r/coldcard: whether a 25th word passphrase protects Mk3 users
reddit-passphrase-save-mk3
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vcpdux author: bje332013 created_utc: 1785595816 title: Will having a '25th word' / passphrase save MK3 users? body: It was recently announced that Coldcard users who trusted the device's random number generator to generate their seed phrase ended up with seed phrases that are non-random enough that hackers could predict them and drain the wallets of Coldcard users. This is VERY similar to the very recent fiasco re: the SecondFi desktop wallet software for Cardano. That's because, in both cases, the problem had to do with random number generation being too predictable. So here's my question: **If a user** relies on a random number generator that is faulty, but **adds a 25th word / passphrase to the not-so random seed phrase, is that wallet still unsafe** or at risk of being drained? comment: p12ylwm parent: t3_1vcpdux author: bitusher created_utc: 1785596945 edited: false body: > but adds a 25th word / passphrase to the not-so random seed phrase, is that wallet still unsafe This is a horrible term Ledger started marketing which confuses many new users into believing the 25th word passphrase is a single word. Passphrases = **multiple** words , passwords = often single words+extra characters, pins = small set of numbers The extended passphrase should be at least 6-8 random words at minimum to be secure. There is another problem here with that term as well, it insinuates that users should keep the extended passphrase backed up with the existing 24 seed words because its simply another "word" needed to recover the wallet along with the other words (12 to 24) which is incorrect. The extended passphrase would be backed up but kept separately from the 12 to 24 word backup seed. Also there is a third problem with that term as it insinuates that there are only 24 word seed backups and the extended passphrase is the "25th word" which is also wrong. Seed word backups can be 12, 15, 18, 20, 21, or 24 , with 12 being the most common. You are safe temporarily as long as your passphrase is not weak or a "25th word" but should still eventually migrate over to a new seed regardless. comment: p134kza parent: t3_1vcpdux author: stay_safe_and_calm created_utc: 1785598691 edited: false body: The entropy of the additional passphrase must be really high to be safe!!! That means at least 20 random characters upper and lower cases, numbers and even special characters if you want. Just choosing 2 or 3 normal words is not enough because the human languge has only about 12,000 unique words which is a really low entropy ! But keep in mind that the risk is always that you forget this passphrase and then you are screwed. So please(!) write down your passphrase at least three times on different pieces of paper and do at least two small test transactions of receiving and spending before sending large amounts to it!!! You should also write down the fingerprint of this passphrase wallet. You could also create 3 different wallets with three different passphrases in order to spread the risk that one of them gets hacked. ... But then you have to keep 3 passphrases and the (comprromise) seed.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.