Bitcoin Forum
September 06, 2026, 05:25:01 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: Bitcoin wallet seed phrase with an optional (extended) passphrase  (Read 704 times)
DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1148
Merit: 723


Let love lead


View Profile WWW
September 02, 2026, 06:51:29 PM
 #41

Let's say you have a two-digit number of BTC in your wallet, would it be excessive to protect them with a passphrase of more than 20 characters? Of course, it would not be excessive, but it would also not make sense for me to use any hardware device, but I would only use an old laptop in airgapped mode, on which I would generate a seed that would be additionally protected with an extra strong passphrase.

Yes, most people are very lazy and think that nothing bad can happen to them, and that was the case with coldcard - when you least expect it, something very bad happens.
If a person is talking about the security side in relation to the value like you are, then yes it is not excessive. But security is not linear like that, a longer passphrase increases complexity and risk of a failed backup.

Reimport the seedphrase + pass phrase in another offline wallet or instance of the wallet(if you use desktop) and confirm the addresses before backing up  safely offline, complexity should not be the excuse to let your guard down, complexity is good in having a pass phrase so it is much harder to bruteforce. It would interest you to know that 1,2 and 3 word passphrases wallets were swept as well in the recent coldcard hack.
Quote
The passphrase length should be long enough to provide good security,
In your own terms, how long should it be?

Quote
but also related to the value that is being protected and be reasonable in the total length to avoid creating other issues.
There is no relationship between these, this statement is pointless.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
Charles-Tim
Legendary
*
Offline

Activity: 2394
Merit: 6533


Leading Crypto Sports Betting & Casino Platform


View Profile
September 02, 2026, 07:16:43 PM
 #42

In your own terms, how long should it be?
Lucius has given a perfect answer about this on the first page of this thread.

This is his post about it: https://bitcointalk.org/index.php?topic=5590296.msg67046733#msg67046733

How long it should be would be about if only it is having only alphabets which means it has to be very long. Hard numbers to it to make it shorter to retain the excellent security. Add upper case and other characters to it to make it shorter and still have excellent security.

You will need a tool to have idea about it and I think the one given by Lucius will be helpful.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1148
Merit: 723


Let love lead


View Profile WWW
September 02, 2026, 07:55:39 PM
 #43

In your own terms, how long should it be?
Lucius has given a perfect answer about this on the first page of this thread.

This is his post about it: https://bitcointalk.org/index.php?topic=5590296.msg67046733#msg67046733.
Yeah Charlie, I've read this thread thoroughly, and I agree to it, but it feels the user I quoted is having a hard time recognizing that. I only wanted to evaluate the extent to which he's misinformed about the correct use of a passphrase. A passphrase should be made as hard as possible just like you and Lucius explained, else the aim of having it is defeated.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
Lucius
Legendary
*
Offline

Activity: 4088
Merit: 7764


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 03, 2026, 02:04:50 PM
 #44

@Charles-Tim & @DubemIfedigbo001, I honestly don't know is the password strength assessment based on the current capabilities of a computers/supercomputers, or do they take into account quantum computers as well? One obviously advanced user in the coldcard hack thread says he has a passphrase of as much as 50 characters, so while there's no doubt that such a passphrase definitely has better protection than one of 15 or 20 characters, I still wonder if quantum computers with the help of artificial intelligence will one day be able to hack such passphrases?

Anyway, I think everyone should take into account that hackers today have far better tools than they did 5-10 years ago, and that they will have even better ones in the future. The only way to outsmart them is to be at least one step ahead of them - which means we should always strive to improve our setup no matter how good it is.

DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1148
Merit: 723


Let love lead


View Profile WWW
September 03, 2026, 03:18:02 PM
Last edit: September 03, 2026, 03:46:57 PM by DubemIfedigbo001
Merited by Lucius (1)
 #45

One obviously advanced user in the coldcard hack thread says he has a passphrase of as much as 50 characters, so while there's no doubt that such a passphrase definitely has better protection than one of 15 or 20 characters
You know, the strength of these passphrases is not only in it's number, but in its composition and we cannot tell the composition of the 50 characters. If the person has the 50 characters as only letters, then it is less secure than someone who has 20 characters but comprises of 8 letters, 4 numbers and 8 special characters arranged randomly.

Again if for example, the 50 characters is comprising of a good mixture of 10 uppercase letters, 10 lowercase letters, 15 numbers and 15 special characters, then it would really take a long time to get it cracked.

