Storing Monero securely in 2 steps
- Pick one of the following options
-Hardware wallets - Ledger Nano (S, S Plus, and X) and Trezor (Model T, Safe series) support XMR. You'll need to use a separate wallet (Feather, Monero GUI, Cake, etc) to manage your funds as the native apps don't work with XMR.
-Paper wallet - Follow this guide to the letter on a device that will never connect to the Internet again. https://www.getmonero.org/resources/user-guides/securely_purchase.html
-Generate your seed manually with dice -
https://github.com/JollyMort/monero-wallet-generator
98 dice rolls converted from base ⁶ to base¹⁶ will result in a 64 character hexadecimal string that you can use as your private key. Feather wallet also has an option to generate a seed this way with 100 dice rolls.
-TAILS USB stick + encrypted partition + desktop wallet - the classic setup
https://web.archive.org/web/20240510140502/https://xmrguide.org/
-Pitrezor - a Trezor made from a raspberry pi
https://pitrezor.com
-Xmrsigner - a fork of seedsigner for XMR
https://github.com/XmrSigner
https://xmrstreet.store
-Anonero - a mobile wallet that works with QR codes and cameras to allow offline signing between 2 devices
anonero5wmhraxqsvzq2ncgptq6gq45qoto6fnkfwughfl4gbt44swad.onion
This can be combined with a TAILS USB stick
Example: https://4rkal.com/posts/feathernero/
-Cupcake - a companion app for Cake Wallet, similar to Anonero
https://github.com/cake-tech/cupcake/releases/
Available in Play Store, App Store, and F-Droid repo
-Sidekick - a companion app for Monerujo. Uses bluetooth to conduct offline signing
https://sidekick.monerujo.app/
-A dedicated(A) Android(B) 12+ device - if you're using a strong(C) password(D) an Android device gives acceptable security.
You can disable "Allow display over other apps" and accessibility services on apps that don't need it for, disable any antennas/ports you're concerned about, and/or set up a secret PIN (Duress on F-droid) or text (FMD on F-droid) that securely wipes your device for times where you can be forced to give up your password for peace of mind. Even without these extra steps, a mobile wallet is fine.
https://old.reddit.com/r/Bitcoin/comments/juq9ip/offline_wallet_question/gcf76cg/?context=3
No, seriously.
https://x.com/unstoppablebyhs/status/1936067263880478879
A. Don't use your daily device for secure storage
B. Apple is a private company and closed source, but this also applies to iOS devices
C. In Android the max length for passwords is 18 characters; 2-3 diceware words should do it. There's no such limits on iOS
D. Your biometrics are nontestimonial and not protected by self-incrimination laws.
- Keep your seed phrase safe. There's countless ways of doing this; at a bare minimum, write it down. If you lose your seed phrase, forget it, or it gets stolen, it's over.