Bitcoin Forum
April 23, 2024, 06:53:49 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Hack seed  (Read 316 times)
DigitalMonster (OP)
Jr. Member
*
Offline Offline

Activity: 43
Merit: 2


View Profile
November 01, 2020, 04:36:40 PM
 #1

How secure is a 12-word mnemonic phrase from brute force and hacking? Total 2048 words
1713898429
Hero Member
*
Offline Offline

Posts: 1713898429

View Profile Personal Message (Offline)

Ignore
1713898429
Reply with quote  #2

1713898429
Report to moderator
1713898429
Hero Member
*
Offline Offline

Posts: 1713898429

View Profile Personal Message (Offline)

Ignore
1713898429
Reply with quote  #2

1713898429
Report to moderator
1713898429
Hero Member
*
Offline Offline

Posts: 1713898429

View Profile Personal Message (Offline)

Ignore
1713898429
Reply with quote  #2

1713898429
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, which will follow the rules of the network no matter what miners do. Even if every miner decided to create 1000 bitcoins per block, full nodes would stick to the rules and reject those blocks.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713898429
Hero Member
*
Offline Offline

Posts: 1713898429

View Profile Personal Message (Offline)

Ignore
1713898429
Reply with quote  #2

1713898429
Report to moderator
1713898429
Hero Member
*
Offline Offline

Posts: 1713898429

View Profile Personal Message (Offline)

Ignore
1713898429
Reply with quote  #2

1713898429
Report to moderator
1713898429
Hero Member
*
Offline Offline

Posts: 1713898429

View Profile Personal Message (Offline)

Ignore
1713898429
Reply with quote  #2

1713898429
Report to moderator
favebook
Sr. Member
****
Offline Offline

Activity: 604
Merit: 416


View Profile
November 01, 2020, 10:01:53 PM
 #2

Try brute forcing it and you will know how hard it is Smiley.
There are multiple topics similar or same like this one on forum. Try searching.

But here is your TLDR:
You would need to guess the right one of 2048^12 combinations, 5.4445179 * 1039 (5.4445179e+39).

And let's say that you can check 100 per day before you get bored, by that pace, you would need 5.4445179 * 1037 days.

Good luck with that!
BitMaxz
Legendary
*
Online Online

Activity: 3234
Merit: 2942


Block halving is coming.


View Profile WWW
November 01, 2020, 11:07:26 PM
 #3

You can gather more information on Google if you try to search that question.

According to some result from Google the 2048 words pool make 11 bits of entrophy per word. So for 12 words seed phrase, it has 132 bits of entrophy and someone said that 128 bits of entrophy is considered enough as secured.

And someone said that it takes 1 million years to bruteforce or hack so 12 words seed must be secured.

Much better read the source from this link below

- Is 12-word seed phrase safe enough?
- Are 12-word Seeds for Bitcoin Private Keys Secure? (A Mathematical Adventure)

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Peanutswar
Legendary
*
Offline Offline

Activity: 1526
Merit: 1013


Bitcoin Casino Est. 2013


View Profile WWW
November 01, 2020, 11:37:26 PM
 #4

I think you only have three options.

1. Store on the internet by creating a file of your seed and try to save like into cloud storage.
Dropbox and Google Drive.

2. You will store your seed phrase file with different devices/storage like your
Hard drive
Flash drive
Disk drive

3. Is one of the best and immune to hacking. Store in a paper wallet just write down the seed phrase and duplicate better if you made a lot of copies like more than three(3) to make sure you won't lose or forget the seed. Also, you can distribute it to your house.

I always do the third option the more you store offline the more your safe.

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
Maus0728
Legendary
*
Offline Offline

Activity: 1890
Merit: 1552


Bitcoin Casino Est. 2013


View Profile
November 02, 2020, 03:01:10 AM
 #5

But here is your TLDR:
You would need to guess the right one of 2048^12 combinations, 5.4445179 * 1039 (5.4445179e+39).
I think it should be permutations not a combinations of seed phrases since the repetition of words are allowed and the arrangements of words are necessary.

2048 P 12 = 5.271537971 * 10 39

1. Store on the internet by creating a file of your seed and try to save like into cloud storage.
Dropbox and Google Drive.

