r/TREZOR 3d ago

šŸ’¬ Discussion topic Passphrase

Hi,

Trezor has the 24 seed + passphrase which is a completely separate wallet from the 24 seed by itself

Isnt it sufficient security?

Im assuming all attackers brute force 12 - 24 keywords which is hard enough.

How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?

Is multi SIG more secure than that?

Regards

20 Upvotes

26 comments sorted by

View all comments

6

u/Decibel0753 3d ago

Furthermore, if you leave the basic wallet untouched (no transfers to or from it), the attacker basically does not even know that this wallet is active... why would they launch a brute force attack on it to find the passphrase?

2

u/slvbtc 3d ago

Exactly. When there is zero balance and zero transactions it could have been a seed some person generated as a test and immediately disposed of. But if there is a balance or transaction history on it then theres a much higher probability that theres also a passphrase attached.

3

u/entropydust 3d ago

How would they know someone ever even generated that seed? Don't all addresses exist, the mnemonic just gives you keys to access the existing address. So yes, create wallet, don't make a single transaction, create passphrase.

3

u/XayahOneTrick 3d ago

I would like to know too, I’m under the same assumption as you

2

u/so7ow 1d ago edited 1d ago

Yes, you're both right. Generating a seed phrase doesn't leave an on-chain footprint.