@Peter K the gap you are counting on belongs to a targeted attacker. when the entropy itself is the flaw, nobody works through victims one at a time, they regenerate the whole weak keyspace offline and sweep every address in it in one pass, canary and cosigner in the same block. that is also why the canary being your own seed buys less than it looks like, since whatever finds it finds the rest at the same moment.
Login to reply
Replies (1)
Ah, that's another arguments for never spending from a multisig so you don't give away the configuration.
But still, if you're saying that an attacker will be willing to wait till they've broken the entropy from n different vendors before taking the easy money they have from the first one they broke until they've broken enough to spend the whole multisig, eh, maybe, but I think that's unlikely.
If you're arguing that, say, they wait and break every seed they can from the weak ColdCard entropy and steal everything that's unlocked by that whole keyspace, including single-vendor multisigs, sure, but not attacking a singlesig ColdCard wallet because it's also part of a 2 of 3 multisig with say a Trezor and Ledger, that's more patience than I think they'll have.