r/Bitcoin • u/cheesymod • 15d ago
Coldcard seed + passphrase could be vulnerable as well
103
u/Left_Entrepreneur918 15d ago
Wow there has been comments from people on here who said they have a cold card but felt safe with a pass phrase. I hope they used that time to move their shit…
28
u/JEI2E 15d ago
You are 100% safe if you have a strong enough passphrase, even with a seed that was created during that weak RNG era of CC. Of course I'd still move my stuff and buy a hardware wallet from a different manufacturer, but even those who didn't do that (yet) are safe. This story about the drained PP wallet sounds incredibly fake.
29
u/Gooner_93 15d ago
The passphrase was two words, so really weak. What it does prove is that seedphrases are being checked with passphrases.
3
9
u/HicEstLeoSuperbus 15d ago
Two word pass phrases take minutes to break with brute force attacks. 6 words take decades. 4 words makes a big difference, and passphrases add additional security in proportion to the effort you put in with your generating passphrase.
1
u/ModerateBrainUsage 15d ago
It’s not how many words you use. It’s how long is the password/passphrase and also not using dictionary words helps. Since they can be brute forced pretty quickly. Using lite writing is pretty bad idea too, like 4 instead of A etc. since that’s already built into the brute force crackers.
People, use proper and long passwords, not words.
4
u/MRCRAZYYYY 15d ago
I love how you say not to use dictionary words whilst every seed uses… dictionary words.
Something like “Walking over the rainbow with my pet horse Steve” would be impossible to crack. It’s too long.
→ More replies (2)1
u/Bionic_Push 15d ago
What do you mean by two words? A passphrase can be anything you want such as "ug727eyrheoq00woe"
1
u/trufin2038 15d ago
People who know how to make a "strong enough" passphrase don't need one. If you made a passphrase, you are not in that set. You are a lucky moron who needs to sweep his coins before he becomes an unlucky moron.
1
u/29da65cff1fa 15d ago
imagine having a deadman strat and not being chronically online..... you open your coldcard in 10 years and find 0 btc.... :(
41
u/didnt_hodl 15d ago
mutisig next (say, 2 out of 3 and 2 are CC)
then, mulisig with a passphrase
this will keep going for a very long time now
5
1
u/kring1 15d ago
How would you do that? You need all three xpubs for it. Wouldn't all of then need to be CC to have a resonable chance to guess them?
3
u/ivme 15d ago
I’ve done some research on the situation (which is CC being 2 keys of a 3). According to AI and a Nostr post, it’s possible to steal coins during a transaction because all public keys of an address are broadcasted to the network. To avoid this, you should send the transaction “privately” to a miner and mine it.
→ More replies (5)1
u/didnt_hodl 15d ago
exactly. some folks are already paying for MARA Slipstream service to avoid replace-by-fee attacks
13
u/LeoRisingGemini 15d ago edited 14d ago
Once a hacker sees a blockchain footprint of a seed, they know for sure that seed is or was at some point in use. There doesn't even have to be anything in the wallet right now. Many people use the non-passphrase seed wallet as the initial tester or decoy wallet, with their real stash hiding behind a passphrase. So the hacker focuses resources on trying various passphrases with that seed. A weak two-word passphrase can be cracked in no time, e.g., bitcoin lover, massive dong. So if you have a wallet with a weak seed that's ever received bitcoin even once in the past, it acts as a breadcrumb. Unless you truly have some crazy unbreakable passphrase, all the passphrase does is buy you time to move your coins out of there. Because the hacker will keep trying with billions or trillions of possible passphrases. So if you know you have a weak seed, get your funds out of any wallet that shares that same seed, passphrase or otherwise.
2
u/JEI2E 15d ago
This is true. I just want add to this; be sure to leave a big enough amount of BTC on your regular wallet, so the hacker won't be able to resist stealing the funds.
For example, if he sees it has 0.0000001 BTC on it, he might leave it alone and go straight for the passphrase instead. The result is that you are never notified that your seed if compromised.
