Bitcoin Forum
August 12, 2026, 06:57:55 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: coldcard issue  (Read 179 times)
Hasslong (OP)
Newbie
*
Offline

Activity: 25
Merit: 24


View Profile
August 01, 2026, 07:14:12 PM
 #1

do electrum is in safe , entropy is ok , iam really concerning
what difference between entropy on coldcard , and electrum
Mia Chloe
Legendary
*
Offline

Activity: 1162
Merit: 2275


Contact me for your designs...


View Profile
August 01, 2026, 07:20:34 PM
 #2

do electrum is in safe , entropy is ok , iam really concerning
what difference between entropy on coldcard , and electrum
Entropy is basically randomness. In wallets and seed generation we use the word entropy to define how random your seed phrase actually is because the more random it is the harder it becomes to brute force or guess and the less random it is the easier it is to guess or brute force too.

As for ELECTRUM, it's his a wallet software and what kinda makes it stand out is it has it's own default seed dictionary slightly different from your regular BIP39. Lastly, Cold cards are a form of hardware storage.

Charles-Tim
Legendary
*
Offline

Activity: 2366
Merit: 6485


Leading Crypto Sports Betting & Casino Platform


View Profile
August 01, 2026, 07:32:48 PM
 #3

As of now, the way Electrum generates seed phrase is safe. But if you are really not feeling secure with your coins on addresses generated on Electrum wallet, just create new wallet or wallets on Electrum with extended word (passphrase) and send your coins to the addresses of the newly generated wallet or wallets so that even if such Coldcard attack happen to Electrum users, your coins will still be safe.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1633



View Profile
August 01, 2026, 07:46:47 PM
 #4

Electrum itself is safe.  It is only unsafe if your Electrum wallet is just software layer for a coldcard hardware wallet OR if your seed phrase is generated on a coldcard hw, seedphrase which you imported into Electrum (and if so that depends on coldcard firmware at the time it was generated.) 

Theoretically, any software wallet or hardware device that generates seed phrases using a pseudo-random number generator (PRNG) could theoretically have an entropy bug in it.  But honestly this is really extremely unlikely if a piece of widely popular software like Electrum with a lot of ppl looking at the code would get such a problem.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
EL MOHA
Hero Member
*****
Offline

Activity: 1232
Merit: 503



View Profile
August 01, 2026, 08:03:39 PM
 #5

do electrum is in safe , entropy is ok , iam really concerning
what difference between entropy on coldcard , and electrum

I think your question is difference between the entropy for electrum and the affected entropy on cold card, the simple answer is randomness, the cold card which is an hardware wallet actually uses an hardware wallet random number generator (RNG) which the affected cold card wallets had entropy of 40 bits or 72 bits and this was considerably low because the standard for Bip-39 wallets is actually 128 bits entropy for 12 seed phrase and 256 bits for 24 words seed phrase, the 128 bits is considered save because private keys are also 128 bits entropy.

Electrum then uses your device operating system for random number generation (CSPRNG) that’s why it’s actually best to generate it in an offline environment. Electrum entropy is actually 132 which is safe and far higher than that of coldcard which is 40 bits or 72 bits

BitMaxz
Legendary
*
Offline

Activity: 4074
Merit: 3662


♻️ Automatic Exchange


View Profile WWW
August 01, 2026, 08:12:12 PM
 #6

As of now I have never experienced any issue yet on using Electrum, but Coldcard and Electrum have different ways to generate their seed phrase.

Electrum seed generation is based on CSPRNG, while Coldcard is based on a secure element TRNG, meaning they have different algorithms used to generate seeds.

You might be concerned about the trending news recently about ColdCard? I suggest try Electrum in cold storage; it is way safer than using hardware wallets like Coldcard if you make sure you will never connect it online.

