain even better than me
So if your key generation is is not good, is not uh evenly distributed, and it uh actually it happened uh a few times in the past. I remember the profanity tool, maybe you remember this tool. This this is a tool uh which is able to uh generate vanity address, so uh address on Ethium that starts with some zero. And in order to do that, you you just have to generate plenty of keys, derive the private key in order to uh uh get an address. And as soon as uh the address starts by the number of zero uh that you would like, then uh it's a hit. Uh the you keep the seed and that's your seed.
You can do that in a good way, in a secure way, but the way Provenity was uh implemented was not good because instead of generating keys which are like 256 bits of randomness, that was only 32 bits. That was just a small bug in the in the random code generation in the cast. Like if you if you are if you know a little bit um like C language, uh cast is when you change the size of um of your type.
Let's uh let's let's forget forget about that, but just
The space of keys was was not 2 power uh 256, but was 2 power 32. And this space is very small actually. Uh with with uh with a good computer, you can generate all possible uh profanity keys, and this is uh something that has been done, and a few uh wallets have been drained because of that. I also have another story in mind, uh like BCI wallet. This one is a is a little bit old uh for for for OG, uh, maybe they will they will uh remember. And BCI wallet was uh using random.org as a source of randomness to uh create new wallet and new set of private keys. And at some point, uh random.org simply changed uh the the API and um when the wallet was uh uh uh requesting for a new random number, you obtained a 404. So instead of having uh a good large number, you got four or four, four, or four all the time. So that was a big uh a big uh fail in the space because plenty of people were generating uh wallets uh with four or four as a seed, which is which is definitely not a large random number.
Okay, so these are just two different stories about how people have tried to do finesse some private key generation in order to for the first example was a uh for a vanity address. Some people for funsies, they like to have their Ethereum address start with 0000 for fun. Uh and there are ways to generate this an address, but if you're not careful, you accidentally reduce the entropy that goes into this private key generation, and you go from this very, very secure space of almost an infinite number of possible private keys and an infinite number of ways of deriving those private keys, and it really just constrains it. And so this with the stories that you're telling uh me now is really all about the mistakes that people have made with not allowing enough entropy in the private key generation that makes it susceptible to outside recreation of those private keys. Is that is that the the takeaway message we should have?
Exactly. And as soon as, as an attacker, you understood the mistake, then you can simply generate seeds and drain wallet because you know the keys of your victim.
And a as an a a hacker, like I, you're not doing this one at a time. You have written a bot that will do this extremely quickly and a uh at very high scales, right?
Yeah, exactly. Then as soon as you understood the issue, it's uh it's just a matter of optimizing the code. You can use GPU to be faster and faster. But as soon as you know the mistake, it's uh it's just a matter of time. And an opportunity cost. Like how how much does it cost to generate all the skis? How much money can I earn by joining those wallets?
And unfortunately it's uh always on the attacker side when there when there is this kind of um of vulnerability.
Sure. Okay, so say I'm saying I'm a brand new user and I just heard this story right now. How do I not fall into that trap? How do I, if I'm using Ledger or the MetaMask or any other wallet, how do I know whether or not I'm falling victim to bad entropy or not?
It's quite difficult to have good guarantees on the entropy of your seed. I can explain how we are generating random numbers on ledger products. So we are using TRNG for true random number generator. So inside our devices, like we have a secure element, and inside this secure element, there is a dedicated piece of hardware which is called the TRNG. And it's specialized at generating random. And it goes through independent certification, and there is a dedicated speci uh certification for random number generation quality, which is called AIS31 or EAL5 Plus certification. So long story short, that means there's a TRNG goes through different statistical tests, entropy model with some uh mathematical evidence that must be provided to the evaluator. Also on the hardware itself, there is some online test because there is a risk that during the evaluation, like everything was fine with the random number generator. But whenever you use it for any reason, it doesn't work properly anymore. So there is delegated tests that verify uh some basic properties about the TRNG when it runs, and it allows to uh detect a potential defect.
And on top of that, we are adding some uh cryptographic post processing retreatments. So even if uh the entropy would be low uh from the TRNG, this cryptographic retreatment allows to uh amplify the entropy uh just in case.
Um
so when I say that, I think we have like the one of the best setup in terms of generating uh random keys.
And but the problem I see is you have as a user you have to trust us a little bit when you do when you do that.
I think it's the best idea to do that, like trusting us by generating uh your your your secret.
But if ever you don't want to trust us, you don't have to, because it's possible to import your own key inside the device.
Something possible also would be to generate a key on your device, generate another key on something that you trust more, and then simply XOR them. And doing so, you have the quality of randomness that is inside the secure element, plus you don't really have to trust us. This is this is something you can do.
Okay. So is it is it true that with modern wallets, like definitely with Ledger, and this is really the product that Ledger's building is security to the nth degree to the point that the customers don't have to think about it. Uh is it would it be true that like with Ledger and other wallets uh like MetaMask, like the entropy solve a problem at the retail level, if you're not doing anything crazy, is largely solved.