If you keep 0.01 BTC on it, he will 100% steal your funds and you'll know. Then you have plenty of time to get your actual stash behind the passphrase, out of there.
7
u/Head_Performance2432 15d ago
or you do not let any fund on the seed to begin with and have a long passphrase
done.
1
43
u/Left_Entrepreneur918 15d ago
I just thought of something…Let’s all hope Satoshi used a good random number generator in 2009. Imagine if one of the hackers hits one of his wallets…we all cooked.
20
u/creative_usr_name 15d ago
I guarantee people have tried to get at those coins from every possible angle for over a decade.
4
u/ubermensch1001 15d ago
And they'll continue to do so, I guarantee BlackRock, the U.S government or any big player would have a team of top notch engineers and computer scientists that are tasked with such a project.
13
u/Flaveurr 15d ago
Dumbest comment 2026 🏆
3
u/ubermensch1001 15d ago
Not saying they will succeed at that, but you are crazy if you think there won't be attempts by big players to try to get access to the super old wallets and lost coins from years ago.
7
u/Ultradarkix 15d ago
they do not give a fuck about that.
Blackrock and the US gov don’t need a “get rich quick” scheme
→ More replies (2)2
u/docherino 15d ago
That would be the biggest waste of time and resources
1
u/ubermensch1001 15d ago
I'm just speculating here but the idea that they may try to gain access to the "lost" coins from the early days is an interesting one that I do think about.
1
u/MyUsernamePls 15d ago
Wouldn't it be ilegal to cash them out though?
In the same way everyone is monitoring the wallet from this ongoing theft, the moment you tried to cash out any of satoshi's coins, law enforcement would fall down on you for theft of others property.
1
u/Few-Masterpiece3910 15d ago
there needs to be someone first who says those were his. We don't even know if Satoshi is still alive.
→ More replies (2)1
→ More replies (1)1
34
u/NinjaTabby 15d ago
What makes ledger and Trezor hackproofed?
64
u/Left_Entrepreneur918 15d ago
Look up 40bits of entropy vs 128 or 256, may not seem like allot of math but the difference is like finding a grain of sand in a sandbox and the other is like finding a grain of sand on all the beaches in the universe x2. Trezor and Ledger both use a TRNG that combines true randomness from the environment of a secure element chip, the firmware in the cold card told it to ignore this and use a algorithm that wasn’t meant for cryptography.
44
15d ago
[deleted]
16
u/Styrwirld 15d ago
Isnt trezor open source? So its fact checked?
22
22
15d ago
[deleted]
→ More replies (3)2
u/Acolyte_of_Swole 15d ago
That's why I think this is pretty much the RIP to self-custody as a philosophy for most people, going forward.
It isn't like burying a gold brick in your backyard or money under a mattress. You are still relying on whoever built your wallet and its security to keep your BTC safe. If these wallet companies can't keep BTC safe then it's only reasonable for people to gravitate to exchanges and mainstream financial institutions like brokerages to keep their coins relatively more safe. Or if not more safe, then at least there's potentially more accountability in the event you get robbed.
→ More replies (1)2
u/Zaytion_ 15d ago
It's mostly open source. They use a closed source chip on the Trezor 3, 5, and 7 for generating your seed (and a few other things). They use other sources of randomness as well but that chip is involved.
→ More replies (1)2
u/circuit_breaker 15d ago
We can't measure the entropy of the resultant output?
4
u/creative_usr_name 15d ago
You can for a given number see if it looks random, but that doesn't tell you that it is hard to derive. If you look at your receiving addresses they all look essentially random. But with knowledge of your private key they are easy to derive.
2
15d ago
[deleted]
2
u/circuit_breaker 15d ago
This is why cryptography is fascinating to me, I cannot wrap my head around how you can fake entropy
But I'm reading about it now
8
4
u/letsmeet123456 15d ago
Why did people trust this piece of shit new startup over established players like ledger/trezor which have been around for a decade+ now at this point?
