Bitcoin Forum
August 15, 2026, 08:38:02 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: Passphrase: What is it & when to use it (or not to)  (Read 381 times)
Pumpsta (OP)
Member
**
Offline

Activity: 93
Merit: 17


View Profile
August 09, 2026, 05:03:32 PM
Last edit: August 10, 2026, 01:32:37 PM by Pumpsta
Merited by hugeblack (2), sunsilk (1), ColdLava40 (1)
 #1

Introduction

When we buy Bitcoin, we buy self sovereignty. We're responsible for whatever mistake we end up making and its level of security depends on what we do & how we treat our coins.

But it's often difficult to keep in touch with the Bitcoin community all the time & make sure all incidents can be avoided. Perhaps you know you don't enter a seed on a website. Perhaps you moved your Bitcoin to an offline setup. But there are situations where even that isn't enough because the seed you generated was easy to compromise in the first place.

Being a non technically advanced Bitcoiner, reading about the Coldcard incident frightened me. I was asking myself: do I sell now? Is it over? Because when you're not technically knowledgeable, you can only fear you'll be next in line for the attacker.

Here's where passphrases come in handy.



What is a passphrase?

Passphrases (also known as 13th word, 25th word or extra word) are an extra layer of security on top of your Bitcoin wallet seed. It was introduced through BIP39 in 2013 together with mnemonic (seed) phrases.

While mnemonic phrases are a group of words leading to a Bitcoin wallet, the passphrase is similar to a password. It's not conditioned or limited by anything: it can be an extra group of words, a password-like string or anything like that:

Code:
bitcoinwalleta
Code:
bitcoin wallet a
Code:
Bitcoin wallet #A
Code:
BTC_wallet_#A_2026
Code:
0174627193927261329
Code:
@OS4A(taL4regf1rZSqESYqUizWcu3MxsAoR4THw

^ all the above are valid passphrases!

Fun fact: unlike account passwords, your passphrase can be as long as you want. Make it a million characters long - no problem, just make sure you wrote it down somewhere safe!



How does it work?

Passphrases work by creating a hidden wallet on top of your seed. This is a great addition because instead of multiple separate seeds, you can have as many passphrases as you want for a single one (and each passphrase will generate a brand new wallet!).

Example: If your seed phrase is:
Code:
recipe leave mechanic rice upset leave town assume panther duty police lake alarm music pistol area nature opera inherit wet duty easily arrange settle

Then you can add an extra word also known as a passphrase to it. Now it becomes the 24-word phrase above + your passphrase.

Important note: just like seeds & private keys, passphrases should never be shared with anyone.

As a family, we can use the same main seed (don't do it tho!). If each family member adds their own strong passphrase, they can't see or spend each other's BTC. That's because each member now has a different wallet:

  • Wallet A: Original 12/24-word seed
  • Wallet B: Original 12/24-word seed + your passphrase
  • Wallet C: Original 12/24-word seed + my passphrase



How do we use it?

It's a feature most wallets already have. I'll guide you for Electrum mobile:

  • 1. Open Electrum & pick a name for your wallet
  • 2. Choose "Standard Wallet"
  • 3. If you don't have a seed, choose "Create a new seed", otherwise choose "I already have a seed".
  • 4. You'll be given a new seed or be asked to insert yours. In my case Electrum gives me a new one. If it's new, write it down somewhere safe (not on your phone)!
  • 5. Tick the "Extend the seed using custom words" box. Insert your strong passphrase. Write it down somewhere safe and don't share it with anyone!
  • 6. Continue the wallet setup process as guided by Electrum

Well done! Now you have a seed secured by a passphrase!



The Coldcard incident

This is where many of us got frightened. Watching the theft happen in real-time without enough Bitcoin technical knowledge made it look like a doomsday situation. Bitcoin is over if it's that easy to steal it even from a hardware wallet, right? Huh

It's not!

The Coldcard incident was caused by a low security generation of seeds. A firmware bug generated its users seeds using a not-so-random random number generator. The Coldcard chip had a true random number generator but the code simply didn't use it.

