BIP 0039
How can a wallet backup become a list of words?
Twelve ordinary words can stand in for 128 random bits. There is no encryption involved, just counting, a small checksum and a list of 2,048 words.
Many wallets ask you to write down a dozen or two dozen words and keep them somewhere safe. The words are not a password you chose, and nobody composed them as a sentence. BIP 39 describes them as a way to carry computer-generated randomness in a form people can write on paper or read over the telephone.12
The proposal, assigned in 2013 and recorded as deployed, has two halves: turning random bits into words, and turning words into a binary seed for later wallet machinery. This chapter follows both, using only published test phrases that anyone can look up, and values computed from them.34
Source details
This chapter is an independent explanation, not the proposals themselves. Preamble fields are shown as recorded in the pinned files, with author e-mail addresses omitted. Status is the proposal’s own field, not an endorsement or a sign of consensus.
BIP 39: Mnemonic code for generating deterministic keys
- BIP
- 39
- Layer
- Applications
- Title
- Mnemonic code for generating deterministic keys
- Authors
- Marek Palatinus
Pavol Rusnak
Aaron Voisine
Sean Bowe - Status
- Deployed
- Type
- Specification
- Assigned
- 2013-09-10
- License
- MIT
Public test vector · never use for funds
- 01ozone#1268
- 02drill#535
- 03grab#810
- 04fiber#685
- 05curtain#433
- 06grace#811
- 07pudding#1385
- 08thank#1790
- 09cruise#421
- 10elder#570
- 11eight#567
- 12picnic#1313
12 words · 128 bits of entropy + 4 checksum bits · English wordlist
Randomness first
Everything starts with entropy: a block of random bits produced by a computer. BIP 39 allows between 128 and 256 bits, in steps of 32. More bits make a stronger backup and a longer sentence.7
Why words at all? A 128-bit number written in hexadecimal is thirty-two characters of digits and letters, easy to transpose and tiring to read aloud. Twelve familiar words carry the same information in a form that is easier to copy by hand and to check against the original.18
The proposal is explicit that it transcribes randomness. It is not a way to turn a sentence someone made up into a wallet; such brainwallets are outside its scope.2
A checksum from a hash
Before any words appear, the entropy gets a short checksum. Hash the entropy with SHA-256 and keep the first ENT / 32 bits of the result, where ENT is the number of entropy bits: 4 checksum bits for 128 bits of entropy, 8 for 256. Append them to the end.89
The total is now a multiple of 11: 132 bits for 128 bits of entropy, 264 for 256. Cut it into 11-bit groups. Each group is a number from 0 to 2,047, and each number picks one word from a list of exactly 2,048. Twelve groups give twelve words; twenty-four give twenty-four.58
The published all-zero sample shows the whole procedure at its plainest. Its 128 entropy bits are all zero. The SHA-256 hash of those sixteen zero bytes happens to begin with the bits 0011, so those four bits become the checksum. The first eleven groups are eleven zeros each, index 0, the word abandon. The last group is seven zeros followed by 0011: index 3, the word about. That is why this famous test phrase reads abandon eleven times and then about. All-zero entropy is, of course, useless as a real backup: it is public precisely because it is predictable.5910
The figure below starts from the bits of a public sample. Reveal the groups to see where the cuts fall, then step through to the last word.5
Static view of the first sample with every 11-bit group revealed. With JavaScript you can switch samples and sizes and step through the groups.
128 entropy bits+4 checksum bits= 132 bits= 12 × 11
SHA-256(entropy)374708fff7719dd5…first 4 bits0011
The last word holds 7 entropy bits and 4 checksum bits.
Sample source: trezor-python-mnemonic-vectors.json (english[0]), pinned by commit. Public test material; never use it for funds.
Details: every allowed length
| Entropy bits | Checksum bits | Total bits | Words | Entropy bits in last word |
|---|---|---|---|---|
| 128 | 4 | 132 | 12 | 7 |
| 160 | 5 | 165 | 15 | 6 |
| 192 | 6 | 198 | 18 | 5 |
| 224 | 7 | 231 | 21 | 4 |
| 256 | 8 | 264 | 24 | 3 |
Leading zeros count. The 24-word sample beginning all hour comes from entropy whose first five bits are zero, and those zeros are part of its first group like any other bits.56
A list built for people
The list has 2,048 words for a reason: 2,048 is two to the eleventh power, so every word stands for exactly 11 bits, no more and no less. That is what lets the bit string and the sentence convert into each other without anything left over.58
The English list was chosen with care. BIP 39 describes an ideal list as one where the first four letters identify each word, where near-pairs such as build and built or woman and women are avoided, and which is sorted so software can search it quickly.12
The pinned English list used on this page has 2,048 entries, and the tests behind it confirm that no two share their first four letters. Lists with accented or composed characters must be stored in a Unicode form called NFKD, a detail that returns below.1314
Other languages exist, but BIP 39 strongly discourages generating sentences from them, because most wallets support only the English list.15
How short is the checksum?
