Bitcoin Forum
August 27, 2026, 06:01:14 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4]  All
  Print  
Author Topic: Seed Generation in Hardware Wallets  (Read 1251 times)
Romeo1290
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
May 01, 2025, 11:18:40 AM
 #61

Read through the whole thread - really great to see people discussing actual security criteria, not just brand names.
 Huh Also - has anyone here tried the ERA? It looks solid on paper, but I’d love to hear real user feedback from someone who actually held it in hand, not just read the site.
dkbit98 (OP)
Legendary
*
Offline

Activity: 3066
Merit: 8838



View Profile WWW
August 07, 2026, 10:01:31 AM
Merited by vapourminer (1)
 #62

In light of recent debacle of c0ldcard crap devices, it is good idea to check entropy strength for most popular hardware wallets.
You can see comparison list and difference in entropy when 12 and 24 words are sued.
Using 24 words is obviously producing much better entropy, and is harder to break it.


▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
PX-Z
Legendary
*
Offline

Activity: 2282
Merit: 1372


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 08, 2026, 11:15:06 PM
 #63

Using 24 words is obviously producing much better entropy, and is harder to break it.
..
Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
satscraper
Legendary
*
Offline

Activity: 1568
Merit: 2903



View Profile
August 09, 2026, 08:15:51 AM
 #64

I would not rely on that SEED security table.

Any flaw that touches on randomness will undermine those estimates, so wallet owners must assume the worst-case scenario, i.e.  such flaws exist even if they have still not been revealed for their wallets. The only step users can take to mitigate this risk is to use the multisig setup.
 

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Cricktor
Legendary
*
Offline

Activity: 1596
Merit: 4357



View Profile
August 13, 2026, 06:19:49 AM
 #65


From 40-->72 bits, 32 bits difference being ~4.3 billion times harder, totally understandable, math checks out right.

From 72-->128 bits, 56 bits difference being only ~72 million times harder? New math?? What could possibly weaken a much larger bit difference to make it much easier to break? I don't understand this. ~72 quadrillion or ~72 million billion times harder, I'd be fine with this.

dkbit98 (OP)
Legendary
*
Offline

Activity: 3066
Merit: 8838



View Profile WWW
August 14, 2026, 10:04:02 PM
 #66

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.

I would not rely on that SEED security table.
You don't have to really on anything, this is not holly scripture, just math.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
PX-Z
Legendary
*
Offline

Activity: 2282
Merit: 1372


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 14, 2026, 10:59:46 PM
 #67

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.
Can you link to the source for this?
I searched for information regarding weak entropy generation combined with a strong bip39 passphrase, and from what i can find, a sufficiently strong and independently generated passphrase should make the resulting wallet significantly harder to compromise, since the attacker would need to recover both the weakly generated seed and the passphrase.

That said, if the experiment/research demonstrates that the passphrase does not provide the expected protection in this particular scenario, that's obviously concerning.


 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Cricktor
Legendary
*
Offline

Activity: 1596
Merit: 4357



View Profile
August 15, 2026, 09:29:05 AM
Merited by vapourminer (1)
 #68

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.
I would like to see the source of this claim, too.

From my understanding of the BIP39 derivation processsee chart below and at what point the mnemonic passphrase (the additional part) is introduced, a complex and basically not feasibly brute-forceable mnemonic passphrase should yield a wallet with not-attackable private keys.

The mnemonic passphrase is introduced before the PBKDF2 2048 hashing rounds with HMAC-SHA512. Depending on how much entropy the mnemonic passphrase introduces or carries, being at best basically not-brute-forceable, you can't reasonably crack such a wallet's derived private keys IF the mnemonic passphrase IS strong enough (no dictionary attack possible e.g.). It shouldn't then matter how "weak" the mnemonic recovery words' entropy is.

So, I very much doubt the claim of that one developer. And we've seen how badly developers can screw up in the example of Coinkite...

