Seed entropy analysis
Hardware wallet seed security
Entropy, possibilities & time to crack
Your seed phrase is only as strong as the randomness behind it. Below: effective entropy per device, how many possible seeds that produces, and how long a brute-force attempt would take at one billion guesses per second.
| Device / model | Effective entropy | Possibilities | Time to crack @ 1 billion guesses/sec | Where to buy |
|---|---|---|---|---|
Coldcard Mk3 (Affected) | ~40 bits | 1.1 trillion (1.1 × 10¹²) | ~9–18 minutes | Coldcard store → |
Coldcard Mk4 / Mk5 / Q (Affected) | ~72 bits | 4.7 sextillion (4.7 × 10²¹) | ~75–150 years | Coldcard store → |
Trezor 12-word / SLIP-39 | 128 bits | 3.4 × 10³⁸ | ~10²² years | Buy Trezor Safe 5 → |
Trezor 24-word | 256 bits | 1.16 × 10⁷⁷ | Many times longer than the age of the universe | Buy Trezor Safe 7 → |
Ledger (all models) | 256 bits | 1.16 × 10⁷⁷ | Many times longer than the age of the universe | Buy on Ledger → |
"Affected" refers to Coldcard devices whose BIP-39 seed was generated on firmware shipped between March 2021 and July 2026, where seed generation fell back to a software PRNG instead of the hardware TRNG. Coinkite published a security advisory on July 30, 2026 after ~594 BTC was swept from dormant Mk3 wallets — see our security incidents archive.
How much harder to crack?
From 40 → 72 bits
~4.3 billion times harder
From 72 → 128 bits
~72 million times harder
From 128 → 256 bits
~3.4 × 10³⁸ times harder
Add a passphrase and the search space becomes absurd
A strong passphrase on top of a 256-bit seed multiplies the search space again. Even a mediocre 40–60 bit passphrase turns 256 bits into something completely out of reach for any conceivable attacker.
Key takeaway
40–72 bits can be brute-forced in minutes to years. 128 bits is already beyond practical. 256 bits is effectively unbreakable. If you generated a seed on an affected Coldcard firmware, migrate to a freshly generated 24-word seed and move your funds.