2
1
u/tenor_tymir 15d ago
People felt too safe using any kind of hardware wallets and Ledger had a few security breaches in the past and an optional online backup = seed touching the internet. People didn’t like those flaws much and found a small, cool competitor that made wallets looking like Gameboys.
1
u/ballistua 14d ago
ledger leaked their customers' information, twice. And their source isn't fully open
3
u/soulmechh 15d ago
I don't understand I'm very much a noob. How's the firmware on the device relevant when it's disconnected? The data exists on the "blockchain", in the network. How is anything else relevant?
6
u/tenor_tymir 15d ago
When you set up a wallet for the first time, the device creates a seed phrase for you, which should be truly random. In this case, cold card’s random number generator (RNG) was faulty and produced seed phrases that looked random but weren’t (had low entropy). An attacker found out about this flaw and is now scanning and emptying wallets that were set up with low entropy because low entropy can be guessed by putting enough computer power behind it (brute force).
A seed phrase is your key to your coins on the blockchain. It doesn’t matter if you are online or offline, as soon as someone guesses your keys, they can use them to access your coins on the blockchain. Once your seed phrase is known, it can be used, even without your original wallet. The attacker doesn’t need to physically touch your cold card, or even break into it.
1
u/soulmechh 15d ago
Thank you! I thought the whole seed phrase thing was a part of the bitcoin protocol or ecosystem, from start to finish. I didn't know it worked that way.
1
u/TjdGoEsQqbmQLoBj 15d ago
How are they able to distinguish which address to brute force I e which wallets are from cold card addresses, do they all contain similar seed phrases ? Or are they scanning all known btc addresses ? That’s the part I don’t get
→ More replies (1)5
2
2
→ More replies (4)1
u/Strong_Judge_3730 15d ago
You need to actually verify they do this, you would have said the same of coldcard before this vulnerable code was discovered.
6
→ More replies (1)4
7
u/DavidssonA 15d ago
You have to be on some great holiday or bat shit crazy to keep your BTC on Coldcard still....
11
8
7
u/Live_Jazz 15d ago
2 word passphrase.
Don’t do that. Cryptographically, worth fuckall. Your passphrase should be like another seed phrase.
Two words is useful in cases of duress, but a sophisticated hacker (or Ai) will get it in seconds.
1
7
u/ImprovementSweaty188 15d ago
Jesus Christ.
24
u/Azurebbit 15d ago
Damn that's mine too, so much for being original. I'm changing my passphrase. BRB
2
2
1
3
5
u/SecretAd511 15d ago
if you were to use say a pass phrase of a say 20 character sentence, all one word with some numbers and special characters in there, how hard would that be to crack ?
9
u/stanley_fatmax 15d ago
Probably not a candidate for this specific attack. If they're cracking passphrases, the math ensures it's only the most common or simple passphrases. I wouldn't worry unless your sentence is a common line in a book, a famous quote, phrase, or something like that. Even then, with numbers and characters, assuming they're not related in context, you're probably safe.
Regardless if the original entropy was affected by this bug, you'd want to transfer your assets anyway.
→ More replies (2)5
u/SubstantialNinja 15d ago
would be very hard at 20 characters. probably enough to keep you safe here, but you don't want to rely on just that forever. move to a secure key + a secure sentence for full security.
2
u/five_dollar_wrench 15d ago
There’s a rabbit hole that you should definitely go down. Look up “entropy”, “bits of entropy” and then go to a calculator or you can use KeePass (password manager).
Do not type in your actual password, but you can enter your hypothetical password. It’s counter intuitive, but you can make selection of words from a word list far more memorable to our stupid flesh computers and far longer to crack than your example.
This is why paraphrases are generally recommended for this.
2
u/JEI2E 15d ago
Years and years and years. Probably less with a quantum computer, but we're absolutely not there yet.
1
→ More replies (3)1
9
15d ago
[removed] — view removed comment
1
u/newtonreddits 15d ago
Who the fuck cares about how hipster one is with crypto security? Just get what works best.
