Bitcoin Forum
July 31, 2026, 07:10:23 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Wallet's seeds 0% guess is false  (Read 70 times)
Agbamoni (OP)
Hero Member
*****
Offline

Activity: 1134
Merit: 679


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
Today at 01:41:17 PM
 #1

A wallet's seed phrase is a secret number meant to be generated randomly from a ballot so vast that guessing is impossible. By mathematical calculation, the chances of guessing a 12-word seed phrase or a 24-word seed phrase are 0.0000000000000000000000000000000000000002939%, approximately 0% chance between 0% and 100%.

Breaking news on the internet regarding the Coldcard wallet has raised concern about seed phrases from public wallets. Is it possible that the 0% chance is false? That should be a mathematical error. I guess the chances range from 0% to 3%.

Roughly 594 Bitcoins were removed in less than 25 minutes.

Do the maths;
 
 25 minutes is 1,500 seconds
 1,500 ÷ 594 ≈ 2.53 seconds per 1 transaction.

Should we be afraid of using wallets, both cold wallets or hardwallet, since nowhere is much safer?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6465


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 01:58:42 PM
Merited by Dr.Bitcoin_Strange (1)
 #2

It is not about guessing the wallet seed phrase. The hacker did not guess the wallet seed phrase, but Coldcard is vulnerable to the attack in a way that update can not even fix wallet that their seed phrases has been generated.

Use passphrase while generating wallet can help you against some attacks and I think against attacks like this one.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1106
Merit: 710


Let love lead


View Profile WWW
Today at 02:00:43 PM
 #3

Should we be afraid of using wallets, both cold wallets or hardwallet, since nowhere is much safer?
From what I know about the ColdCard wallet hack, they explored a vulnerability in their firmware update and had access to drain certain wallets.

Coldcard is closed source and not the best option.
People should be more inclined to using open-source wallets like Electrum, blue wallet, sparrow e.t.c and extend their security with a passphrase. It's another warning to people to avoid hardware wallets that are closed source, it's either open-source or it's security isn't guaranteed.

Cold wallets are the safest, air-gapped devices can never be in contention for social engineering. It's much safer.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
coinlary
Sr. Member
****
Offline

Activity: 728
Merit: 275


Make decisions without looking back


View Profile
Today at 02:45:21 PM
 #4

Read this : Technical Deep Dive into the Entropy Issue

It's  not  like a direct guess work that compromise every wallet on this earth lol , it was as a result of vulnerability  from existing bugs  on some  COLDCARD  firmware versions.

Quote
In 2021, we moved COLDCARD’s elliptic-curve operations to Bitcoin Core’s libsecp256k1, using the same implementation trusted by Bitcoin Core instead of maintaining a separate EC stack. That required adding libNgU, an embedded MicroPython library that exposes libsecp256k1 and other Bitcoin primitives.

The cryptographic choice was sound. The integration was not. During that migration, wallet seed generation moved from ckcc.rng_bytes() to ngu.random.bytes(). That path resolved rng_get() to MicroPython’s software fallback instead of COLDCARD’s hardware RNG implementation.

The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base (it is from a submodule, Micropython).

They've responded with a new update to fix the issue now.

Someone probably used AI to  reviewed their code as mentioned and instead of contacting their Team to fix it, they decide to take the opportunity as usual.
It doesn't affect other wallets or hardware wallets, but it's only a matter of time before we start seeing other exploits targeting wallet vulnerabilities.

If you have any wallet now , consider adding extra layer of security  like passphrase . If you want to go harder and you kn̈ow what you're doing the and a cosigner.

Obim34
Hero Member
*****
Offline

Activity: 1050
Merit: 727



View Profile WWW
Today at 03:36:10 PM
 #5

Roll Eyes
Coldcard is closed source and not the best option.
People should be more inclined to using open-source wallets like Electrum, blue wallet, sparrow e.t.c and extend their security with a passphrase. It's another warning to people to avoid hardware wallets that are closed source, it's either open-source or it's security isn't guaranteed.

Cold wallets are the safest, air-gapped devices can never be in contention for social engineering. It's much safer.
Coldcard is an open-source hardware wallet that also supports air-gapping.

Electrum, BlueWallet, and Sparrow are all hot wallets, different from Coldcard, which is a cold storage device.

updated drained 1082.65 Bitcoin stolen


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀
 
..PLAY NOW..
Karl_3000
Full Member
***
Offline

Activity: 364
Merit: 186


Bitcoin can not fail you


View Profile WWW
Today at 03:46:32 PM
 #6

Roll Eyes
Coldcard is closed source and not the best option.
People should be more inclined to using open-source wallets like Electrum, blue wallet, sparrow e.t.c and extend their security with a passphrase. It's another warning to people to avoid hardware wallets that are closed source, it's either open-source or it's security isn't guaranteed.

Cold wallets are the safest, air-gapped devices can never be in contention for social engineering. It's much safer.
Coldcard is an open-source hardware wallet that also supports air-gapping.

Electrum, BlueWallet, and Sparrow are all hot wallets, different from Coldcard, which is a cold storage device.

updated drained 1082.65 Bitcoin stolen
Yes these are all true, Coldcard is an open source hardware wallet that is airgapped, the only way the wallet was vulnerable is because the seed phrase the wallet is generating is not secure and the hackers used the privilege to get access to some peoples private keys.

😳 More coins have been stolen. It has almost double the coins that were initially reported to have been stolen.

Edit: some people are saying Coldcard is not open source but that its code is publicly verifiable.

IjawMan
Full Member
***
Online Online

Activity: 518
Merit: 241



View Profile
Today at 04:06:36 PM
 #7

A wallet's seed phrase is a secret number meant to be generated randomly from a ballot so vast that guessing is impossible. By mathematical calculation, the chances of guessing a 12-word seed phrase or a 24-word seed phrase are 0.0000000000000000000000000000000000000002939%, approximately 0% chance between 0% and 100%.

Breaking news on the internet regarding the Coldcard wallet has raised concern about seed phrases from public wallets. Is it possible that the 0% chance is false? That should be a mathematical error. I guess the chances range from 0% to 3%.
The zero chance is not false with open source decentralized wallets

The bitcoins that were drained were not done through random guess work on the wallets seed phrases, it was a bit of a vulnerability issue with how Coldcard wallet seeds were been generated.
 
Quote
Coldcard maker, Coinkite, confirmed hours after the exploit that seed generation within its Mk3 wallet, and its subsequently updated versions beyond March 2021 (version 4.0.1), may not have been random at all.
https://protos.com/coldcard-attack-25-minutes-500-wallets-38m-in-btc-gone/


DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1106
Merit: 710


Let love lead


View Profile WWW
Today at 04:08:22 PM
Last edit: Today at 04:19:45 PM by DubemIfedigbo001
 #8

Coldcard is an open-source hardware wallet that also supports air-gapping.
Yeah, you're partially right, it's open to viewing and validation, but it uses restrictive license instead of standard open-source license, and has a clause in its first paragraph on Github, so it's not fully open-source.

Quote
Electrum, BlueWallet, and Sparrow are all hot wallets, different from Coldcard, which is a cold storage device.
You're not totally correct here, I use Electrum as a cold storage in my old PC and removed the network cards to make it air-gapped. I sign transactions in it and broadcast through my watch only wallet in my hot device. It can both be used as a hot wallet and cold storage. Electrum can serve as a cold storage if the device it's installed in never goes online

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
Curious T
Full Member
***
Offline

Activity: 378
Merit: 105



View Profile
Today at 04:52:48 PM
 #9

What are the odds of guessing 12 words out of 2,048 accurately? You would need time that is more than the age of the Earth to be able to do that, even with the kind of technology we have today. So, it is mathematically impossible to guess a seed phrase. As others have said, the hackers exploited a vulnerability, not by guessing the seed phrase.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!