Skip to content
BIP ATLAS

BIP 0039

How can a wallet backup become a list of words?

Twelve ordinary words can stand in for 128 random bits. There is no encryption involved, just counting, a small checksum and a list of 2,048 words.

Many wallets ask you to write down a dozen or two dozen words and keep them somewhere safe. The words are not a password you chose, and nobody composed them as a sentence. BIP 39 describes them as a way to carry computer-generated randomness in a form people can write on paper or read over the telephone.12

The proposal, assigned in 2013 and recorded as deployed, has two halves: turning random bits into words, and turning words into a binary seed for later wallet machinery. This chapter follows both, using only published test phrases that anyone can look up, and values computed from them.34

Source revision
bitcoin/bips @ 3a10b5b
Source checked
1 October 2026
Review state
Draft — independent technical review applied; awaiting human sign-off
Source details

This chapter is an independent explanation, not the proposals themselves. Preamble fields are shown as recorded in the pinned files, with author e-mail addresses omitted. Status is the proposal’s own field, not an endorsement or a sign of consensus.

BIP 39: Mnemonic code for generating deterministic keys

BIP
39
Layer
Applications
Title
Mnemonic code for generating deterministic keys
Authors
Marek Palatinus
Pavol Rusnak
Aaron Voisine
Sean Bowe
Status
Deployed
Type
Specification
Assigned
2013-09-10
License
MIT

Pinned source · Reader view on bips.dev
SHA-256 afcbcbed36fe9eb734bd607398a8c124683ded2a75c3830e1b16c47b043a9134
Git blob 2a6118b26a2acc72351b659f77eb1a24e16e554a

FIG. A01.1 A published test phrase

Public test vector · never use for funds

  1. 01ozone#1268
  2. 02drill#535
  3. 03grab#810
  4. 04fiber#685
  5. 05curtain#433
  6. 06grace#811
  7. 07pudding#1385
  8. 08thank#1790
  9. 09cruise#421
  10. 10elder#570
  11. 11eight#567
  12. 12picnic#1313

12 words · 128 bits of entropy + 4 checksum bits · English wordlist

Each word stands for a number from 0 to 2,047. The numbers carry the entropy, but the seed is later computed from the words themselves.56

Randomness first

Everything starts with entropy: a block of random bits produced by a computer. BIP 39 allows between 128 and 256 bits, in steps of 32. More bits make a stronger backup and a longer sentence.7

Why words at all? A 128-bit number written in hexadecimal is thirty-two characters of digits and letters, easy to transpose and tiring to read aloud. Twelve familiar words carry the same information in a form that is easier to copy by hand and to check against the original.18

The proposal is explicit that it transcribes randomness. It is not a way to turn a sentence someone made up into a wallet; such brainwallets are outside its scope.2

A checksum from a hash

Before any words appear, the entropy gets a short checksum. Hash the entropy with SHA-256 and keep the first ENT / 32 bits of the result, where ENT is the number of entropy bits: 4 checksum bits for 128 bits of entropy, 8 for 256. Append them to the end.89

The total is now a multiple of 11: 132 bits for 128 bits of entropy, 264 for 256. Cut it into 11-bit groups. Each group is a number from 0 to 2,047, and each number picks one word from a list of exactly 2,048. Twelve groups give twelve words; twenty-four give twenty-four.58

The published all-zero sample shows the whole procedure at its plainest. Its 128 entropy bits are all zero. The SHA-256 hash of those sixteen zero bytes happens to begin with the bits 0011, so those four bits become the checksum. The first eleven groups are eleven zeros each, index 0, the word abandon. The last group is seven zeros followed by 0011: index 3, the word about. That is why this famous test phrase reads abandon eleven times and then about. All-zero entropy is, of course, useless as a real backup: it is public precisely because it is predictable.5910

The figure below starts from the bits of a public sample. Reveal the groups to see where the cuts fall, then step through to the last word.5

FIG. A01.2 From bits to words Interactive

Static view of the first sample with every 11-bit group revealed. With JavaScript you can switch samples and sizes and step through the groups.