A checksum lets software notice a wrong word, but this one is small. BIP 39 lists it among its own shortcomings: it gives only modest odds of catching random errors, citing one in 256 missed, and offers no help correcting them.16
That figure matches the 8 checksum bits of a 24-word phrase. A 12-word phrase has only 4, so swapping its last word for a random one still passes one time in sixteen. The tests behind this page count exactly 128 of the 2,048 possible last words that do.817
BIP 39 does require software to compute the checksum of a sentence and to warn when it is invalid. A warning is the whole of the job: the checksum cannot say which word is wrong.1618
From words to a seed
The second half of BIP 39 does not reverse the first, and never recovers the entropy. Instead it feeds the sentence itself into PBKDF2, a deliberately repetitive function: HMAC-SHA512, 2,048 iterations, a 64-byte result. The sentence is the password. The salt is the word mnemonic followed by an optional passphrase. Both are normalized to NFKD first.1920
The result is 512 bits, four times the 128 bits of entropy behind a 12-word phrase, yet it holds no new randomness. Every bit of it is fixed by the words and the passphrase. A wallet that never asks for a passphrase is simply using the empty one.192021
Public test values · never use for funds
"mnemonic" + passphraseUTF-8, NFKD-normalized- Passphrase
"TREZOR"274ddc525802f7c8…69a41028Matches the published test vector - Passphrase empty
""e2f88a043776c828…f0e73a6cComputed by the tested implementation
Exact seeds, all 64 bytes
- Passphrase "TREZOR"
274ddc52 5802f7c8 28d8ef7d dbcdc530 4e87ac35 35913611 fbbfa986 d0c9e547 6c91689f 9c8a54fd 55bd3860 6aa6a859 5ad213d4 c9c9f9ac a3fb2170 69a41028- Passphrase "" (empty)
e2f88a04 3776c828 063d4c3c 97173944 d32cf847 a925b6e4 0b0b8bd0 b4bead3b a734bdda 5250d469 8b310a71 c9934e1a 48e56231 5ce22bf8 5f89459d f0e73a6c
Because this step starts from the words rather than the entropy, the seed depends on exactly how the sentence is written. The same entropy written with another wordlist gives a completely different seed, and there is no way back from a seed to a sentence.2023
Details: why NFKD matters
Unicode can write some visible text in more than one way. NFKD picks one decomposed form, so that two devices showing the same characters feed the same bytes into PBKDF2. The Japanese test vectors referenced by BIP 39 use passphrases full of symbols such as ㍍, which NFKD expands into the four characters メートル. The tests behind this page check all 24 of those vectors.61924
Notice also what the seed step leaves out. It never checks the checksum and places no constraints on how the sentence is built; clients are free to use their own wordlists or even whole sentence generators, though BIP 39 advises against using sentences its own algorithm did not produce. Software must still compute the checksum with a wordlist and warn if it is invalid.182025
A passphrase is not a password
The optional passphrase changes the seed entirely, and every passphrase produces a valid one. BIP 39 presents this as plausible deniability: only the right passphrase opens the intended wallet, while any other opens a different, working wallet rather than an error.2122
That makes it unlike an app’s unlock password, which protects a file on one device and complains when you get it wrong. Mistype a BIP 39 passphrase and nothing complains; the words simply lead somewhere else.26
Still not a key
The 64-byte seed still signs nothing. BIP 39 hands it to BIP 32 or a similar scheme, which grows a whole tree of keys from it. That is the next chapter.27
It is tempting to call the words a private key. They are not. They encode entropy; the seed is produced by stretching the sentence; keys come from the seed in a further step. All three must stay secret, because each one, together with the passphrase if one is used, is enough to rebuild everything that follows.41927
BIP 39 lists other shortcomings too, including the lack of a versioning scheme, which it notes is now largely mitigated by descriptor wallets. Its authors proposed a scheme called SLIP-0039 as an intended successor.28
Evidence
Each numbered marker in the text points here. Quotes are verbatim from the BIP files at commit
3a10b5b, including their wiki markup; links open
the exact lines; the quoted text sits under each entry. Labels say what kind of statement each is: a rule, the author’s rationale, history,
a test vector, or our own inference.