From Entropy to Address

The source once was (unfortunately now not working anymore as the Github repo seems to have been deleted): https://raw.githubusercontent.com/EAWF/BTC-Toolbox/3938785f186c76598989cc0aa017ad351483d3b1/Images/KeyDerivationTechnicalOverview.png
It was added to the repository with this commit: https://github.com/EAWF/BTC-Toolbox/commit/3938785f186c76598989cc0aa017ad351483d3b1 -- But it was removed by the uploader for a slightly insignificant reason, some surviving image copies in Reddit show that it's uploaded by the same user. Link to the commit that deleted it: https://github.com/EAWF/BTC-Toolbox/commit/f75e2b352ec9facc8d2da52b5ec303fb280c3298

rdluffy
Legendary
*
Offline

Activity: 3066
Merit: 2069



View Profile WWW
August 15, 2026, 02:14:30 PM
 #69

This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.

Did they manage to extract even the passphrase that wasn't on the BIP39 list?
As far as I remember, that person had also generated one of those passphrases

In any case, there's already talk on Reddit that this might be an inside job, which would explain how they were able to access even those wallets with passphrases.

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
satscraper
Legendary
*
Offline

Activity: 1568
Merit: 2903



View Profile
August 16, 2026, 07:30:53 AM
Last edit: August 16, 2026, 07:50:29 AM by satscraper
 #70

Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.


Then I would advise that "developer" to use passphrases with good entropy, the more the better.

According to BIP39 spec, the binary SEED results from the function PBKDF2(HMAC-SHA512, mnemonic, "mnemonic"+passphrase, 2048, 64), in which two of the arguments namely, the mnemonic and "mnemonic"+passphrase are independent variables. Being independent, their entropies add roughly additively to joint entropy which accordingly increases the search space for the bruteforce attack.

So, for example, adding 88-bit-entropy passphrase to a wallet with 40-bit mnemonic entropy would result in a wallet with 128 bits of combined entropy, which is currently computationally infeasible to bruteforcing.


Plus, using extended bip39 passphrase can add another layer of security and make the resulting wallet much harder to attack through seed generation weaknesses.
This doesn't really matter if you are using seed phrase generated with weak entropy.

Pls, don't mislead users.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Cricktor
Legendary
*
Offline

Activity: 1596
Merit: 4357



View Profile
August 16, 2026, 10:53:18 AM
Merited by vapourminer (1)
 #71

...
So, for example, adding 88-bit-entropy passphrase to a wallet with 40-bit mnemonic entropy would result in a wallet with 128 bits of combined entropy, which is currently computationally infeasible to bruteforcing.
But when in the case of Coinkite the ~40-bit mnemonic recovery words entropy is quite predictable, you can't reasonably add it to the entropy of the mnemonic passphrase, in my opinion. Otherwise, I'm with your argumentation.

If someone uses only words from the BIP39 wordlist for the mnemonic passphrase, every word regardless of its length only contributes 11 bits of entropy. I would always mix in numbers and special characters to throw off simple dictionary attacks.

satscraper
Legendary
*
Offline

Activity: 1568
Merit: 2903



View Profile
August 16, 2026, 12:03:37 PM
Last edit: August 16, 2026, 12:22:01 PM by satscraper
 #72

...
So, for example, adding 88-bit-entropy passphrase to a wallet with 40-bit mnemonic entropy would result in a wallet with 128 bits of combined entropy, which is currently computationally infeasible to bruteforcing.
But when in the case of Coinkite the ~40-bit mnemonic recovery words entropy is quite predictable, you can't reasonably add it to the entropy of the mnemonic passphrase, in my opinion. Otherwise, I'm with your argumentation.

If someone uses only words from the BIP39 wordlist for the mnemonic passphrase, every word regardless of its length only contributes 11 bits of entropy. I would always mix in numbers and special characters to throw off simple dictionary attacks.

Definitely, if part of the entropy comes from predictable SEED phrase, then to be on the safe side you should add the passphrase that contributes at least 128 bit of entropy at once.

