Bitcoin Forum
August 24, 2026, 07:07:53 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Bitcoin wallet seed phrase with an optional (extended) passphrase  (Read 519 times)
joniboini
Legendary
*
Offline

Activity: 3024
Merit: 1919



View Profile WWW
August 18, 2026, 04:58:18 AM
 #21

I think the biggest take here is that fact that as much as hard wallets are open source and are cold wallets, they are not 100% safe. People like to treat them like they are very secure and can't be hacked.
I always think enthusiasts will never claim that open source software is 100% safe. If someone boldly say that, they probably don't know what they're talking about. Even the most popular software used regularly by most people, like Electrum, have been attacked through various ways. The key is how much can we verify. If the code is open source it'd be easier to check every single thing, which is why most people prefer them.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Dogedegen
Sr. Member
****
Offline

Activity: 490
Merit: 279



View Profile
August 18, 2026, 06:00:20 PM
 #22

~snip~
Yeah that would be about the range that I think is enough. Remembering is not good at all, but sometimes people get lazy and create their backups without checking things and that can also lead to problems.

Let's say you have a two-digit number of BTC in your wallet, would it be excessive to protect them with a passphrase of more than 20 characters? Of course, it would not be excessive, but it would also not make sense for me to use any hardware device, but I would only use an old laptop in airgapped mode, on which I would generate a seed that would be additionally protected with an extra strong passphrase.

Yes, most people are very lazy and think that nothing bad can happen to them, and that was the case with coldcard - when you least expect it, something very bad happens.
Well it depends also what perspective are you talking about with excessive. If a person is talking about the security side in relation to the value like you are, then yes it is not excessive. But security is not linear like that, a longer passphrase increases complexity and risk of a failed backup. There is some point after which each character added gives more risk to the user than it does the benefit, that was the point that I was trying to aim at. I do not know if literature has established this exact point, but I know that they have established this direction of the effect, This is one of the reasons why we need to be careful when we give advice to people. The passphrase length should be long enough to provide good security, but also related to the value that is being protected and be reasonable in the total length to avoid creating other issues.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Darker45
Legendary
*
Offline

Activity: 3416
Merit: 2133


Spinly.io - Next-gen Crypto iGaming Platform


View Profile
August 19, 2026, 04:22:58 AM
 #23

~snip~

Let's say you have a two-digit number of BTC in your wallet, would it be excessive to protect them with a passphrase of more than 20 characters?

I remember when I created a long passphrase with my hardware wallet, complete with small and big letter, numbers, special characters, space. My goodness, it indeed felt excessive!

I felt like my Trezor would fall apart. Imagine pushing those small fragile buttons countless of times just to finish half of it only to reenter them all over again because you're provided with a wallet with zero balance, and it's next to impossible to get it right after only a single attempt despite double-checking it.

But, yeah, I got your point. I was just reminded of the big difference between the ideal and the practical. Cheesy


░▄████████████▀▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▄██
████████████░█▀
████░▄▄▄███████
████▄▄▄▄▄▄▄▄░▄██
▀▀▀▀▀▀▀▀████░███
████████████░███
████████████░█▀

░▄████████████▀▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▄██
████████████░███
████████████░███
████████████░███
████▄▄▄▄████░██▀
████▀▀▀▀▀▀▀▀░▀
████░█▀

░▄████████████▀▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▄██
████████████░█▀
█████████░▄▄▄
█████████░███
░▄░██████░██▀██
▀▀░██████░▀██▄██
████████████░█▀

░▄███████▀░▄██▀▄
▀▀▀▀▀▀▀▀██▀▀▀▄██
████████████░███
████████████░███
██░▄░███████░███
██░█░███████░███
████████████░███
████████████░█▀

░▄██████▀▄
▀▀▀▀▀▀▀▄██
██████░███
██████░███
██████░███
██████░███████▀▄
██████░▀▀▀▀▀▀▄██
████████████░█▀

░▄████▀██▄█████▀▄
▀▀▀▀▀███▀▀▀▀▀▀▄██
█████████████░███
█████░█░█████░███
█████░▀░█████░███
█████████████░█▀
██████████░▄▄▄
██████████░█▀
 
.....  Next−Gen Crypto iGaming  .....
| 
     Play now      
Taskford
Legendary
*
Offline

Activity: 3318
Merit: 1065


A swap that needs a hand? zeto.cash@proton.me


View Profile
August 19, 2026, 02:15:15 PM
 #24

~snip~

Let's say you have a two-digit number of BTC in your wallet, would it be excessive to protect them with a passphrase of more than 20 characters?