-
Author’s rationale A mnemonic sentence is meant to be easier for people to handle than raw binary or hex: it can be written on paper or spoken over the telephone.
Quoted source text (2)
A mnemonic code or sentence is superior for human interaction compared to the handling of raw binary or hexadecimal representations of a wallet seed.
The sentence could be written on paper or spoken over the telephone.
-
Rule BIP39 transports computer-generated randomness; it is not a way to turn user-created sentences (brainwallets) into seeds.
Quoted source text (1)
This guide is meant to be a way to transport computer-generated randomness with a human-readable transcription. It's not a way to process user-created sentences (also known as brainwallets) into a wallet seed.
-
History BIP39 was assigned in 2013 and its preamble records the status Deployed.
Quoted source text (2)
Assigned: 2013-09-10
Status: Deployed
-
Rule BIP39 has two parts: generating the mnemonic and converting it into a binary seed.
Quoted source text (1)
It consists of two parts: generating the mnemonic and converting it into a binary seed.
-
Rule The combined bits are split into 11-bit groups, each a number from 0 to 2047 used as an index into the wordlist.
Quoted source text (1)
these concatenated bits are split into groups of 11 bits, each encoding a number from 0-2047, serving as an index into a wordlist.
-
Test vector BIP39's test vectors live in trezor/python-mnemonic and use the passphrase TREZOR; separate Japanese vectors exercise heavily normalized passphrases.
BIP 39 L130–131 BIP 39 L133 BIP 39 L137
Quoted source text (3)
The passphrase "TREZOR" is used for all vectors.
https://github.com/trezor/python-mnemonic/blob/master/vectors.json
(Japanese wordlist test with heavily normalized symbols as passphrase)
-
Rule Entropy must be a multiple of 32 bits, between 128 and 256 bits.
Quoted source text (2)
The mnemonic must encode entropy in a multiple of 32 bits.
The allowed size of ENT is 128-256 bits.
-
Rule CS = ENT/32 and MS = (ENT+CS)/11: 128 bits of entropy give 4 checksum bits and 12 words; 256 bits give 8 and 24.
BIP 39 L56–57 BIP 39 L61 BIP 39 L65
Quoted source text (3)
CS = ENT / 32 MS = (ENT + CS) / 11
| 128 | 4 | 132 | 12 |
| 256 | 8 | 264 | 24 |
-
Rule The checksum is the first ENT/32 bits of the SHA-256 hash of the entropy, appended to its end.
Quoted source text (1)
A checksum is generated by taking the first <code>ENT / 32</code> bits of its SHA256 hash. This checksum is appended to the end of the initial entropy.
-
Test vector For the published all-zero 128-bit vector, the 4 checksum bits are 0011, so eleven groups are index 0 (abandon) and the last is index 3 (about).
Quoted source text (1)
The test vectors include input entropy, mnemonic and seed.
-
Editorial inference Because the checksum is appended after the entropy, the final word mixes the last entropy bits with the checksum: 7 + 4 bits for 12 words, 3 + 8 bits for 24 words.
BIP 39 L44–46 BIP 39 L61 BIP 39 L65
Quoted source text (3)
This checksum is appended to the end of the initial entropy.
| 128 | 4 | 132 | 12 |
| 256 | 8 | 264 | 24 |
-
Author’s rationale BIP39 describes an ideal wordlist: the first four letters identify a word, similar word pairs are avoided, and the list is sorted for efficient lookup.
BIP 39 L70 BIP 39 L73–74 BIP 39 L77 BIP 39 L82
Quoted source text (4)
An ideal wordlist has the following characteristics:
it's enough to type the first four letters to unambiguously identify the word
word pairs like "build" and "built", "woman" and "women", or "quick" and "quickly"
the wordlist is sorted which allows for more efficient lookup of the code words
-
Test vector The pinned English wordlist has 2,048 sorted, unique entries whose first four letters are all distinct.
Quoted source text (1)
[[bip-0039/bip-0039-wordlists.md|Wordlists]]
-
Rule Wordlists with native characters must be encoded in UTF-8 using NFKD.