My passphrase delivers around 163 bit, so I don't care whether SEED phrase I use is predictable or not, though I'm inclined to think that it is not predictable because the source used to generate it was Avalanche diode, as stated by Foundation, which manufactured my Passport Core wallet.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
dkbit98 (OP)
Legendary
*
Offline

Activity: 3066
Merit: 8838



View Profile WWW
August 18, 2026, 05:56:51 PM
 #73

Can you link to the source for this?
I searched for information regarding weak entropy generation combined with a strong bip39 passphrase, and from what i can find, a sufficiently strong and independently generated passphrase should make the resulting wallet significantly harder to compromise, since the attacker would need to recover both the weakly generated seed and the passphrase.
I don't have the exact link, but you can find this on twitter, guy performed experiment with his coldcard crap, and all passphrase addresses got emptied.
You can also believe what you want and think that ''strong'' passphrase is ultimate protection.
I did manage to find similar tweet, it's not the original and you will need to translate it to english:
https://x.com/DragonCrip/status/2087521268438352124







▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Meuserna
Sr. Member
****
Offline

Activity: 357
Merit: 634


View Profile WWW
August 18, 2026, 11:18:58 PM
Merited by vapourminer (2), dkbit98 (1)
 #74

Can you link to the source for this?
I searched for information regarding weak entropy generation combined with a strong bip39 passphrase, and from what i can find, a sufficiently strong and independently generated passphrase should make the resulting wallet significantly harder to compromise, since the attacker would need to recover both the weakly generated seed and the passphrase.
I don't have the exact link, but you can find this on twitter, guy performed experiment with his coldcard crap, and all passphrase addresses got emptied.

There had to be a reason for the attacker to search the seed for passphrase wallets in the first place. That's why I've changed my mind on using the seed-only wallet as a decoy. I've never done this, but I used to think it's a good idea. Now, I realize it isn't.

Using the seed-only wallet as a decoy isn't a good idea because it shows a would-be attacker that the seed was used, which gives them a reason to search for passphrase wallets, especially if the seed-only wallet looks like a decoy (a small amount of sats, probably used only once, or everything else was moved from that wallet, probably to a passphrase wallet). If a seed has never been used as a seed-only wallet, there's no reason for an attacker to search it, assuming the attacker didn't find the physical backup of course.

The ColdCard attackers had to search billions of seeds, maybe as many as a trillion, which is why they're still finding things. It isn't realistic for them to do brute-force passphrase searches on a trillion seeds. But once they narrow down the list of candidates by looking at seeds that have either been used or look like decoys, their odds increase drastically.


You can also believe what you want and think that ''strong'' passphrase is ultimate protection.
I did manage to find similar tweet, it's not the original and you will need to translate it to english:
https://x.com/DragonCrip/status/2087521268438352124

Look at how quickly adding just one word makes a passphrase exponentially stronger:

Quote
- 1 word is trivial: seconds or less. 
  Combinations: 2,048

- 2 words is easy: minutes with decent hardware. 
  Combinations: 4.2 million

- 3 words is moderate: hours with modern GPUs. 
  Combinations: 8,590 million

By the time you're talking about 5 or 6 words, it takes decades and centuries to crack. I'm a big believer in using 7 words or more.

Here's a great video about passphrase strength, by Crypto Guide. Note the size of the dictionary examples he uses. I wish he'd used the BIP39 word list (2048 words) instead of a 1226 word dictionary in his example. The time to crack passphrases made from the BIP39 wordlist would be significantly longer than his 1226 word dictionary examples. Still, his chart is helpful.

I think it's a shame that so few hardware wallets include passphrase QR. Passphrase QR makes it easy to load very strong passphrases effortlessly.

