What security? Bitcoin enthusiast cracks known 12-word seed phrase in minutes

Share This Post

If the words of a 12-word seed phrase are known, it’s deceptively easy to enter the wallet and sweep the funds.

A systems architect cracked a seed phrase and won a 100,000 Satoshi bounty, or 0.001 Bitcoin (BTC), worth $29, in just under half an hour. Cointelegraph spoke to Andrew Fraser in Boston, who underscored how critical it is to keep a Bitcoin wallet seed phrase secure and offline. 

A seed phrase or recovery phrase is a string of random words generated when a wallet is created that can access the wallet, similar to a master key. Fraser brute forced a 12-word seed phrase that Bitcoin educator “Wicked Bitcoin” shared on Twitter:

As shown, Wicked’s Tweet challenged users to decipher the correct order of the 12-word seed phrase.

“Anyone wants to try and brute force this 12-word seed phrase securing 100,000 sats? I’ll give you all 12 words but in no particular order. Standard derivation path m/84’/0’/0’…no fancy tricks. GL.”

It took just 25 minutes to unlock the 100,000 Satoshis–or just under $30. The incident serves as a timely reminder for Bitcoin users and crypto enthusiasts to take crypto security seriously.

Fraser cracked the code using BTCrecover, a software application available on GitHub. The software offers a range of tools that can determine seed phrases with missing or scrambled mnemonics and passphrase-cracking utilities. Over Twitter DMs, Fraser told Cointelegraph:

“My gaming GPU was able to determine the correct order of the seed phrase in about 25 minutes. Though a more capable system would do it much faster.”

He noted that anyone with a basic knowledge of running Python scripts, using the Windows command shell, and understanding the Bitcoin protocol–particularly BIP39 mnemonics– should be able to replicate his success.

Cointelegraph queried Fraser about the security of 12-word seed keys. Fraser explained they are “perfectly secure if the words remain unknown to an attacker or there is a passphrase ’13th seed word’ used in the derivation path of the wallet.”

Moreover, he emphasized the superior security of 24-word seed keys.

“Even if an attacker knew the out of order words of your 24-word seed key, they would never stand a hope of discovering the correct seed.”

Fraser broke down the entropy calculations to explain the difference in security between the two types of seed keys. A 12-word seed has approximately 128 bits of entropy, while a 24-word seed boasts 256 bits. When an attacker knows the unordered words of a 12-word seed, there are only around half a billion possible combinations, which is relatively easy to test with a decent GPU. A 24-word seed, however, has roughly 6.24^24 possible combinations–and that’s a lot of zeros. 

Related: The worst places to keep your crypto wallet seed phrase

Even the probability of an attacker cracking a 12-word seed phrase is borderline absurd. 24-word seed phrases may be superior, but as Wicked points out in a post-mortem to the seed phrase challenge; “it’s not going to be hacked tbh.”

Ultimately, it’s a timely reminder to readers to ensure seed phrases are never published or shared online. That means a seed phrase should not be stored in a password manager, a cloud storage solution, and they certainly should not be typed out into a phone. 

Fraser also stressed the importance of keeping seed keys secret and to take advantage of a passphrase that functions as part of the derivation path. As for the 100,000 Sats Fraser took home? Fraser tweeted that he spent them on dinner that night: Chicken Marsala. Talk about circular economy. 

Cointelegraph Magazine: Bitcoin in Senegal: Why is this African country using BTC?

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Avalanche (AVAX) Rallies On Fed Rate Cut, DeFi Growth Boosts Long-Term Outlook

With its price climbing 17% over the past seven days, Avalanche (AVAX) has lately been on a winning run Right now, the cryptocurrency is trading at $2812, up 7% over the past 24 hours alone This

US Sentences Nigerian Darknet Fraud Leader to Five Years in Prison for $6M Scheme

A Nigerian national has been sentenced to five years in federal prison for his role in a massive darknet fraud scheme that intended to cause over $6 million in losses, according to the US Department

XRP Bullish Signal: Whales Go On $223 Million Buying Spree

On-chain data shows the XRP whales have gone on a large shopping spree recently, a sign that could be bullish for the cryptocurrency’s price XRP Whales Have Been Expanding Their Holdings

Bitcoin Approaches $65,000: Is Now The Perfect Time To Buy?

As Bitcoin price valuation inches closer to the $65,000 mark, the asset has grabbed the attention of market analysts, with one recently highlighting a key indicator that now suggests a potential

FATF Urges India to Strengthen Virtual Asset Regulation

India has achieved a high level of technical compliance with Financial Action Task Force (FATF) standards, addressing illicit finance, money laundering, and terrorist financing In a joint assessment

Bitcoin Bull Run Begins: Expert Points To Massive Upside Potential In Coming Months

The cryptocurrency industry could be gearing up for a remarkable cycle as a market expert has claimed that the long-awaited Bitcoin bull run is finally starting, pointing to a potential significant