24 words. 256 bits.
No second chances.

Understanding BIP-39 seed phrase entropy — and why the number of words in your recovery phrase is the most important security decision you'll make.

Entropy, in plain words

Every BIP-39 word encodes 11 bits of data. More words mean more entropy — and the key space grows exponentially.

12 words

Entropy
128 bits
  • 132 bits total: 128-bit entropy + 4-bit checksum
  • 3.4 × 10³⁸ possible phrases
  • Secure against brute force today

24 words

Entropy
256 bits
  • 264 bits total: 256-bit entropy + 8-bit checksum
  • 1.2 × 10⁷⁷ possible phrases
  • Squares the search space vs 12 words
Entropy comes from randomness, not from picking "harder" words. A 24-word phrase from a weak random source is weaker than an honest 12-word phrase. The generator below uses your browser's cryptographic RNG (crypto.getRandomValues) — nothing is sent or stored.

12 vs 24 — side by side

Both are valid BIP-39 lengths. The difference is the raw key space.

12 words
2¹²⁸ keys

At 1 trillion guesses/second, cracking 2¹²⁸ takes ~10²⁶ years — trillions of times the age of the universe.

24 words
2²⁵⁶ = (2¹²⁸)²

Doubling the words squares the search space — the same jump as AES-128 → AES-256.

Generate & test strength

Generated entirely in your browser with crypto.getRandomValues. Nothing is transmitted, stored, or logged.

Educational purposes only. Generated client-side with nothing transmitted or stored. Never enter a phrase you intend to use with real funds into any website — use a hardware wallet's own RNG for real keys.