Quoted source text (1)
The wordlist can contain native characters, but they must be encoded in UTF-8 using Normalization Form Compatibility Decomposition (NFKD).
-
Author’s rationale Because most wallets support only English, BIP39 strongly discourages non-English wordlists for generating sentences.
Quoted source text (1)
Since the vast majority of BIP39 wallets supports only the English wordlist, it is '''strongly discouraged''' to use non-English wordlists for generating the mnemonic sentences.
-
Author’s rationale BIP39 lists its short checksum as a shortcoming: modest odds of catching random errors (it cites 1 in 256 missed) and no help correcting them.
Quoted source text (1)
The checksum is short. This means it only gives modest odds of catching random errors (1-in-256 errors will be missed). It is also not able to provide any assistance in correcting errors.
-
Test vector With 4 checksum bits, 128 of the 2,048 possible final words give a valid 12-word sentence (1 in 16); with 8 bits, 8 of 2,048 give a valid 24-word sentence (1 in 256).
Quoted source text (2)
CS = ENT / 32
1-in-256 errors will be missed
-
Rule Using a sentence not generated by BIP39's algorithm is possible but not advised, and software must compute its checksum and warn if it is invalid.
Quoted source text (1)
Although using a mnemonic not generated by the algorithm described in "Generating the mnemonic" section is possible, this is not advised and software must compute a checksum for the mnemonic sentence using a wordlist and issue a warning if it is invalid.
-
Rule The seed is PBKDF2 with the NFKD sentence as password, "mnemonic" + passphrase (NFKD) as salt, 2048 iterations of HMAC-SHA512, and a 64-byte output.
Quoted source text (1)
we use the PBKDF2 function with a mnemonic sentence (in UTF-8 NFKD) used as the password and the string "mnemonic" + passphrase (again in UTF-8 NFKD) used as the salt. The iteration count is set to 2048 and HMAC-SHA512 is used as the pseudo-random function. The length of the derived key is 512 bits (= 64 bytes).
-
Rule Seed generation uses the sentence and is completely independent from how the sentence was generated.
Quoted source text (1)
The conversion of the mnemonic sentence to a binary seed is completely independent from generating the sentence.
-
Rule The passphrase is optional; when absent, the empty string is used.
Quoted source text (1)
If a passphrase is not present, an empty string "" is used instead.
-
Author’s rationale Every passphrase generates a valid seed and wallet; only the correct one opens the intended wallet. BIP39 calls this plausible deniability.
Quoted source text (1)
every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available.
-
Author’s rationale Because the seed is computed from the words, the same entropy written with another wordlist gives a different seed, and a seed cannot be turned back into a sentence.
Quoted source text (2)
translating the mnemonic to a different wordlist necessarily creates a completely different seed.
the conversion is one-way only (from BIP-0039 sentence to BIP-0032 seed).
-
Test vector NFKD expands the single character ㍍ into the four characters メートル; all 24 Japanese vectors depend on this kind of normalization.
Quoted source text (2)
(Japanese wordlist test with heavily normalized symbols as passphrase)
(again in UTF-8 NFKD)
-
Rule The seed step places no constraints on sentence structure; clients may use their own wordlists or sentence generators.
BIP 39 L103–106 BIP 39 L108–109
Quoted source text (2)
there are no constraints on sentence structure and clients are free to implement their own wordlists or even whole sentence generators
is possible, this is not advised
-
Editorial inference Unlike an application's unlock password, a wrong BIP39 passphrase does not fail: it silently leads to a different wallet.
Quoted source text (1)
every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available.
-
Rule The seed can then be used to generate deterministic wallets using BIP32 or similar methods.
Quoted source text (1)
This seed can be later used to generate deterministic wallets using BIP-0032 or similar methods.
-
Author’s rationale BIP39 lists the lack of a versioning scheme among its shortcomings, noting it is now largely mitigated by descriptor wallets; its authors proposed SLIP-0039 as an intended successor.
Quoted source text (2)
No versioning scheme. When originally introduced, there was no way to distinguish the address format that should be used for a BIP-0039 key. This is now largely mitigated by use of descriptor wallets (BIP-0380) in addition to a seed however.
The authors of BIP-0039 proposed the [https://github.com/satoshilabs/slips/blob/master/slip-0039.md SLIP-0039] scheme as an intended successor to BIP-0039 improving on the above shortcomings.