2⁴⁰ Was a To-Do List, Not Security and the List Is Done
A pure 40-bit Coldcard seed wasn’t really cryptography. It was just a huge list of 1.1 trillion possibilities.
Once the first serious attackers had working code, it was pretty clear what to do: finish the list. There was a small space, enough money, and lots of groups trying to get in. So, there was no reason to stop at 40% or 70%.
Now, it seems like the real thing is that the pure 40-bit space has already been checked against the UTXO set. We already know those seeds were broken. That part is done.
If a pure 40-bit Coldcard address still has coins on it today, what’s left to find? Just dust, very recently funded leftovers, or maybe a rare address that somehow slipped through.
Everything that was worth taking has almost certainly already been taken.
[link] [comments]