The 40bits are hashed so they are 128 or 256 bits long but contain only 40 bits of entropy. They look as valid as if you super random key sha256(00000000... 000) would or any legit key. The hashing part just hides it otherwise you would see a bunch of 40 random bits followed by a lot of 0's