128 entropy bits+4 checksum bits= 132 bits= 12 × 11

SHA-256(entropy)374708fff7719dd5…first 4 bits0011

010abandon
020abandon
030abandon
040abandon
050abandon
060abandon
070abandon
080abandon
090abandon
100abandon
110abandon
123about

The last word holds 7 entropy bits and 4 checksum bits.

Sample source: trezor-python-mnemonic-vectors.json (english[0]), pinned by commit. Public test material; never use it for funds.

The last word is not “the checksum word”. In a 12-word phrase it carries 7 bits of entropy and 4 checksum bits; in a 24-word phrase, 3 and 8.56911
Details: every allowed length
The first four columns are BIP 39’s own table. The last follows from appending the checksum after the entropy.811
Entropy bitsChecksum bitsTotal bitsWordsEntropy bits in last word
1284132127
1605165156
1926198185
2247231214
2568264243

Leading zeros count. The 24-word sample beginning all hour comes from entropy whose first five bits are zero, and those zeros are part of its first group like any other bits.56

A list built for people

The list has 2,048 words for a reason: 2,048 is two to the eleventh power, so every word stands for exactly 11 bits, no more and no less. That is what lets the bit string and the sentence convert into each other without anything left over.58

The English list was chosen with care. BIP 39 describes an ideal list as one where the first four letters identify each word, where near-pairs such as build and built or woman and women are avoided, and which is sorted so software can search it quickly.12

The pinned English list used on this page has 2,048 entries, and the tests behind it confirm that no two share their first four letters. Lists with accented or composed characters must be stored in a Unicode form called NFKD, a detail that returns below.1314

Other languages exist, but BIP 39 strongly discourages generating sentences from them, because most wallets support only the English list.15

How short is the checksum?

A checksum lets software notice a wrong word, but this one is small. BIP 39 lists it among its own shortcomings: it gives only modest odds of catching random errors, citing one in 256 missed, and offers no help correcting them.16

That figure matches the 8 checksum bits of a 24-word phrase. A 12-word phrase has only 4, so swapping its last word for a random one still passes one time in sixteen. The tests behind this page count exactly 128 of the 2,048 possible last words that do.817

BIP 39 does require software to compute the checksum of a sentence and to warn when it is invalid. A warning is the whole of the job: the checksum cannot say which word is wrong.1618

From words to a seed

The second half of BIP 39 does not reverse the first, and never recovers the entropy. Instead it feeds the sentence itself into PBKDF2, a deliberately repetitive function: HMAC-SHA512, 2,048 iterations, a 64-byte result. The sentence is the password. The salt is the word mnemonic followed by an optional passphrase. Both are normalized to NFKD first.1920

The result is 512 bits, four times the 128 bits of entropy behind a 12-word phrase, yet it holds no new randomness. Every bit of it is fixed by the words and the passphrase. A wallet that never asks for a passphrase is simply using the empty one.192021

FIG. A01.3 Words and passphrase to seed

Public test values · never use for funds

Passwordthe sentence, ozone drill grab …UTF-8, NFKD-normalized
Salt"mnemonic" + passphraseUTF-8, NFKD-normalized
PBKDF2HMAC-SHA512 · 2,048 iterations · 64-byte output
  • Passphrase "TREZOR"274ddc525802f7c8…69a41028Matches the published test vector
  • Passphrase empty ""e2f88a043776c828…f0e73a6cComputed by the tested implementation
Exact seeds, all 64 bytes
Passphrase "TREZOR"
274ddc52 5802f7c8 28d8ef7d dbcdc530 4e87ac35 35913611 fbbfa986 d0c9e547 6c91689f 9c8a54fd 55bd3860 6aa6a859 5ad213d4 c9c9f9ac a3fb2170 69a41028
Passphrase "" (empty)
e2f88a04 3776c828 063d4c3c 97173944 d32cf847 a925b6e4 0b0b8bd0 b4bead3b a734bdda 5250d469 8b310a71 c9934e1a 48e56231 5ce22bf8 5f89459d f0e73a6c
The same words with a different passphrase give an unrelated seed. An empty passphrase is still a passphrase; it is simply the default.6192122

