What is a seed phrase? How 12 or 24 words protect a whole wallet
A seed phrase is the master backup of a self-custody wallet. Here is how the words are made, why they are so hard to guess, and why they are so easy to lose to a scammer.

Photo: “Parker 51 Special Fountain Pen” by mrbill, CC BY 2.0, via Flickr (edited: cropped and resized).
A seed phrase is a list of 12 to 24 ordinary words that encodes the random number a wallet uses to create all of its keys [1]. Anyone who has it can access every account in that wallet, so it should never be shared, typed into websites or photographed [2].
Key points
- 1Seed phrase, recovery phrase, secret recovery phrase and mnemonic all mean the same thing.
- 2The words are a human-friendly way to write down 128 to 256 bits of computer-generated randomness, following the BIP39 standard.
- 3One phrase can regenerate every past and future address in a modern (deterministic) wallet.
- 4A randomly generated 12-word phrase is practically impossible to guess. The real danger is someone seeing or stealing it.
- 5No legitimate company, support agent or website will ever ask for your seed phrase.
On this page
- What is a seed phrase, in plain terms?
- How do the words turn into keys?
- Why are some phrases 12 words and others 24?
- What does the checksum catch — and what does it miss?
- What is the optional passphrase?
- How should you store a seed phrase?
- Can you restore the phrase in a different wallet app?
- What happens if you lose your phone, or the paper?
- What mistakes do beginners make here?
- Frequently asked questions
- The bottom line
- Sources
What is a seed phrase, in plain terms?#
When you create a self-custody wallet, the app generates a large random number and shows it to you as a list of words. That list is your seed phrase — also called a recovery phrase or secret recovery phrase. Ethereum.org describes it as the master key to your wallet: anyone who has it can access all of your accounts and drain every asset [2].
A widely deployed standard for this is BIP39 [1]. Its authors chose words because a sentence is easier for people to handle than raw binary or hexadecimal numbers — it can be written on paper or even read out loud [1]. The point is to transport computer-generated randomness in a form humans can copy, not to let people invent their own phrases [1].
How do the words turn into keys?#
From randomness to a tree of keys
BIP39 converts the phrase into a 512-bit binary seed by running it through a function called PBKDF2 with 2,048 rounds of HMAC-SHA512 [1]. That seed then feeds the BIP32 standard, which derives a whole tree of key pairs from a single seed [3]. Because every key comes from that one root, the phrase is the only thing you need to back up to regenerate every key the wallet creates, as long as you use the same wallet software settings [4]. Bitcoin.org puts it simply: in most modern wallets, a single backup of the recovery phrase is enough to restore all past and future addresses [5].
Why are some phrases 12 words and others 24?#
The length depends on how much randomness the wallet started with. BIP39 allows 128 to 256 bits, in steps of 32, and adds one checksum bit for every 32 bits of entropy [1]. The table shows the five allowed sizes.
| Entropy (bits) | Checksum (bits) | Words | Possible phrases |
|---|---|---|---|
| 128 | 4 | 12 | 2¹²⁸ ≈ 3.4 × 10³⁸ |
| 160 | 5 | 15 | 2¹⁶⁰ ≈ 1.5 × 10⁴⁸ |
| 192 | 6 | 18 | 2¹⁹² ≈ 6.3 × 10⁵⁷ |
| 224 | 7 | 21 | 2²²⁴ ≈ 2.7 × 10⁶⁷ |
| 256 | 8 | 24 | 2²⁵⁶ ≈ 1.2 × 10⁷⁷ |
Entropy, checksum and word counts are from the BIP39 table. Possible phrases = 2 to the power of the entropy bits, computed by us; the checksum bits add no extra possibilities because they are calculated from the entropy.
| Step | Value |
|---|---|
| Possible 12-word phrases | 2¹²⁸ ≈ 3.4 × 10³⁸ |
| Guesses per second (hypothetical) | 1,000,000,000,000 |
| Seconds in a year (365.25 days) | 31,557,600 |
| Years to try every phrase | ≈ 1.1 × 10¹⁹ |
That is about ten billion billion years. Guessing is not how people lose seed phrases. They lose them to phishing pages, fake support agents, malware, photos synced to the cloud — or by simply misplacing the paper. One caveat: this only holds for phrases generated randomly by the wallet. BIP39 explicitly says it is not designed for phrases people make up themselves [1].
What does the checksum catch — and what does it miss?#
Because the last few bits are a checksum, a wallet can often tell when a phrase has been copied wrongly, and BIP39 requires software to warn you if the checksum is invalid [1]. But the checksum is short. A 12-word phrase carries 4 checksum bits, so by our arithmetic roughly 1 in 16 random wrong-word mistakes would still look valid; a 24-word phrase carries 8 bits, about 1 in 256. BIP39’s authors list the short checksum as a known shortcoming: it gives only modest odds of catching errors and cannot help correct them [1].
What is the optional passphrase?#
BIP39 lets you add a passphrase of your choice on top of the words. If you set none, an empty string is used [1]. Every passphrase produces a valid but completely different wallet, and only the correct one opens the wallet you funded [1]. Some hardware wallets ask for a passphrase or PIN when you sign [4].
