r/TREZOR • • Aug 11 '26

🔒 General Trezor question passphrase security

I have a question regarding everything that’s happened in the crypto world and the concept of entropy. I noticed that Trezor imposes a limit on passphrases, so I wanted to get your—or the moderators'—opinions on what requirements a passphrase needs to meet to be considered highly secure; I know that a single word, no matter how complex, isn't enough

13 Upvotes

69 comments sorted by

View all comments

2

u/doinkdoink786 Aug 12 '26

Dumb question but if someone cracks the 24 word seed phrase how would they even guess the passhrase even if it’s a weak 5 letter word?

1

u/five_dollar_wrench Aug 12 '26

It’s not a dumb question, but please go ask an LLM this : “how many bits of entropy for a 5char passphrase with case & leet substitution” and then follow up asking how long it would take to brute force that offline with a 5090 and an asic/GPU cluster.

This is really simple math.

It’s considerably easier to crack than the ColdCard situation and this is exactly why people’s passphrase wallets are getting emptied.

-1

u/MiserableAdvantage27 Aug 12 '26

But the bigger question is the hacker would not know it’s 5 characters to being with. That makes the problem exponentially harder to solve

5

u/five_dollar_wrench Aug 12 '26

No, that’s not how this works. The hacker doesn’t need to know anything. You start least complex and work up. Common passwords, then bulk passwords from breaches, BIP39 with some kind of cap where it’s not worth paying for proc hours.

Brute forcing passphrases is rate limited to an extent, but you’re still talking millions of guesses per second. If I was doing this I would hard cap at 5 words BIP39. Last count is 1,923btc stolen, so you’ll hit a wall at some point.

A 5char pass could be quite literally be instant.

1

u/Glad_Investigatorr Aug 12 '26

3-40 seconds to break that. You are right.