Because this step starts from the words rather than the entropy, the seed depends on exactly how the sentence is written. The same entropy written with another wordlist gives a completely different seed, and there is no way back from a seed to a sentence.2023

Details: why NFKD matters

Unicode can write some visible text in more than one way. NFKD picks one decomposed form, so that two devices showing the same characters feed the same bytes into PBKDF2. The Japanese test vectors referenced by BIP 39 use passphrases full of symbols such as ㍍, which NFKD expands into the four characters メートル. The tests behind this page check all 24 of those vectors.61924

Notice also what the seed step leaves out. It never checks the checksum and places no constraints on how the sentence is built; clients are free to use their own wordlists or even whole sentence generators, though BIP 39 advises against using sentences its own algorithm did not produce. Software must still compute the checksum with a wordlist and warn if it is invalid.182025

A passphrase is not a password

The optional passphrase changes the seed entirely, and every passphrase produces a valid one. BIP 39 presents this as plausible deniability: only the right passphrase opens the intended wallet, while any other opens a different, working wallet rather than an error.2122

That makes it unlike an app’s unlock password, which protects a file on one device and complains when you get it wrong. Mistype a BIP 39 passphrase and nothing complains; the words simply lead somewhere else.26

Still not a key

The 64-byte seed still signs nothing. BIP 39 hands it to BIP 32 or a similar scheme, which grows a whole tree of keys from it. That is the next chapter.27

It is tempting to call the words a private key. They are not. They encode entropy; the seed is produced by stretching the sentence; keys come from the seed in a further step. All three must stay secret, because each one, together with the passphrase if one is used, is enough to rebuild everything that follows.41927

BIP 39 lists other shortcomings too, including the lack of a versioning scheme, which it notes is now largely mitigated by descriptor wallets. Its authors proposed a scheme called SLIP-0039 as an intended successor.28

Evidence

Each numbered marker in the text points here. Quotes are verbatim from the BIP files at commit 3a10b5b, including their wiki markup; links open the exact lines; the quoted text sits under each entry. Labels say what kind of statement each is: a rule, the author’s rationale, history, a test vector, or our own inference.

  1. Author’s rationale A mnemonic sentence is meant to be easier for people to handle than raw binary or hex: it can be written on paper or spoken over the telephone.

    Quoted source text (2)

    A mnemonic code or sentence is superior for human interaction compared to the handling of raw binary or hexadecimal representations of a wallet seed.

    BIP 39, lines 30–31

    The sentence could be written on paper or spoken over the telephone.

    BIP 39, lines 31–32
  2. Rule BIP39 transports computer-generated randomness; it is not a way to turn user-created sentences (brainwallets) into seeds.

    Quoted source text (1)

    This guide is meant to be a way to transport computer-generated randomness with a human-readable transcription. It's not a way to process user-created sentences (also known as brainwallets) into a wallet seed.

    BIP 39, lines 34–36
  3. History BIP39 was assigned in 2013 and its preamble records the status Deployed.

    Quoted source text (2)

    Assigned: 2013-09-10

    BIP 39, line 11

    Status: Deployed

    BIP 39, line 9
  4. Rule BIP39 has two parts: generating the mnemonic and converting it into a binary seed.

    Quoted source text (1)

    It consists of two parts: generating the mnemonic and converting it into a binary seed.

    BIP 39, lines 20–21
  5. Rule The combined bits are split into 11-bit groups, each a number from 0 to 2047 used as an index into the wordlist.

    Quoted source text (1)

    these concatenated bits are split into groups of 11 bits, each encoding a number from 0-2047, serving as an index into a wordlist.

    BIP 39, lines 46–48
  6. Test vector BIP39's test vectors live in trezor/python-mnemonic and use the passphrase TREZOR; separate Japanese vectors exercise heavily normalized passphrases.

