Beveiligingsonderzoek

Seed Entropy: How to Check Whether Your Wallet Actually Has It
Main Takeaway: A seed phrase is only as strong as the true randomness present at the moment it was created, and a firmware update cannot put that randomness back afterwards. The 2026 Coldcard case showed why that matters, because a build error routed seed generation to a software formula instead of the physical noise source on the board, so phrases that looked ordinary were narrow enough to guess. This page explains how to find out where your own wallet's randomness comes from. Quick reference Term What it means Entropy The unpredictability collected at the instant a seed is created, counted in bits. A 12 word phrase targets 128 bits and a 24 word phrase targets 256 bits. Seed phrase (BIP39) The 12 to 24 words that encode that entropy. Every private key and address in the wallet is derived from those words. PRNG (pseudo random number generator) Software that produces random looking output by running a formula forward from a starting...

Crypto Security in 2025 and 2026: 5 Major Events and What They Mean for Self-Custody
From the Trust Wallet $7M browser hack to the Drift $285M multisig takeover, 5 events in 2025-2026 reshape what self-custody looks like in 2026. Here's what each teaches.

Drift Protocol Hacked for $285M: What It Reveals About Exchange Risk
The Drift Protocol exploit proved "decentralized" doesn't mean safe. Here's why self-custody with an air-gapped hardware wallet is the only real protection.

North Korean Hackers Just Poisoned a Library Used by 83 Million Apps — Here's Why Your Air-Gapped Wallet Didn't Flinch
North Korean hackers compromised Axios, an npm library downloaded 83 million times per week, injecting malware that targets crypto assets. Meanwhile, two teens drove...

Trust Wallet $7M Hack: What It Means for Wallet Security in 2026
$7 million stolen. 2,520 wallets drained. 48 hours. The Trust Wallet Christmas hack proved browser wallets are fundamentally vulnerable. With crypto theft hitting $3.4...

🚨 Supply Chain Attack on NPM: What It Means for Crypto Users
Your crypto could be stolen without you knowing. A malicious NPM package is live. ELLIPAL’s Clear Signing cold wallets are the only defense.

Wat zijn supplychainaanvallen op hardware wallets en hoe kun je ze voorkomen?
Hardware wallets beschermen crypto offline, maar aanvallen op de toeleveringsketen kunnen ze al vóór aankomst compromitteren. Leer manipulatie te herkennen en je apparaat van...

Beveiliging van cross-chainbruggen: hardwarewallets gebruiken voor multi-chaintransacties
Leer hoe hardware wallets je tegoeden beschermen tijdens cross-chaintransacties en waarom ze essentieel zijn voor veilige, naadloze cryptotransacties over meerdere blockchains.

De Bybit-roof: hoe schermen van hardware wallets de laatste verdedigingslinie van crypto werden
Op 21 februari 2025 werd Bybit—de op twee na grootste cryptovalutabeurs ter wereld—getroffen door een overval van filmische proporties. De beruchte Lazarus Group uit...

Pas op voor de zero-transferfraude
Cryptovaluta zijn snel gegroeid, bieden veel voordelen en openen nieuwe mogelijkheden voor mensen om te investeren en financiële vrijheid te bereiken. Maar zoals bij...

DEXX onthuld: Het belang van echt gedecentraliseerde wallets
Onlangs kreeg het DEXX-platform te maken met een beveiligingsinbreuk die binnen de Web3-community ernstige zorgen opriep. Hoewel het platform beweerde “non-custodial” diensten aan te...
Wat is een cryptodrainer?
Laat cryptodrainers je wallet niet leegroven! Ontdek hoe deze sluwe dieven te werk gaan en welke stappen je kunt nemen om je digitale bezittingen...