(I don't know who to thank for a lot of this information because it comes from multiple intelligent minds in the other Coldcard incent thread, so thank you to all who replied and took their time to explain how & what happened)


Practically, it means that by a simple exploit of the code somebody was able to generate the same seeds Coldcard users were generating. But, while over 1.5k BTC is gone, two types of users were untouched by the attack:

  • Bitcoiners who had a multi-sig setup
  • Bitcoiners who had a strong passphrase.

I just explained a couple rows above that using a passphrase generates a completely new wallet on top of the main seed. This explains the escapees: if the attackers were able to generate their seed, it was all in vain unless they're also able to find their passphrase.



When do we use a passphrase?

Ideally, we should use a passphrase every time we generate & want to use a new Bitcoin seed. If you already have a seed, it's recommended to add a passphrase and move your balance to the now-13-or-25-word seed. But there are more situations:

  • Some Bitcoiners leave a small amount on the 13/24-word seed as decoy and use the extra word as their real wallet. If someone robs them, they will only take what's on the decoy wallet.
  • A student who's living in the dorms won't have their Bitcoin stolen by any prying eyes if they use a passphrase. They can only see the decoy wallet, unless they find the passphrase too.
  • Someone who needs multiple wallets can have as many passphrases for a single seed. For 5 separate wallets, you can have 13/24 words and 5 separate passphrases instead of 65 or 120 words.



What are the risks?

The main risk of having a passphrase involves forgetfulness or loss. If you can find the 12/24 word seed phrase but can't figure out what the passphrase was, you're out of luck - your Bitcoin is gone. Since both are required to access your BTC & it's recommended to store them separately, the chance of screwing up increases.



How do we store it?

We store it in a safe place, of course. But a passphrase needs a place separate from your seed so even if anyone finds the seed, they can do nothing with it unless they find the passphrase too. Avoid paper & other materials that quickly degrade/combust, or places with high traffic.



Is my passphrase strong?

Your passphrase shouldn't be easy to guess. Even the passphrase "bitcoin" is better than none, but a hacker can crack it instantly.

For a strong passphrase, it's recommended to have at least 12-15 characters including numbers, symbols and uppercase & lowercase letters. A bruteforce-calculating website estimates it'd take approximately 45 quintillion years to crack a random password of 20 characters using a modern GPU rig.

The rule's simple: the longer & more complex, the better.



Conclusion

Bitcoin is true self sovereignty and responsibility. If you can't be responsible, bad things happen. But for many years now, Bitcoin's been prepared for all situations - even for scary incidents like Coldcard that left so many people with empty balances overnight.

Passphrases offer a risk mitigation for such situations. It's only your responsibility to level up to a seed that's even tougher to reach. That way, when somebody gets access to your seed phrase, your Bitcoin's still intact in the strong hidden pocket of the same seed.


I wrote this thread for everyone who's been frightened by the Coldcard story. I'm sorry for any technical mistake I made in the process; I'm not an advanced knowledgeable user myself so I tried to explain in my terms what I learned from my prior research about passphrases. There's no reference links because this information came from what I know but I'll add some if they're required.
Charles-Tim
Legendary
*
Offline

Activity: 2366
Merit: 6496


Leading Crypto Sports Betting & Casino Platform


View Profile
August 09, 2026, 05:20:06 PM
 #2

Passphrases (also known as 25th word) are an extra layer of security on top of your Bitcoin wallet seed
Best way to describe it is 'extra word'. In a 12 word seed phrase, it is not the 25th word but rather the 13th word.

While mnemonic phrases are a group of words, the passphrase can be any chain of characters. It's not conditioned or limited by anything: it can be an extra group of words, a password-like string or anything like that.
It is not a group of word, it is all a single word. Space is a valid character in passphrase. Space or no space, and with other characters, it is still a single word.

Code:
recipe leave mechanic rice upset balcony town assume panther swing police lake alarm music pistol area nature opera 
It will be good to leave a warning that people should not share or let anyone see their seed phrase and passphrase because it can be used to steal their coins.

