If you have ever set up a self-custody crypto wallet, you have seen it: a screen with 12 or 24 plain English words and a stern warning to write them down. As developers we tend to treat that list like a password. It isn't. It is an encoding of raw entropy, and once you see how it is built, the security rules around it stop feeling like superstition.
What the words actually encode
Most wallets follow a standard called BIP-39. The recipe is short:
- Generate random entropy: 128 bits for 12 words, 256 bits for 24.
- Hash it with SHA-256 and append the first few bits of the hash as a checksum (4 bits for 128-bit entropy, 8 bits for 256).
- Split the result into 11-bit chunks. Each chunk is an index into a fixed list of 2,048 words.
That's it. 132 bits / 11 = 12 words. 264 bits / 11 = 24 words. The words are just a human-friendly serialization, and the checksum is why your wallet can tell you when you mistyped one.
A tiny Python demo (toy data only)
Here is the entropy-to-indices step, so you can see the mechanics. Never run anything like this with a real phrase, and never paste a real phrase into any script, website, or chat.
import hashlib, secrets
entropy = secrets.token_bytes(16) # 128 bits -> 12 words
h = hashlib.sha256(entropy).digest()
cs_bits = len(entropy) * 8 // 32 # 4-bit checksum
bits = bin(int.from_bytes(entropy, "big"))[2:].zfill(len(entropy) * 8)
bits += bin(h[0])[2:].zfill(8)[:cs_bits]
indices = [int(bits[i:i + 11], 2) for i in range(0, len(bits), 11)]
print(indices) # 12 numbers in 0..2047, each maps to one BIP-39 word
Map those indices to the official wordlist and you have a valid mnemonic. A real wallet then runs the words (plus an optional passphrase) through PBKDF2 to get a 512-bit seed, and derives a whole tree of keys from it using BIP-32. One seed, unlimited addresses, which is why one backup covers everything.
Seed phrase vs private key vs PIN
A quick mental model:
- PIN / password: a local lock on one device. Resettable.
- Private key: controls one address. Not resettable.
- Seed phrase: generates every key in the wallet. Not resettable. Whoever has it owns the funds.
The PIN protects the device; the seed phrase is the wallet. NutshellCrypto has a clear breakdown of this in its guide on what a seed phrase is and how to store it safely.
12 or 24 words?
128 bits is already far beyond brute-force range. For most people the threat model isn't guessing; it is phishing, malware, cloud backups, and plain loss. Use whatever your wallet generates and spend your effort on storage.
The optional passphrase ("25th word")
BIP-39 lets you add a passphrase that is mixed into the PBKDF2 step. Same words plus a different passphrase gives a completely different wallet. That's useful against someone who finds your written words, but it adds a second secret you can lose, and there is no recovery if you forget it.
Thinking about storage like an engineer
Treat the phrase as an offline root secret:
- Never digitize it. No screenshots, notes apps, password managers synced to the cloud, or photos. Your threat surface is every device that ever touched it.
- Plan for physical failure. Paper burns and fades; metal backup plates survive fire and water better.
- Avoid single points of failure. Consider more than one copy in separate secure places, weighing theft risk against loss risk.
- Test recovery with a small amount before trusting a wallet with more.
- Assume any prompt asking for it is a scam. No legitimate support team, airdrop, or "wallet sync" site needs your words.
Takeaways
- A seed phrase is 128 or 256 bits of entropy plus a checksum, encoded as words.
- It derives every key in your wallet; losing it, or leaking it, is final.
- Words beat brute force easily; humans and malware are the real attack surface.
- Keep it offline, durable, redundant, and never typed into a website.
For storage options, common scams, and what to do if you lose your phrase, read the full guide on NutshellCrypto.
Not financial advice; this post is for education only.
This post was written with AI assistance.
Top comments (0)