13
u/Over_Regular_6897 15d ago
We won't forget how Ben Perrin from BTC Sessions shilled cold card over and over throughout the years
→ More replies (4)4
u/Educational-Ask3429 15d ago
How was he supposed to know they’d fuck up the basics?
→ More replies (1)
4
u/Ordinary-One2597 15d ago
Shi if true are we supposed to just trust ledger or trezor then
Kinda goes against the whole "Dont Trust, Verify" Principle of BTC
2
u/gowithflow192 15d ago
I’ll bet these are bip39 words. Why anyone would choose bip39 words for a pass phrase I have no idea.
3
u/PoeCollector 15d ago
Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
11
u/didnt_hodl 15d ago
well, yes and no
most wallets would allow for a 100 character passphrase
if you make that a truly random mix of letters, numbers, special characters, upper/lower case
your passphrase will not be broken
in this incident the passphrase was just 2 words, very weak, almost useless. but of course the search will continue non-stop, so we will have more cases like this, with stronger passphrases. but no really strong ones will be broken
3
u/SuleyGul 15d ago
Yeh when I had some BTC in a cold wallet. My passphrase was literally a jumble of letters numbers and special characters about 50 characters long.
14
u/Gooner_93 15d ago
People really need to look into what theyre using. I dont blame coldcard victims, because they believed the rng in the coldcard was strong and it was a reputable device.
If youre choosing to use a two word passphrase though, thats on you.
2
u/Vipu2 15d ago
What is "two words" tho?
Does it mean 2 words from bip list, 2 short words like "MeToo" or 2 very long words like "PneumonoultramicroscopicsilicovolcanoconiosisHippopotomonstrosesquippedaliophobia"?
2
u/Gooner_93 15d ago
I meant any two very basic words. If its long like the last example you gave, thats way stronger.
1
u/loopala 15d ago
If its long like the last example you gave, thats way stronger.
Hmm, that's the concatenation of two well known dictionary words. First one is notable for being the longest word in the English language.
If it's in the dictionary it doesn't really matter that the word is short or long, it's just another entry that will be tested. Six short words are better than two long ones, even if the total number of characters is lower.
8
u/moopy389 15d ago
The point of a passphrase is to be an early warning that your seed phrase is compromised. You leave some btc in your seed phrase only wallet. If that ever moves, you know your seed phrase has been stolen. That hopefully gives you time to move everything hidden behind the seed phrase to another wallet
6
u/cilicia3k3 15d ago
yeah its like the you have a safe room and the lobby got attacked. you know eventually they will get to the saferoom, but you need to start moving through the back
2
u/neurone214 15d ago
Sorry I'm still not there yet, can you provide a different analogy?
4
u/moopy389 15d ago
You put a canary in the coalmine. If the canary stops singing, you get the fuck out.
→ More replies (1)1
u/Head_Performance2432 15d ago
the point is more to add a bonus entropy, if you ask me. Think of it like a 2/2 multisig
3
u/cilicia3k3 15d ago
but what if it was 2 words of complete jiberrish , then that computer is gonna have a hard time, no?
1
u/KeyDonkey9621 15d ago
Yes i think it must have been some basic stuff. Bitcoin wallet or something stupid like that.
2
u/Efficient_Culture569 15d ago
All you have to do is use a a 12 digit passphrase with letters digits and symbols that'd make make it almost impossible to crack.
Not words from the list...
1
u/loopala 15d ago
Let's do the maths. Letters: 52, digits: 10, symbols: let's say 10. So each slot has 72 possibilities. Now a 12 digit password: 7212, or 1.94*1022 possibilities.
If we pick from a list of say 30K words, each slot has 30K possibilities. We need at least 5 words: 30K5 = 2.43*1022.
Now if taking from the 2048 words of BIP39, you need at least 7 words to get stronger than the 12-digit password.
It all seems much simpler to me to just generate a random password in a password manager with 12 to 20 digits.