ShieldSigner and Krux both do passphrase QR, and both are excellent. Free and open source, airgapped and stateless.

dkbit98 (OP)
Legendary
*
Offline

Activity: 3066
Merit: 8838



View Profile WWW
August 19, 2026, 09:29:39 PM
Merited by vapourminer (1), Cricktor (1)
 #75

I wrote before that hardware wallets are using different methods for generating seed words and good entropy.
Most of them are combining multiple things, and this gives decent results, but it is not standardized.
Developer Keith Mukai is trying to standardize alternative way of using dice correctly to generate strong entropy.
I think this is a good idea and it can prevent future exploits, but it will take time for all manufacturers to accept it.
This is not a quick read, so take your time and read it slowly to understand it better.


https://kdmukai-bot.github.io/seedsigner-ai-analysis/dice/standard.html

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
rdluffy
Legendary
*
Offline

Activity: 3066
Merit: 2069



View Profile WWW
August 22, 2026, 02:42:46 PM
Merited by vapourminer (2), bitmover (2)
 #76

I don't know if you've seen this Trezor response


https://x.com/Trezor/status/2089697469042979060

I found it really interesting, they're considering offering the option to roll the dice for entropy

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
bitmover
Legendary
*
Offline

Activity: 3136
Merit: 7687


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 25, 2026, 11:59:03 PM
 #77

I don't know if you've seen this Trezor response


https://x.com/Trezor/status/2089697469042979060

I found it really interesting, they're considering offering the option to roll the dice for entropy

Entropy wasn't something "sexy" to talk about before this coldcard incident. I think ledger lost a lot of customers, who migrate to coldcard and trezor. Now, trezor entropy revealed to be inferior to competitors, they might be trying to fix this.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
m2017
Legendary
*
Offline

Activity: 2590
Merit: 1710


keep walking, Johnnie


View Profile
August 26, 2026, 03:13:27 AM
 #78

I don't know if you've seen this Trezor response


https://x.com/Trezor/status/2089697469042979060

I found it really interesting, they're considering offering the option to roll the dice for entropy

Entropy wasn't something "sexy" to talk about before this coldcard incident. I think ledger lost a lot of customers, who migrate to coldcard and trezor. Now, trezor entropy revealed to be inferior to competitors, they might be trying to fix this.
Does trezor really have a choice? If their entropy lags behind that of competitors, they will lose marketing ground (market share). Especially after the Coldcard incident, users will be extremely particular about such details.

In short, HW's manufacturers  (all of them) have no choice in the sense that they must constantly improve their devices and seek ways to enhance reliability. If generating the seed-phrase using dice "strengthens" trezor, then so be it (if only they don't break anything Smiley).

Trezor owners will await the addition of this feature and prepare to migrate their crypto-assets.

satscraper
Legendary
*
Offline

Activity: 1568
Merit: 2903



View Profile
August 26, 2026, 10:41:19 AM
 #79

I don't know if you've seen this Trezor response


https://x.com/Trezor/status/2089697469042979060

I found it really interesting, they're considering offering the option to roll the dice for entropy

Interesting development. Now everyone is obsessed with the entropy/randomness generated by wallets, but the same matters for the nonce generated bywallet when signing transaction. Unfortunately, this part can't be ensured by dice rolling. Any weakness in that runtime RNG like bad seeding, insufficient entropy pool on embedded/hardware devices, buggy PRNG leaks directly into the nonce.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
rdluffy
Legendary
*
Offline

Activity: 3066
Merit: 2069



View Profile WWW
August 26, 2026, 05:04:05 PM
 #80

...

Entropy wasn't something "sexy" to talk about before this coldcard incident. I think ledger lost a lot of customers, who migrate to coldcard and trezor. Now, trezor entropy revealed to be inferior to competitors, they might be trying to fix this.

At least I hope this incident serves as a lesson so that nothing like this ever happens again
If that happens, it will at least be a step forward for security

I ended up regenerating some wallets I had here, including my Trezor, where instead of 12 words, I generated a 24-word seed with a passphrase
I hope I won’t have to regenerate them and move everything again, but if Trezor improves the entropy, I’ll end up doing it again

My Ledger wallet was already generated with 24 words, I think that was standard back then, so I didn’t change anything on that one

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
Pages: « 1 2 3 [4]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!