VRExpress (OP)
Member


Activity: 296
Merit: 27
|
 |
July 31, 2026, 08:24:17 PM |
|
Is it possible to still use passphrase on a already generated seed phrase using a hardware wallet? With the way things are going now nothing is certain anymore.
The person who is responsible for this coldcard hack have gotten themselves into trouble because I believe that those Bitcoin would end up been useless for the hacker and the owners, this will be a full 200% manhunting.
I'm just trying to be careful and my Keystone wallet is showing that I can add passphrase under settings but I'm not sure what to do, I just extra security later, anyone using Keystone?
|
|
|
|
|
OmegaStarScream
Staff
Legendary

Activity: 4284
Merit: 7496
|
 |
July 31, 2026, 08:28:45 PM |
|
Adding a passphrase would basically generate a new wallet for you. The whole point of it is that if someone gain access to your seed, he won't find anything because the wallet that has the funds is seed + passphrase which only you know (preferably something you can memorise) If you add a passphrase and continue to use the old generated wallet, it's as if you have not done anything. Here's a good article by trezor if you want to read more about it: https://trezor.io/guides/backups-recovery/advanced-wallets/what-is-a-passphrase?Keystone already published an tweet about the incident: https://x.com/i/status/2083142459274690743But still, adding a passphrase is never a bad idea.
|
|
|
|
Antidote47k
Jr. Member

Activity: 56
Merit: 38
|
 |
July 31, 2026, 08:54:04 PM |
|
Yes you can add a passphrase to an existing seed phrase but keep in mind that adding a passphrase generates a new wallet so this doesn’t automatically protect your coins which is in current wallet, you will need to activate the passphrase derived wallet and move your coin to the address generated by that wallet.
Also you have to make sure to test and backup your passphrase correctly before you proceed, evidently your seed phrase alone won’t be able to recover the wallet if the passphrase is lost or entered incorrectly. Every different passphrase creates a different valid wallet, which is why it’s important to write it down accurately and verify your recovery procedure.
|
|
|
|
|
Sunshine1525
Full Member
 

Activity: 166
Merit: 102
Bitcoin shall soon shine... Say it faster, hahaha.
|
 |
July 31, 2026, 09:11:45 PM |
|
Yes you can add a passphrase to an existing seed phrase but keep in mind that adding a passphrase generates a new wallet so this doesn’t automatically protect your coins which is in current wallet, you will need to activate the passphrase derived wallet and move your coin to the address generated by that wallet.
Also you have to make sure to test and backup your passphrase correctly before you proceed, evidently your seed phrase alone won’t be able to recover the wallet if the passphrase is lost or entered incorrectly. Every different passphrase creates a different valid wallet, which is why it’s important to write it down accurately and verify your recovery procedure.
I was about saying, how about someone move their coins from the old wallet to a new one whereby a paraphrase was generated, until I read where you said it. If that's possible then it cool atleast there's an alternative for more security until coldcard figure out how to avoid such mess from happening again. Although lots of people would lose trust in coldcard and seek other alternatives for the security of their coins.
|
|
|
|
|
ColdLava40
Full Member
 

Activity: 462
Merit: 158
Bitcoin
|
 |
July 31, 2026, 10:14:07 PM |
|
Yes you can add a passphrase to an existing seed phrase but keep in mind that adding a passphrase generates a new wallet so this doesn’t automatically protect your coins which is in current wallet, you will need to activate the passphrase derived wallet and move your coin to the address generated by that wallet.
With all these drama and cases of coldcard that has been a headline lately, I think hardware wallets might have been over hyped. The vulnerability in hardware wallet posses minimal practical risk until it's discovered by hackers and explored. No where is 100% safe from having a flaw. If I'm to make a choice I'll stick to the traditional paper and pen instead. It has less flaw except you expose it to the internet or through the means which your keys were generated and that's why you use good and standard wallets they pose less risk.
|
|
|
|
|
iBaba
|
 |
July 31, 2026, 10:18:37 PM |
|
Is it possible to still use passphrase on a already generated seed phrase using a hardware wallet? With the way things are going now nothing is certain anymore.
The person who is responsible for this coldcard hack have gotten themselves into trouble because I believe that those Bitcoin would end up been useless for the hacker and the owners, this will be a full 200% manhunting.
I'm just trying to be careful and my Keystone wallet is showing that I can add passphrase under settings but I'm not sure what to do, I just extra security later, anyone using Keystone?
One thing I would advise is not to enable a passphrase until you fully understand how it works, because a passphrase can significantly improve your wallets security but it also add another responsibility to it. So the passphrase doesn’t replace or change your existing seed phrase, it creates a completely separate wallet derived from the same seed. What it means is that if you lose or forget the passphrase, your seed phrase alone won’t be enough to recover the funds stored in that wallet. If I were setting it up for the first time, I would test it with a small amount of bitcoin first and make sure I could successfully recover the wallet before transferring any significant amount. Extra security is good but only when you can manage it yourself.
|
|
|
|
|
PrivacyG
Legendary

