COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: whether a passphrase protects an affected COLDCARD seed

reddit-passphrase-vulnerable-question

https://www.reddit.com/r/Bitcoin/comments/1vdzo8p/coldcard_seed_passphrase_could_be_vulnerable_as/

Latest reviewed change

source content difference between and

A new comment dismissed state-actor attribution by saying the stolen amount is peanuts to major governments.

seen +8 -0 full history below
 edited: false
 body:
 no. it can be anything including spaces and special characters.  also an empty passphrase is also valid, which is what you're effectively using  when you use the seed phrase without an additional passphrase.
+
+comment: p2kba5n
+parent: t1_p1elhar
+author: Suibeam
+created_utc: 1786237625

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
9
Detected differences
9
Unreviewed
0
Copies held
10

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    A new comment dismissed state-actor attribution by saying the stolen amount is peanuts to major governments.

    seen · Captured here 68,883 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     no. it can be anything including spaces and special characters.  also an empty passphrase is also valid, which is what you're effectively using  when you use the seed phrase without an additional passphrase.
    +
    +comment: p2kba5n
    +parent: t1_p1elhar
    +author: Suibeam
    +created_utc: 1786237625
    +edited: false
    +body:
    +Why would the US government do this lol. That money is peanuts for countries like USA, China and Germany.
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    The thread gained a new comment explaining that a passphrase can include spaces and special characters and that an empty passphrase is valid when the seed is used without an additional passphrase.

    seen · Captured here 68,680 chars
    What changed from the previous capture 8 lines
     Add in mixed case, a few numbers and symbols, and it's basically uncrackable. 
     
     People seem to think passphrases are just ok security but you can have a passphrase with as much if not more security as the 24 word seed.
    +
    +comment: p2ftz5n
    +parent: t1_p1f5nh3
    +author: TechnologyGrouchy679
    +created_utc: 1786186596
    +edited: false
    +body:
    +no. it can be anything including spaces and special characters.  also an empty passphrase is also valid, which is what you're effectively using  when you use the seed phrase without an additional passphrase.
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +10 -0

    The thread gained a comment asserting that a mixed-case passphrase with numbers and symbols can provide security comparable to or greater than a 24-word seed.

    seen · Captured here 68,362 chars
    What changed from the previous capture 10 lines
     edited: false
     body:
     I'll hazard a guess and say yes, but who knows what this guy was using. All I heard about his passphrase was "two words". 
    +
    +comment: p1vhwon
    +parent: t1_p1dzv08
    +author: read_more_comments
    +created_utc: 1785944135
    +edited: false
    +body:
    +Add in mixed case, a few numbers and symbols, and it's basically uncrackable. 
    +
    +People seem to think passphrases are just ok security but you can have a passphrase with as much if not more security as the 24 word seed.
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +12 -62

    A series of comments by one participant was removed or replaced with deleted-account placeholders, withdrawing opinions about passphrase strength, wallet trust and seed-generation risks.

    seen · Captured here 68,035 chars
    What changed from the previous capture 74 lines
     
     comment: p1dd68m
     parent: t1_p1d86u9
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785723435
     edited: false
     body:
    -people often recommend putting dust on the main account, and that just helps identify the account as likely having a passphrase assocated with it.
    +[deleted]
     
     comment: p1ddd9f
     parent: t1_p1dbbny
     
     comment: p1ddf0w
     parent: t1_p1dc2z3
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785723522
     edited: false
     body:
    -> Trezor and Ledger both use a TRNG that combines true randomness from the environment of a secure element chip
    -
    -at this point, i think its safer to claim allegedly, because you don't know with any certainty that any wallet maker is doing random properly unless you can see the src code and verify what you are running has that in place. 
    -
    -Best to assume nothing is safe and be paranoid about your security.
    +[deleted]
     
     comment: p1ddhws
     parent: t1_p1d86nl
     
     comment: p1ddkvx
     parent: t1_p1d86u9
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785723580
     edited: false
     body:
    -people often recommend putting dust on the main account, and that just helps hackers identify the account as likely having a passphrase associated with it.
    -
    -far easier to scan those for weak passphrases than billions of empty accounts that may not have ever been used.
    +[deleted]
     
     comment: p1ddm36
     parent: t1_p1da89o
     edited: false
     body:
     Stupid FUD. Where's the proof?
    -
    -comment: p1de315
    -parent: t1_p1d6ya1
    -author: OldHamburger7923
    -created_utc: 1785723760
    -edited: 1785723971
    -body:
    -wrong. There is a massive difference between using a password of admin123 and a random 20 character string.
    -
    -It's only as secure as you make it. Hackers have no throttle when cracking accounts, so they can scan as fast as their computers can process. One of the first things they'll do is use dictionary words, combinations of dictonary words, leaked password files (never reuse a pass) letter and number substitutions (0 and o, i l and 1, etc), camel case, and so on. They can't try every combination on your account, it would take thousands of years and they won't know if you even have a passphrase account there to crack. So it's all rapid scanning of easy to crack seeds and passphrases and move on to the next.
    -
    -What we are seeing is people who have weak security losing funds.
    -
    -Your passphrase can be as secure as the seed itself.
     