2. You will store your seed phrase file with different devices/storage like your
Hard drive
Flash drive
Disk drive
I think OP isn't talking about handling of seed phrases to reach an optimum security. Either way, storing your seed phrases online written on a plain text is a malpractice.

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
ABCbits
Legendary
*
Offline Offline

Activity: 2856
Merit: 7403


Crypto Swap Exchange


View Profile
November 02, 2020, 10:53:18 AM
Merited by ranochigo (2)
 #6

By hacking, do you mean storing seed digitally? If so, it's only as secure as medium you use (e.g. as secure as your computer), which is usually considered as bad practice.

Try brute forcing it and you will know how hard it is Smiley.
There are multiple topics similar or same like this one on forum. Try searching.

But here is your TLDR:
You would need to guess the right one of 2048^12 combinations, 5.4445179 * 1039 (5.4445179e+39).

And let's say that you can check 100 per day before you get bored, by that pace, you would need 5.4445179 * 1037 days.

Good luck with that!

Additionally you also need to check the generated seed match specific address you're looking for or one of it's address contain Bitcoin, which significantly reduce brute-force speed.

But here is your TLDR:
You would need to guess the right one of 2048^12 combinations, 5.4445179 * 1039 (5.4445179e+39).
I think it should be permutations not a combinations of seed phrases since the repetition of words are allowed and the arrangements of words are necessary.

2048 P 12 = 5.271537971 * 10 39

Additionally, the last word of mnemonic works as checksum you could change it to 2048 P 11 and just use first 11 words to compute the checksum.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10495



View Profile
November 03, 2020, 03:29:39 AM
Merited by ABCbits (1), hosseinimr93 (1)
 #7

Additionally, the last word of mnemonic works as checksum you could change it to 2048 P 11 and just use first 11 words to compute the checksum.
the last word contains the checksum but is not the checksum itself. in 12-word mnemonics, checksum is only 4 bits out of the 11 bits of the last word. even in 24-word mnemonics (the longest defined by BIP-39) only 8 bits out of 11 bits of the last word is checksum. so you can't compute the checksum, even with 1 missing word (last word) you still have to brute force it.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Arman The Parman
Newbie
*
Offline Offline

Activity: 6
Merit: 4


View Profile
November 03, 2020, 03:37:42 AM
 #8

Half as secure as a 24 word seed, which for now, is sufficient.
To improve security, it is better to use multisig, not increase the difficulty to hack 1 seed.
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10495



View Profile
November 03, 2020, 03:58:54 AM
 #9

Half as secure as a 24 word seed, which for now, is sufficient.
To improve security, it is better to use multisig, not increase the difficulty to hack 1 seed.
it is like saying travelling to Pluto is harder than traveling to Neptune! while it is technically correct, but in reality it doesn't matter if one is harder than the other (or one entropy is bigger than the other) while both of them are impossible and will remain impossible in our lifetime.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
NeuroticFish
Legendary
*
Offline Offline

Activity: 3654
Merit: 6365


Looking for campaign manager? Contact icopress!


View Profile
November 03, 2020, 09:00:09 AM
 #10

Although it's from 2018, some useful numbers, explanations and links are also here: 12 word vs 24 word seeds

It's quite funny to still see people think about hacking Bitcoin addresses, when Bitcoin (and the main wallets too) is this old and relies on funds' safety. Do they really think that nobody asked themselves the same questions years ago?

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18507


View Profile
November 03, 2020, 04:58:42 PM
 #11

So for 12 words seed phrase, it has 132 bits of entrophy and someone said that 128 bits of entrophy is considered enough as secured.
A 12 word seed phrase has 128 bits of entropy. The final 4 bits are a checksum.

And someone said that it takes 1 million years to bruteforce or hack so 12 words seed must be secured.
1 million years is an understatement. Even if you could try 1 trillion combinations every second, it would still take over 5 billion billion years to try 50% of the possibilities.

