BIP 39 seed phrases are human readable encodings of computer generated entropy. The proposal defines how entropy and a checksum become words, then how the mnemonic and optional passphrase become a 512 bit seed for a deterministic wallet.
The words are not an ordinary password and should never be invented as a sentence. Anyone who obtains the correct mnemonic and passphrase can usually recreate the wallet's keys. A safe guide must therefore explain both the mathematics and the private recovery process.
Estimated reading time: 7 minutes
TL;DR
- BIP 39 uses 128 to 256 bits of generated entropy and a checksum to create 12 to 24 words.
- Every passphrase produces a valid looking seed, so a typing mistake can open an empty different wallet.
- A recovery test must use trusted offline tools and confirm the correct wallet details without exposing the live secret.
What This Means in Simple English
A BIP 39 phrase is a careful way to write random wallet material as ordinary words. The wallet turns the words and optional passphrase back into a seed, then derives keys and addresses. The phrase controls funds, so it must stay private and recoverable.
Simple Example
A person records twelve words and adds a passphrase. During recovery, one wrong passphrase still creates a working wallet, but it shows different addresses and no expected history. The person checks the fingerprint and known receive address before sending any funds.
Key Terms in Plain English
| Entropy: | Computer generated randomness used before the mnemonic words exist. |
|---|---|
| Checksum: | Extra bits used to detect many transcription errors. |
| Mnemonic: | The ordered BIP 39 word sequence. |
| Passphrase: | Optional text combined with the mnemonic to produce a different seed. |
| Derivation Path: | Instructions a wallet uses to derive a particular family of keys and addresses. |
What BIP 39 Specifies
BIP 39 has two main parts. It converts generated entropy into a mnemonic sentence, then converts that mnemonic and an optional passphrase into a binary seed. BIP 32 or another deterministic system can use the seed to build keys.
The document is a wallet application standard, not a Bitcoin consensus rule. A valid Bitcoin transaction does not reveal whether the wallet used BIP 39. Wallet compatibility therefore has to be checked separately.
From Entropy to Words
The proposal accepts 128 to 256 bits of entropy in 32 bit steps. It appends checksum bits taken from SHA-256 of the entropy. The total is divided into 11 bit indexes, each selecting one word from a list of 2,048.
The allowed lengths produce 12, 15, 18, 21 or 24 words. More words represent more initial entropy, but physical backup quality and device security still matter. Twenty four words stored badly are not safer than twelve generated and protected correctly.
Why the Checksum Matters
The checksum helps a wallet reject many incorrect word combinations. It is not an encryption layer and does not make a photographed phrase safe. It also cannot prove that the restored wallet uses the expected passphrase or derivation path.
Do not fix a failed checksum by guessing replacements on a website. Work from the original backup and a trusted recovery process. Repeated guesses can disclose words to malware or a remote service.
How the Seed Is Derived
BIP 39 seed phrases are processed with PBKDF2 using HMAC SHA-512 for 2,048 iterations. The normalised mnemonic is the password. The salt is the normalised word mnemonic followed by the optional passphrase.
The result is a 512 bit seed. The same mnemonic and passphrase should produce the same seed in compatible implementations. A different character, spacing or passphrase produces a different result.
Understand the Optional Passphrase
The passphrase is sometimes called an extra word, but it is not limited to one word and is not part of the mnemonic list. Every passphrase creates a valid seed, which provides no simple warning when the text is wrong.
A passphrase can separate wallets, yet it creates another secret that must be backed up accurately. Losing it can make the correct mnemonic useless for that wallet. Do not rely on memory alone or store it beside the phrase without a considered threat model.
Check Wallet Compatibility
Some wallets use different mnemonic schemes or do not implement every BIP 39 wordlist. The BIP repository discourages creating new local wordlists and notes that the English list has the broadest support.
Recovery can also need the wallet type, network, derivation path, account index and script type. A phrase may restore successfully while the expected addresses remain hidden because those details differ.
Create a Private Backup
Generate BIP 39 seed phrases on trusted hardware or software with a verified source. Record the words in order and check each one. Never email, photograph, type or paste the phrase into an untrusted connected device.
Protect against theft, fire, water, accidental disposal and unauthorised copying. The best medium and location depend on the value and household. Avoid creating one obvious copy that a visitor can read.
Test Recovery Safely
A recovery test for BIP 39 seed phrases should prove that the backup, passphrase and wallet details recreate known addresses. Use a trusted offline or dedicated environment and follow the wallet maker's instructions. Confirm a fingerprint or receive address before moving value.
Plan the test so the live secret is not exposed to a new general purpose computer. If compromise is suspected, create a new wallet securely and move funds after careful verification rather than continuing to rely on the old phrase.
Plan for Inheritance and Emergencies
A backup that only one person understands can fail through illness or death. Instructions should identify the wallet type, where authorised people can find the protected material and which professional help may be needed.
Do not place the full secret in an ordinary will or open note. Balance access and privacy, review the plan after wallet changes and test that the instructions still match the current addresses.
What the Current Data Can and Cannot Tell You
BIP 39 seed phrases come from a proposal marked Deployed in the BIPs repository, while its comments summary discourages new implementation. Existing wallet support remains a separate compatibility question.
Wallet software and recovery instructions can change. Check the official documentation for the exact wallet before entering any secret.
Decision Table
| Recovery Item | Why It Matters |
|---|---|
| Mnemonic | Carries the encoded entropy and checksum |
| Passphrase | Selects a different valid seed |
| Wallet scheme | Must understand BIP 39 |
| Derivation details | Find the expected keys and addresses |
| Private test | Proves recovery without exposing the secret |
A table is a starting point, not a promise. Verify current official sources and apply each detail to the decision you are actually making.
Frequently Asked Questions
Are BIP 39 Words the Same as a Private Key?
No. The words and optional passphrase derive a seed, which a deterministic wallet then uses to derive keys.
Can I Choose My Own Seed Phrase Sentence?
No. BIP 39 is designed to encode computer generated randomness, not a sentence invented by a person.
What Happens If I Forget the BIP 39 Passphrase?
The mnemonic alone creates a different valid seed. Without the correct passphrase, the intended wallet may be unrecoverable.
Why Can a Correct Seed Phrase Show No Funds?
The passphrase, wallet scheme, network, derivation path or account may differ. Check known addresses before assuming the backup failed.
Should I Type a Seed Phrase into a Website?
No. Use the official recovery process for a trusted wallet in an appropriate private environment.
Conclusion: BIP 39 Seed Phrases
BIP 39 seed phrases make random wallet material easier for people to record, but they also create a powerful bearer secret. Preserve the exact words, passphrase and recovery context. Test privately with known addresses, never invent the entropy and never expose the phrase to an untrusted website or device.



Join the ASIC Mining Discussion
Members can read and join the discussion
Log in to read comments from other miners. Create a free account if you would like to ask a question or share your experience.
Membership helps us protect the discussion from spam and keep answers useful.