Damus
nix · 3d
You mean they somehow have existing access to the encrypted seed and were able to decrypt it because the pass was weak right?
Cyph3rp9nk profile picture
They gained access to the seeds generated by Coldcard because they had an entropy of just 40 bits.

That was the attack in the first wave, but now they’re targeting those seeds and also performing brute-force attacks on passphrases.

If you have a seed generated by Coldcard—regardless of the model or year (let’s keep things simple and forget about exceptions)—migrate your data to a new seed with sufficient entropy, which can be generated on a Trezor, Jade, or an offline computer (freshly formatted with Linux) using Sparrow or Electrum.

After creating the seed, generate a passphrase with KeepassXC that has at least 90 bits of entropy. Ideally, it would be 128, but certain hardware wallets won’t accept passphrases of that length based on the number of words, so let’s not overcomplicate things—90 bits of entropy can’t be hacked.

Store the passphrase and the seed separately.

Let’s also not overcomplicate things with multisignature—not everyone is ready for that.

The current passphrase acts as a 2-of-2 multisignature.
58❤️10🤙21👌1🚀1🧡1
Beerborn · 3d
Out of curiosity, why words for the passphrase? Wouldn't a full keyboard 20+ characters string already take you above 128 bits?
Guerrilla Mind War · 3d
90bit of entropy cannot be hacked...TODAY.
Francisco d Anconia · 3d
Regarding entropy: I wasn’t able to find a clear answer to how to calculate the entropy of a complex passphrase, which does not contain words in English language, but rather words in other languages / invented words and combinations of numbers and symbols But I’m guessing theoretically the entr...
Dao of The Dao · 3d
It looks like Coldcard were missing an entropy check on their devices. This really shows the amateur level of coding they were doing there. We need much better scrutiny and audits of these devices from the bitcoin space. It seems Trezor are doing an entropy check on their devices. These guys have be...
PHILIP · 3d
Redarding the generated passphrase: that’s something that has to be entered each time you want to transact and when you lose or forget it you are locked out. There are possibilities to store it on micro sd cards instead of remembering, but those are hard to lose as well. Do you suggest a safe pro...
Wussel Powa · 2d
wasabi wallet no good?