Bitcoin Forum
August 02, 2026, 07:55:23 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: So with the cold wallet hack I am thinking about using core 29 to store.  (Read 174 times)
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
July 31, 2026, 05:27:32 PM
Merited by Welsh (4)
 #1

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.

So I have a core 29 with a tiny amount of btc in it.

How to make the core 29 wallet be safe is the question.

I never encrypted it.

So I suppose I can make a long passhrase.

Like:

 abcdefgh87654321HGFEDCBA

Encrypt it.

Then test that I can get into the wallet.

Then make 5 backups of the  wallet.

I WOULD guess that is safer than a hardware wallet.

Also should I upgrade to core 30 or stay on core 29

Or use core 28.

I DO NOT WANT KNOTS .


So  ideas of setting up a  core to store a few btc.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6466


Leading Crypto Sports Betting & Casino Platform


View Profile
July 31, 2026, 05:43:22 PM
 #2

I do not know much maybe Bitcoin Core can be offline while you still run it as a node. If possible the wallet can be offline, it will be better.

You can have your own Electrum server and still have an Electrum wallet setup on an airgapped device and make use of your server on a watch-only wallet for transactions.

I am not a node runner, but there is option to use Electrum with Tor and have a seed phrase (+passphrase) set up on it.  This has been the option for me.

You would have seen on some of my posts that I do not like hardware wallet because it can reduce people's privacy. But getting one and setup a wallet with passphrase to extend the seed phrase will make that kind of Coldcard attack not possible.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
retaur
Member
**
Offline

Activity: 196
Merit: 34


View Profile
July 31, 2026, 06:06:47 PM
Merited by NotATether (10), Welsh (2)
 #3

Airgapping and cold storage is superior to everything.

Next is multisigging with different hardware wallets.

If you've not got much to store, you can use core and other software wallets. If you know what you're doing you can use software only with a decent amount of funds but it's really not recommended (I just used to do it with electrum though).
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22399


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 31, 2026, 06:33:45 PM
Merited by Welsh (2), ABCbits (1), Charles-Tim (1)
 #4

I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.

Quote
Then make 5 backups of the  wallet.
Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
OgNasty
Donator
Legendary
*
Offline

Activity: 5544
Merit: 6435


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
July 31, 2026, 07:36:57 PM
 #5

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
July 31, 2026, 09:19:31 PM
 #6

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

og my fear would be  if one company can be exploited  due to a 40 bit vs a 256 bit search

then maybe other wallets may do short cuts.  making shorter search areas for a pc to crack the wallet.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
nc50lc
Legendary
*
Offline

Activity: 3220
Merit: 8951


Self-proclaimed Genius


View Profile
August 01, 2026, 03:59:17 AM
Merited by Welsh (3)
 #7

Also should I upgrade to core 30 or stay on core 29

Or use core 28.
If you're using a descriptor wallet anyways, go for 30.2+ (skip 30.0 and .1).

And if you're using a descriptor wallet, you can use a Cold-Storage Bitcoin Core setup by exporting the no-secrets descriptors to a watch-only Bitcoin Core wallet.
Transaction creation, export and signing procedures are supported by the GUI so it should be easy.
The only complicated part is the first time setup
Or wait for this in the next release version: github.com/bitcoin/bitcoin/pull/32489

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22399


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 01, 2026, 04:14:33 AM
Merited by Welsh (1)
 #8

if one company can be exploited  due to a 40 bit vs a 256 bit search then maybe other wallets may do short cuts.
If that's your fear, why don't you use dice rolls or coin tosses to create your seed?

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10045


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 01, 2026, 08:45:18 AM
Merited by Welsh (3)
 #9

Is the coldcard bug really a reason to panic if you aren’t using one? It seemed like an exploit for that service only. I’m not sure I understand the panic. Am I not worrying enough to be planning to do absolutely nothing? My private keys were generated more than a decade ago. I’d like to think they’re battle tested by now.

That's right, there's no panic unless you used Coldcard hardware wallets to generate your seed.

If your seed was generated from non-coldcard hardware, you are safe.

If it was generated with coldcard hardware with firmware preceding v4, you are also safe.

Multisig is superior to all this anyway, and it is the method you should be using when you have a bunch of hardware wallets.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7671



View Profile WWW
August 01, 2026, 03:26:00 PM
 #10

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.
~snip~


Given that you are a Trezor user, the simplest thing would be to create a new account in the same device, choose passphrase as additional protection (a unique password of 10+ characters, letters, numbers) and then transfer all your coins to that protected account. A seed generated with such low entropy is not something that users of other hardware wallets should worry about, because this is obviously an isolated case.

I think there is no room for panic, everyone can protect their coins today in the very simple way already mentioned. Additionally, an air-gapped wallet + strong passphrase are more than enough protection to allow you to sleep peacefully until super quantum computers and some perhaps still unknown threats appear.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Satofan44
Sr. Member
****
Offline

Activity: 462
Merit: 1178


Don't hold me responsible for your shortcomings.