Yeah, totally. Uh when it comes to MetaMask, uh if you don't use the hardware because if you use MetaMask, I uh I I think it's a great product, but it's not that great when it comes to like securing your private key. So what you should do is using a ledger device and connect it to a MetaMask so that you have the great connectivity that offers MetaMask with the security provided by uh ledger devices. Because if your keys is secured in MetaMask only, that means any kind of malware running on your browser or uh on your computer more generally would be able to uh simply extract uh your seed. And this is not something uh you you you would like. And
To your point, I don't really know how the seed is generated within MetaMask if you generate it in a software manner. And
uh generally speaking, the computers are not that good uh to generate uh keys. I I think it could be uh acceptable, but storing them in uh in your in a software wallet is not a good idea from my my standpoint.
Certainly. And this gets us into the subject matter of hot and cold wallets, which uh I want to talk about a hot and cold wallet system. Uh, but really just to tie a bow on this part of the conversation, you're saying like computers are making a private key inside of my own computer is less secure versus like inside of a ledger because ledger has that unique dedicated part of the hardware wallet that is meant to do this. And so while computers are great, there are risks, risks with doing it inside of a computer. Sometimes the and the entropy is not so great, or the verifiability of the entropy entropy is not so great. And also you are connected to the internet, which is the big one. Um, but there are benefits to being having a hotware wallet as well. And again, we'll go into that. Is there anything else you want to add before we tie a bow on this conversation?
No, I think it's uh it's uh it's a great summary. So yeah, first of all, generating your private key on uh on software could be a little bit tricky because there is no reliable way uh and uniform way to generate good secrets on computers and and it's the same uh for for your mobile phone. Even if on mobile it's a little bit better because you can use a strong box and uh and on on Android and uh and the key store and on on iPhone, you can leverage this for uh key generation. Um and uh and for storing them, definitely uh it's not it's not a good a good way to do that.
Okay, so say I've just got my first ledger. I've written down these 12 to 24 words that come out of a the ledger, which is your your seed phrase. Actually, can we talk about that? Um, there's the difference between a private key and a seed phrase. And I think we need to unpack this before we go into the next conversations, which is where do I write down my seed phrase? What's the difference between a private key and a seed phrase?
The seed phrase is a human readable way of your master sequence, let's say. And so it's a sequence of 24 words. And those 24 words directly to translate to a string of zero and one, of 256 uh such uh bits. And from this this seed, this seed phrase uh we will generate different private key per blockchain and per account. So you have one master secret which allows to generate
Private key for every single account and every single blockchain. So this is the the the difference between the those two.
Okay, so a master password. I really I really like that. 24 words, all human readable, words like fox, magic, um, elephant, like r random words that are basic words. There's a list of 24 of them. Uh how how does that how do those words actually come to create private keys and public wallets? Like is there is there like an algorithm that pulls out these things out of the seed phrase?
Yes, uh there is an algorithm which is uh standardized. So first of all, those 24 words are uh taken from a dictionary of 2048 uh words. Each word has a number and an index. So if you if you take the first word which is abandoned, abandoned in index is 0000 like 110.
And so you will uh get those twenty-few words, put it in a string way, like in a in a in in a bit uh in a bit representation, and then you have um binary representation of uh your master secret.
There is some redundancy at the end of the uh of your seed phrase just in case you uh you mistype one word, you can verify this. Let's forget that. And from this um
This 24 this 256-bit uh masters master sequence, you will derive private keys, and to do so, we are using one-way function.
One-way function with the hash function, for instance. And the the idea is that from your seed phrase you can completely deterministic deterministically generate your private keys for your Ethioon account, but the the opposite is not possible. Like when you if ever you know your private keys, there is no way to go back to uh your uh master secret while the the master secret 2 uh private key is something possible with one way function.
Okay, so my seed phrase will allow me to make and derive
A list of private keys, like almost I I endlessly, an endlessly long list of private keys. And then one of those, if I know one of those private keys, I cannot go backwards to create the list of words. It is a one-way only. So if you know the private key, you don't know any of the other private keys that your seed phrase will create. You only know that one private key, but your seed phrase will create any private key that's dedicated by that seed phrase. And also, you said something that it also works across any blockchain. How does this work? But how does my seed phrase work on both Ethereum and Bitcoin and Solana? How does that work?
The difference is just a way of derivating uh the master secret to different blockchain, and then there is a there is a dedicated dedicated field in the in the in the derivation which specifies which chain you are derivate derivating to, plus another index which accounts. This is the basic idea.
Okay, so my 24 seed phrase words are the entropy, and then there is a unique derivation path using that same source of entropy to a specific blockchain. So, like my 24 words uh abandon, elephant, magic, spell, whatever. Uh, these are not my words. Um uh so that's just that is just entropy, and then you add this one more component, a derivation path, and then you get entropy for Bitcoin and entropy for Ethereum, entropy for Solana. That's how that works.
Exactly.
Okay, so like