    Quoted source text (3)

    The passphrase "TREZOR" is used for all vectors.

    BIP 39, lines 130–131

    https://github.com/trezor/python-mnemonic/blob/master/vectors.json

    BIP 39, line 133

    (Japanese wordlist test with heavily normalized symbols as passphrase)

    BIP 39, line 137
  7. Rule Entropy must be a multiple of 32 bits, between 128 and 256 bits.

    Quoted source text (2)

    The mnemonic must encode entropy in a multiple of 32 bits.

    BIP 39, line 40

    The allowed size of ENT is 128-256 bits.

    BIP 39, line 42
  8. Rule CS = ENT/32 and MS = (ENT+CS)/11: 128 bits of entropy give 4 checksum bits and 12 words; 256 bits give 8 and 24.

    Quoted source text (3)

    CS = ENT / 32 MS = (ENT + CS) / 11

    BIP 39, lines 56–57

    | 128 | 4 | 132 | 12 |

    BIP 39, line 61

    | 256 | 8 | 264 | 24 |

    BIP 39, line 65
  9. Rule The checksum is the first ENT/32 bits of the SHA-256 hash of the entropy, appended to its end.

    Quoted source text (1)

    A checksum is generated by taking the first <code>ENT / 32</code> bits of its SHA256 hash. This checksum is appended to the end of the initial entropy.

    BIP 39, lines 44–46
  10. Test vector For the published all-zero 128-bit vector, the 4 checksum bits are 0011, so eleven groups are index 0 (abandon) and the last is index 3 (about).

    Quoted source text (1)

    The test vectors include input entropy, mnemonic and seed.

    BIP 39, lines 130–131
  11. Editorial inference Because the checksum is appended after the entropy, the final word mixes the last entropy bits with the checksum: 7 + 4 bits for 12 words, 3 + 8 bits for 24 words.

    Quoted source text (3)

    This checksum is appended to the end of the initial entropy.

    BIP 39, lines 44–46

    | 128 | 4 | 132 | 12 |

    BIP 39, line 61

    | 256 | 8 | 264 | 24 |

    BIP 39, line 65
  12. Author’s rationale BIP39 describes an ideal wordlist: the first four letters identify a word, similar word pairs are avoided, and the list is sorted for efficient lookup.

    Quoted source text (4)

    An ideal wordlist has the following characteristics:

    BIP 39, line 70

    it's enough to type the first four letters to unambiguously identify the word

    BIP 39, lines 73–74

    word pairs like "build" and "built", "woman" and "women", or "quick" and "quickly"

    BIP 39, line 77

    the wordlist is sorted which allows for more efficient lookup of the code words

    BIP 39, line 82
  13. Test vector The pinned English wordlist has 2,048 sorted, unique entries whose first four letters are all distinct.

    Quoted source text (1)

    [[bip-0039/bip-0039-wordlists.md|Wordlists]]

    BIP 39, line 126
  14. Rule Wordlists with native characters must be encoded in UTF-8 using NFKD.

    Quoted source text (1)

    The wordlist can contain native characters, but they must be encoded in UTF-8 using Normalization Form Compatibility Decomposition (NFKD).

    BIP 39, lines 86–87
  15. Author’s rationale Because most wallets support only English, BIP39 strongly discourages non-English wordlists for generating sentences.

    Quoted source text (1)

    Since the vast majority of BIP39 wallets supports only the English wordlist, it is '''strongly discouraged''' to use non-English wordlists for generating the mnemonic sentences.

    BIP 39, lines 119–121
  16. Author’s rationale BIP39 lists its short checksum as a shortcoming: modest odds of catching random errors (it cites 1 in 256 missed) and no help correcting them.

    Quoted source text (1)

    The checksum is short. This means it only gives modest odds of catching random errors (1-in-256 errors will be missed). It is also not able to provide any assistance in correcting errors.

    BIP 39, line 147
  17. Test vector With 4 checksum bits, 128 of the 2,048 possible final words give a valid 12-word sentence (1 in 16); with 8 bits, 8 of 2,048 give a valid 24-word sentence (1 in 256).