View Profile
August 01, 2026, 05:07:02 PM
Last edit: August 01, 2026, 07:40:21 PM by Satofan44
Merited by Welsh (3), stwenhao (1)
 #11

Airgapping and cold storage is superior to everything.
Superior by far yes, but not recommended for those that don't know what they are doing which represents a majority of users. Perhaps you or other users of this forum would be surprised how many people are not able to create proper backups of 24 words -- which is literally among the easiest things in the world, therefore we need to be careful what we suggest and to whom. I can completely see cases of people using a cold storage airgap system, eventually getting frustrated with it and entering their wallet details on onlinecoldstorage.com.  Cheesy

OKAY i  have hardware wallets. I am a bit nervous they can get cracked like cold wallet hack has happened.
~snip~

Given that you are a Trezor user, the simplest thing would be to create a new account in the same device, choose passphrase as additional protection (a unique password of 10+ characters, letters, numbers) and then transfer all your coins to that protected account. A seed generated with such low entropy is not something that users of other hardware wallets should worry about, because this is obviously an isolated case.

I think there is no room for panic, everyone can protect their coins today in the very simple way already mentioned. Additionally, an air-gapped wallet + strong passphrase are more than enough protection to allow you to sleep peacefully until super quantum computers and some perhaps still unknown threats appear.
Correct. People keep over complicating these topics because of anxiety and fear. The attack vector that was used here is completely mitigated by using a passphrase. Nobody is going to be brute-forcing all the seed phrases that they have managed to re-generate from a vulnerability with the hope that one of them will have a matching passphrase before the Sun runs out of fuel. Always use a strong passphrase with every hardware wallet, it could not get more simple than that. This prevents the low entropy attack vector, and it does not require additional hardware, knowledge, or multisig. It does not require anything at all. People, don't be modern day NPC overthinking machines, and just solve problems with the best and simplest solutions.

philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
August 01, 2026, 07:23:19 PM
 #12

I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.

Quote
Then make 5 backups of the  wallet.
Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version.


I made a reply to this post and the mod to the bot did not realize that it was a reply thus deleted it.

quotes are from the pm

"Deleted Post
« Sent to: philipma1957 on: Today at 06:21:09 AM »
Reply with quoteReply with quote  Remove this messageDelete  
A reply of yours, quoted below, was deleted by a Bitcoin Forum moderator. Posts are most frequently deleted because they are off-topic, though they can also be deleted for other reasons. In the future, please avoid posting things that need to be deleted.


Quote
Quote from: LoyceV on July 31, 2026, 02:33:45 PM
Quote from: philipma1957 on July 31, 2026, 01:27:32 PM
I never encrypted it.
Is it an online hot wallet? If so, I wouldn't use it to replace a Trezor.
For cold storage, I find Electrum easier for offline signing than Bitcoin Core (read my sweep method to get an idea).

Quote
So I suppose I can make a long passhrase.
 abcdefgh87654321HGFEDCBA
abcdefgh and 87654321 are very easy for a (dictionary) attack.  yeah sorry I thought I was being obvious with that.



Quote
Then make 5 backups of the  wallet.

Make them on different storage media: different brand USB stick, HDD or even CDrom. If one of them has a limited shelf life, another one might last longer.

Then test the backups of your wallet!

Quote
I WOULD guess that is safer than a hardware wallet.
It's a lot more difficult. How about a combination of both: offline signing with Electrum connected to a hardware wallet?

Quote
Also should I upgrade to core 30 or stay on core 29
Or use core 28.
As far as I know, they're all safe. I'm still using an older version. "




If you look at the bold my reply was on topic.

and an attempt to show that my original post was not clear enough about  the passphrase


my intention to make a passphrase is to make this chart it shows the 94 letters numbers and symbols of my keyboard

01 ~       11 %         21 )        31 E            41  I           51  |        61 G        71 :      81 V       91 >
02 `       12 6          22 -         32 r            42  o           52 a         62 h        72 ‘      82 b        92 /
03 1       13 ^          23 _        33 R           43  O          53 A         63 H        73 “      83 B        93 ?
04 !        14 7          24 =        34 t           44 p            54 s          64  j        74 z      84 n        94 5
05 2       15 &         25 +         35 T           45   P         55 S          65 J         75 Z     85 N
06 @      16 8          26 q        36 y            46 [           56 d          66 k         76 x     86 m
07 3       17 *          27 Q        37 Y           47  {          57 D          67 K        77 X      87 M
08 #      18 9          28 w        38 u            48   ]         58 f           68 l         78 c       88 ,
09 4       19 (          29 W       39 U            49    }        59 F          69 L         79 C      89 <
10 $       20 0         30 e         40 i             50   \          60 g         70 ;         80 v       90 .


I will buy this from amazon

https://www.amazon.com/100pcs-Wooden-Number-Wedding-Decoration/dp/B07MBJ3DLR/ref=sr_1_9?