If you look more about CSPRNG and TRNG, check this comparison between them

- https://crypto.stackexchange.com/questions/63555/what-is-the-difference-between-trng-and-csprng

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8972


Self-proclaimed Genius


View Profile
August 02, 2026, 05:24:42 AM
Merited by ABCbits (3)
 #7

do electrum is in safe , entropy is ok , iam really concerning
As far as I can tell, there's no issue in Electrum's seed phrase generation code below; Coldcard's firmware code had.
Link: github.com/spesmilo/electrum/blob/ebe20010111f00dad2d8bd52ac2a6030d3b26d8b/electrum/mnemonic.py#L201-L238
You might also need to get second opinion from others to make sure.

Also, its entropy is pretty strong with secrets.randbelow() method which is considered cryptographically strong.
Ref:
On a side note: future updates might introduce "extra entropy" to further "scramble" the entropy generated by the OS (in case the OS is not 100% safe)
But only if this is implemented: github.com/spesmilo/electrum/pull/8839

NotATether
Legendary
*
Offline

Activity: 2422
Merit: 10117


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 05, 2026, 06:32:15 AM
 #8

On a side note: future updates might introduce "extra entropy" to further "scramble" the entropy generated by the OS (in case the OS is not 100% safe)
But only if this is implemented: github.com/spesmilo/electrum/pull/8839

Ubuntu 20/22/24 LTS random number generator is considered as 100% safe, right?

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8972


Self-proclaimed Genius


View Profile
August 05, 2026, 06:46:22 AM
 #9

On a side note: future updates might introduce "extra entropy" to further "scramble" the entropy generated by the OS (in case the OS is not 100% safe)
But only if this is implemented: github.com/spesmilo/electrum/pull/8839
Ubuntu 20/22/24 LTS random number generator is considered as 100% safe, right?
It's hard to answer this confidently since I (or anyone) can't verify the quality of the result random number.
Also, it requires extensive research about the specific OS.

But if its os.urandom isn't flawed, then it's considered safe.

BTW, one example of application of that PR is the old Android PRNG vulnerability.
It's a precaution in case a similar unknown bug is existing in current available OS.

^BuTcH^2
Member
**
Offline

Activity: 123
Merit: 20


View Profile
August 05, 2026, 03:31:26 PM
 #10

Can I generate a seed of 24 words plus an invented passphrase in electrum?
hosemary
Legendary
*
Offline

Activity: 3220
Merit: 7187



View Profile
August 05, 2026, 08:07:05 PM
Merited by ABCbits (2), Z-tight (1), ^BuTcH^2 (1)
 #11

Can I generate a seed of 24 words plus an invented passphrase in electrum?
To generate a 24 word seed phrase in electrum, you need to use the following command in Console.

Code:
make_seed(264)

If you don't see the Console tab, click on "View" at top of the window, and check "Console".


After generating the seed phrase, create a new wallet, select "Standard Wallet" and then "I already have a seed". After that, click on "Options" and check "Extend this seed with custom words."
Enter the 24 word seed phrase you generated in console, and in the next window, enter your passphrase.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..

















































  PLAY NOW  
The Avatar:


https://i.bitlist.co/5hm3yn5b6VIk.png


Code:
@Mia Chloe
@JollyGood
@SFR10
@nc50lc
@Lucius
@babo
@Cricktor
@ABCBits
@shasan
@fillippone
@d5000
@Ambatman
@hafiztalha
@Etranger
@Forsyth Jones
@Cookdata
@Zwei
@taufik123
@m2017
@Adbitco
@AakZaki
@goldkingcoiner
@Real-Duke
@lovesmayfamilis
@hosemary
@CLS63
@famososMuertos
@JeromeTash
@promise444c5
@katanic97
@xzone
@Ale88
@Trofo
@Upgrade00
@darxiaomi
@_act_
@GeorgeJohn
@alegotardo
@Lillominato89
@Vod
Report to moderator 
 
 b1exch.to       
Mia Chloe
Legendary
*
Offline

Activity: 1162
Merit: 2275


Contact me for your designs...