I remember when I created a long passphrase with my hardware wallet, complete with small and big letter, numbers, special characters, space. My goodness, it indeed felt excessive!

I felt like my Trezor would fall apart. Imagine pushing those small fragile buttons countless of times just to finish half of it only to reenter them all over again because you're provided with a wallet with zero balance, and it's next to impossible to get it right after only a single attempt despite double-checking it.

But, yeah, I got your point. I was just reminded of the big difference between the ideal and the practical. Cheesy

Once of common reason on why there are people choose to use those manageable wallets and try to use strong passphrase.

Those wallet could actually handle those complex actions, but somehow the true cost of this is there are several people can't handle the changes and also the stress that might get.

So somehow a great lesson to get from them. Also best set up is the one they mentioned. but they should consider to use those things which they can able to operate then handle consistently, since its not good to look only cool in papers.


Comeacross
Full Member
***
Offline

Activity: 266
Merit: 120


Spinly.io - Next-gen Crypto iGaming Platform


View Profile
August 19, 2026, 03:02:55 PM
 #25

I saw one guy was doing some testing with generating several passphrase on stupid c0ldcard crap devices, and they all got drained right after they were generated.
That proves that it doesn't really matter if you used optional passphrases if you had weak entropy for generation seed words.

You mean you actually saw the wallet get drained right in front of him just after he generated it on the ColdCard? There's possibility the device was tempered with or probably a fake device or maybe the seed was already compromised? Perhaps, he was testing on already compromised old seeds but applying different passphrase. Of course, if your seeds were generated with a weak entropy, adding a passphrase doesn't change much and might be just useless.

notocactus
Legendary
*
Offline

Activity: 3108
Merit: 5155


Glory to Ukraine!


View Profile
August 19, 2026, 04:09:03 PM
 #26

You mean you actually saw the wallet get drained right in front of him just after he generated it on the ColdCard? There's possibility the device was tempered with or probably a fake device or maybe the seed was already compromised?
Some cases reported in 2022 and in 2026 even with 2 word passphrase - I could not find that post but it was discussed somewhere perhaps in another thread.

In 2022, a brand new Coldcard user was drained after transferring funds to it.

https://www.reddit.com/r/Bitcoin/s/NJXFF7hI0a





This definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this.

Crazy to see the sweeps just need 10 seconds after the deposit.


https://x.com/we_satoshis/status/2085034468935450918

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Monetarium
Newbie
*
Offline

Activity: 7
Merit: 7


View Profile
August 19, 2026, 05:03:40 PM
 #27

I saw one guy was doing some testing with generating several passphrase on stupid c0ldcard crap devices, and they all got drained right after they were generated.
That proves that it doesn't really matter if you used optional passphrases if you had weak entropy for generation seed words.

Huh What does that mean? I made a thread on passphrases like a day before op & I genuinely thought I had it all right after all my prior research....but now I'm worried I don't have it all?! How can a rlly strong passphrase still get the btc swept?

On the swept wallets question, one thing worth separating out: the passphrase is not a password that gets checked anywhere. In BIP39 the seed comes out of PBKDF2 with the mnemonic as the password and the string "mnemonic" plus your passphrase as the salt, so there is nothing stored to compare your input against. The BIP says it outright, that every passphrase generates a valid seed and only the correct one makes the wallet you wanted available. A typo does not throw an error, it opens a different wallet that happens to be empty.

