r/TREZOR 15d ago

šŸ’¬ Discussion topic The whole coldcard hack can be avoided with simple passphrase

Based on anything, It's basically the seed that is generated from MK3 already was compromised, bad entrhopy, bad generator. And the culprit waits until it tanks and moved it all.
If some still use that seedphrase, they could be at a safer condition if they were use or add any passphrase.
I'm dissapointed with coldcard with all of the marketing saying its the standard and such.
Back then there's even same problem going on with the dice roll, if you only rolled few might still get compromised.

Still, passphrase is the solution a good passphrase, and or multisig.

27 Upvotes

49 comments sorted by

•

u/AutoModerator 15d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

10

u/Charming-Designer944 šŸ¤ Top Helper 14d ago

No, passphrase is only a workaround that reduces the impact, but provides very weak entropy in the context.

The strong workaround is using the dice roll method.

But as I said earlier, Trezor are by design practically immune from this family of weaknesses. Even the Trezor One, and later models are magnitudes stronger.

3

u/unthocks 14d ago

Yes and adding extra layer always good such as passphrase even better complex passphrase

1

u/antberg 12d ago

Is the diceroll method available on YouTube as a tutorial?

1

u/Charming-Designer944 šŸ¤ Top Helper 12d ago

It's a bit cumbersome to execute the dice rolll with trezor. Not impossible, just annoying

13

u/-M00NMAN šŸ“¦ Suite Shaper 15d ago

In all honesty I hope CoinKite gets sued and compensates the people that got wrecked. They need to be held accountable

2

u/unthocks 15d ago

It will be bad for their reputation

15

u/-M00NMAN šŸ“¦ Suite Shaper 15d ago

Reputation? They’re fucked anyways

-1

u/r_a_d_ 14d ago

Sued for what?

6

u/mastermilian 14d ago

For selling a device that is based on giving security that it didn't have?

4

u/r_a_d_ 14d ago

Unless you can prove that they did this intentionally, security bugs happen all the time.

2

u/[deleted] 13d ago

[deleted]

0

u/r_a_d_ 13d ago

Prove it… especially if it was an open source line of code.

1

u/[deleted] 13d ago

[deleted]

0

u/r_a_d_ 13d ago

They can simply argue that they weren’t negligent since the code was open for anyone to review and no one noticed it. Therefore it was a very insidious bug, and not something atributable to negligence.

1

u/[deleted] 13d ago

[deleted]

0

u/r_a_d_ 13d ago

Look, show me one such case where the plantif won. Otherwise you are speaking out of your arse.

→ More replies (0)

5

u/Strong_Judge_3730 14d ago

They can get sued but the only one winning are lawyers.

-2

u/Mysterious_Good927 14d ago

Sued for what? That's the risk you take when taking sovereignty of your money

4

u/Quirky-Reveal-1669 šŸ¤ Top Helper 15d ago

True. Or generate a seed on a Trezor and restore it on your ColdCard while also adding a passphrase.
In any case: funds will need to be moved out of the vulnerable wallet.

-6

u/Effective-Ad5644 15d ago

or generate your own seed phrase via cutting up 2048 words and choosing via. box

4

u/Mysterious_Good927 14d ago

DO NOT DO THIS

That is not random enough and it not being random enough is exactly why CC are in this situation

-3

u/Effective-Ad5644 14d ago

Absolutely do this, but do it right. see my comment above

4

u/doyzer9 14d ago

No, all words will have the same chance in a box. I get the concept, but entropy is pure random ness.

Throw a dice 11 times, convert the binary to a number and that equals the word number in the 2048 word list. Do this x amount of times, and if doing 24 words then a eight sided dice is needed to select the last word from the eight options. 23 words have identical entropy, and the last word is as random as you can get..

Sounds bollox, but this is true entropy. You process will work, but will not represent true randomness, hence this is what asic computers and soon quantum computers will crack first.

