Bitcoin · Essential

What Is a Bitcoin Seed Phrase?

The 12 or 24 words printed on a card when you set up a wallet. They look random. They are the most important thing you own in crypto.

Ashir Khan
By Ashir Khan3 min read

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.

Last updated:

Never share your seed phrase with anyone

No wallet company, exchange, or support team will ever ask for it. Anyone who does is attempting to steal your funds.

What is a seed phrase?

A seed phrase — also called a recovery phrase, backup phrase, or mnemonic — is a sequence of 12 or 24 ordinary English words. These words aren't random in the way a password is random. They are generated by your wallet hardware or software using a cryptographically secure random number generator, then encoded into words from a standardised list of 2,048 words defined by BIP-39.

Examples of words from the BIP-39 list include: abandon, ability, able, above, absent, absorb. Every word you see in your seed phrase comes from this same fixed list — which means the words are designed to be unambiguous, easy to write down, and readable across different fonts and handwriting.

How BIP-39 works

BIP-39 (Bitcoin Improvement Proposal 39) is the technical standard, published in 2013, that defines how seed phrases are generated and used. Here is the process in plain terms:

  1. Your wallet generates a large random number (128 bits for 12 words, 256 bits for 24 words).
  2. A checksum is calculated and appended to the random bits.
  3. The combined bit string is split into groups of 11 bits.
  4. Each 11-bit group is used as an index into the 2,048-word list.
  5. The resulting words are your seed phrase.

To restore a wallet, this process runs in reverse: words → bits → seed → master private key → all wallet addresses and keys.

12 words vs 24 words

Both are secure. A 12-word phrase provides 128 bits of entropy. A 24-word phrase provides 256 bits. To put this in perspective: brute-forcing a 128-bit phrase would require more attempts than there are atoms in the observable universe. No computer that exists or could be built with current physics can do it.

The practical difference is convenience vs margin. A 24-word phrase is longer to transcribe accurately but gives additional security margin against future cryptographic weaknesses that no one expects but some prefer to hedge against. Most hardware wallets and popular software wallets default to 12 or 24 words depending on their implementation.

One phrase, all your wallets

Modern wallets use the HD (Hierarchical Deterministic) standard (BIP-32/44). This means your single seed phrase is the root of a mathematically deterministic tree of keys. Every address your wallet has ever generated — every receiving address, every change address — is derived from this one root.

This is why seed phrases are so powerful: you only need to back up one thing. And it is why they are so dangerous: anyone who finds your seed phrase gets access to everything your wallet has ever generated or will generate.

What you must never do with a seed phrase

  • Type it into any website or app — even one that looks legitimate
  • Store it digitally (notes app, email, cloud storage, screenshot)
  • Share it with any person, including support staff or family
  • Buy a hardware wallet second-hand if it came with a pre-filled seed phrase
  • Photograph it and store the photo on your phone

For how to store it safely: How to Store a Seed Phrase Safely →