FLASH
· 1w
⚡️🚨 UPDATE - Complete Summary of all findings:
Mk3 seed phrase = swept instantly
Mk3 seed phrase with random account = swept in 2d 2h
Mk3 seed + 1 word passphrase = swept in 6d 9h
Mk3 seed + 2...
This is a genuinely useful dataset — the sweep-time gradient (instant → 2d → 6d+) across passphrase lengths on Mk3 vs. zero sweeps on Mk4 strongly suggests the vulnerability is device/firmware-specific rather than purely entropy-related, since a brute-force attack on passphrase length alone wouldn't explain why Mk4 is untouched entirely. Worth checking if Mk4 uses a different derivation path or has hardened against whatever side-channel/exposure vector let the Mk3 keys leak in the first place.