Badania nad bezpieczeństwem

Seed Entropy: How to Check Whether Your Wallet Actually Has It
Main Takeaway: A seed phrase is only as strong as the true randomness present at the moment it was created, and a firmware update cannot put that randomness back afterwards. The 2026 Coldcard case showed why that matters, because a build error routed seed generation to a software formula instead of the physical noise source on the board, so phrases that looked ordinary were narrow enough to guess. This page explains how to find out where your own wallet's randomness comes from. Quick reference Term What it means Entropy The unpredictability collected at the instant a seed is created, counted in bits. A 12 word phrase targets 128 bits and a 24 word phrase targets 256 bits. Seed phrase (BIP39) The 12 to 24 words that encode that entropy. Every private key and address in the wallet is derived from those words. PRNG (pseudo random number generator) Software that produces random looking output by running a formula forward from a starting...

Crypto Security in 2025 and 2026: 5 Major Events and What They Mean for Self-Custody
From the Trust Wallet $7M browser hack to the Drift $285M multisig takeover, 5 events in 2025-2026 reshape what self-custody looks like in 2026. Here's what each teaches.

Drift Protocol Hacked for $285M: What It Reveals About Exchange Risk
The Drift Protocol exploit proved "decentralized" doesn't mean safe. Here's why self-custody with an air-gapped hardware wallet is the only real protection.

North Korean Hackers Just Poisoned a Library Used by 83 Million Apps — Here's Why Your Air-Gapped Wallet Didn't Flinch
North Korean hackers compromised Axios, an npm library downloaded 83 million times per week, injecting malware that targets crypto assets. Meanwhile, two teens drove...

Trust Wallet $7M Hack: What It Means for Wallet Security in 2026
$7 million stolen. 2,520 wallets drained. 48 hours. The Trust Wallet Christmas hack proved browser wallets are fundamentally vulnerable. With crypto theft hitting $3.4...

🚨 Supply Chain Attack on NPM: What It Means for Crypto Users
Your crypto could be stolen without you knowing. A malicious NPM package is live. ELLIPAL’s Clear Signing cold wallets are the only defense.

Czym są ataki na łańcuch dostaw portfeli sprzętowych i jak im zapobiegać?
Portfele sprzętowe chronią kryptowaluty w trybie offline, ale ataki na łańcuch dostaw mogą narazić je na niebezpieczeństwo, zanim dotrą do odbiorcy. Dowiedz się, jak...

Bezpieczeństwo mostów międzyłańcuchowych: korzystanie z portfeli sprzętowych do transakcji w wielu łańcuchach
Dowiedz się, jak portfele sprzętowe chronią Twoje aktywa podczas transakcji między łańcuchami oraz dlaczego są niezbędne do bezpiecznej i płynnej obsługi kryptowalut w wielu...

Napad na Bybit: jak ekrany portfeli sprzętowych stały się ostatnią linią obrony kryptowalut
21 lutego 2025 roku Bybit — trzecia co do wielkości giełda kryptowalut na świecie — padła ofiarą napadu rodem z filmu. Odpowiedzialna za słynne...

Uważaj na oszustwo polegające na przelewie zerowym
Kryptowaluty szybko zyskały popularność, oferując wiele korzyści i otwierając nowe możliwości inwestowania oraz osiągnięcia niezależności finansowej. Jednak, podobnie jak każda nowa szansa, przyciągają również...

DEXX ujawniony: znaczenie prawdziwie zdecentralizowanych portfeli
Niedawno platforma DEXX padła ofiarą naruszenia bezpieczeństwa, które wzbudziło poważne obawy w społeczności Web3. Mimo deklarowania świadczenia usług „niepowierniczych” DEXX przechowywała klucze prywatne użytkowników...
Czym jest drainer kryptowalut?
Nie pozwól, by drenażery kryptowalut opróżniły Twój portfel! Dowiedz się, jak działają ci podstępni złodzieje i jakie kroki możesz podjąć, aby chronić swoje cyfrowe...




