Bitcoin Forum
August 16, 2026, 07:19:04 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bitcoin wallet seed phrase with an optional (extended) passphrase  (Read 261 times)
UchihaSarada (OP)
Full Member
***
Offline

Activity: 938
Merit: 204


View Profile
August 04, 2026, 03:37:20 AM
Last edit: August 11, 2026, 09:50:08 AM by UchihaSarada
 #1

This hack is a first time ever hardware wallet hack at this scale.
Large-scale Coldcard compromise (1360.23 BTC stolen so far)
Technical details and some reported cases before and after this hardware wallet hack.
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
https://blog.coinkite.com/entropy-technical-backgrounder/
Cracking Unsafe Bitcoin Wallets + Coldcard Mk4 Warning (Insecure Dice Based Seeds & Private Keys)
https://www.reddit.com/r/Bitcoin/s/NJXFF7hI0a
https://x.com/Zenul_Abidin/status/2083756420843839872

In Bitcoin, there are two main ways of storing your coins, with hot wallets and cold wallets. Cold wallets are best like hardware wallets and Coldcard is a hardware wallet. Wallets beyond hot and cold, are also classified as open-source and close source. Security advice is prioritizing open-source wallets over close-source wallets but it does not make a bad hardware open-source wallet is secure.

Wallet seed phrases need to be created in a secure way and the hack on Coldcard wallet is because of their manufacturer broke this security principle, and ignored warnings from community in recent years.

The most common reminder is "Not your keys, not your coins" but it's not enough as we all saw with Coldcard hardware wallet hack since days ago. It's still a good time to remind people about this, again but it's worth to do so.
Reminder: do not keep your money in online accounts.
Bitcoin Q&A: Not your keys, not your coins.
Wallet: DOs and DON'Ts.

From Coldcard hack, the importance of passphrase (extended custom phrase/ words) is known more and it's time to dive into it for learning before applying it for your Bitcoin wallet creation, backup, and storage.

Before diving into it, there is another reminder. Firstly read below.
IMPORTANT UPDATE: We just had our first confirmed loss of a Mk3 + 2 Word Passphrase.

Drained at 2pm Aug 2nd Australia Time - Roughly 17hrs ago.

-- @BTCsessions
That post means only a passphrase is not enough to secure your wallet if the wallet seed phrase was created too weakly for example by Coldcard. You can read this test and report from Jameson Lopp to understand further about it.
How many Bitcoin seed phrases are only one repeated word?
Clearly nobody will use such Bitcoin wallet seed phrases but I want to use it for reminding that with such weak wallets, if you add any passphrase (extended/ custom words), it won't be too much helpful because it won't repair weak wallet seed phrase that was created with not enough dice rolls for strong entropy like 128 bits or 256 bits.

What is entropy and how does Trezor generate your wallet?
Generating entropy.


|
Entropy
|
Checksum (bits)
|
Entropy + checksum (bits)
|
Recovery code words
|
|128|4|132|12|
|160|5|165|15|
|192|6|198|18|
|224|7|231|21|
|256|8|264|24|

How many dice rolls or coin flips are enough for entropy?
Dice roll to Bitcoin seed - Convert Dice Entropy to BIP-39 Mnemonic


|
Mode
|
Bits/ roll
|
12 words (128 bit)
|
24 words (256 bit)
|
|Base-6 dice (1-6)|2.585|50 rolls|100 rolls|
|Base-10 dice (0-9)|3.322|39 rolls|78 rolls|
|Coin flip (0/1)|1|128 rolls|256 rolls|

A wallet seed creation method used by NotATether
How to use dice and a Seedsigner to make a seed phrase (with pictures).



What is a wallet passphrase?
Passphrase
What does a Bitcoin wallet passphrase do?

When you add a passphrase, even with only one word, it will create a new tree of keys, that is unique and different than an initial wallet created by only wallet seed phrase. This means of security improvement but if you lose the optional passphrase, you can not recover your wallet.

If you decide to create and use a wallet with wallet seed phrase + an optional passphrase, you must keep both as your wallet backups. Losing one of these two parts will cause completely loss of your wallet and any fund in it.

