Printed to order · ships from the USAFree US shipping over $75

Seed Phrase Explained, What 12 or 24 Recovery Words Really Are

A seed phrase is a list of 12 or 24 ordinary words that can rebuild every key in your bitcoin wallet. Here is how the words are made, why they must stay private and the basics of backing them up offline.

Updated · 4 min read

A seed phrase, also called a recovery phrase, is a list of 12 or 24 ordinary words that your wallet turns into the keys that control your bitcoin. Whoever has the words can spend the coins, which is why you write them down once, store them offline and never share them with anyone.

That is the whole idea. The rest of this guide explains how a short list of words can stand in for a long secret number, what the BIP-39 standard says, and the backup habits that keep the words both safe and recoverable. It is general education, not financial advice, and it recommends no brand of wallet.

What a seed phrase actually is

Your wallet needs a very large random number to create your private keys. Humans are bad at remembering long strings of digits and worse at copying them without a mistake. A seed phrase is a human-friendly way to write that number down.

When you set up a new wallet, it generates the random number and shows you the matching words. Later, if you lose your phone or your hardware device fails, you can type the same words into a compatible wallet and it recreates your keys. The coins themselves never moved, since they live on the blockchain. The words only let you take control of them again.

Our bitcoin wallets explained guide covers where the phrase fits among the different types of wallet.

BIP-39 in plain words

Most wallets follow a standard called BIP-39. A BIP is a Bitcoin Improvement Proposal, a public document that describes a shared way of doing something, and number 39 covers "mnemonic codes," meaning words that represent a number. It was written in 2013 and is listed as deployed on bitcoin.org.

Here is how it works, step by step:

  1. Random data. The wallet generates 128 bits of randomness for a 12-word phrase, or 256 bits for a 24-word phrase.
  2. A checksum. It adds a few extra bits, 4 for 12 words and 8 for 24 words, calculated from the random data. They let the wallet notice most typing mistakes.
  3. Cut into pieces. All the bits are split into groups of 11.
  4. Look up the words. Each group of 11 bits is a number from 0 to 2,047, and that number picks a word from a fixed list of 2,048 words.

The English list was designed so that each word is distinguishable by its first four letters, which helps when you are copying a phrase by hand or reading it back. The standard defines lists in other languages too, though most wallets only support the English one.

Finally, the wallet runs the words through a function called PBKDF2, with 2,048 rounds, to produce a 512-bit seed. From that single seed, a second standard called BIP-32 derives all of your keys and addresses. One phrase, many addresses, which is why a single backup is enough to restore a whole wallet.

You can read the full technical text on the Bitcoin Wiki's BIP-39 page.

Why your words must stay private

The seed phrase is not a password to your wallet. It is the wallet. There is no company to call and no reset button, because nobody holds a copy for you. This has two consequences:

  • Anyone with the words can take the coins. They do not need your device, your PIN or your account. They only need the list.
  • Anyone asking for the words is not helping you. No real wallet maker, exchange, developer or support agent needs your phrase to help with a problem.

So the rule is simple: never type your words into a website, a chat, a form, an email, a photo or a voice call, even when the request looks official. The ones who ask are the scammers, and they are patient and convincing.

This is the practical side of the idea behind not your keys, not your coins: if you hold the keys, you hold the responsibility too.

Offline backup basics

Because the words are both the key and the backup, the goal is to keep them offline, out of sight and hard to lose. The following are general habits, not a complete security plan.

  • Write it down by hand. Paper works, and so do metal plates made for the purpose. Check each word twice.
  • Keep it off your devices. A phone photo, a notes app, a screenshot or an email draft can end up in cloud backups, where the phrase sits next to your password.
  • Keep the order. The sequence matters, so number the words.
  • Think about fire, water and curious people. A home safe, a locked drawer or a second location are common ideas.
  • Plan for the unlucky day. A backup nobody can find is no backup, so a trusted person or written instructions can matter.
  • Test your recovery. Many people practice with a small amount first, to confirm the backup restores the same wallet.

Some wallets also offer an optional extra passphrase, sometimes called the 25th word, on top of the standard words. It makes a different wallet from the same phrase, and if you forget it, there is no way to recover those coins. Add one only if you understand that trade.

Tees for people who take backups seriously

If you have been meaning to do this chore, there is merchandise built on that exact mood:

Sources: the BIP-39 text on bitcoin.org and the Bitcoin Wiki.

Questions

Quick answers

Why is a seed phrase 12 or 24 words and not some other number?

The standard ties word count to the size of the random data. It allows phrases of 12, 15, 18, 21 and 24 words, and wallets in practice mostly use 12 or 24. More words mean more underlying randomness and a longer thing to back up.

Does the order of the words matter?

Yes, completely. The same words in a different order give you a different phrase, and usually an invalid one, since the checksum no longer matches. Always record the numbered order.

Can I choose my own words?

You should not. The words must come from the standard list, and the last word carries part of the checksum, so a phrase you invent is generally not valid. Handpicked phrases are also far easier to guess than random ones, so let the wallet generate it.

Is it safe to take a photo of my seed phrase?

It is risky. A photo is a digital copy that can sync to cloud storage, be shared by accident or be seen by anyone who borrows your phone. An offline written copy keeps the phrase out of that chain.

Keep reading

More guides

All guides