nix
· 3d
You mean they somehow have existing access to the encrypted seed and were able to decrypt it because the pass was weak right?
They gained access to the seeds generated by Coldcard because they had an entropy of just 40 bits.
That was the attack in the first wave, but now they’re targeting those seeds and also performing brute-force attacks on passphrases.
If you have a seed generated by Coldcard—regardless of the model or year (let’s keep things simple and forget about exceptions)—migrate your data to a new seed with sufficient entropy, which can be generated on a Trezor, Jade, or an offline computer (freshly formatted with Linux) using Sparrow or Electrum.
After creating the seed, generate a passphrase with KeepassXC that has at least 90 bits of entropy. Ideally, it would be 128, but certain hardware wallets won’t accept passphrases of that length based on the number of words, so let’s not overcomplicate things—90 bits of entropy can’t be hacked.
Store the passphrase and the seed separately.
Let’s also not overcomplicate things with multisignature—not everyone is ready for that.
The current passphrase acts as a 2-of-2 multisignature.