With this importance of passphrase, you must store it somewhere different than where you store your wallet seed phrase. It must be never online storage/ backup while memory can be used with some possible drawbacks similarly to how it is not recommended to remember your wallet seed phrase by memory.
How to back up a wallet?
Quote
What about memorizing your backups? Well, I can only think of one situation in which I'd ever consider that - if I'm fleeing from some calamity without much time to prepare and I'm worried about physical attackers accosting me during the journey or at border crossings. That is to say - I only think memorization is a good strategy for temporary emergency use. As a long term storage strategy it creates single points of failure:

    You may forget the seed phrase.
    You could be injured and unable to recall it.
    You could die and your heirs would be unable to access it.
    You could have seed phrase coerced out of you.

Applying same steps in the article above for your wallet backups with / without a passphrase.
Create a wallet
Make its backup
Test its backup
Fund a wallet with small deposit
Test the backup for recovery
Use it when everything confirmed accurately.

It's about practice, for more technical details, you can read with
https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc
https://learnmeabitcoin.com/beginners/security/#passphrase
https://bitcoinsecurity.org/guide/passphrase/

Another advantage of wallet with passphrase
You can create your decoy/ duress wallet to fool hackers
Quote
   On the positive, if someone obtains your recovery code (but not your passphrase), they will see a valid BIP32 tree of keys. If you prepared for that contingency and sent some bitcoins to the nonpassphrase tree, they will steal that money. Although having some of your bitcoins stolen is normally a bad thing, it can also provide you with a warning that your recovery code has been compromised, allowing you to investigate and take corrective measures. The ability to create multiple passphrases for the same recovery code that all look valid is a type of plausible deniability.

    On the negative, if you’re coerced to give an attacker a recovery code (with or without a passphrase) and it doesn’t yield the amount of bitcoins they expected, they may continue trying to coerce you until you give them a different passphrase with access to more bitcoins. Designing for plausible deniability means there’s no way to prove to an attacker that you’ve revealed all of your information, so they may continue trying to coerce you even after you’ve given them all of your bitcoins.

    An additional negative is the reduced amount of error detection. If you enter a slightly wrong passphrase when restoring from a backup, your wallet can’t warn you about the mistake. If you were expecting a balance, you will know something is wrong when your wallet application shows you a zero balance for the regenerated key tree. However, novice users may think their money was permanently lost and do something foolish, such as give up and throw away their recovery code. Or, if you were actually expecting a zero balance, you might use the wallet application for years after your mistake until the next time you restore with the correct passphrase and see a zero balance. Unless you can figure out what typo you previously made, your funds are gone.

Lopp also writes about it
Can duress wallets stop Bitcoin attacks?

Which passphrases to use and how to have a strong one?

Two articles can help you.
Bitcoin / Crypto Wallet Passphrase — How to Generate a Strong Extra Passphrase
How Many Words Should a Passphrase Have? (Entropy Bits Explained)

First let's check the entropy table
The table is for passphrase generated from 2048-word list of BIP-39.

|
Words
|
Bits of entropy
|
Possible combinations
|
Threat resistance
|
|3|33|8.6 billion|Hours (modern GPU)|
|4|44|17.6 trillion|Months|
|5|55|36 quadrillion|Decades|
|6|66|73 quintillion|Millennia|
|7|77|149 sextillion|Effectivelly forever (today)|
|8|88|303 septillion|Effectively forever|
|9|99|617 octillion|Effectively forever|
|10|110|1.3 nonillion|Effectively forever|

There are more details and recommendations for account passphrases here, but in this topic, the main discussion is about wallet passphrase, so let's move on.

How strong should the passphrase be?

|
Use case
|
Recommended length
|
Bits of entropy
|
|Small holdins (<$1k)|5-6 words|55-66|
|Medium holdings ($1k - $100k)|6-7 words|66-77|
|Large holdings ($100k+)|7-8 words|77-88|
|Whale / institutional|8-10 words|88-110|

Now, let's move to a hard part of backing up your wallet passphrase. A wallet passphrase is as important as your wallet seed phrase, so backing up these parts of your wallet is similar. When you need to recover your wallet, you will need both parts correctly.

