Wallets and Asset Security Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Wallets and Asset Security flashcards as text
A hardware wallet uses a BIP-39 mnemonic derived from entropy. If a 256-bit entropy seed is used, how many words will the resulting mnemonic phrase contain, and why does adding more entropy not always translate to proportionally greater security in practice?
Answer: 24 words; because the practical security ceiling is often bounded by physical access control and supply-chain integrity rather than entropy bits alone
256-bit entropy under BIP-39 produces 24 mnemonic words (256 bits entropy + 8-bit checksum = 264 bits ÷ 11 = 24 words). While 256-bit entropy is cryptographically very strong, real-world security is frequently limited by physical attack vectors—supply-chain tampering, shoulder surfing, insecure seed backups, or $5 wrench attacks—making the entropy ceiling largely theoretical in operational settings.
An attacker compromises a watch-only wallet by injecting a malicious address into the clipboard during a withdrawal. Which defense mechanism is specifically designed to mitigate this attack vector on hardware wallets?
Answer: Address display and manual verification on the hardware wallet's trusted screen
Clipboard hijacking (address substitution malware) is defeated by verifying the destination address on the hardware wallet's own tamper-resistant display before signing—this screen is isolated from the potentially compromised host OS. 2FA protects account login, not transaction signing. Shamir Secret Sharing protects key backup, not live transaction integrity. wallet.dat encryption protects the private key at rest, not the address shown during signing.
In the context of BIP-44 hierarchical deterministic wallets, what is the correct derivation path for the first external receiving address on the third account of Bitcoin Mainnet?
Answer: m/44'/0'/2'/0/0
BIP-44 path structure is m/purpose'/coin_type'/account'/change/address_index. Purpose=44', Bitcoin Mainnet coin_type=0', the third account is index 2 (zero-indexed, so account'=2'), external chain (receiving) is change=0, and the first address is index 0. Therefore: m/44'/0'/2'/0/0. Option B uses account index 3 (fourth account). Option C uses change=1 which is the internal/change chain. Option D uses coin_type=1 which is Bitcoin Testnet.
A multisig wallet is configured as 2-of-3 using P2SH. One of the three hardware wallet cosigners is permanently lost. Which statement best describes the security and recovery posture of this wallet?
Answer: Funds remain fully accessible and secure; the quorum is still achievable with the two remaining signers, but the effective security model has degraded to 1-of-2 for future compromise tolerance
A 2-of-3 multisig only requires any two of the three keys to authorize a transaction, so losing one cosigner doesn't freeze the funds—the two remaining signers can still spend. However, the security model has effectively degraded: previously an attacker needed 2 of 3 keys; now they only need to compromise 2 of the 2 remaining keys (essentially 1 failure away from total loss). Best practice is to immediately sweep funds to a fresh multisig wallet with a new key set. Blockchains have no rekeying mechanism.
Which attack specifically targets the random number generator (RNG) of a hardware wallet during the key generation ceremony, and what property of elliptic curve cryptography makes weak RNG catastrophically exploitable in ECDSA?
Answer: A nonce reuse or biased-nonce attack; in ECDSA, if the per-signature nonce k is reused or predictable across two signatures, the private key can be algebraically derived
ECDSA requires a unique, cryptographically random nonce k per signature. The private key d can be computed as d = (s·k − z) / r mod n, where s, r, z are all public from the signature. If k is reused across two signatures (or sufficiently biased/predictable), an attacker solving two such equations can isolate d exactly. This was exploited in the PlayStation 3 hack and has been demonstrated against weak hardware wallet RNGs. ECDSA has no padding (eliminating option D), timing attacks target key bits not RNG bias directly, and fault injection works differently.
A security researcher discovers that a popular mobile wallet derives its seed from a combination of the device's IMEI number, installation timestamp, and a user-supplied 4-digit PIN. Ignoring the IMEI and timestamp, what is the upper bound on the brute-force search space for the PIN alone, and which broader vulnerability class does this wallet design exemplify?
Answer: 10,000 possible PINs; it exemplifies insufficient entropy in key derivation (low-entropy KDF input), classified under CWE-331
A 4-digit numeric PIN has exactly 10^4 = 10,000 possible values—trivially brute-forceable offline without rate limiting. This design exemplifies CWE-331 (Insufficient Entropy), a well-documented cryptographic weakness where a secret's search space is far too small to resist exhaustive search. Device-specific values like IMEI reduce anonymity but don't expand the effective PIN search space when the PIN is the binding secret. This is distinct from rainbow tables (which apply to unsalted hashes of longer secrets) and timing attacks (which require observable execution differences).