Activity: 1596
Merit: 2905
Fight for Privacy.
|
 |
July 31, 2026, 11:12:18 PM |
|
Ideally. When a Seed is possibly vulnerable, it is best that you get rid of it and generate a brand new one, preferably manually instead of using a Software. Manually as in, for example, using dice as an entropy source. If you get rid of the current Seed by generating another one through Electrum, you run the same risk of possibly generating a Seed from a version that may have a similar bug in its code!
The other way around, although a LOT LESS SECURE considering the current situation of Coldcard, is generating a Pass phrase and using that one for the time being. What this means is that even if an evil intended person gets access to your Seed, they will see zero balance and only your transaction history unless they also get to your Pass phrase.
But if you DO get a Pass phrase, make sure it is as secure as it can be! Not '2026', not 'Bitcoin2026' and not even 'Bitcoin2026?LOL'. Make that random, include multiple symbols, letters, numbers and as long as it can get. The reason for this is not only security but that if you all of a sudden move all your Bitcoin out of the Seed to the Pass phrased Seed, if someone eventually gets access to your Seed they can correlate the sudden movement to the Coldcard exploit and include your Seed in a list of many others that may have been moved to a weak Pass phrase, eventually trying to 'brute force' them one by one.
|
|
|
|
Cleanshit
Full Member
 

Activity: 225
Merit: 107
✿♥‿♥✿
|
 |
July 31, 2026, 11:49:08 PM |
|
One thing I would advise is not to enable a passphrase until you fully understand how it works, because a passphrase can significantly improve your wallets security but it also add another responsibility to it. So the passphrase doesn’t replace or change your existing seed phrase, it creates a completely separate wallet derived from the same seed. What it means is that if you lose or forget the passphrase, your seed phrase alone won’t be enough to recover the funds stored in that wallet. If I were setting it up for the first time, I would test it with a small amount of bitcoin first and make sure I could successfully recover the wallet before transferring any significant amount. Extra security is good but only when you can manage it yourself.
Passphrase will only be useful for you only if understand how to use it and also recover it, adding more security shouldn’t be what one will focus on. We should forget that a forgotten passphrase can permanently lock you out of your own funds. The safest thing to do is to create the passphrase wallet try and send in little amount of Bitcoin to it then verify so one can recover using both seed phrase and also passphrase before you can now decide to move the remaining coins in. With this it gives the confidence that your backup is active
|
|
|
|
|
MusaMohamed
|
 |
Today at 02:16:45 AM |
|
Is it possible to still use passphrase on a already generated seed phrase using a hardware wallet? With the way things are going now nothing is certain anymore.
You can use a hardware wallet to create many wallets with different wallet seed phrases and with passphrases if you want. It's important that with a same wallet seed phrase, if you add different passphrases, you will have many different wallets. About passphrase https://learnmeabitcoin.com/beginners/security/#passphraseThe person who is responsible for this coldcard hack have gotten themselves into trouble because I believe that those Bitcoin would end up been useless for the hacker and the owners, this will be a full 200% manhunting.
I'm just trying to be careful and my Keystone wallet is showing that I can add passphrase under settings but I'm not sure what to do, I just extra security later, anyone using Keystone?
I recommend to avoid importing wallet seed phrase created by one wallet software or hardware wallet brand/ model to another wallet software or hardware wallet brand or different model. Like you gave an example of Coldcard, it's risky. The better and safer practice is moving your bitcoin to a new wallet. So there will be no chance for any bitcoin loss because of your previous wallets by any technical exploitation on any (previous) wallet softwares/ models. Example I visit this site to find a page and information about passphrase and see this red alarm at the main page. It's excellent action from people behind this site. https://learnmeabitcoin.com/Note: Do not import the same ColdCard seed in to a new wallet; generate a new seed with a different wallet and send your coins there. Either use a different hardware wallet if you have one, or use a software wallet like Electrum. Sending to an exchange is also reasonable if that's your only option. Do not purchase and wait for a new hardware wallet to arrive.
You can sweep if you want.
|
|
|
|
|
X-ray
|
 |
Today at 03:05:24 AM |
|
Keystone doesn't suffer the same entropy bug coldcard is having, you don't need to worry.
But if you're so worried you can generate a new wallet with dice roll + passphrase for maximum security but be sure to save your old seed phrase.
You can never be too paranoid when it comes to your self custody security but the point is coldcard is different to keystone and they don't even share the same code.
I'm pretty sure after the coldcard incident every hardware wallet company are looking at their codebase right now.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
omenswap
Copper Member
Newbie