You can read this article How to back up a seed phrase?

|
Backup method
|
Pros
|
Cons
|
Recommended for
|
|Memorize only|No physical artifact to steal|Risk of forgetting|Small holdings|
|Steel plate|Survives fire and water|Visible if found|Medium - large holdings|
|Paper in safe|Cheap, hidden|Vulnerable to fire/ flood|Backup of backup|
|Split (Shamir/ SLIP-39)|Distributed risk|Setup complexity|Whales, institutions|
UchihaSarada (OP)
Full Member
***
Offline

Activity: 938
Merit: 204


View Profile
August 11, 2026, 09:49:18 AM
 #2

I updated the topic, any ideas?
Charles-Tim
Legendary
*
Offline

Activity: 2366
Merit: 6496


Leading Crypto Sports Betting & Casino Platform


View Profile
August 11, 2026, 10:04:54 AM
 #3

Before diving into it, there is another reminder. Firstly read below.
IMPORTANT UPDATE: We just had our first confirmed loss of a Mk3 + 2 Word Passphrase.

Drained at 2pm Aug 2nd Australia Time - Roughly 17hrs ago.

-- @BTCsessions
That post means only a passphrase is not enough to secure your wallet if the wallet seed phrase was created too weakly for example by Coldcard. You can read this test and report from Jameson Lopp to understand further about it.
How many Bitcoin seed phrases are only one repeated word?
Clearly nobody will use such Bitcoin wallet seed phrases but I want to use it for reminding that with such weak wallets, if you add any passphrase (extended/ custom words), it won't be too much helpful because it won't repair weak wallet seed phrase that was created with not enough dice rolls for strong entropy like 128 bits or 256 bits.
What I see on the quote is that the passphrase is weak.

Passphrase is enough to make the hack not affect you, but the passphrase should be long. I will recommend using at least 30 characters passphrase with upper case, lower case, numbers and other characters added to it.

Backup the passphrase offline in two or three different locations from the seed phrase.

2 word passphrase which I think are even guessable words can be brute forced within seconds or instantly.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
UchihaSarada (OP)
Full Member
***
Offline

Activity: 938
Merit: 204


View Profile
August 13, 2026, 02:53:52 AM
 #4

IMPORTANT UPDATE: We just had our first confirmed loss of a Mk3 + 2 Word Passphrase.
What I see on the quote is that the passphrase is weak.
I did not say a passphrase with two words are strong.

2 word passphrase which I think are even guessable words can be brute forced within seconds or instantly.
There are advises in the OP, with a passphrase with 5-6 words just for a small holding.

Quote
Passphrase is enough to make the hack not affect you, but the passphrase should be long. I will recommend using at least 30 characters passphrase with upper case, lower case, numbers and other characters added to it.
A passphrase can be a word, words (chosen from a word list) or a phrase. You can use any of them, and it's not actually only possible with a phrase like a password.

Quote
Backup the passphrase offline in two or three different locations from the seed phrase.
It was in OP too, and Lopp recommended it in his guide for using Decoy/ Duress wallets without a passphrase, while your actual wallet is with a passphrase.

It's also guided in tips from learnmeabitcoin.com.
dkbit98
Legendary
*
Offline

Activity: 3052
Merit: 8812



View Profile WWW
August 13, 2026, 07:54:40 PM
 #5

I saw one guy was doing some testing with generating several passphrase on stupid c0ldcard crap devices, and they all got drained right after they were generated.
That proves that it doesn't really matter if you used optional passphrases if you had weak entropy for generation seed words.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
ultrloa
Legendary
*
Offline

Activity: 3472
Merit: 1472



View Profile WWW
August 14, 2026, 09:43:10 AM
 #6

I saw one guy was doing some testing with generating several passphrase on stupid c0ldcard crap devices, and they all got drained right after they were generated.
That proves that it doesn't really matter if you used optional passphrases if you had weak entropy for generation seed words.


Correct because those things what they have done can't be fixed by weak entropy on seed level. If they made poor seeds behind those things what they have done, there's a chance that their wallet is already compromised since start doing those actions.

The passphrase only adds protection on their wallet, but they could not really make those weak generation to a strong security.

So what I really think the true or real strong defense is to make sure their wallet is generated with high quality entropy.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
KiaKia
Hero Member
*****
Offline

Activity: 1484
Merit: 635


Rainbet


View Profile WWW
August 14, 2026, 05:32:03 PM
 #7

I think there is no point in creating a passphrase for a recovery seed that was originally generated using weak entropy, it will be best if one move their coins into a better one and then use Passphrase.

Someone should confirm is this is good, because I don't expect a ColdCard user to say because he can use passphrase he should just go with that when is recovery seed is weak.

I am actually asking this on behalf of someone who decided to tell me their plan, never knew they had ColdCard wallet until very resent, and I feel this is the right place for this question.

Pumpsta
Member
**
Offline

Activity: 95
Merit: 17


View Profile
August 14, 2026, 05:45:36 PM
 #8

I saw one guy was doing some testing with generating several passphrase on stupid c0ldcard crap devices, and they all got drained right after they were generated.
That proves that it doesn't really matter if you used optional passphrases if you had weak entropy for generation seed words.

Huh What does that mean? I made a thread on passphrases like a day before op & I genuinely thought I had it all right after all my prior research....but now I'm worried I don't have it all?! How can a rlly strong passphrase still get the btc swept?
bitmover
Legendary
*
Online Online

Activity: 3122
Merit: 7672


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 14, 2026, 05:57:52 PM
 #9

I saw one guy was doing some testing with generating several passphrase on stupid c0ldcard crap devices, and they all got drained right after they were generated.
That proves that it doesn't really matter if you used optional passphrases if you had weak entropy for generation seed words.

Huh What does that mean? I made a thread on passphrases like a day before op & I genuinely thought I had it all right after all my prior research....but now I'm worried I don't have it all?! How can a rlly strong passphrase still get the btc swept?

If you are using a compromised seed (all coldcard seeds are compromised), you passphrase would need to be really strong because that is basically your only line of defense.

Certainly not recommended.

But after this attack, we all learned that any wallet should have a strong passphrase

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Ambatman
Legendary
*
Offline

Activity: 1092
Merit: 1404


Don't tell anyone


View Profile WWW
August 14, 2026, 06:36:37 PM
Merited by bitmover (2)
 #10

This hack is a first time ever hardware wallet hack at this scale.
The hardware wallet wasn't hacked
The attacker took advantage of the flaws that created a pattern when generating seedphrase for their wallets.


|
Use case
|
Recommended length
|
Bits of entropy
|
|Small holdins (<$1k)|5-6 words|55-66|
|Medium holdings ($1k - $100k)|6-7 words|66-77|
|Large holdings ($100k+)|7-8 words|77-88|
|Whale / institutional|8-10 words|88-110|


The entropy you listed are not strong enough especially for institutional level
And the number of words means nothing if they can be easily guessed or linked.
What matter is the amount of true entropy behind them
And whether they can be link to a predictable pattern.
128bits should at least be bare minimum of genuine entropy.

bitmover
Legendary
*
Online Online

Activity: 3122
Merit: 7672


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 14, 2026, 07:17:23 PM
 #11

This hack is a first time ever hardware wallet hack at this scale.
The hardware wallet wasn't hacked
The attacker took advantage of the flaws that created a pattern when generating seedphrase for their wallets.


|
Use case
|
Recommended length
|
Bits of entropy
|
|Small holdins (<$1k)|5-6 words|55-66|
|Medium holdings ($1k - $100k)|6-7 words|66-77|
|Large holdings ($100k+)|7-8 words|77-88|
|Whale / institutional|8-10 words|88-110|


The entropy you listed are not strong enough especially for institutional level
And the number of words means nothing if they can be easily guessed or linked.
What matter is the amount of true entropy behind them
And whether they can be link to a predictable pattern.
128bits should at least be bare minimum of genuine entropy.

You are right.

The disaster of coldcard happened because the total entropy of seeds was about 40 bits.

