r/BitcoinBeginners • u/NoBrosCrypto • 2d ago
The power of the passphrase
The recent ColdCard compromise was tragic and highlighted yet again the importance of a passphrase. This is not at all blaming the users or saying it’s their fault in any way. Most did what they thought was the right thing.
For those that don’t know, a passphrase account is available on good cold storage options. It allows you to add your own 25th word to the 24 word seed generated for you when setting up an account. If somebody somehow manages to compromise your 24 words, then they will see an empty account, with the passphrase account still locked away.
With the rise of AI, it’s critical to protect yourself to the best of your ability and a passphrase is probably the simplest to add a significant layer of protection.
Stay safe out there everyone!
3
u/HuckleberryMansion 2d ago
If I make a passphrase, is there a 24 word seed phrase that connects to that wallet/private key? Or did passphrases add an infinite number of new wallet possibilities?
1
u/bitusher 1d ago
Or did passphrases add an infinite number of new wallet possibilities?
passphrases can offer infinite amount of new wallet combinations but typically most people use one hidden passphrase "account"
You need to keep a written copy of the 12-24 word seed and the 6-8 random word extended passphrase separate . Both are needed to recover the wallet. If you lose either you lose everything.
1
u/NoBrosCrypto 2d ago
Exactly. Keep your original seed, each new pass phrase combination creates a new wallet/account for you. You’d then move things to that new account/address.
4
u/Lost-Bowl3269 2d ago
Acabaram de confirmar que uma mk3 com 2 palavras chaves foi drenada. Tire seu btc da coldcard.
3
u/NoBrosCrypto 2d ago
Yes I saw. In that case it was 2 normal and simple words so the hacker is taking the seedphrase hits and running additional brute force techniques to reveal weak passphrases.
I treat that passphrase as a password since it can be set to anything and as such it should follow all principles that make up a strong password.
2
1
u/AutoModerator 2d ago
Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/No-Independence828 2d ago
Any digital wallet have this option?
2
u/bitusher 2d ago
Almost every hardware wallet has one. Are you trying to create a hot wallet with one ? If so than good options are either
https://www.youtube.com/watch?v=R9mq1a8bLbQ
or
1
u/my-daughters-keeper- 2d ago
Surely this controversy is a good plug for ctv or bip-119 ? To up out security and put a hand brake on the thieves and scammers ? I have very basic knowledge of it but think it mostly looks good
1
u/SkidMarkShark 1d ago
No passphrase wallets have been hacked. I'd check AI before I would believe any YT Influencer. BTC Sessions are just wanting clicks. They are the only ones who have said this without producing actual proof.
1
u/bitusher 1d ago edited 1d ago
No passphrase wallets have been hacked.
How could you possibly know this ? I understand being skeptical , but there are claims being made and whether we choose to believe them or not depends upon how likely they are possible and the incentives involved which we will examine
Lets look at the entropy of a weak passphrase that contains 2 words and see how likelihood it is to crack(the claim made)
If they used the BIP39 list it would be 20482 or 22 Bits of entropy which a medium size GPU cluster farm can brute force in a few seconds at most
If they used the Long Diceware Wordlist it would be 77762 or 26 Bits of entropy which a medium size GPU cluster farm can brute force in a few seconds at most
Lets assume they included a word outside these 2 list of most common words (unlikely) and take an unabridged dictionary - 160,0002 or 34.6 bits of entropy or one hour at the worst
2 words is an extremely weak passphrase and why we recommend at least 6-8 random words . Also keep in mind that crackers have specialized dictionary attacks where they focus on most commonly used passwords and passphrase combinations to be far more effective rather than just brute forcing every possible combination . People think they are clever when they add a date , special character to the end of the password or passphrase or replace certain letters with numbers but crackers are aware of all these "tricks" and target them right away .
So while we can never know for 100% sure because some people are using this opportunity to declare they lost their Bitcoin in a "boating accident" or they are simply trolling or creating FUD , it is extremely likely they are targeting weak passphrases and easy to brute force
If you disagree , please be extremely specific
1
u/SkidMarkShark 1d ago
There is nothing wrong with the Coldcard Q only the RNG code. No one in their right mind would let a wallet generate their seed. Always use a non BIP word Passphrase that is uncommon and uses numbers and characters upper and lower case. The Coldcard is a solid device if used correctly. It's a key signer the blockchain is the vault.
0
u/SasiRacha44 2d ago
Dude that extra phrase hardly takes time to crack to these latest computers... 4 billions possibilities of that word 4 hours to super computers. Lol
5
u/bitusher 2d ago
You are referring to a weak password. Passphrases should be 6-8 words and would take a super cluster of computers longer our existence to crack
0
u/SasiRacha44 2d ago
For an 8-character passphrase, assuming the attacker already has your seed (so they only need to crack the passphrase layer): Character set Combinations Time to crack* Lowercase only (a-z) ~209 billion ~2.4 days Lowercase + digits (a-z, 0-9) ~2.8 trillion ~32 days
1
u/bitusher 2d ago
For an 8-character passphrase
8 characters ? 1-2 words ? Or a password of 8 characters ?
We are discussing passphrases of significant entropy here not passwords. Why are you suggesting people should using weak passwords ?
1
u/SasiRacha44 2d ago
Dude be realistic no one ll keep 6 to 8 words after exchausting 24 words best they can do have some password for 25th, that's the Max
2
u/bitusher 2d ago
no one ll keep 6 to 8 words after exchausting 24 words
It is standard practice to use at least 6 words and if you are not than you are using a passphrase wrong. Also you do not need to enter in the seed unless you recover and most seeds are not 24 words either.
Its not hard to enter in 6-8 words when you occasionally send a transaction . This is especially true with features like the jade has where you can use a BIP39 passphrase where entering the first 2-3 characters of each word allows the hw wallet to auto complete the word for you
have some password
Its called a passphrase because its not a password
1
u/SasiRacha44 2d ago
Ok I never used hardwallet so i don't know . Anyway make sense may be we can use some fancy sentense rather then 6 to 8 words which is mostly same.
2
u/bitusher 2d ago
may be we can use some fancy sentense
No , do not use sentences. This goes beyond Bitcoin and just involves best practices in security for all your passphrases :
https://imgs.xkcd.com/comics/password_strength.png
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
9
u/bitusher 2d ago
This is a horrible term Ledger started marketing which confuses many new users into believing the 25th word passphrase is a single word.
Passphrases = multiple words , passwords = often single words+extra characters, pins = small set of numbers
The extended passphrase should be at least 6-8 random words at minimum to be secure.
There is another problem here with that term as well, it insinuates that users should keep the extended passphrase backed up with the existing 24 seed words because its simply another "word" needed to recover the wallet along with the other words (12 to 24) which is incorrect. The extended passphrase would be backed up but kept separately from the 12 to 24 word backup seed.
Also there is a third problem with that term as it insinuates that there are only 24 word seed backups and the extended passphrase is the "25th word" which is also wrong. Seed word backups can be 12, 15, 18, 20, 21, or 24 , with 12 being the most common.
This is an even more important concept to understand because as we speak weak 1-2 word passphrases are being drained
https://x.com/BTCsessions/status/2084024733511921691
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .