Bitcoin Forum
August 15, 2026, 05:33:42 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4]  All
  Print  
Author Topic: Seed Generation in Hardware Wallets  (Read 1102 times)
Romeo1290
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
May 01, 2025, 11:18:40 AM
 #61

Read through the whole thread - really great to see people discussing actual security criteria, not just brand names.
 Huh Also - has anyone here tried the ERA? It looks solid on paper, but I’d love to hear real user feedback from someone who actually held it in hand, not just read the site.
dkbit98 (OP)
Legendary
*
Offline

Activity: 3052
Merit: 8812



View Profile WWW
August 07, 2026, 10:01:31 AM
Merited by vapourminer (1)
 #62

In light of recent debacle of c0ldcard crap devices, it is good idea to check entropy strength for most popular hardware wallets.
You can see comparison list and difference in entropy when 12 and 24 words are sued.
Using 24 words is obviously producing much better entropy, and is harder to break it.


▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
PX-Z
Legendary
*
Online Online

Activity: 2268
Merit: 1367


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 08, 2026, 11:15:06 PM
 #63

Using 24 words is obviously producing much better entropy, and is harder to break it.
..
Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
satscraper
Legendary
*
Offline

Activity: 1554
Merit: 2885



View Profile
August 09, 2026, 08:15:51 AM
 #64

I would not rely on that SEED security table.

Any flaw that touches on randomness will undermine those estimates, so wallet owners must assume the worst-case scenario, i.e.  such flaws exist even if they have still not been revealed for their wallets. The only step users can take to mitigate this risk is to use the multisig setup.
 

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Cricktor
Legendary
*
Offline

Activity: 1582
Merit: 4249



View Profile
August 13, 2026, 06:19:49 AM
 #65


From 40-->72 bits, 32 bits difference being ~4.3 billion times harder, totally understandable, math checks out right.

From 72-->128 bits, 56 bits difference being only ~72 million times harder? New math?? What could possibly weaken a much larger bit difference to make it much easier to break? I don't understand this. ~72 quadrillion or ~72 million billion times harder, I'd be fine with this.

dkbit98 (OP)
Legendary
*
Offline

Activity: 3052
Merit: 8812



View Profile WWW
August 14, 2026, 10:04:02 PM
 #66

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.

I would not rely on that SEED security table.
You don't have to really on anything, this is not holly scripture, just math.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
PX-Z
Legendary
*
Online Online

Activity: 2268
Merit: 1367


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 14, 2026, 10:59:46 PM
 #67

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.
Can you link to the source for this?
I searched for information regarding weak entropy generation combined with a strong bip39 passphrase, and from what i can find, a sufficiently strong and independently generated passphrase should make the resulting wallet significantly harder to compromise, since the attacker would need to recover both the weakly generated seed and the passphrase.

That said, if the experiment/research demonstrates that the passphrase does not provide the expected protection in this particular scenario, that's obviously concerning.


 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Cricktor
Legendary
*
Offline

Activity: 1582
Merit: 4249



View Profile
Today at 09:29:05 AM
Merited by vapourminer (1)
 #68

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.
I would like to see the source of this claim, too.

From my understanding of the BIP39 derivation processsee chart below and at what point the mnemonic passphrase (the additional part) is introduced, a complex and basically not feasibly brute-forceable mnemonic passphrase should yield a wallet with not-attackable private keys.

The mnemonic passphrase is introduced before the PBKDF2 2048 hashing rounds with HMAC-SHA512. Depending on how much entropy the mnemonic passphrase introduces or carries, being at best basically not-brute-forceable, you can't reasonably crack such a wallet's derived private keys IF the mnemonic passphrase IS strong enough (no dictionary attack possible e.g.). It shouldn't then matter how "weak" the mnemonic recovery words' entropy is.

So, I very much doubt the claim of that one developer. And we've seen how badly developers can screw up in the example of Coinkite...

From Entropy to Address

The source once was (unfortunately now not working anymore as the Github repo seems to have been deleted): https://raw.githubusercontent.com/EAWF/BTC-Toolbox/3938785f186c76598989cc0aa017ad351483d3b1/Images/KeyDerivationTechnicalOverview.png
It was added to the repository with this commit: https://github.com/EAWF/BTC-Toolbox/commit/3938785f186c76598989cc0aa017ad351483d3b1 -- But it was removed by the uploader for a slightly insignificant reason, some surviving image copies in Reddit show that it's uploaded by the same user. Link to the commit that deleted it: https://github.com/EAWF/BTC-Toolbox/commit/f75e2b352ec9facc8d2da52b5ec303fb280c3298

rdluffy
Legendary
*
Offline

Activity: 3052
Merit: 2056



View Profile WWW
Today at 02:14:30 PM
 #69

This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.

Did they manage to extract even the passphrase that wasn't on the BIP39 list?
As far as I remember, that person had also generated one of those passphrases

In any case, there's already talk on Reddit that this might be an inside job, which would explain how they were able to access even those wallets with passphrases.

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
Pages: « 1 2 3 [4]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!