The Coldcard incident was caused by a low security generation of seeds. This was the fault of a vulnerable firmware that didn't use the Coldcard chip's random number generator but instead used a replacement generator which wasn't really random.
Being random does not mean it can not be brute forced. The reason for the Coldcard hardware wallet vulnerability was that the seed phrases were generated by another thing which is generating seed phrases that do not have 128 bit of security and which is less secure.

The main risk of having a passphrase involves forgetfulness or loss. If you can find the 24 word seed phrase but can't figure out what the passphrase of your wallet was, you're out of luck and your Bitcoin is gone. And because both are required to access your BTC & it's recommended to store them separately, the chances are higher to screw up.
This is the reason to backup the passphrase, although in different locations from the seed phrase backups.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
BitMaxz
Legendary
*
Offline

Activity: 4074
Merit: 3666


♻️ Automatic Exchange


View Profile WWW
August 09, 2026, 06:15:45 PM
 #3

Doing all of this in an online device, you are still vulnerable to possible attacks; if you generated the seed and passphrase with the internet, the chances still high so you still need to go generate your seed phrase and passphrase into offline device before you permanently delete the wallet.
Or keep it and learn the manual way to make an unsigned transaction and transfer the raw transaction to sign it in your offline device.
So that you are also protected from hijacking your transactions.

A passphrase is extra protection, but still it depends on how long your passphrase is; a shorter passphrase can be easily brute-forced, so a long passphrase is a must.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
EL MOHA
Hero Member
*****
Online Online

Activity: 1232
Merit: 504



View Profile
August 09, 2026, 07:54:39 PM
 #4


Ideally, we should use a passphrase every time we generate & want to use a new Bitcoin seed. If you already have a seed, it's recommended to add a passphrase and move your balance to the now-25-word seed. But there are more situations:

Personally I wouldn’t recommend using your old seed phrase and just extending it with a pass phrase rather it will be actually better you create a new seed phrase plus another passphrase. This is safer most especially if the initial seed phrase was actually generated from an online wallet or even closed source wallet. While it will remotely take an hacker hard time brute forcing your passphrase after finding your seed phrase I will have a new seed phrase plus pass phrase is more secure,

For example example it would be unwise to say cold card user should just extend this their vulnerable seed phrase instead of moving their coins off that seed phrase.

Quote
Some Bitcoiners leave a small amount on the 24-word seed as decoy and use the 25-word seed as their real wallet. If someone robs them, they will only take what's on the decoy wallet.

Decoy is a great idea but personally if I am doing it like I have read recently from the forum I will be creating a decoy from an extended seed phrase. Example is I will be extending my seed phrase with just 1 word as passphrase and this will now be my decoy wallet and then use same seed phrase plus say 5 plus words as passphrase and then this is my main wallet.

If the hacker gets to the main seed phrase before they could get to the seed phrase with one word passphrase which is my decoy wallet will take time and before getting to the main wallet will take more longer time and I would have swept that wallet to another one already

Comeacross
Full Member
***
Online Online

Activity: 252
Merit: 118


Spinly.io - Next-gen Crypto iGaming Platform


View Profile
August 09, 2026, 08:32:16 PM
 #5

When we buy Bitcoin, we buy self sovereignty. We're responsible for whatever mistake we end up making and its level of security depends on what we do & how we treat our coins.

This responsibility is the reason why some people are running to centralized exchanges to handle their coins. But does it really mean they are safe? No, they only shift the responsibility instead of standing strong to fix them. This way, you don't really buy sovereignty since you don't have full control of your coin. You shift responsibility, you also shift the sovereignty.

It will be good to leave a warning that people should not share or let anyone see their seed phrase and passphrase because it can be used to steal their coins.

Exactly my thought. The example given is good for illustration but it's necessary to put a disclaimer warning never to share real seed phrase. Some people are too dumb to understand the context and the purpose of the illustration.

ColdLava40
Full Member
***
Offline

Activity: 476
Merit: 173


Bitcoin


View Profile WWW
August 09, 2026, 09:08:19 PM
 #6


What are the risks?