Activity: 14
Merit: 1
omenswap.com
|
 |
Today at 03:08:36 AM |
|
Yes you can add a passphrase to an existing seed phrase but keep in mind that adding a passphrase generates a new wallet so this doesn’t automatically protect your coins which is in current wallet, you will need to activate the passphrase derived wallet and move your coin to the address generated by that wallet.
With all these drama and cases of coldcard that has been a headline lately, I think hardware wallets might have been over hyped. The vulnerability in hardware wallet posses minimal practical risk until it's discovered by hackers and explored. No where is 100% safe from having a flaw. If I'm to make a choice I'll stick to the traditional paper and pen instead. It has less flaw except you expose it to the internet or through the means which your keys were generated and that's why you use good and standard wallets they pose less risk. I think this is a bit of an overreaction. The coldcard vulnerability was in the code that handles the random process through which the wallet seed gets generated (using an insecure PRNG). The issue absolutely should have been discovered and would have been discovered by a competent vendor -- the problem is coldcard is some third-rate hardware company that doesn't have the proper security posture required for a system that protects millions of dollars in value.
|
|
|
|
|
|
Iranus
|
 |
Today at 03:52:26 AM |
|
With all these drama and cases of coldcard that has been a headline lately, I think hardware wallets might have been over hyped.
The vulnerability in hardware wallet posses minimal practical risk until it's discovered by hackers and explored. No where is 100% safe from having a flaw.
If I'm to make a choice I'll stick to the traditional paper and pen instead.
It has less flaw except you expose it to the internet or through the means which your keys were generated and that's why you use good and standard wallets they pose less risk.
I think this is a bit of an overreaction. The coldcard vulnerability was in the code that handles the random process through which the wallet seed gets generated (using an insecure PRNG). The issue absolutely should have been discovered and would have been discovered by a competent vendor -- the problem is coldcard is some third-rate hardware company that doesn't have the proper security posture required for a system that protects millions of dollars in value. I agree. We shouldn't lump everything together and assume that hardware wallets in general are over hyped. This is simply a coldcard issue. They were too careless with their product security review process. It's not a systemic flaw in hardware wallets as a whole. From what I have learned, this vulnerability has existed since 2021, meaning it went unnoticed for 4 year before it was discovered and exploited. It's fair to say this was a failure of coldcard's own security process. We should not generalize it when wallets like trezor, keystone, and blockstream use different RNG architecture and different codebases.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
Darker45
Legendary

Activity: 3388
Merit: 2129
|
 |
Today at 05:09:39 AM |
|
~snip~
I think this is a bit of an overreaction... I agree. We shouldn't lump everything together and assume that hardware wallets in general are over hyped... Uh-uh. To me, this is justified, especially because we're talking of Bitcoin--an asset that beats inflation, intergenerational, to be hodled long-term, and so on. People all over the world are risking so much on Bitcoin. And this isn't just a wallet issue; it's a hardware wallet issue, and not just a hardware wallet but one that's Bitcoin-only that even respected legendaries here found to be reliable. Ledger used to be highly recommended by many OGs here. Alas, it proved to be wrong. Here comes an alternative. Coldcard was also loved by some respected members. And now, we're here. Is it, therefore, hasty to generalize that the rest are also trustworthy until they aren't? This issue right now has pushed me to try manually generating my own seed phrase. Not being techy, I need to learn a lot. Perhaps this is the best way forward for now. Of course, passphrase helps. That's another security layer. Additionally, perhaps diversifying your Bitcoin into different storage has become a must. Nobody knows which hardware wallet is next to bite the dust.
|
|
|
|
omenswap
Copper Member
Newbie

Activity: 14
Merit: 1
omenswap.com
|
 |
Today at 05:26:17 AM |
|
~snip~
I think this is a bit of an overreaction... I agree. We shouldn't lump everything together and assume that hardware wallets in general are over hyped... Uh-uh. To me, this is justified, especially because we're talking of Bitcoin--an asset that beats inflation, intergenerational, to be hodled long-term, and so on. People all over the world are risking so much on Bitcoin. And this isn't just a wallet issue; it's a hardware wallet issue, and not just a hardware wallet but one that's Bitcoin-only that even respected legendaries here found to be reliable. Ledger used to be highly recommended by many OGs here. Alas, it proved to be wrong. Here comes an alternative. Coldcard was also loved by some respected members. And now, we're here. Is it, therefore, hasty to generalize that the rest are also trustworthy until they aren't? This issue right now has pushed me to try manually generating my own seed phrase. Not being techy, I need to learn a lot. Perhaps this is the best way forward for now. Of course, passphrase helps. That's another security layer. Additionally, perhaps diversifying your Bitcoin into different storage has become a must. Nobody knows which hardware wallet is next to bite the dust. It depends on how you use Bitcoin. If you plan to use it like burying gold bars in your yard pending the collapse of society/pure long term investment, then generating a seed manually and keeping on some physical medium is a good plan. But if you actually use Bitcoin like money (how it is intended to be used), then this becomes super cumbersome. The whole idea of a hardware wallet is to allow for convenient transfers without needing to expose your keys to an internet connected computer. A hardware wallet is essentially just a secure, airgapped computer that contains your seed, encrypted at rest, and exposes an interface for signing transactions.
|
|
|
|
|
|