     comment: p1dem4v
     parent: t1_p1dd5sp
     
     comment: p1djtnz
     parent: t1_p1dfp2b
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785725866
     edited: false
     body:
    -ask yourself what you'd say about coldcard last week if someone asked you the same thing. I bet you'd say its secure, its open source, etc.
    -
    -Even if you scan a wallet's codebase right now along with 100 security researchers, there could be bugs in the code you didn't identify, that no one else identified, that no one will find for years.  That's just how it is.
    -
    -Also any wallet with a hardware chip is not going to have its source available even if the rest of the firmware is open source. 
    -
    -This stuff all works with hindsight, but you can't know whats coming up.
    +[deleted]
     
     comment: p1dk14d
     parent: t1_p1demao
     
     comment: p1e62bs
     parent: t1_p1e4svr
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785735391
     edited: false
     body:
    -What if it's designed to look random but it isn't? Don't think just bugs, think backdoor. Google kleptogrum PRNG, but there are other ways to do it too.
    +[deleted]
     
     comment: p1e6ge2
     parent: t1_p1dd68m
     This is why cryptography is fascinating to me, I cannot wrap my head around how you can fake entropy 
     
     But I'm reading about it now
    -
    -comment: p1e6xbg
    -parent: t1_p1e6ge2
    -author: OldHamburger7923
    -created_utc: 1785735810
    -edited: false
    -body:
    -I usually do a test transaction on the main account but I didn't when I setup my jade. I also started being worried about RNG and generated my own seed because I'm paranoid like that. The stuff with ledger offering cloud seed exports made me think this space is crowded with absolute morons. Don't trust them 
    -
    -comment: p1e71rb
    -parent: t1_p1e6nm2
    -author: OldHamburger7923
    -created_utc: 1785735870
    -edited: false
    -body:
    -It's not just you, humans are not designed to understand large numbers. We never encountered a need for it with our ancestors.
     
     comment: p1e7pqw
     parent: t1_p1di6l1
     
     comment: p1ez3fz
     parent: t1_p1ex8ex
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785749956
     edited: 1785750481
     body:
    -You can backdoor it so the results appear random, eg; kleptogrum PRNG attack. Applicable to closed source especially.
    +[deleted]
     
     comment: p1ezxfg
     parent: t1_p1dqf6m
     edited: false
     body:
     they were able to reverse engenieer the results from the coldcard bug. So they have a startingpoint from which to build their attack.
    -
    -comment: p1g8g6m
    -parent: t1_p1ek5zg
    -author: OldHamburger7923
    -created_utc: 1785766248
    -edited: false
    -body:
    -I know someone who's been buying BTC since the beginning and he rolled his own wallet. He isn't worried. I'm also not worried about self custody. A wallet with a properly random seed is not at risk. The issue though is for Joe Average out there. It's already painful to use bitcoin, this makes it much worse. People's perception on the security they have has been shattered to some degree. On the flip side, people are sheep and since it didn't affect them, they don't seem to care - look at how many people are now shilling Ledger as an example of a secure wallet. As if having firmware with seed export to the cloud is something that we should proclaim a good idea.
     
     comment: p1g8oh2
     parent: t1_p1eqqsm
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +32 -0

    The Reddit thread gained 4 new comments.

    seen · Captured here 72,052 chars
    What changed from the previous capture 32 lines
     edited: false
     body:
     Apparently these guys cared a lot. I’m with you, just get what works the best. It’s just that a lot of these people deliberately ignored companies like Trezor because it wasn’t cypherphunky enough for them.
    +
    +comment: p1p2kfb
    +parent: t3_1vdzo8p
    +author: Javanaut018
    +created_utc: 1785866533
    +edited: false
    +body:
    +Ya, 2 dictionary words adding roughly 32 bits of entropy. Less so if these were on a word list.
    +
    +comment: p1p2zi0
    +parent: t1_p1ixvd7
    +author: Javanaut018
    +created_utc: 1785866639
    +edited: false
    +body:
    +Smart thought...
    +
    +comment: p1p45hw
    +parent: t1_p1d8pcq
    +author: Javanaut018
    +created_utc: 1785866927
    +edited: false
    +body:
    +Are there really people using bip-39 words as passphrase anywhere?
    +
    +comment: p1p4ktr
    +parent: t1_p1p45hw
    +author: so7ow
    +created_utc: 1785867033
    +edited: false
    +body:
    +I'll hazard a guess and say yes, but who knows what this guy was using. All I heard about his passphrase was "two words". 
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +2 -2

    An existing Reddit comment was edited or removed.

