‹ Crypto Foundations Lesson 11 of 16
Contents Lesson 11 of 16

4 min read · practitioner

What is a seed phrase, and what does it actually contain?

Unit 2 gave you the safety rule: the phrase is entered exactly once, into the wallet you deliberately chose to restore. This lesson explains what those words are, because understanding the construction makes several confusing behaviours obvious.

A seed phrase is not a password. It is your entropy, written in a form a human can copy without errors.

The construction, step by step (BIP-39)

  1. Generate entropy. The wallet produces 128 or 256 bits of randomness.
  2. Add a checksum. Append entropy ÷ 32 bits derived from the hash of that entropy — 4 bits for 128, 8 bits for 256.
  3. Slice into 11-bit groups. Each group is a number from 0 to 2047, indexing a published wordlist of exactly 2048 words.
    • 128 + 4 = 132 bits ÷ 11 = 12 words
    • 256 + 8 = 264 bits ÷ 11 = 24 words
  4. Stretch into a seed. The phrase, plus an optional passphrase, is run through PBKDF2-HMAC-SHA512 for 2048 iterations with the salt "mnemonic" + passphrase, producing a 512-bit seed.

Everything else in your wallet comes from that seed.

From one seed to every address (BIP-32 / BIP-44)

The seed generates a master key, and from it an unlimited tree of child keys derived by a path:

m / purpose' / coin_type' / account' / change / index

  • m/44'/60'/0'/0/0 — the first Ethereum account
  • m/84'/0'/0'/0/0 — the first native-SegWit Bitcoin account

This is called hierarchical deterministic derivation, and it answers a common confusion: one phrase restores every address the wallet ever showed you, on every chain it supports, because none of them were stored anywhere. They were all computed from the same seed, on demand.

It also explains a classic support case. Restore a phrase into different wallet software and the balance can look wrong — not because anything is lost, but because the second wallet defaulted to a different derivation path. The funds are at the addresses on the original path, exactly where they always were.

Four facts people get wrong

  • Word order is part of the secret. The checksum means a wrong order is usually detected, not corrected. Detection is not recovery.
  • The wordlist is public. Secrecy comes from which 12 of the 2048, in which order — never from the words being obscure. Every word is uniquely identified by its first four letters, which is a deliberate design choice for handwriting.
  • 12 words carry 128 bits of entropy, not 132. The four checksum bits are computed, not random. So 2¹²⁸ ≈ 3.4 × 10³⁸ valid phrases exist — vastly fewer than the 2¹³² sequences you could write down, and still far beyond brute force.
  • The optional passphrase creates a different wallet. Sometimes marketed as a "25th word", it changes the derived seed entirely. The same 24 words with and without it produce two unrelated sets of addresses. It protects against someone finding the paper — and it destroys everything if you forget it, because there is no record of it anywhere.

The storage problem, stated honestly

Every copy of the phrase is another place it can be stolen from. Every missing copy is another way to lose everything. These pull in opposite directions and there is no configuration that eliminates both.

Paper burns, floods and fades. A photo lives in whatever cloud backs up your gallery. A password manager moves the problem to that vault's master password. Metal plates survive fire and do nothing about theft. What matters is that you can name every location, and that the number of people who could reach any of them is a number you actually know.

Try it now

  1. Verify the arithmetic yourself: 2048 words is 2¹¹, so 12 words hold 12 × 11 = 132 bits, of which 4 are checksum, leaving 128 bits of real entropy. This is not trivia — it is the reason 12 words are considered sufficient.
  2. Look up the published BIP-39 English wordlist and confirm two claims: it contains exactly 2048 entries, and no two words share their first four letters.
  3. On a block explorer, note that nothing about derivation paths or phrases appears anywhere on-chain. The ledger only ever sees addresses and signatures — the entire seed structure is a convenience that exists on your device alone.