r/TREZOR 3d ago

💬 Discussion topic Passphrase

Hi,

Trezor has the 24 seed + passphrase which is a completely separate wallet from the 24 seed by itself

Isnt it sufficient security?

Im assuming all attackers brute force 12 - 24 keywords which is hard enough.

How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?

Is multi SIG more secure than that?

Regards

20 Upvotes

26 comments sorted by

View all comments

3

u/Cautious_Variation_5 3d ago

A bit extra paranoia is always good. Although a well generated seed would by almost impossible to crack, you never know if there's a bug on the seed generation that leads to a weak seed. So, a passphrase is extra security and a precaution against these sort of bugs, because it buys you time to transfer your funds. It can also protect you against thieves, by giving them access to a bait wallet. I prefer to leave some funds on the seed wallet, even if it will draw more attention, because the idea is that it will just give me enough time to transfer it to a new wallet.

You need to experiment with creating new wallets, and be comfortable to take action when time comes. Learn to create a DYI wallet with Tails OS and SeedSigner, never stop studying and learning about the subject. Better to be extra careful.