Generate
Generate unpredictable secrets
A wallet requires sufficient reliable entropy and a cryptographically secure random number generator. Lengthy seeds offer little strength if their origin is predictable.
GhostlyInc · Private keys
Understand wallet risks, protect your keys, and check your backups.
Each layer addresses a distinct issue. A secure backup cannot make up for poor key generation, nor can a hardware wallet protect a payment if the wrong recipient is approved.
Generate
A wallet requires sufficient reliable entropy and a cryptographically secure random number generator. Lengthy seeds offer little strength if their origin is predictable.
Back up
A backup must correspond with the wallet's design. Early loose-key wallets might generate new change keys post-backup, whereas modern deterministic wallets rely on safeguarding the recovery phrase.
Sign and store
Private keys, signing nonces, wallet software and storage boundaries all matter. A flaw in any can expose control without compromising the blockchain itself.
Verify and send
Irreversible transactions mean recipient verification is essential to wallet security. History entries, shortened addresses, or lookalike destinations must never replace an independent check.
This research series tracks real wallet failures from weak randomness to misleading transaction history. Published investigations are full case studies; others remain unlinked until sources and guidance are ready.
Which seeds are impacted, why updated firmware cannot fix existing keys, and how to move bitcoin securely without transferring vulnerabilities to a new wallet.
How lookalike addresses appear in transaction history and why users must verify the full recipient, not just familiar prefixes or suffixes.
How a missing change key rendered an apparently valid wallet backup incomplete, and why Bitcoin introduced a key pool for safer recovery.
A wallet may employ robust cryptography yet still produce insecure seeds or private keys. Discover how poor randomness can jeopardise your funds and the steps users should take.
How a seed command offered far less security than its output length implied, and lessons for wallet developers.
How outdated browser environments and JavaScript randomness can leave long-lived wallets vulnerable years after creation.
Why weak or repeated randomness in ECDSA signing can expose private keys, even if key generation differs.
Use a wallet with regular updates, clear recovery instructions, and precise approval details. Don’t rely solely on advertising.
Store your seed phrase or wallet backup offline in at least two secure locations. Test recovery before it's needed, and never save the seed phrase in cloud storage.
If you no longer trust an old wallet, create a new one with up-to-date software and transfer funds to its new address. Always send a small test amount first.
Compare the full recipient address with a trusted source. Double-check it on the signing device, especially if copied from your transaction history.