r/Bitcoin: Jade owner asking if their seed is safe after the incident
reddit-jade-passphrase-safety
https://www.reddit.com/r/Bitcoin/comments/1veiiif/i_have_a_jade_plus_with_a_passphrase/
Latest reviewed change
source content difference between and
Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.
edited: false
body:
I am going to try with Parman’s method.
+
+comment: p1w1cse
+parent: t1_p1oa6we
+author: AggressiveGas4637
+created_utc: 1785948950
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 3
- Detected differences
- 3
- Unreviewed
- 0
- Copies held
- 4
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 39 lines
edited: false body: I am going to try with Parman’s method. + +comment: p1w1cse +parent: t1_p1oa6we +author: AggressiveGas4637 +created_utc: 1785948950 +edited: false +body: +> + As for adding a very weak passphrase as a trivial ornamental addition, no it doesn't add any value. + +I disagree here only because of stuff you yourself said earlier + +It’s good not to have your whole stack in one space, we agree there. + +12 word seed is enough, we agree there. 12 properly random generated words won’t get brute forced. You are functionally safe. + +So if I wanted to generate a second wallet, wouldn’t the absolute easiest way would be to put in my 12 mnemonic with a passphrase of “wallet2”? + +As you yourself state, no one’s gonna guess the twelve words. So the passphrase being weak isn’t relevant + +And remembering “wallet2” is a lot easier than remembering a new set of 12 words. That’s in alignment with your don’t over complicate things as that leaves room for error + +Agree with the stateless, use your 12 words as a passphrase. But since those 12 words aren’t guesssable (in your own words) I fail to see how the easiest and most efficient way to mentally make new wallets would be to continue to use your 12 phrase mnemonic, with passphrases for the extra wallets. + +Anyways I rolled a new wallet + +comment: p1wxf5k +parent: t1_p1w1cse +author: trufin2038 +created_utc: 1785956883 +edited: false +body: +As for a "second wallet" that's going to depend heavily on how you define wallet. If you define it as a bip33 key series, then the correct method to make a "new wallet" is to increment the wallet ID in the derivation path. Then you get a new base root and the key id's start at zero again, and they are cryptographically isolated because its a hard path separation. + +If you define a wallet as a separate address like some people do, then you get those automatically as you make transactions. + +If you mean different hardware&software, then you probably want a different root secret altogether to keep them fully separate. + +I honestly don't think there is any good case for the extra word feature whatsoever. Imo, it should not have been in the spec as is. At the very least if not left out entirely, it should follow the same rules as the mnemonic, being 12, 18, or 24 machine generated words.Extracted text as captured
post: 1veiiif author: AggressiveGas4637 created_utc: 1785774909 title: I have a Jade Plus with a passphrase body: Am i good? or should i roll a new wallet with coin flips? 24 word seed + a roughly 16 character alphanumeric symbol passphrase comment: p1he5yc parent: t3_1veiiif author: trufin2038 created_utc: 1785776977 edited: false body: Jade doesn't matter, and the passphrase doesn't help it only gives a false sense of security. What matters is how you generated the root mnemonic. Using dice or coin flips or a deck of cards is how its done. Anything less is blind trust. Bitcoiners don't do blind trust. comment: p1hj5aq parent: t1_p1he5yc author: AggressiveGas4637 created_utc: 1785778190 edited: false body: Yeah fair enough - the pass phrase certainly helps as it adds entropy but to your point I am blind trusting that Blockstream generated my mnemonic accurately just like the CC folks trusted CC to be doing that accurately…..guess I’ll get to rolling comment: p1hksde parent: t3_1veiiif author: GettingFasterDude created_utc: 1785778593 edited: false body: This only affects Coldcard wallets. comment: p1ho98h parent: t1_p1hksde author: AggressiveGas4637Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
Jade has a nice feature called stateless. I would recommend using that, and treating the mnemonic as your passphrase. Because that's what it is. People using passphrases often make mistakes, such as writing down the mnemonic or stamping it into metal etc. + +comment: p1uwy22 +parent: t3_1veiiif +author: Ok_Knowledge_4977 +created_utc: 1785938697 +edited: false +body: +I am going to try with Parman’s method.Extracted text as captured