A standard 24 words seed with decent entropy  should have 128 bits.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
avp2306
Hero Member
*****
Offline

Activity: 1820
Merit: 633


Latest promotion? Go to contesthunters.com


View Profile
August 14, 2026, 10:14:18 PM
 #12

This hack is a first time ever hardware wallet hack at this scale.
The hardware wallet wasn't hacked
The attacker took advantage of the flaws that created a pattern when generating seedphrase for their wallets.


|
Use case
|
Recommended length
|
Bits of entropy
|
|Small holdins (<$1k)|5-6 words|55-66|
|Medium holdings ($1k - $100k)|6-7 words|66-77|
|Large holdings ($100k+)|7-8 words|77-88|
|Whale / institutional|8-10 words|88-110|


The entropy you listed are not strong enough especially for institutional level
And the number of words means nothing if they can be easily guessed or linked.
What matter is the amount of true entropy behind them
And whether they can be link to a predictable pattern.
128bits should at least be bare minimum of genuine entropy.

You are right.

The disaster of coldcard happened because the total entropy of seeds was about 40 bits.

A standard 24 words seed with decent entropy  should have 128 bits.

There's major exploit already happened on Coldcard due to weak seed generation. Then now they want to repeat that incident and try to create or suggest same thing.

Definitely its good to drop some sample to refresh those people who forget about the exploit happened on that device.

Quote
The vulnerability stemmed from a March 2021 firmware issue that weakened seed generation on certain Coldcard models.

https://bitcoinmagazine.com/news/casa-ceo-nick-neuman-233k-btc-moved-to-safety-after-coldcard-exploit-proves-self-custody-resilience

So reading these news make us realize that from start Coldcard RNG is so weak, since start. So that suggestion to have 24 seed word and have 128 bits of entropy is best to make sure our wallet is more secured.

███████▄▄▀▀▀▀▀▄▄▄▄██████▄▄▀▀████▀▀▄▄
████▄▄▀▄▄████▄██▄▄▄█████▀▀▀▀█████
██▄▀▄▄██▀▀███▄▀██████▀▄▄██████▄██▄█
▄█▄▄▀▀████▄▄▀███████▄██████████▌████
█▀██▀▀▀▀███▄▄██████▐██████████████
▐▌█████▄▄▀█▀▀█████████████████▌███
█████▀▀▐▌████████▐█████████▀
██████████████████▄████████▀▄███▄▀
███████▄▄█████▄▀██▀▀▀▀▀███▀████▀
████▀▄▄▄▄▀▀███▄▄▄▀▄██▄▄▄▄███▄▄▀▀█▀▄█
█████████▀▀▀▀▀▀████▀▀████▀▀▀▄▄▄▀▄█▀
██▄▄▀▀▀▀▀▀██████▄▄▄██▀▀▀▀▀▀▀▄▄▄██▀
▄▀█████████████▀▀▀███████████▀▀▀
████
██
██
██
██
██
██
██
██
██
██
██
████
 

🛡️

📱
 
INSTANT TRANSACTIONS
SECURE & TRUSTWORTHY
24/7 ENTERTAINMENTS
PLAY ON ANY DEVICE
████
██
██
██
██
██
██
██
██
██
██
██
████
██
██
██
██
██
██
██
██
██
██
██
██
██
 
 $20 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
  PLAY NOW  
Lucius
Legendary
*
Offline

Activity: 4060
Merit: 7719



View Profile WWW
August 15, 2026, 01:16:23 PM
 #13

Huh What does that mean? I made a thread on passphrases like a day before op & I genuinely thought I had it all right after all my prior research....but now I'm worried I don't have it all?! How can a rlly strong passphrase still get the btc swept?

If someone adds a weak/easy to brute force passphrase then it is logical that hackers will be able to hack such a wallet, but if you look at the example password I generated of only 13 characters you will see that there is no chance that any hacker will be able to hack such a protected wallet.


Code:
https://www.passwordstrength.io/

Unless there is an even more significant flaw in coldwallet, I really don't know how it would be possible to hack a wallet with a strong passphrase.