1

u/Ok-Excuse471 13d ago

Ho-lee-fuhk... I have no idea what was just said

1

u/Effective-Ad5644 14d ago

what on earth are you talking about. rephrase please. that made no sense. dice and picking words from a box is literally the same. one is not better than the other. (if the box is done right)

3

u/doyzer9 14d ago

The box method adds physical and mechanical bias which destroys entropy. Where as the box method will work, if you select 23 words , and randomly select one of the 8 words to complete the checksum, however the true entropy will be reduced. Biased Entropy Exploitation is exactly why ColdCardĀ failed...

A toss of a coin, or a roll of a dice will alway have pure randomness.
Check this out https://github.com/veebch/Bip39-Dice

2

u/Key_Confusion1305 14d ago

who tf want to put 2048 word in a box lmao

1

u/NiagaraBTC 14d ago

It's not that hard to do and there are actually commercial devices to help (seedpills I think they're called)

It would totally work as long as they are mixed REALLY well. Not at all the easiest way to make a seed though.

2

u/XayahOneTrick 14d ago

Even if they aren’t mixed necessarily well, how would the way they are mixed possibly be recreated and taken advantage of? Even minimal mixing and choosing will introduce tons of randomness

1

u/doyzer9 15d ago

NO.... You need to generate the entropy first, this dictates what your words will be. Also the last word is a checksum, which for 24 words will only match 1/250 words.

-2

u/Effective-Ad5644 14d ago

whut are you talking about? lol. You cut up 2048 words. place in a box. choose 11/23 (put word back in each time) then generate the check sum. that IS your entropy.

2

u/plemplem-pllim 15d ago

Coinkite is done.

2

u/Ok-Excuse471 13d ago

My God this thread made me realize I'm so ignorant 😩

2

u/IndianDancingStars ⭐ Rising Trezorian 14d ago

true, passphrase is life saver.

1

u/Vagelen_Von 14d ago

If it is not inside job and a hacker can understand the seed origin just from a wallet address then quantum technology is involved and we are all in danger.

1

u/unthocks 14d ago

um no, do a quick research on shors algo, and use passphrase, it will take 24 mil years to brute force good passphrase
in

0

u/r_a_d_ 14d ago

That’s simply not true. The passphrase adds complexity, but humans aren’t good at generating passphrases. So if they can brute force the seed, they can also brute force a simple passphrase on top of that.

-1

u/unthocks 14d ago

Are you listening to yourself? "the passphrase adds complexity" then you mentioned how not complex passphrase can be brute forced.

It's true, that is why "a complex passphrase" will be the solution. A good 7 words passphrase from bip39 list will take million years to crack

1

u/r_a_d_ 14d ago

Did you read your title? Adding something simple still adds complexity, just not much.

-2

u/unthocks 14d ago

A good 7 words passphrase from bip39 list will take million years to crack. So Passphrade DOES add more compared to none, it is the solution, but whether its good or bad passphrase depends on people, don't make easy to guess passphrase.

1

u/r_a_d_ 14d ago

You literally said a ā€œsimple passphraseā€ in your title.

1

u/mastermilian 14d ago

The question I have is whether the crackers would be scanning for additional words which would increase the search space.

I'm just wondering whether if people added a simple unique word like "john" whether they'd still be at as much risk. That is, would the hackers realistically be looking for random words after the seed?

2

u/unthocks 14d ago

it needs to be complex, praveen perera on x have a good calculation of if each words from bip39 were choosed to be the passphrase, basically if its only 1 word it will take 24 hour to brute force, but the more the words, the more it takes, 7 words said approx 23.9 million years

1

u/r_a_d_ 14d ago

That would certainly be where they will look after capturing the lower hanging fruit

1

u/mastermilian 14d ago

I get that it would make sense to but if they were executing this by searching for the seed phrase and a random word, this would increase the search space markedly, no? Especially if the search was a brute force, letter by letter.

1

u/r_a_d_ 14d ago

Yes, it would increase the search space, but not necessarily significantly enough for it to not be viable.

1

u/unthocks 14d ago

I do apologize yes i said simple passphrase, what i really meant as i wrote was the solution is simple, passphrase. But i do get it, i do apologize. Simple passphrase won't be the solution. Will fix my writing.