    Quoted source text (2)

    CS = ENT / 32

    BIP 39, line 56

    1-in-256 errors will be missed

    BIP 39, line 147
  18. Rule Using a sentence not generated by BIP39's algorithm is possible but not advised, and software must compute its checksum and warn if it is invalid.

    Quoted source text (1)

    Although using a mnemonic not generated by the algorithm described in "Generating the mnemonic" section is possible, this is not advised and software must compute a checksum for the mnemonic sentence using a wordlist and issue a warning if it is invalid.

    BIP 39, lines 108–111
  19. Rule The seed is PBKDF2 with the NFKD sentence as password, "mnemonic" + passphrase (NFKD) as salt, 2048 iterations of HMAC-SHA512, and a 64-byte output.

    Quoted source text (1)

    we use the PBKDF2 function with a mnemonic sentence (in UTF-8 NFKD) used as the password and the string "mnemonic" + passphrase (again in UTF-8 NFKD) used as the salt. The iteration count is set to 2048 and HMAC-SHA512 is used as the pseudo-random function. The length of the derived key is 512 bits (= 64 bytes).

    BIP 39, lines 94–97
  20. Rule Seed generation uses the sentence and is completely independent from how the sentence was generated.

    Quoted source text (1)

    The conversion of the mnemonic sentence to a binary seed is completely independent from generating the sentence.

    BIP 39, lines 102–103
  21. Rule The passphrase is optional; when absent, the empty string is used.

    Quoted source text (1)

    If a passphrase is not present, an empty string "" is used instead.

    BIP 39, lines 91–92
  22. Author’s rationale Every passphrase generates a valid seed and wallet; only the correct one opens the intended wallet. BIP39 calls this plausible deniability.

    Quoted source text (1)

    every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available.

    BIP 39, lines 113–115
  23. Author’s rationale Because the seed is computed from the words, the same entropy written with another wordlist gives a different seed, and a seed cannot be turned back into a sentence.

    Quoted source text (2)

    translating the mnemonic to a different wordlist necessarily creates a completely different seed.

    BIP 39, line 143

    the conversion is one-way only (from BIP-0039 sentence to BIP-0032 seed).

    BIP 39, line 145
  24. Test vector NFKD expands the single character ㍍ into the four characters メートル; all 24 Japanese vectors depend on this kind of normalization.

    Quoted source text (2)

    (Japanese wordlist test with heavily normalized symbols as passphrase)

    BIP 39, line 137

    (again in UTF-8 NFKD)

    BIP 39, lines 95–96
  25. Rule The seed step places no constraints on sentence structure; clients may use their own wordlists or sentence generators.

    Quoted source text (2)

    there are no constraints on sentence structure and clients are free to implement their own wordlists or even whole sentence generators

    BIP 39, lines 103–106

    is possible, this is not advised

    BIP 39, lines 108–109
  26. Editorial inference Unlike an application's unlock password, a wrong BIP39 passphrase does not fail: it silently leads to a different wallet.

    Quoted source text (1)

    every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available.

    BIP 39, lines 113–115
  27. Rule The seed can then be used to generate deterministic wallets using BIP32 or similar methods.

    Quoted source text (1)

    This seed can be later used to generate deterministic wallets using BIP-0032 or similar methods.

    BIP 39, lines 99–100
  28. Author’s rationale BIP39 lists the lack of a versioning scheme among its shortcomings, noting it is now largely mitigated by descriptor wallets; its authors proposed SLIP-0039 as an intended successor.

    Quoted source text (2)

    No versioning scheme. When originally introduced, there was no way to distinguish the address format that should be used for a BIP-0039 key. This is now largely mitigated by use of descriptor wallets (BIP-0380) in addition to a seed however.

    BIP 39, line 149

    The authors of BIP-0039 proposed the [https://github.com/satoshilabs/slips/blob/master/slip-0039.md SLIP-0039] scheme as an intended successor to BIP-0039 improving on the above shortcomings.

    BIP 39, line 153