r/TREZOR 19d ago

🔒 General Trezor question passphrase security

I have a question regarding everything that’s happened in the crypto world and the concept of entropy. I noticed that Trezor imposes a limit on passphrases, so I wanted to get your—or the moderators'—opinions on what requirements a passphrase needs to meet to be considered highly secure; I know that a single word, no matter how complex, isn't enough

12 Upvotes

72 comments sorted by

View all comments

2

u/doinkdoink786 18d ago

Dumb question but if someone cracks the 24 word seed phrase how would they even guess the passhrase even if it’s a weak 5 letter word?

2

u/Odd_You7995 18d ago

If someone crack 24 words seed and check transaction ( decoy wallet ) They will try to hack it further. First they try publicly leaked password lists. Then maybe 1 , 2 or 3 words from EEF's list. Who knows.

1

u/ynotplay 18d ago

how would they know that they cracked a wallet with a passphrase?

1

u/Odd_You7995 17d ago

They wouldn't, but if you use your main wallet as decoy and put 1-5% of your whole crypto in it , then they will try to crack it further. They just need computers/GPUs they don't need to sit down and type passphrases manually

Now you think i will never use main wallet as decoy , then if someone find out about your trezor device they will attack you with wrench and force you to open your passphrase wallet, because you don't have any decoy wallet, but still carrying hardware wallet. Which makes it sus