Wallets and Asset Security Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Wallets and Asset Security flashcards as text
A hardware wallet generates a 24-word BIP39 seed phrase. An attacker gains access to words 1–23 but not word 24. Assuming the attacker uses a brute-force approach against the missing word, how many valid BIP39 candidates must they check at most?
Answer: 2048
The BIP39 wordlist contains exactly 2048 words. Since the attacker knows 23 of the 24 words, they only need to iterate through all 2048 possible words for the missing 24th position. The last word also encodes a checksum, which further reduces valid candidates slightly below 2048, but 2048 is the correct upper bound.
A multisig wallet is configured as 3-of-5. Two co-signers are unavailable indefinitely and one signing device is stolen (but PIN-protected). Which statement BEST describes the security and recovery posture?
Answer: Funds are inaccessible now, but safe from theft as long as the remaining 4 key holders hold their keys securely and quorum cannot be formed by an attacker
With only 2 available signers and a 3-of-5 threshold, the quorum cannot be met, so funds cannot be moved — either by the owners or an attacker who holds only the stolen device (1 key). The funds are frozen but not at immediate theft risk, because an attacker also lacks the 2 additional keys needed to reach threshold. Sweeping is impossible with only 2 signers.
Which attack vector specifically exploits the gap between what a hardware wallet's screen displays and what the connected host computer actually transmits to the blockchain?
Answer: Address substitution via compromised host software
Address substitution attacks occur when malware on the host computer silently replaces the recipient address in the transaction before it is sent to the hardware wallet for signing. The hardware wallet screen may show the attacker's address only if the user does not carefully verify it on the device's trusted display. This exploits the trust gap between what the user typed and what the compromised software transmits.
A Shamir's Secret Sharing (SSS) scheme splits a wallet seed into 5 shares with a threshold of 3. Compared to a standard 3-of-5 multisig wallet, which statement is MOST accurate regarding on-chain footprint?
Answer: SSS produces no additional on-chain footprint because reconstruction happens entirely off-chain before a standard single-sig transaction is broadcast
Shamir's Secret Sharing reconstructs the original secret (seed) off-chain by combining shares, then uses that seed to produce a normal single-signature transaction. This leaves no indication on-chain that SSS was used. In contrast, native multisig (especially legacy P2SH or P2WSH multisig) reveals the multisig structure in the transaction's scriptSig or witness data, creating a larger and distinguishable on-chain footprint.
A cold wallet's extended public key (xpub) is accidentally posted publicly. No private keys were exposed. Which risk is MOST significant?
Answer: An attacker can monitor all past and future transactions and addresses derived from that xpub, severely compromising financial privacy
An xpub (extended public key) in BIP32 hierarchical deterministic wallets allows anyone to derive all child public keys and therefore all receiving addresses in that branch. While private keys cannot be derived from the xpub alone (absent hardened derivation vulnerabilities), an attacker gains complete visibility into the wallet's transaction history and future addresses — a critical privacy breach. Funds are not directly at theft risk, but the wallet should ideally be retired.
A developer stores a wallet seed in an HSM (Hardware Security Module) and uses the HSM's key derivation function to sign transactions. The HSM enforces a policy: private keys never leave the module. Which limitation does this architecture introduce compared to a self-custodied hardware wallet with an offline seed backup?
Answer: If the HSM vendor discontinues the product or the device is destroyed without a seed export, fund recovery may be impossible
HSMs with non-exportable key policies provide strong runtime security, but introduce a critical custody risk: if the HSM is destroyed, becomes unavailable, or the vendor discontinues support without a migration path, and no seed backup exists outside the module, funds can be permanently lost. Self-custodied hardware wallets mitigate this with a recoverable seed phrase stored separately. This trade-off between key exposure risk and recovery risk is a core consideration in enterprise crypto custody design.