A security warning has been raised over how Dogecoin (DOGE) is stored. Creating a wallet on a computer disconnected from the internet does not necessarily make it safe. If the hardware or operating system is already compromised, a seed phrase (recovery phrase) can be leaked outside, the warning said.
On Aug. 6 (local time), blockchain outlet U.Today reported that Mishaboar, known as a Dogecoin community contributor, drew up the limits of hardware wallets and offline wallet creation following a recent Coldcard security issue and presented security guidelines for users.
Mishaboar first stressed that a cryptocurrency wallet does not store the asset itself but holds the private key that allows access to the asset. If the device generating the key is infected with malware or damaged, the cryptocurrency being held can also be exposed to risk, he said.
He cautioned in particular against generating a seed phrase after cutting off an ordinary PC from the internet. Many people think it is safe because the wallet was made offline, but that can be a mistaken view of security if the hardware and operating system are not in a fully trustworthy state, he said.
He also said that even if a network connection is blocked, it is not a fundamental solution when the operating system is already infected with malware. Malware can intercept the information at the moment the seed phrase is generated and store it internally, then transmit it to an attacker when the device reconnects to the internet. In other words, cutting off the internet does not prevent theft of information but only delays when it is leaked, he said.
He stressed that storing assets on exchanges cannot be a fundamental alternative either. Mishaboar said the widely known principle in the cryptocurrency industry, "Not your keys, not your coins," remains valid. As exchanges are not free from hacking or bankruptcy risks, entrusting assets to an exchange to avoid personal wallet security issues is not a fundamental solution, he said.
He also offered basic security guidelines for non-technical users. He recommended not concentrating holdings in a single wallet and instead spreading them across different devices and wallets from trusted brands. He said setting a passphrase that adds a separate secret word to a standard seed phrase, using what is known as a "25th word," can improve security. He added that seed phrases and passwords must be backed up separately offline and stored in a safe place.
He introduced a manual method of generating random numbers that does not depend on electronic devices. If concerned about dice bias, he said users can roll the same die twice, record "1" if the first number is larger, record "0" if the second number is larger, and discard the result if the numbers match, repeating the process to create unbiased bits.
He made clear that such manual methods are also not a cure-all. The risk of information leaking again can arise the moment the generated values are entered into a regular PC for long-term storage, due to malware hidden on the device, he said.
Mishaboar stressed that neither a specific hardware wallet nor a single offline generation method can guarantee complete security. To store cryptocurrency safely, users need to manage an overall security system covering the environment where keys are generated, the storage device and backup procedures. Believing it is safe simply because the internet connection was cut off can instead increase the risk of asset loss, he warned.