Skip to content
Archive

Post

Back to deliverables

Q QuintenFrancois
Quinten | 048.eth
@QuintenFrancois

Coldcard Mk3: ~40 bits of entropy
Coldcard Mk4/5/Q: ~72 bits of entropy
Trezor 12-word / SLIP-39: 128 bits of entropy
Trezor 24-word: 256 bits of entropy
Ledger (all models): 256 bits of entropy 40 bits: 1.1 trillion possibilities
72 bits: 4.7 sextillion
128 bits: 3.4 × 10³⁸
256 bits: 1.16 × 10⁷⁷ From 40 → 72 bits it’s about 4.3 billion times harder to crack
From 72 → 128 bits it’s another ~72 million times harder.
From 128 → 256 bits it’s another 3.4 × 10³⁸ times harder. Being generous, if a hacker can guess a billion seeds per second:
40-bit → found in ~9–18 minutes
72-bit → ~75–150 years
128-bit → ~10²² years
256-bit → many times longer than the age of the universe Add a strong passphrase on top of a 256-bit seed and the search space becomes even more absurd.

· 317 Views

replies reposts likes
1 replies collected
Quinten | 048.eth @QuintenFrancois · 224K

Why was the Coldcard failure possible, and why are Ledger & Trezor different? The issue wasn’t a faulty hardware chip. It was a software bug. Coldcard’s firmware was supposed to generate seeds using the device’s hardware random number generator. Instead, due to a silent fallback in the code, some devices used a much weaker software random number generator seeded from predictable values. As a result, seeds that should have contained 128 bits of entropy ended up with only about 40 or 72 bits. Ledger generates its seed inside a certified Secure Element using a hardware random number generator that is designed and evaluated for cryptographic use. Trezor also relies on a hardware random number generator and, on newer models, combines multiple entropy sources during seed generation. Its open source firmware has been extensively audited by the security community over many years.

1 1