Security Research

Seed Entropy: How to Check Whether Your Wallet Actually Has It
Main Takeaway: A seed phrase is only as strong as the true randomness present at the moment it was created, and a firmware update cannot put that randomness back afterwards. The 2026 Coldcard case showed why that matters, because a build error routed seed generation to a software formula instead of the physical noise source on the board, so phrases that looked ordinary were narrow enough to guess. This page explains how to find out where your own wallet's randomness comes from. Quick reference Term What it means Entropy The unpredictability collected at the instant a seed is created, counted in bits. A 12 word phrase targets 128 bits and a 24 word phrase targets 256 bits. Seed phrase (BIP39) The 12 to 24 words that encode that entropy. Every private key and address in the wallet is derived from those words. PRNG (pseudo random number generator) Software that produces random looking output by running a formula forward from a starting...

Crypto Security in 2025 and 2026: 5 Major Events and What They Mean for Self-Custody
From the Trust Wallet $7M browser hack to the Drift $285M multisig takeover, 5 events in 2025-2026 reshape what self-custody looks like in 2026. Here's what each teaches.

Drift Protocol Hacked for $285M: What It Reveals About Exchange Risk
The Drift Protocol exploit proved "decentralized" doesn't mean safe. Here's why self-custody with an air-gapped hardware wallet is the only real protection.

North Korean Hackers Just Poisoned a Library Used by 83 Million Apps: Why Your Air-Gapped Wallet Didn't Flinch
North Korean hackers compromised Axios, an npm library downloaded 83 million times per week, injecting malware that targets crypto assets. Meanwhile, two teens drove...

Trust Wallet $7M Hack: What It Means for Wallet Security in 2026
$7 million stolen. 2,520 wallets drained. 48 hours. The Trust Wallet Christmas hack proved browser wallets are fundamentally vulnerable. With crypto theft hitting $3.4...

Supply Chain Attack on NPM: What It Means for Crypto Users
Your crypto could be stolen without you knowing. A malicious NPM package is live. ELLIPAL’s Clear Signing cold wallets are the only defense.

What are Supply Chain Attacks on Hardware Wallets and How to Prevent Them?
Hardware wallets protect crypto offline, but supply chain attacks can compromise them before arrival. Learn to spot tampering and secure your device from factory...

Cross-Chain Bridge Security: Using Hardware Wallets For Multi-Chain Transactions
Learn how hardware wallets protect your assets during cross-chain transactions and why they are essential for secure, seamless multi-chain crypto operations.

The Bybit Heist: How Hardware Wallet Screens Became Crypto's Last Line of Defense
On February 21, 2025, Bybit—the world’s third-largest cryptocurrency exchange—was hit by a heist of cinematic proportions. North Korea’s notorious Lazarus Group made off with...

Beware of the Zero Transfer Scam
Cryptocurrencies have grown quickly, offering a ton of benefits and opening up new ways for people to invest and achieve financial freedom. But, just...

DEXX Exposed: The Importance of True Decentralized Wallets
Recently, the DEXX platform suffered a security breach that raised serious concerns within the Web3 community. Despite claiming to offer “non-custodial” services, DEXX stored...

What Is a Crypto Drainer?
Don't let crypto drainers empty your wallet! Learn how these sneaky thieves operate and the steps you can take to protect your digital assets.