View Profile
August 07, 2026, 08:33:39 PM
 #12

To generate a 24 word seed phrase in electrum, you need to use the following command in Console.
Code:
make_seed(264)
If you don't see the Console tab, click on "View" at top of the window, and check "Console".
After generating the seed phrase, create a new wallet, select "Standard Wallet" and then "I already have a seed". After that, click on "Options" and check "Extend this seed with custom words."
Enter the 24 word seed phrase you generated in console, and in the next window, enter your passphrase.
How possible is this on mobile too? Please just for courtesy sake can we normalise chipping in mobile Electrum when we generally discuss hacks and tricks on the software generally. It doesn't really matter if the mobile version can do it or not you could just leave a little clue on if it's possible it helpful trust me.

Alright back to topic, is there really much of a difference if you're using 12 words or 24 words? Both seem near equally safe to me so long the entropy is good enough.

hosemary
Legendary
*
Offline

Activity: 3220
Merit: 7187



View Profile
August 07, 2026, 11:00:12 PM
Merited by Mia Chloe (2)
 #13

How possible is this on mobile too?
The mobile version of electrum only allows generating a 12 word seed phrase. However, it allows you to import seed phrases with other lengths.
Therefore, if you want to have a wallet with a 24 word seed phrase in the mobile version of electrum, you have to generate the seed phrase using the desktop version first.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..

















































  PLAY NOW  
The Avatar:


https://i.bitlist.co/5hm3yn5b6VIk.png


Code:
@Mia Chloe
@JollyGood
@SFR10
@nc50lc
@Lucius
@babo
@Cricktor
@ABCBits
@shasan
@fillippone
@d5000
@Ambatman
@hafiztalha
@Etranger
@Forsyth Jones
@Cookdata
@Zwei
@taufik123
@m2017
@Adbitco
@AakZaki
@goldkingcoiner
@Real-Duke
@lovesmayfamilis
@hosemary
@CLS63
@famososMuertos
@JeromeTash
@promise444c5
@katanic97
@xzone
@Ale88
@Trofo
@Upgrade00
@darxiaomi
@_act_
@GeorgeJohn
@alegotardo
@Lillominato89
@Vod
Report to moderator 
 
 b1exch.to       
nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8972


Self-proclaimed Genius


View Profile
August 08, 2026, 04:40:13 AM
 #14

How possible is this on mobile too? Please just for courtesy sake can we normalise chipping in mobile Electrum when we generally discuss hacks and tricks on the software generally. It doesn't really matter if the mobile version can do it or not you could just leave a little clue on if it's possible it helpful trust me.
QML Electrum doesn't have a console but if you know how to compile an APK file;
Just edit this 1 line in mnemonic.py from num_bits = 132 to num_bits = 264
This one: /electrum/mnemonic.py#L206
Then build your Electrum android APK (guide), that'll generate 24 words by default.

Quote from: Mia Chloe
Alright back to topic, is there really much of a difference if you're using 12 words or 24 words? Both seem near equally safe to me so long the entropy is good enough.
In face value, yes that's 2048^12 vs 20248^24 or the entropy used in Electrum 2^132 vs 2^264
But 128 or 132 bits are not unsafe to use in today's standard.

Also the derived extended private key's security is basically 128-bit if the extended public key is already in the hands of the attacker.
And since it's meant to be used "publicly", a hacker can easily get their hands to it. (e.g. from your watch-only wallet)

There's also your address, most address are encoded 160-bit hash, so if an attacker wants to brute force its private key, he'll need 160-bit operations to do so.
That's still lower than a 24-word mnemonic's security.

So having a 256-bit strong mnemonic will only reduce your attack vector in case something that can break 128-bit surfaced, specifically from entropy to mnemonic.
But like I've said, 128 or 132 or 160 bits are not by any means unsafe.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!