post: 1veiiif author: AggressiveGas4637 created_utc: 1785774909 title: I have a Jade Plus with a passphrase body: Am i good? or should i roll a new wallet with coin flips? 24 word seed + a roughly 16 character alphanumeric symbol passphrase comment: p1he5yc parent: t3_1veiiif author: trufin2038 created_utc: 1785776977 edited: false body: Jade doesn't matter, and the passphrase doesn't help it only gives a false sense of security. What matters is how you generated the root mnemonic. Using dice or coin flips or a deck of cards is how its done. Anything less is blind trust. Bitcoiners don't do blind trust. comment: p1hj5aq parent: t1_p1he5yc author: AggressiveGas4637 created_utc: 1785778190 edited: false body: Yeah fair enough - the pass phrase certainly helps as it adds entropy but to your point I am blind trusting that Blockstream generated my mnemonic accurately just like the CC folks trusted CC to be doing that accurately…..guess I’ll get to rolling comment: p1hksde parent: t3_1veiiif author: GettingFasterDude created_utc: 1785778593 edited: false body: This only affects Coldcard wallets. comment: p1ho98h parent: t1_p1hksde author: AggressiveGas4637Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, by trufin2038, arguing for a Linux air gap and Jade's stateless mode.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 21 lines
If they used (for example) Claude Fable to analyse the source to find the flaw, they've had less than 2 months since it was released (June 9th re-release). Coldcard's own statement on this is that the attacker used a sufficiently advanced AI to find the flaw, and that CoinKite themselves have used advanced models to look through their source, and found nothing. + +comment: p1oa6we +parent: t1_p1kcmh6 +author: trufin2038 +created_utc: 1785859487 +edited: false +body: +If your jade is ever used for transactions, those have to go via some internet connected computer. That computer being Linux is key. + +If you are running an airgap in addition to a Linux, that is an additional level of security; but it's no substitute. It's something added on to a working system. a hardware wallet is generally a much inferior form of airgap backend than simply using another Linux tho. + +Also, the jade uses a camera for sneakernet, which is one of the least secure types of sneakernet. It's still an overall well designed system with a few little hitches, imo. + +As for adding a very weak passphrase as a trivial ornamental addition, no it doesn't add any value. If you do it perfectly, all you have done is make things slightly more complicated but not any more secure. + +Trezor often suggested passphrases, but that was due to a flaw in their design: you can extract the key from it physically. That in fact is a general flaw in all hardware wallets. Securing an offline key would require a passphrase at least as strong as the key itself...obviously making the whole storage redundant. Imagine a safe that only unlocks when it's contents are used as the key. + + +Jade has a nice feature called stateless. I would recommend using that, and treating the mnemonic as your passphrase. Because that's what it is. + +People using passphrases often make mistakes, such as writing down the mnemonic or stamping it into metal etc.Extracted text as captured
post: 1veiiif author: AggressiveGas4637 created_utc: 1785774909 title: I have a Jade Plus with a passphrase body: Am i good? or should i roll a new wallet with coin flips? 24 word seed + a roughly 16 character alphanumeric symbol passphrase comment: p1he5yc parent: t3_1veiiif author: trufin2038 created_utc: 1785776977 edited: false body: Jade doesn't matter, and the passphrase doesn't help it only gives a false sense of security. What matters is how you generated the root mnemonic. Using dice or coin flips or a deck of cards is how its done. Anything less is blind trust. Bitcoiners don't do blind trust. comment: p1hj5aq parent: t1_p1he5yc author: AggressiveGas4637 created_utc: 1785778190 edited: false body: Yeah fair enough - the pass phrase certainly helps as it adds entropy but to your point I am blind trusting that Blockstream generated my mnemonic accurately just like the CC folks trusted CC to be doing that accurately…..guess I’ll get to rolling comment: p1hksde parent: t3_1veiiif author: GettingFasterDude created_utc: 1785778593 edited: false body: This only affects Coldcard wallets. comment: p1ho98h parent: t1_p1hksde author: AggressiveGas4637Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1veiiif author: AggressiveGas4637 created_utc: 1785774909 title: I have a Jade Plus with a passphrase body: Am i good? or should i roll a new wallet with coin flips? 24 word seed + a roughly 16 character alphanumeric symbol passphrase comment: p1he5yc parent: t3_1veiiif author: trufin2038 created_utc: 1785776977 edited: false body: Jade doesn't matter, and the passphrase doesn't help it only gives a false sense of security. What matters is how you generated the root mnemonic. Using dice or coin flips or a deck of cards is how its done. Anything less is blind trust. Bitcoiners don't do blind trust. comment: p1hj5aq parent: t1_p1he5yc author: AggressiveGas4637 created_utc: 1785778190 edited: false body: Yeah fair enough - the pass phrase certainly helps as it adds entropy but to your point I am blind trusting that Blockstream generated my mnemonic accurately just like the CC folks trusted CC to be doing that accurately…..guess I’ll get to rolling comment: p1hksde parent: t3_1veiiif author: GettingFasterDude created_utc: 1785778593 edited: false body: This only affects Coldcard wallets. comment: p1ho98h parent: t1_p1hksde author: AggressiveGas4637Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.