I will  put numbers 1 to 94 in a bag shake them

pull out a tile

mark it down

put tile back

pull out a tile mark it down

do this 24 times

giving me a random passphrase of 94 to the 24 power or


The full number form of 94 to the 24th power is 22,650,014,605,289,804,187,822,243,772,656,756,034,402,621,8496


      Ai missed a comma but this should be a tough passphrase

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
nc50lc
Legendary
*
Offline

Activity: 3220
Merit: 8951


Self-proclaimed Genius


View Profile
Today at 04:33:33 AM
Merited by Welsh (4)
 #13

The full number form of 94 to the 24th power is 22,650,014,605,289,804,187,822,243,772,656,756,034,402,621,8496
Even so, if Bitcoin Core is used as a Hot wallet, that passphrase can just be key logged with one sneaky malware.
It's safe as long as the machine is safe, but not safer than an air-gap setup by any means.

BTW, it's worth mentioning that the "Passphrase" that they've mentioned in that Coldcard topic isn't the same as Bitcoin Core's wallet passphrase.
In that thread, it's about the "salt" that's used together with the mnemonic to change the resulting binary seed.
Since it's the entropy that's flawed in Coldcard, adding a strong passphrase will essentially make it hard for the attacker to reproduce the correct wallet even if he can reproduce the mnemonic/seed phrase.

Bitcoin Core's Passphrase on the other hand is just a "Password", it encrypts its mkey that encrypts the secrets inside the wallet.
All the attacker needs are the wallet.dat file and the passphrase which can be hacked as you attempt to decrypt the wallet, e.g.: when sending bitcoins.
Bitcoin Core in Air-Gap setup is safer against that.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10045


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 04:36:38 AM
 #14

Phil, you should probably use the Base64 character set instead of that custom character set you made.

It's a power of 2, and is also standard so it helps in case you forget the details on how to make the seed again.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
BlackHatCoiner
Legendary
*
Offline

Activity: 2100
Merit: 9979


Cross Chain Crypto Swap


View Profile
Today at 01:00:57 PM
 #15

If cold wallets are threatened right now, then this means you should absolutely stay away from putting your life savings on a hot wallet.

What I would do if I wanted to be completely certain my funds are safe is make a 2-of-3 multi-sig, with three different hardware wallets / signing devices, to not rely on the competency of one vendor.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7671



View Profile WWW
Today at 01:26:12 PM
 #16

~snip~
I will buy this from amazon

https://www.amazon.com/100pcs-Wooden-Number-Wedding-Decoration/dp/B07MBJ3DLR/ref=sr_1_9?


I will  put numbers 1 to 94 in a bag shake them

pull out a tile

mark it down

put tile back

pull out a tile mark it down

do this 24 times

giving me a random passphrase of 94 to the 24 power or


The full number form of 94 to the 24th power is 22,650,014,605,289,804,187,822,243,772,656,756,034,402,621,8496


Ai missed a comma but this should be a tough passphrase


I think you can do this much more easily with the help of one of the online tools that will show you all the parameters of your possible password. Of course, you will never use that identical password, which is just an example - but it will give you a better idea of ​​how strong it is.

Check this tool :

Code:
https://passcheck.io/

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
Today at 03:40:16 PM
Last edit: Today at 04:42:19 PM by philipma1957
 #17

after reading and studying the issue.

i will do passphrase with my trezors.


so a trezor 5

put a long passphrase i can do up to 50 characters. my keyboard has 94 characters.

the tiles come tomorrow .

i am allowed to do multiple passphrases.

so  5.386×10¹⁹  is a 10 symbol field

53,860,000,000,000,000,000,000.  is the size of the set of combos

what is even better you can create the passphrase offline with the tiles.

but don’t lose it or you are fucked.

also the trezor has its seed my trezor 5 uses 20 words

that is 2048th to the  20th power..

plus if they crack the seed they see say 0.015 btc

and do not see the passphrase with say .33 btc

the trezor can do more passphrases.

so you can have

0.015 in the normal wallet
0.333 in passphrase 1
0.333 in passphrase 2
0.333 in passphrase 3



now for me if I do passphrase on the trezor

i can code it on washers.


I have 36 punches


thus using 3 washers with 8 symbols each

I get 36 to the 24th power is 101559956668416 x 101559956668416 x 101559956668416=

1.04753254e42

pretty safe  about 142 bits which is better than 128 security

add a 4th washer of 8

and you go to  1.06387359e56 or 189 bits

which is stacked on top of the 20 word seed

place the 36 punches in the box




use sledge to make a 8 symbol washer


pull out 1 punch


put it back in the box


the washer fits 8 symbols easy peasy you can clearly see beginning and end

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
philipma1957 (OP)
Legendary
*
Offline

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
Today at 06:09:55 PM
 #18

So here is what the trezor looks like

the standard wallet has 20 word seed

the first passphrase has same 20 word seed and a 14 character length using 94 symbols and letters

the second passphrase has same 20 word seed and a 16 character length using 36 punches in the photos above.













but the issue remains that when the passphrase is entered the first time it could be compromised

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!