The main risk of having a passphrase involves forgetfulness or loss. If you can find the 24 word seed phrase but can't figure out what the passphrase of your wallet was, you're out of luck and your Bitcoin is gone. And because both are required to access your BTC & it's recommended to store them separately, the chances are higher to screw up.
The passphrase is just an extra security you add to your seedphrase, it doesn't have to be too complex, does it?

We can memorize that instead of memorizing our seedphrase which could be forgotten because of how unreliable the human brain is. But the passphrase could be short and not complex so it can be memorized and easily remembered.

Quote
Conclusion

Bitcoin is true self sovereignty and responsibility. If you can't be responsible, bad things happen. But for many years now, Bitcoin's been prepared for all situations - even for scary incidents like Coldcard that left so many people with empty balances overnight.
Bitcoin wasn't the cause of the coldcard vulnerability, The wallet was. I think this might even be an confusion for many. The wallet is provided by a company as Bitcoin has no connection with what happened. Like many other asset. Bitcoin is just stored there.

AVE5
Sr. Member
****
Offline

Activity: 994
Merit: 368


Winning & Loosing is the option. Take a decision


View Profile
August 09, 2026, 09:22:30 PM
 #7

When we buy Bitcoin, we buy self sovereignty. We're responsible for whatever mistake we end up making and its level of security depends on what we do & how we treat our coins.

What you've said here's very factual.
When you buys bitcoin, you owns monetary freedom that it's security, risks and controls is rest on you while the bitcoin network is already decentralized and given every user's right to custody their coins..
Because custody is being a right is the reason why learned user's who can afford hardware wallet spends extra money to buy just to store private keys offline to strengthen the security.
Some also goes beyond engraving their seed phrases of metal objects to prevent natural disasterous threats like fire and water.

sunsilk
Hero Member
*****
Offline

Activity: 3738
Merit: 656



View Profile
August 09, 2026, 09:59:11 PM
 #8

Fun fact: unlike account passwords, your passphrase can be as long as you want. Make it a million characters long - no problem, just make sure you wrote it down somewhere safe!
And can also add that somewhere safe isn't the online/cloud storage that some people might think because it's owned by google, yahoo, microsoft and other mailing services or cloud services and tech companies.

They're not safe places to keep the seedphrases and passphrases.

Because the assumption of people that writing down can be done on online docs and not on a physical paper. I'd say that the latter has always been safe as it's offline.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
moneystery
Sr. Member
****
Offline

Activity: 1512
Merit: 330


⭐ Razed.com ⭐ LM Management ✅


View Profile WWW
August 09, 2026, 10:03:56 PM
 #9

You need to explain that the passphrase is case-sensitive, so any differences in letters, symbols, numbers, or uppercase and lowercase letters in the passphrase matters. Even a single difference in the passphrase will generate a different address.
So anyone planning to add a passphrase to their wallet needs to pay close attention to what they're typing, because even the slightest mistake can lead to a completely incorrect passphrase. That's why it's important to make sure you understand what are you doing and keep an exact record of it.

RAZED | 100%  
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
|
NO
KYC
██████████████████
 RAZE THE LIMITS   PLAY NOW
██████████████████
PX-Z
Legendary
*
Offline

Activity: 2268
Merit: 1367


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 09, 2026, 11:14:04 PM
 #10

And remember, regardless how long and secure the passphrase is, and if you put your backup on a very safe place, if you setup this wallet in an unsafe environment/device, the result will be the same, it's catastrophic. So be responsible enough to do scan your device regularly, avoid downloading and installing stuff from random website to avoid malware stealing info.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Patikno
Sr. Member
****
Offline

Activity: 924
Merit: 323



View Profile WWW
August 10, 2026, 04:02:10 AM
 #11

And remember, regardless how long and secure the passphrase is, and if you put your backup on a very safe place, if you setup this wallet in an unsafe environment/device, the result will be the same, it's catastrophic. So be responsible enough to do scan your device regularly, avoid downloading and installing stuff from random website to avoid malware stealing info.
I completely agree with you. A common problem with hacking, or data theft is installing apps from unknown or unofficial sources, especially pirated apps (which may be infected with malware). Furthermore, modified apps are often infected with viruses; that can damage your device, or steal your data. Therefore, I strongly advise you (especially for beginners) not to attempt installing such malicious apps.