That is also why a strong passphrase does not really answer the sweep. It covers one case, the one where someone has your seed words and not the phrase. If the entropy was bad when the seed was generated then nobody is guessing anything, the same keys get derived and the passphrase never comes into it. And 2048 iterations is not much work per candidate if it does come down to guessing, so a memorable phrase buys less than its length suggests.

Coins moving seconds after a deposit reads more like that than like a search. If someone had to brute force their way in, the timing would not be that tight.
Cookdata
Legendary
*
Offline

Activity: 1778
Merit: 1466


Not Your Keys, Not Your Bitcoin


View Profile
August 19, 2026, 09:31:59 PM
 #28

I think the biggest take here is that fact that as much as hard wallets are open source and are cold wallets, they are not 100% safe. People like to treat them like they are very secure and can't be hacked.
I always think enthusiasts will never claim that open source software is 100% safe. If someone boldly say that, they probably don't know what they're talking about. Even the most popular software used regularly by most people, like Electrum, have been attacked through various ways. The key is how much can we verify. If the code is open source it'd be easier to check every single thing, which is why most people prefer them.

An open source gives you protection, but it is limited to things that are hidden and the building components that create a project. However, being open source again does not fully protect you from what is hidden because just because it is public does not mean everyone can even verify it. Not everyone is a tech bro to run through everything on GitHub. I'm sure that if everyone knew how to verify firmware, the MK3 exploit wouldn't have happened in the first place.

Another thing is that if something is open source, you don't have to worry about the integrity of the software, but you still need to play your own part for security. Let's say you use a Trust Wallet app, and you get hack, your coins are drained, if you do everything right the first thing that will come to your mind is perhaps there is something wrong with the app that you don't know, only a closed source makes you doubt an app. An open source most often they are transparent unless something went wrong just like in the case of Coldcard firmware.

Dogedegen
Sr. Member
****
Offline

Activity: 490
Merit: 279



View Profile
August 20, 2026, 04:47:25 PM
 #29

An open source gives you protection, but it is limited to things that are hidden and the building components that create a project. However, being open source again does not fully protect you from what is hidden because just because it is public does not mean everyone can even verify it. Not everyone is a tech bro to run through everything on GitHub. I'm sure that if everyone knew how to verify firmware, the MK3 exploit wouldn't have happened in the first place.

Another thing is that if something is open source, you don't have to worry about the integrity of the software, but you still need to play your own part for security. Let's say you use a Trust Wallet app, and you get hack, your coins are drained, if you do everything right the first thing that will come to your mind is perhaps there is something wrong with the app that you don't know, only a closed source makes you doubt an app. An open source most often they are transparent unless something went wrong just like in the case of Coldcard firmware.
I think that you are mixing up a bit the concepts with small distinctions. When you talk about the word verify and process of verifying firmware, that is not the same as being able to understand or audit some big code online. When you talk about verification you are talking about making sure that the firmware on the device matches what you have downloaded or the original code. Knowing how to verify firmware or downloads would not prevent the MK3 exploit. The case of MK3 is clear, firmware verification would not prevent anything because the exploit comes from an error in the software implementation because an error made it use the wrong RNG implementation.

Teaching people to verify firmware is not that hard, we sometimes teach people to verify wallet software downloads with hashes and that. To learn that you don't need to be any kind of tech bro, it can be part of basic computer use. But to be able to read code and understand it is very hard, and to be able to find security bugs in code is even harder. So the issue that we had here is that there was a big code error that was overlooked by everyone for a long time, knowing how to verify firmware would not have prevented that.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Charles-Tim
Legendary
*
Offline

Activity: 2380
Merit: 6503


Leading Crypto Sports Betting & Casino Platform


View Profile
August 21, 2026, 12:15:24 AM
 #30

An open source gives you protection, but it is limited to things that are hidden and the building components that create a project. However, being open source again does not fully protect you from what is hidden because just because it is public does not mean everyone can even verify it.
Some developers will verify it, unlike close source wallets.