Dogedegen
Sr. Member
****
Offline

Activity: 476
Merit: 278



View Profile
August 15, 2026, 05:42:35 PM
 #14

Huh What does that mean? I made a thread on passphrases like a day before op & I genuinely thought I had it all right after all my prior research....but now I'm worried I don't have it all?! How can a rlly strong passphrase still get the btc swept?

If someone adds a weak/easy to brute force passphrase then it is logical that hackers will be able to hack such a wallet, but if you look at the example password I generated of only 13 characters you will see that there is no chance that any hacker will be able to hack such a protected wallet.


Code:
https://www.passwordstrength.io/

Unless there is an even more significant flaw in coldwallet, I really don't know how it would be possible to hack a wallet with a strong passphrase.
What also people forget is that the passphrase does not need to be that strong for this, you don't need to create a passphrase that is years or decades resistant to brute force attacks. We are talking about a particular case of compromise that happened recently. People should avoid completely insecure ones like 123456 or password but other than that medium security is good enough for this attack vector. If we ever have a compromise of a hardware wallet like with Coldcard, a decent passphrase will be enough. Let's assume there are 1 million users affected, now the attackers have 1 million seeds. Attacking 1 million seeds with brute force attacks is much much harder than it is to attack a single user with brute force attack because the search space is a million times larger.

All the passphrase needs to do is provide you with enough time to react, it does not need to be something that takes 1000 years to crack. Having extremely complicated passphrases increases the chance of human error and at some point the balance of security gain is outweighed by the increase in the likelihood of a catastrophic error because of the complexity of the passphrase.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Antotena
Hero Member
*****
Offline

Activity: 1176
Merit: 607



View Profile
August 15, 2026, 08:58:31 PM
 #15

All the passphrase needs to do is provide you with enough time to react, it does not need to be something that takes 1000 years to crack. Having extremely complicated passphrases increases the chance of human error and at some point the balance of security gain is outweighed by the increase in the likelihood of a catastrophic error because of the complexity of the passphrase.

I don't think it's advisable to tell somebody not to use passphrase that will takes 1000 years to crack. If I can remember a password that is going to be simple and will take 1000 years before they brute force it, it's even impossible to brute force regular 24 seed word if it's well generated, if you now include pass phrase, it will takes billions of billions of years before they brute force that seed phrase, theoretically it's impossible to brute force.

A seed phrase with passphrase are better reimport after backup to test if the generated wallet is the real wallet. It absolutely make no sesnee to generate a wallet with passphrase and not test of the wallet is what you have with the passphrase or it's another one entirely. This has been the usual way to test passphrase with a seed phrase before you fund it with Bitcoin.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
PrivacyG
Legendary
*
Offline

Activity: 1610
Merit: 2950


Fight for Privacy.


View Profile
August 15, 2026, 10:57:40 PM
 #16

People should avoid completely insecure ones like 123456 or password but other than that medium security is good enough for this attack vector. If we ever have a compromise of a hardware wallet like with Coldcard, a decent passphrase will be enough. Let's assume there are 1 million users affected, now the attackers have 1 million seeds. Attacking 1 million seeds with brute force attacks is much much harder than it is to attack a single user with brute force attack because the search space is a million times larger.
And if you end up being the first Seed to brute force, good luck with your unsecure Pass phrase because it IS going to be emptied out.

This would definitely NOT be a moment I would like to be the 'lucky one in a million'.  I would advise you not to risk that either.  Keep in mind.  Many attackers will try this out at the same time, not only a single one.  This means the chance to be between the first few in line is a lot higher now.  What you are explaining only works well for the people at the end of the line.  The first ones with a weak Pass phrase would be screwed really fast.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Lucius
Legendary
*
Offline

Activity: 4060
Merit: 7719



View Profile WWW
Today at 12:41:54 PM
 #17

~snip~
All the passphrase needs to do is provide you with enough time to react, it does not need to be something that takes 1000 years to crack. Having extremely complicated passphrases increases the chance of human error and at some point the balance of security gain is outweighed by the increase in the likelihood of a catastrophic error because of the complexity of the passphrase.


Personally, I don't have a hard time entering a password that's about 15 characters long, especially if I use the keyboard on the device itself. I don't think you should overdo it and set passphrases of 30+ characters, but more than 10 should be the minimum, of course if it involves randomly selected numbers, lowercase and uppercase letters, and special characters.