Bearing in mind that there are 10 possible numbers, 26 possible characters for both upper case and lower case letters and let's say 32 common special characters, then applying multinomial coefficient with this formula of n!/n1!n2!n3!....nk!, we could be looking at approximately 217 bits of entropy for the passphrase, that's no child joke to crack, the only thing I believe that may have a chance is quantum computing and they're still far-fetched and it would be harder since the length and buildup of the passphrase is not known.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
Dogedegen
Sr. Member
****
Offline

Activity: 504
Merit: 282



View Profile
September 04, 2026, 03:42:34 AM
Last edit: September 04, 2026, 04:03:35 AM by Dogedegen
 #46

Reimport the seedphrase + pass phrase in another offline wallet or instance of the wallet(if you use desktop) and confirm the addresses before backing up  safely offline, complexity should not be the excuse to let your guard down, complexity is good in having a pass phrase so it is much harder to bruteforce. It would interest you to know that 1,2 and 3 word passphrases wallets were swept as well in the recent coldcard hack.
It is not an excuse, you need to understand how reasonable security works and that is the best practice. Complex security solutions have created many more losses than short pass phrases. If your wallet is exposed to the point that someone is currently able to brute force it, then the issue is not of the passphrase length. The wallet is already compromised it is just a matter of time, it should be changed right away so the passphrase only provides some buffer of time. Multi word passphrases are not a counter point here because we don't have proof of their complexity. It could be something very simple consisting of 3 lowercase words from a dictionary.

Quote
The passphrase length should be long enough to provide good security,
In your own terms, how long should it be?
15 to 20 characters should be enough right now if it is covering all characters, lower case, upper case, numbers and symbols. Don't forget that passphrase is adding entropy to protect exposed seed phrases, but if your seed phrase is not exposed then even a short passphrase is not an issue.

Quote
but also related to the value that is being protected and be reasonable in the total length to avoid creating other issues.
There is no relationship between these, this statement is pointless.
Yes there is, ask ChatGPT if you are not familiar with security best practices. The amount of resources and complexity that is supposed to be invested into cyber security is directly related to the value that you are protecting. An extreme example would be to put a 100 character seed phrase to protect $100 of Bitcoin, and this setup would be wrong.

@Charles-Tim & @DubemIfedigbo001, I honestly don't know is the password strength assessment based on the current capabilities of a computers/supercomputers, or do they take into account quantum computers as well? One obviously advanced user in the coldcard hack thread says he has a passphrase of as much as 50 characters, so while there's no doubt that such a passphrase definitely has better protection than one of 15 or 20 characters, I still wonder if quantum computers with the help of artificial intelligence will one day be able to hack such passphrases?
As long as it is sufficiently long and random, then quantum computers will not be able to crack a 50 character passphrase in any reasonable time. Nobody is going to throw that amount of investment capital and running expenses to crack a wallet that may have very little value in it. How many characters is safe is always a moving target, it is not related to AI or quantum computers at all. Those just speed up how fast the target is moving. Nobody should be using the same passphrase and wallet for very long periods of times if we are talking about decades.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1148
Merit: 723


Let love lead


View Profile WWW
September 04, 2026, 12:45:54 PM
Last edit: September 04, 2026, 02:16:01 PM by DubemIfedigbo001
 #47

Reimport the seedphrase + pass phrase in another offline wallet or instance of the wallet(if you use desktop) and confirm the addresses before backing up  safely offline, complexity should not be the excuse to let your guard down, complexity is good in having a pass phrase so it is much harder to bruteforce. It would interest you to know that 1,2 and 3 word passphrases wallets were swept as well in the recent coldcard hack.
It is not an excuse, you need to understand how reasonable security works and that is the best practice. Complex security solutions have created many more losses than short pass phrases.
I fail to understand your definition of complexity, using longer and better passphrases is no complexity at all, it's only having a stronger character combination using the same process. Is it that difficult to comprehend?

Quote
If your wallet is exposed to the point that someone is currently able to brute force it,
How can your wallet be exposed and still someone has to brute-force it? If your wallet is accesses by a third party, then they only need to retrieve the seed phrase and passphrase from the wallet itself, no need for any extra work


Quote
Multi word passphrases are not a counter point here because we don't have proof of their complexity.
Here is the proof, read it clearly and since you can use ChatGPT, verify how secure this setup is compared to your 3 word weaker pass phrase, maybe you could learn something Wink
Again if for example, the 50 characters is comprising of a good mixture of 10 uppercase letters, 10 lowercase letters, 15 numbers and 15 special characters, then it would really take a long time to get it cracked.

Bearing in mind that there are 10 possible numbers, 26 possible characters for both upper case and lower case letters and let's say 32 common special characters, then applying multinomial coefficient with this formula of n!/n1!n2!n3!....nk!, we could be looking at approximately 217 bits of entropy for the passphrase, that's no child joke to crack, the only thing I believe that may have a chance is quantum computing and they're still far-fetched and it would be harder since the length and buildup of the passphrase is not known.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!