Another thing is that if something is open source, you don't have to worry about the integrity of the software, but you still need to play your own part for security. Let's say you use a Trust Wallet app, and you get hack, your coins are drained, if you do everything right the first thing that will come to your mind is perhaps there is something wrong with the app that you don't know, only a closed source makes you doubt an app. An open source most often they are transparent unless something went wrong just like in the case of Coldcard firmware.
One of the worst wallets are the ones that are reproducible but not open source. According to what many people have posted on this forum, that is the category that Coldcard fall under. It is not an open source wallet.

Many wallet developers just has way that will let people think that their wallet is completely open source. Even they fooled many places on the internet about it.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
hd49728
Legendary
*
Offline

Activity: 2926
Merit: 1375



View Profile
August 21, 2026, 02:30:37 AM
 #31

One of the worst wallets are the ones that are reproducible but not open source. According to what many people have posted on this forum, that is the category that Coldcard fall under. It is not an open source wallet.

Many wallet developers just has way that will let people think that their wallet is completely open source. Even they fooled many places on the internet about it.
Did you miss or confuse anything?

Truly open source wallets are wallets that have open source code so that other developers can verify the code and reproduce wallets from source code.
What you said is source availability but can not be reproduced, and wallets like that are not considered as open source, just source available.

You can search about Reproducible open-source wallets, and Source-Viewable wallets.
With Reproducible open-source wallets, people can reproduce wallets from open source code, and create exactly similar wallets bit-by-bit like official wallets.

Dogedegen
Sr. Member
****
Offline

Activity: 490
Merit: 279



View Profile
August 21, 2026, 06:05:09 PM
 #32

One of the worst wallets are the ones that are reproducible but not open source. According to what many people have posted on this forum, that is the category that Coldcard fall under. It is not an open source wallet.

Many wallet developers just has way that will let people think that their wallet is completely open source. Even they fooled many places on the internet about it.
Did you miss or confuse anything?

Truly open source wallets are wallets that have open source code so that other developers can verify the code and reproduce wallets from source code.
What you said is source availability but can not be reproduced, and wallets like that are not considered as open source, just source available.

You can search about Reproducible open-source wallets, and Source-Viewable wallets.
With Reproducible open-source wallets, people can reproduce wallets from open source code, and create exactly similar wallets bit-by-bit like official wallets.
Many people have been writing different things that are not true here, and many concepts have been mixed up. I don't know why they say this or that about the Coldcard thing when they don't have the correct information. In the case of this hardware they do publish the source code and now this person claims is it not open sources. If you go to Github you will see that they provide a way to reproduce their firmware and then you can also compare it to the release by the company, so in this case this had nothing to do with the hack. If you have a firmware that has a big security hole like this one had, where the random number generator was not good, then verifying hashes, reproducing the firmware and all things like that do not help at all. Those things help you confirm that the code that you have seen online or the file you downloaded is the one that you are running. But if that code has a hole, you are verifying that you have installed something with a security hole.

None of those concepts are related to the issue with Coldcard, it had a big security flaw for some versions of the firmware and that is it. Hash verification, build reproduction and other things do not help with this.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7738



View Profile WWW
August 22, 2026, 01:49:38 PM
 #33

You mean you actually saw the wallet get drained right in front of him just after he generated it on the ColdCard? There's possibility the device was tempered with or probably a fake device or maybe the seed was already compromised?
Some cases reported in 2022 and in 2026 even with 2 word passphrase - I could not find that post but it was discussed somewhere perhaps in another thread.

As far as I remember, I read that someone reported that their seed was hacked despite having a two-word passphrase on coldcard, but also that it was just ordinary words that could be brute-forced very easily. I haven't read anywhere that anyone has lost coins on a coldcard with a strong unique passphrase (so far).

notocactus
Legendary
*
Offline

Activity: 3108
Merit: 5155


Glory to Ukraine!