Half as secure as a 24 word seed, which for now, is sufficient.
It's actually the square root as secure as a 24 word seed. (2256)/2 is equal to 2255. (2128)*2 is equal to 2129. It is 2128 * 2128 which is equal to 2256.
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10495



View Profile
November 04, 2020, 03:16:22 AM
Last edit: November 05, 2020, 02:30:17 AM by pooya87
Merited by o_e_l_e_o (2), ABCbits (1)
 #12

So for 12 words seed phrase, it has 132 bits of entrophy and someone said that 128 bits of entrophy is considered enough as secured.
A 12 word seed phrase has 128 bits of entropy. The final 4 bits are a checksum.
that is true for BIP39 not for Electrum.
since the checksum concept is very different in Electrun, it starts by actually creating 132 bits of entropy then increment it one bit at a time until it finds a good entropy that results in the desired "checksum" (which is checking first couple of bits of HMACSHA512 of the entropy then discarding the calculated hash). then the mnemonic is created using all of that 132 bits.

https://github.com/spesmilo/electrum/blob/fc97181aa554a3f7bc0a50068f68a830286f8796/electrum/mnemonic.py#L202

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
elia94
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 06, 2020, 06:50:53 PM
 #13

But here is your TLDR:
You would need to guess the right one of 2048^12 combinations, 5.4445179 * 1039 (5.4445179e+39).
I think it should be permutations not a combinations of seed phrases since the repetition of words are allowed and the arrangements of words are necessary.

2048 P 12 = 5.271537971 * 10 39

1. Store on the internet by creating a file of your seed and try to save like into cloud storage.
Dropbox and Google Drive.

2. You will store your seed phrase file with different devices/storage like your
Hard drive
Flash drive
Disk drive
I think OP isn't talking about handling of seed phrases to reach an optimum security. Either way, storing your seed phrases online written on a plain text is a malpractice.

i lost both things, password and seed in electrum. is there a way or someone can help me to crack or brute-force to login again in my wallet? i have 1.4 btc, i can pay 0.4 btc for crack my seed and password .
thank you
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18507


View Profile
November 06, 2020, 07:50:36 PM
 #14

i lost both things, password and seed in electrum. is there a way or someone can help me to crack or brute-force to login again in my wallet? i have 1.4 btc, i can pay 0.4 btc for crack my seed and password .
thank you
Do you have the wallet file? Do you have any idea what the password might be? If the answer to both of those questions is yes, then this is the best solution: https://github.com/3rdIteration/btcrecover/.

Follow the instructions on this page (https://github.com/3rdIteration/btcrecover/blob/master/TUTORIAL.md#btcrecover-tutorial) to set up a password token file, provide a copy of your Electrum wallet file, and have the software try brute forcing every combination it can. Whether or not you are successful will depend on how complex your password is, how much of it you can or cannot remember, and the speed your computer can run the software.

If you cannot remember your password at all, you can still use the above program to just try to bruteforce every possible combination, but the chances of being successfully are incredibly small unless you password was very short.

Having said all that, the easiest way is going to be to find your seed phrase back up.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 08, 2020, 04:07:13 PM
 #15

i lost both things, password and seed in electrum. is there a way or someone can help me to crack or brute-force to login again in my wallet?

Bruteforcing the seed is not feasible.

Bruteforcing the password depends on how much information about the password you have.
Do you remember things like
  • Minimum / maximum length of the password
  • Chars you for sure have used
  • Chars you for sure did not use
  • Lower / Upper Case
  • Char set (Numbers, special chars, ..)

Basically any information is extremely helpful.
If you password isn't too long or you still know quite a lot about it, bruetforcing it might be possible.

adaseb
Legendary
*
Offline Offline

Activity: 3738
Merit: 1708



View Profile
November 29, 2020, 03:48:08 AM
 #16

Its funny that you ask this because almost exactly 4 years ago, I had the same worry. So I made a similar thread

https://bitcointalk.org/index.php?topic=1716725

Did my own calculation there and had lots of replies that went into depth on pretty much coming to the conclusion that, its pretty safe. See the thread if you want more info.

I think Electrum is a great wallet. There was some Ledger email leak apparently and some phishing attack is going on. So in my opinion an offline electrum cold storage is a very very safe way to hold your bitcoins.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!