Security6 min read

AES-256-GCM and PBKDF2: How Your Wallet Stays Encrypted

DogeVault encrypts your seed phrase with AES-256-GCM using a key derived by PBKDF2. What those standards do and why your password still matters.

What happens when you set a wallet password

Your seed phrase is never stored in plain text. When you set a password, the wallet runs PBKDF2 — a key derivation function — over it with a random salt and 600,000 iterations of SHA-256, producing a 256-bit encryption key.

That key is then used with AES-256-GCM, an authenticated encryption standard, to encrypt the seed phrase. Only the ciphertext, the salt and the initialization vector are stored — never the password and never the plain phrase.

Why 600,000 iterations matter

PBKDF2 is deliberately slow. Testing one password candidate takes a fraction of a second, which is nothing for you when unlocking — but devastating for an attacker trying millions of guesses.

The salt guarantees that two identical passwords produce different encrypted vaults, killing precomputed rainbow-table attacks. GCM adds authentication: any tampering with the stored ciphertext is detected on decryption.

Strong crypto cannot fix a weak password

All of this mathematics protects the vault against brute force only as well as your password allows. “doge2024” will fall to a dictionary attack regardless of the cipher.

Use a long passphrase: four or five unrelated words, or a generated password from a manager. Length beats complexity — every extra character multiplies the attacker’s work exponentially.

  • At least 8 characters, ideally 16+
  • Unique to this wallet — never reused
  • A passphrase of random words is both strong and memorable

Put it into practice

Create or import your non-custodial Dogecoin wallet — it takes two minutes.