Reimport the seedphrase + pass phrase in another offline wallet or instance of the wallet(if you use desktop) and confirm the addresses before backing up safely offline, complexity should not be the excuse to let your guard down, complexity is good in having a pass phrase so it is much harder to bruteforce. It would interest you to know that 1,2 and 3 word passphrases wallets were swept as well in the recent coldcard hack.
It is not an excuse, you need to understand how reasonable security works and that is the best practice. Complex security solutions have created many more losses than short pass phrases. If your wallet is exposed to the point that someone is currently able to brute force it, then the issue is not of the passphrase length. The wallet is already compromised it is just a matter of time, it should be changed right away so the passphrase only provides some buffer of time. Multi word passphrases are not a counter point here because we don't have proof of their complexity. It could be something very simple consisting of 3 lowercase words from a dictionary.
The passphrase length should be long enough to provide good security,
In your own terms, how long should it be?
15 to 20 characters should be enough right now if it is covering all characters, lower case, upper case, numbers and symbols. Don't forget that passphrase is adding entropy to protect exposed seed phrases, but if your seed phrase is not exposed then even a short passphrase is not an issue.
but also related to the value that is being protected and be reasonable in the total length to avoid creating other issues.
There is no relationship between these, this statement is pointless.
Yes there is, ask ChatGPT if you are not familiar with security best practices. The amount of resources and complexity that is supposed to be invested into cyber security is directly related to the value that you are protecting. An extreme example would be to put a 100 character seed phrase to protect $100 of Bitcoin, and this setup would be wrong.
@Charles-Tim & @DubemIfedigbo001, I honestly don't know is the password strength assessment based on the current capabilities of a computers/supercomputers, or do they take into account quantum computers as well? One obviously advanced user in the coldcard hack thread says he has a passphrase of as much as 50 characters, so while there's no doubt that such a passphrase definitely has better protection than one of 15 or 20 characters, I still wonder if quantum computers with the help of artificial intelligence will one day be able to hack such passphrases?
As long as it is sufficiently long and random, then quantum computers will not be able to crack a 50 character passphrase in any reasonable time. Nobody is going to throw that amount of investment capital and running expenses to crack a wallet that may have very little value in it. How many characters is safe is always a moving target, it is not related to AI or quantum computers at all. Those just speed up how fast the target is moving. Nobody should be using the same passphrase and wallet for very long periods of times if we are talking about decades.