By the way, here is a resource you should read to help you understand the dangers of installing apps from unknown or unofficial sources, here : kaspersky.com - Stealka stealer: the new face of game cheats, mods, and cracks

I also suggest, read about "Info Stealer" : indodax.com - Info Stealer: Malware Targeting Crypto User Data

█████████████████████████████
█████████████████████████
█████████████████████████
███████████▀▄▀███████████
██▄▀▀▀██▀▄███▄▀██▀▀▀████
██▌▐███▄▄█████▀███████▐██
████████████████████████
███▌▐████████████████▐███
████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████████
 rizzy 
██████
██
██
██
██
██
██
██
██
██
██
██
██████
█▌█▌█▌████
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌████
████████████

 
████████████
██████████████████████████████████████████████████████████████████
 
THE HOME OF THE
   MOST REWARDING   
GAMING EXPERIENCE
██████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████
100%DEPOSIT
MATCH
+ 100 FREE SPINS
██████████████████████████████████████████████████████████████████
████████████

 
████████████
████▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
████▐█▐█▐█
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
Pumpsta (OP)
Member
**
Offline

Activity: 93
Merit: 17


View Profile
August 10, 2026, 05:54:22 AM
 #12

I updated the OP (shortened some text & added some of your suggestions), I don't get why some of you are nitpicking my text & putting words in my mouth tho? Huh
Dave1
Hero Member
*****
Offline

Activity: 2128
Merit: 643



View Profile
August 10, 2026, 08:24:01 AM
 #13

And remember, regardless how long and secure the passphrase is, and if you put your backup on a very safe place, if you setup this wallet in an unsafe environment/device, the result will be the same, it's catastrophic. So be responsible enough to do scan your device regularly, avoid downloading and installing stuff from random website to avoid malware stealing info.

Or worst, if you get your back up seed wrong, or at least one word on it. So even if your security is very tight and high but you made that one big mistake (in case it happened to me before). So it's better to test your seed phrase first + passphrase with just small amount before putting it all everything.

There's nothing wrong with passphrase, because it's another layer of security for us. But still, we still need to practice safety hygiene like proper back up. Metal back up is good and there has been a tutorial here for a DIY.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀
 
..PLAY NOW..
Somegory
Full Member
***
Offline

Activity: 378
Merit: 190



View Profile
August 10, 2026, 09:02:02 AM
 #14

Nice 👍 I think I have something to add up here for beginners.

1. Passphrase can also be weak too, but that's in the hard of the holder.
    Make a hell of a strong Passphrase, that will be very difficult to get, use not only worlds but signs too, like the @&

2. Make sure you don't keep the passphrase and the recovery seed in the same location.
    Remember, if one gets leaked the other still got your back, which is why you must keep them in separate locations.

Now make sure that both the seed phrase and the passphrase are stored offline completely, and please let's start using wallets that are more popular than others, I swear I've never heard about ColdCard before, I'm am still surprised that alot of people are using it.


Aanuoluwatofunmi
Sr. Member
****
Online Online

Activity: 1414
Merit: 469



View Profile
August 10, 2026, 12:16:07 PM
 #15

The wallet we are going to use should be on a device that is not connected to the internet. This is another safety measure many are not protein more attention to, and it has been discussed in several locations that our wallet should be on an air-gapped device; some will even suggest that our wallet should not be on the normal device we use for internet connectivity, just to make sure that we are not vulnerable to any form of attack coming through that route.

████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 JACKSCLUB.io       FAIR CRYPTO CASINO & SPORTSBOOK     270% BONUS UP TO $20K   |    NO KYC       PLAY & EARN      [  PLAY NOW  ] 
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
Sticky Bomb
Sr. Member
****
Offline

Activity: 784
Merit: 414



View Profile
August 10, 2026, 04:01:49 PM
 #16

if you generated the seed and passphrase with the internet, the chances still high so you still need to go generate your seed phrase and passphrase into offline device before you permanently delete the wallet.
If such wallet credentials are generated in a hot device, then it is a financial risk. We do not know if the device has been compromised even before the wallet creation and the credentials may have been read by the attacker and stored, patiently waiting for the perfect time to strike.

