Wallets and Asset Security Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wallets and Asset Security flashcards as text
What is a 'brain wallet' and its primary security weakness?
Answer: A wallet memorized as a passphrase, weak because human-chosen phrases are predictable
Brain wallets derive keys from memorized passphrases, but humans choose predictable phrases that attackers can brute-force with dictionary attacks.
What does 'dusting attack' refer to in cryptocurrency security?
Answer: Sending tiny amounts of crypto to addresses to de-anonymize wallet owners
Dusting attacks send minuscule amounts to many addresses; when victims move these funds, attackers can cluster addresses and link identities.
Which feature distinguishes a 'stateless' hardware signer from a traditional hardware wallet?
Answer: It stores no keys on the device itself between sessions
Stateless signers (like some air-gapped devices) derive keys on demand from an externally held seed and store nothing persistently on the device.
What is the purpose of a 'passphrase' (25th word) added to a BIP-39 seed?
Answer: It creates a completely different wallet, adding plausible deniability and extra security
A BIP-39 passphrase acts as an extra factor; any passphrase (including empty) produces a valid but different wallet, enabling plausible deniability.
In the context of cold storage, what does 'air-gap' mean?
Answer: The signing device has no network connectivity at any point
An air-gapped device is physically isolated from all networks, ensuring private keys cannot be exfiltrated remotely.
What is 'key stretching' as used in wallet encryption?
Answer: Applying a computationally expensive hash function to slow brute-force attacks on passwords
Key stretching (e.g., PBKDF2, bcrypt) repeatedly hashes a password to make brute-force attempts computationally expensive.
Which type of wallet vulnerability does a 'supply chain attack' specifically target?
Answer: Hardware or software wallets compromised before they reach the end user
Supply chain attacks compromise the manufacturing, packaging, or distribution of hardware wallets so devices arrive pre-backdoored.