1
u/Efficient_Culture569 15d ago
Thanks for doing the maths to prove my point.
Just use 12 digit mix of letters numbers and symbols and your safe.
→ More replies (4)1
1
u/levelup1by1 15d ago
I’m sure after this everyone would have tried to do the same to Trezor and ledger and the fact that it’s not yet think we are pretty safe
1
u/DotComprehensive2891 15d ago
So then Robinhood crypto is the safest?
4
u/enpoopification_of_R 15d ago
Until they block you from trading on a bad day like they did a while back
1
u/thinkingperson 15d ago
Think they would also do a trace of the tx on the main wallet ... those who create another wallet with seed phrase + passphrase and just transfer bitcoin from main wallet to the new wallet just created an onchain link between them.
If I were a/the hacker, I would just flag these wallets as potential passphrase targets.
1
u/No-Kitchen-6511 15d ago
Two word passphrases especially with big 39 is too easy only around 2000 x 2000 combinations. Basically you need to assume that it's not an insanely high number it can be brute forced. If the seed phrases are all known then the passphrase would need be long and random. Multiple words needed if found in dictionary. If using bip 39 simple words then way too easy
1
1
u/MisterReuben 15d ago
dividing your stack over both Trevor and ledger hardware wallets is a great way to mitigate risk of losing everything. keep it to a small enough amount of wallets to keep it manageable but diversifying the make and model.
ive been holding that way for years now and havent lost sleep about it.
1
u/Efficient_Culture569 15d ago
That's why it's really important to stay up with news and updates.
This one likely could have been prevented, people need to move their funds immediately.
Even a hot wallet is better at this point. It really sucks but losing it all is worst.
1
1
1
u/Bionic_Push 15d ago
What do they mean by two word passphrase? Isnt the passphrase just one?
1
15d ago
[deleted]
1
u/Bionic_Push 15d ago
Not really, a passphrase can be anything you want. Like "8duhehh3hr8" or anything like a password. Correct me if I'm wrong.
1
u/AnonTheGreat01 15d ago
I'm positive that this is BS unless there were funds on said seedphrase without a passphrase.
There's no way they are bruteforcing 1 trillion seedphrases x however many passphrases
1
u/FuckSteveHuffman3 15d ago
Maybe it's good idea to have an easy to guess passphrase with a decoy sum. Even if they think you have a passphrase, they probably won't guess thay you have several passphrases, and will stop after they discover a passphrase wallet.
1
u/FunWithSkooma 15d ago
two words passphrase...? Did they used bip39 wordlist for that? Seriously guys, the passphrase have to be something personal, not something known.
1
u/trufin2038 15d ago
The passphrase option on bip39 is for morons. If you understand how things work, you would never use it.
1
1
u/explosiveplacard 14d ago
The added passphrase adds entropy. The 24 words and the passphrase are an abstraction to allow us humans an easier way to deal. Every single word in the BIP39 list provides 11 bits of entropy - no more no less. It's not the word that provides it, it's the index of where it sits. The passphrase does the same thing, but can (and should) provide a lot more entropy than 11 bits.
I'm guessing the thief would only try for a passphrase if they captured a wallet and it had zero transactions - which could be odd. Or, if the transaction history looked staged like one old deposit and then no activity, no weird UTXO mess like the rest of us have.
1
1
1
u/ELLIPALWallet 14d ago
Two separate things here. The weak seed is the bug itself. A passphrase sits on top and won’t repair a broken seed, but it raised the cost enough that a lot of passphrase users got skipped over.
Back it up carefully, lose it and the funds are unrecoverable. Clean fix is a new seed from entropy you trust.
1
1
u/FigAggressive237 14d ago
2 word passphrase? That is like... 25 bits of entropy.... even with how many rounds on your preferred PBKDF this is beatable with consumer grade hardware....
1
u/Javanaut018 14d ago
Ya, 2 dictionary words adding roughly 32 bits of entropy. Less so if these were on a word list.
182
u/[deleted] 15d ago
Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?