View Profile
August 22, 2026, 03:26:02 PM
 #34

As far as I remember, I read that someone reported that their seed was hacked despite having a two-word passphrase on coldcard, but also that it was just ordinary words that could be brute-forced very easily. I haven't read anywhere that anyone has lost coins on a coldcard with a strong unique passphrase (so far).
Exactly, that is about Coldcard wallet with 2-word passphrase exploited.
https://x.com/BTCsessions/status/2084024733511921691
Quote
IMPORTANT UPDATE: We just had our first confirmed loss of a Mk3 + 2 Word Passphrase.

Drained at 2pm Aug 2nd Australia Time - Roughly 17hrs ago.

Passphrase if used needs to be a strong one but it's not for newbie. Firstly about risk of losing bitcoin by don't know what they're doing with a passphrase, and secondly they must know what is a strong passphrase to use.

I do use my ColdCard as my primary hardware wallet, but none of my seeds were generated on it.  I used a different method/device to generate my seeds and I use strong passphrases on every wallet, including the ones that are mostly transitory.  When generating the seed for my cold wallet I added analogue entropy as well.  So far so good, my bitcoin is still sitting pretty, AlhamduliLah.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Taskford
Legendary
*
Offline

Activity: 3318
Merit: 1065


A swap that needs a hand? zeto.cash@proton.me


View Profile
August 22, 2026, 09:34:13 PM
 #35

As far as I remember, I read that someone reported that their seed was hacked despite having a two-word passphrase on coldcard, but also that it was just ordinary words that could be brute-forced very easily. I haven't read anywhere that anyone has lost coins on a coldcard with a strong unique passphrase (so far).

Passphrase if used needs to be a strong one but it's not for newbie. Firstly about risk of losing bitcoin by don't know what they're doing with a passphrase, and secondly they must know what is a strong passphrase to use.

Passphrase can potentially add strong protection to their wallets, but this is only for those people have great understanding on how the wallet they are using works.

The real risk is not about the feature, but rather on how the user done set set up or how they handle it. Adding it could be a risk if they don't know how to safekeep their phrases or they don't know how to handle then suddenly expose it to somebody else then also they lost it due to negligence.

When choosing a passphrase, picking those what they think easy to think or guess defeats the purpose of having this feature. Because they can easily got compromise with that situation. Better for people to erase that convenience thought and pay attention to make their wallet became more secured. Since if they know how to handle their wallet that passphrase became a additional strong defense of their wallet.

Sticky Bomb
Sr. Member
****
Offline

Activity: 798
Merit: 416



View Profile
Today at 11:12:41 AM
 #36

Huh What does that mean? I made a thread on passphrases like a day before op & I genuinely thought I had it all right after all my prior research....but now I'm worried I don't have it all?! How can a rlly strong passphrase still get the btc swept?

If someone adds a weak/easy to brute force passphrase then it is logical that hackers will be able to hack such a wallet, but if you look at the example password I generated of only 13 characters you will see that there is no chance that any hacker will be able to hack such a protected wallet.


Code:
https://www.passwordstrength.io/

Unless there is an even more significant flaw in coldwallet, I really don't know how it would be possible to hack a wallet with a strong passphrase.
A little pointer to beginners. It's not advisable to first test the strength of the password in this site before using it as your what password or your passphrase. This site might have hidden intentions as well and might have saved every password keyed into it for testing. You can use it to test for strong patterns and then use a different character combination in reality. Your actual passwords and passphrases should be exposed to only you.

Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7738



View Profile WWW
Today at 01:56:28 PM
 #37

A little pointer to beginners. It's not advisable to first test the strength of the password in this site before using it as your what password or your passphrase.
~snip~


It is logical not to use passwords that would be entered on such sites, even though they claim that they do not store them anywhere. Such pages actually serve to give the user insight into the best way to set their password, which of course should be unique for each service they use.

I would just add that even the strongest password has no purpose if someone's computer is infected with a RAT (remote access trojan) or if they have a keylogger on their computer. The first step is to maintain good internet hygiene, if possible have a good antivirus + firewall and if possible use Linux instead of Windows.

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!