    seen · Captured here 71,351 chars
    What changed from the previous capture 4 lines
     
     comment: p1d86u9
     parent: t1_p1d6yjj
    -author: SmokeAndSkate
    +author: [deleted]
     created_utc: 1785721651
     edited: false
     body:
    -Could be that the wallet without passphrase showed some previous activity. Those wallets are more likely to have a passphrase wallet associated. 
    +[deleted]
     
     comment: p1d88d4
     parent: t3_1vdzo8p
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 71,491 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     2 word passphrase? That is like... 25 bits of entropy.... even with how many rounds on your preferred PBKDF this is beatable with consumer grade hardware....
    +
    +comment: p1oqhwz
    +parent: t1_p1e3666
    +author: Candid-Walk-6762
    +created_utc: 1785863569
    +edited: false
    +body:
    +Apparently these guys cared a lot. I’m with you, just get what works the best. It’s just that a lot of these people deliberately ignored companies like Trezor because it wasn’t cypherphunky enough for them.
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +9 -3

    1 new Reddit comment was posted, including FigAggressive237.

    seen · Captured here 71,178 chars
    What changed from the previous capture 12 lines
     created_utc: 1785743657
     edited: 1785842462
     body:
    -Saffron ribbon paddle noodle breezy kettle
    -
    -This post was anonymized with Redact.dev
    +[removed]
     
     comment: p1emwu7
     parent: t1_p1elhar
     edited: false
     body:
     ledger leaked their customers' information, twice. And their source isn't fully open
    +
    +comment: p1npysk
    +parent: t3_1vdzo8p
    +author: FigAggressive237
    +created_utc: 1785854250
    +edited: false
    +body:
    +2 word passphrase? That is like... 25 bits of entropy.... even with how many rounds on your preferred PBKDF this is beatable with consumer grade hardware....
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +38 -12

    4 new Reddit comments were posted, including Apprehensive-Sky9723,Nur_2018,ballistua.

    seen · Captured here 70,989 chars
    What changed from the previous capture 50 lines
     
     comment: p1emo47
     parent: t3_1vdzo8p
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785743657
    -edited: false
    -body:
    -I've been clowned for saying that adding a passphrase isn't enough. Womp womp.
    +edited: 1785842462
    +body:
    +Saffron ribbon paddle noodle breezy kettle
    +
    +This post was anonymized with Redact.dev
     
     comment: p1emwu7
     parent: t1_p1elhar
     body:
     [deleted]
     
    -comment: p1fr99c
    -parent: t1_p1dh7ke
    -author: anon1880
    -created_utc: 1785761184
    -edited: false
    -body:
    -passphrase was : hello kitty
    -
     comment: p1frb83
     parent: t1_p1fr0ya
     author: Bionic_Push
     Two separate things here. The weak seed is the bug itself. A passphrase sits on top and won’t repair a broken seed, but it raised the cost enough that a lot of passphrase users got skipped over.
     
     Back it up carefully, lose it and the funds are unrecoverable. Clean fix is a new seed from entropy you trust.
    +
    +comment: p1mhrvg
    +parent: t1_p1dcv61
    +author: Apprehensive-Sky9723
    +created_utc: 1785840151
    +edited: false
    +body:
    +Bluewallet is a hot wallet. Company behind blue wallet not doing many updates, no forum to discuss things. The issue is here - how did you generate your seed phrase.
    +
    +comment: p1mu464
    +parent: t3_1vdzo8p
    +author: Nur_2018
    +created_utc: 1785844865
    +edited: false
    +body:
    +Fuck!
    +
    +comment: p1ndi6g
    +parent: t1_p1ddr5h
    +author: ballistua
    +created_utc: 1785850863
    +edited: false
    +body:
    +pass the code through AI, now you have checked the code
    +
    +comment: p1ndrbo
    +parent: t1_p1e4zk1
    +author: ballistua
    +created_utc: 1785850934
    +edited: false
    +body:
    +ledger leaked their customers' information, twice. And their source isn't fully open
    
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. Earliest copy held
    seen · Captured here 70,397 chars
    Extracted text as captured
    post: 1vdzo8p
    author: cheesymod
    created_utc: 1785720743
    title: Coldcard seed + passphrase could be vulnerable as well
    
    comment: p1d6rm5
    parent: t3_1vdzo8p
    author: ImprovementSweaty188
    created_utc: 1785721153
    edited: false
    body:
    Jesus Christ.
    
    comment: p1d6ya1
    parent: t3_1vdzo8p
    author: PoeCollector
    created_utc: 1785721218
    edited: false
    body:
    Sorry to hear. Assuming this is true, it shows why I've always believed passphrases were overrated. They have their uses, but what matters is the total entropy. Adding a 25th word might buy you some time if you already know your seed is compromised, but that's about it.
    
    comment: p1d6yjj
    parent: t3_1vdzo8p
    author: CosmicCommute
    created_utc: 1785721220
    edited: false
    body:
    Can you explain how an attacker would know to even try to brute force the passphrase to begin with? Like if they discover an empty wallet, why would they even try to brute force the passphrase instead of moving on?
    
    comment: p1d773s
    parent: t3_1vdzo8p
    author: TheBestintheWest11
    created_utc: 1785721303
    edited: false
    body:
    omg.... we're fcked 
    
    comment: p1d7iun
    parent: t3_1vdzo8p
    author: Over_Regular_6897

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.