This cuts both ways. A thief who finds only your words still cannot open the passphrase-protected wallet. But if you forget the passphrase, the words alone will open an empty wallet, and there is no reset. If you use a passphrase, back it up as carefully as the words — and store it separately.
How should you store a seed phrase?#
- Write it on paper, by hand
Ethereum.org’s advice is to write it down and not store it on a computer [6].
- Never photograph it
Screenshots and photos can sync to cloud storage, a common place for hackers to look for keys [2].
- Keep copies in more than one place
Avoid a single point of failure: separate locations and durable materials make it less likely that one event destroys every copy [5].
- Encrypt anything that touches the internet
Any backup stored online is highly vulnerable to theft, so it should be encrypted [5].
- Tell someone you trust how to find it
Without a plan for family, funds can be lost forever if nobody knows where the backup is [5].
Can you restore the phrase in a different wallet app?#
Usually, yes — that is one of the main benefits of the standard. Ethereum.org notes that you can swap wallet providers at any time, because the wallet is only a tool for using your account [6]. There are caveats. Bitcoin’s developer guide warns that HD wallet programs are not always fully compatible, so the safest choice is the same program with the same settings [4]. BIP39 also has no built-in version number, so the phrase alone does not record which address format the wallet used; the BIP notes that descriptor wallets now largely mitigate this [1]. And the wordlist matters: translating the words into another language produces a completely different seed, which is why BIP39 strongly discourages non-English wordlists [1].
What happens if you lose your phone, or the paper?#
Why is a lost key gone for good? NIST, the US standards agency, explains that if a private key is lost, any digital asset tied to it is lost, because it is computationally infeasible to regenerate the same private key [7]. The same report notes that when the news says crypto was “stolen”, it almost certainly means private keys were found and used to sign a transaction, not that the blockchain network itself was compromised [7]. Because blockchain data generally cannot be changed, such a transfer generally cannot be undone [7].
| Situation | Can you recover? | Why |
|---|---|---|
| Phone or device lost, phrase safe | Yes | Restore the wallet from the phrase on a new device [5] |
| Phrase lost, wallet still opens | Yes, if you act now | Make a new backup, or move funds to a fresh wallet and back that up |
| Both phrase and device lost | No | Nobody can recover funds from a self-custodied wallet [8] |
| Phrase seen or stolen by someone | Only by moving funds first | Whoever has the phrase can access every account [2] |
BIP39 in numbers
What mistakes do beginners make here?#
- Saving the phrase in notes, email or a photo
Anything on an internet-connected device can be stolen by malware or exposed through cloud sync. Paper or another offline medium is the safer default.
- Typing the phrase into a website to “verify” or “sync” a wallet
This is the classic phishing trap. A real wallet only asks for the phrase when you restore it inside the wallet app itself.
- Making up your own words
Human-chosen phrases are far easier to guess than the wallet’s random ones. BIP39 is designed for computer-generated randomness.
- Forgetting the optional passphrase
With the wrong or missing passphrase, the words open a different, empty wallet. Back up the passphrase too.
- Keeping only one copy
A single sheet can be lost, burned or thrown away. Keep at least two copies in separate safe places.
Frequently asked questions#
Is a seed phrase the same as a private key?
Not exactly. A private key controls one account. The seed phrase is the root from which the wallet derives many private keys, so it controls all of them at once [2]. See private key.
Should I use 12 or 24 words?
Both are allowed by BIP39. A randomly generated 12-word phrase already has 128 bits of entropy, which is far beyond guessing range. In practice, how you store the words matters far more than how many there are.
Do exchange accounts have seed phrases?
Usually not. On a custodial exchange the company holds the keys and you log in with a username and password [6]. Seed phrases belong to self-custody wallets. Compare the two in custodial vs self-custody.
Can I store my seed phrase in a password manager?
Someone has seen my seed phrase. What should I do?
Assume the wallet is compromised. Create a brand-new wallet with a new phrase, move your funds there as quickly as you can, and stop using the old one. Changing an app password does not help, because the phrase itself gives full access.
The bottom line#
A seed phrase is a clever piece of engineering: a few ordinary words that safely carry a number too large to guess, and from which a wallet can rebuild every key it will ever use. Its strength is also its weakness — whoever holds the words holds the money.
Keep it offline, keep more than one copy, and never type it anywhere except a wallet you are restoring. To go further, see how a hardware wallet keeps keys off your computer, or read the short definition in our glossary entry for seed phrase.
Sources#
Grade A = primary source (regulator, protocol specification, client code, original author). Grade B = expert secondary source used for explanation only.
- ABitcoin Improvement Proposals (GitHub). BIP 39: Mnemonic code for generating deterministic keys, 2013.
- Aethereum.org. Ethereum security and scam prevention, 2026.
- ABitcoin Improvement Proposals (GitHub). BIP 32: Hierarchical Deterministic Wallets, 2012.
- Abitcoin.org developer documentation. Wallets (Developer Guide), 2026.
- ABitcoin.org. Securing your wallet, 2026.
- Aethereum.org. Ethereum wallets, 2026.
- AU.S. National Institute of Standards and Technology. NISTIR 8202: Blockchain Technology Overview, 2018. Section 3.4.1, Private Key Storage
- ABitcoin.org. Some things you need to know, 2026.