If you save your backup properly and if you are careful while doing something, then you don't need to worry if you enter the wrong passphrase, you can simply try again. I would definitely not advise people to try to remember such things, and probably for that reason they choose shorter and simpler passwords.

Dogedegen
Sr. Member
****
Offline

Activity: 476
Merit: 278



View Profile
Today at 05:33:49 PM
 #18

I don't think it's advisable to tell somebody not to use passphrase that will takes 1000 years to crack. If I can remember a password that is going to be simple and will take 1000 years before they brute force it, it's even impossible to brute force regular 24 seed word if it's well generated, if you now include pass phrase, it will takes billions of billions of years before they brute force that seed phrase, theoretically it's impossible to brute force.

A seed phrase with passphrase are better reimport after backup to test if the generated wallet is the real wallet. It absolutely make no sesnee to generate a wallet with passphrase and not test of the wallet is what you have with the passphrase or it's another one entirely. This has been the usual way to test passphrase with a seed phrase before you fund it with Bitcoin.
You didn't understand my post at all so there is nothing that I can reply to this..

People should avoid completely insecure ones like 123456 or password but other than that medium security is good enough for this attack vector. If we ever have a compromise of a hardware wallet like with Coldcard, a decent passphrase will be enough. Let's assume there are 1 million users affected, now the attackers have 1 million seeds. Attacking 1 million seeds with brute force attacks is much much harder than it is to attack a single user with brute force attack because the search space is a million times larger.
And if you end up being the first Seed to brute force, good luck with your unsecure Pass phrase because it IS going to be emptied out.

This would definitely NOT be a moment I would like to be the 'lucky one in a million'.  I would advise you not to risk that either.  Keep in mind.  Many attackers will try this out at the same time, not only a single one.  This means the chance to be between the first few in line is a lot higher now.  What you are explaining only works well for the people at the end of the line.  The first ones with a weak Pass phrase would be screwed really fast.
Can you see the underlined parts of my post please? I did not say insecure passphrase, I was talking about medium security passphrases which can't be considered insecure. An attacker that has just gained access to a million seed phrases that are actively used is not going to sit around for months or years in the hopes that he brute forces another wallet from the seed phrases since he can not know that there exists a passphrase. There is a big difference between phrases that take years or hundreds or even thousands of years to get cracked and an completely insecure passphrase.

I would bet everything I own that even a passphrase that only provides brute force protection for a year or two which we could consider maybe a weak but secure passphrase would be enough for any attack of this kind that will happen. You forget that the attacker does not know from which seed phrase is also used with a passphrase, because this is not possible to know. Also I forgot to say that if the attacker is going to do brute force attacks at all, then he will not only have to brute force 1 million seed phrases that have balances but he would have to brute force every seed phrase that can be generated by the wallet or software which is a much bigger number so wallets that do not have balances.

People need balanced risk management and not suggestions of extremes, more people have lost complex passphrases or complicated backups than people that have been compromised because of a dual loss both of seed phrase and passphrase. Let's say that the total pool of generated entropy seeds is 1 billion and out of that 1 million have balances. You really want to suggest that an attacker will start brute forcing 1 billion seed phrases hoping that he gets extra lucky with some of them while sitting on big loot maybe $10 or $100 million or more while there is a risk that someone figures out the bug? You must place yourself in the mind of an attacker, this is most likely never going to happen.

quote]

Personally, I don't have a hard time entering a password that's about 15 characters long, especially if I use the keyboard on the device itself. I don't think you should overdo it and set passphrases of 30+ characters, but more than 10 should be the minimum, of course if it involves randomly selected numbers, lowercase and uppercase letters, and special characters.

If you save your backup properly and if you are careful while doing something, then you don't need to worry if you enter the wrong passphrase, you can simply try again. I would definitely not advise people to try to remember such things, and probably for that reason they choose shorter and simpler passwords.
Yeah that would be about the range that I think is enough. Remembering is not good at all, but sometimes people get lazy and create their backups without checking things and that can also lead to problems.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!