It is best to do away with wallets generated in a hot device and create another one offline in an air-gapped device if you intend using it as your main holding wallet, that's the only way you're sure it's safe from social engineering.

9ja Amaka
Full Member
***
Offline

Activity: 406
Merit: 144


Stay true till the end


View Profile
August 10, 2026, 07:21:46 PM
 #17

In addition, the passphrase is not meant to be saved directly to a Google Ledger or any other cloud-based storage, especially that of a mobile device. Most beginners do this by activating " Save to Google " or other cloud storage in the wallet settings they use. A good reason why I do not recommend non-custodian wallet that are not hardware. Our seed phrase is like a lock to a door. If lost or accessible, the entire room will be left empty. It is not a usual device password. That's why we should treat it differently.

BitMaxz
Legendary
*
Offline

Activity: 4074
Merit: 3666


♻️ Automatic Exchange


View Profile WWW
August 10, 2026, 11:11:00 PM
 #18

If such wallet credentials are generated in a hot device, then it is a financial risk. We do not know if the device has been compromised even before the wallet creation and the credentials may have been read by the attacker and stored, patiently waiting for the perfect time to strike.

It is best to do away with wallets generated in a hot device and create another one offline in an air-gapped device if you intend using it as your main holding wallet, that's the only way you're sure it's safe from social engineering.

The attacks, actually, gather more information and log it; they don't just act immediately once they've collected it. I think they use a script to automate everything, sweeping all the seed they stole and moving it to one address. I don't think they have perfect time for me; they have a specific time or free time for doing it.

If you're using an air gap or offline/cold storage device, then you've already prevented someone from seeing what you're doing; no one could see your seed except in physical attacks or possible CCTV. If you do have it in your house, it's better to turn off all your CCTV first before generating an offline wallet.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
SeriouslyGiveaway
Sr. Member
****
Offline

Activity: 812
Merit: 267


Bitz.io Best Bitcoin and Crypto Casino


View Profile
August 11, 2026, 05:21:22 AM
 #19

If you're using an air gap or offline/cold storage device, then you've already prevented someone from seeing what you're doing; no one could see your seed except in physical attacks or possible CCTV. If you do have it in your house, it's better to turn off all your CCTV first before generating an offline wallet.
I would like to create my Bitcoin wallets at home especially if it is my main Bitcoin wallet that is used to store most of my bitcoin fund.
Do it offline, at home, and on an air gapped device if possible.

With main wallet creation, it's very risky to create it when you are on the street or at any public places like a cafeteria, a restaurant for example.
Public locations with public Wifi is risky online for my privacy, and if someone see it, know that I have actions related to Bitcoin and cryptocurrency, I can become a target of physical attacks later, that's very dangerous while it can be avoided very easily.

Just do these things at home.
Database of Physical Attacks Against Crypto Holders.
https://stats.gart.io/

█ 
███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io█ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀██
███████████████▐▌
███████████████▐▌
███▄▄████▄▄▄██▄▄
▄█████████████████████▄
████████████████████
██
█████████████████████
▀██
█████████████████████▀
▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
███████████████▄
▄███████████████████▄
▄██████████████
██████▄
▄██████████████████████
████████████████████████
███████████████████████
██████████████████████
████████████████████████
▀█████████████████████▀
███████████████████▀
███████████████▀
▀▀███████▀▀
HIGH
ODDS
 
█████████   ██

......PLAY NOW......

██   █████████
█ 
FinneysTrueVision
Legendary
*
Offline

Activity: 2478
Merit: 1213



View Profile
August 11, 2026, 08:06:08 AM
 #20

I’ve seen some Bitcoin security experts, such as Jameson Lopp, recommend against using passphrases because they are easy to forget or lose, which leaves you unable to access your Bitcoin.

I have never felt comfortable with that kind of advice and use a long, complex passphrase anyways. If the Coldcard users had done the same, the hackers would not have been able to steal over $100 million so easily. It might not be the perfect setup, but I would rather not take any chances and rely solely on the entropy generated by my hardware wallet.


▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!