Skip to content
Home » Blog » BIP39 Word List Explained: The 2,048 Words That Secure a Crypto Wallet

BIP39 Word List Explained: The 2,048 Words That Secure a Crypto Wallet

BIP39 is the word list behind most crypto seed phrases. It’s a fixed set of 2,048 English words, and a wallet picks 12 or 24 of them when it creates your phrase.

Those words replaced the old habit of backing up a raw string of letters and numbers with something you can actually write down. Here’s how the list works.

What Is the BIP39 Word List?

The BIP39 word list is the standard set of 2,048 English words used to generate a seed phrase. Each word stands in for a number from 0 to 2,047. “abandon” is first and “zoo” is last.

Before this list, a backup was often a hexadecimal string, and people mistyped it. The standard is BIP39, Bitcoin Improvement Proposal 39.

Why Wallets Use the BIP39 List

Early wallets each invented their own backup. A phrase from one app often wouldn’t restore in another, so switching brands meant moving every coin by hand. If the company shut down, you could be stuck with a backup nothing else could read.

A shared list means the same words can travel with you when both wallets follow BIP39. If the software rejects the phrase, that’s a different problem. Our guide to fixing an invalid seed phrase covers a wrong word, bad spelling, and a missing word.

How BIP39 Creates a Seed Phrase

Building the phrase is a three-step process: a random number, a short check, then words from the list.

How a BIP39 phrase is built

The Random Starting Number

The process starts with entropy, a long random string of 1s and 0s. Software wallets pull it from a cryptographically secure random number generator, often called a CSPRNG. Hardware wallets usually pull it from a true random number generator chip, a TRNG. You don’t pick the words, because a phrase you invented is much easier to guess.

The Checksum

The wallet runs that random number through SHA-256 and appends a few bits of the hash. That’s the checksum, a built-in check that the words belong together. It can catch a typo, but it isn’t what makes the phrase hard to guess.

A 12-word phrase carries only four checksum bits, so roughly one wrong-word error in sixteen still passes. A 24-word phrase has eight bits, so about one in 256 slips through. A phrase the wallet accepts isn’t proof it’s yours. It can open a real wallet that doesn’t hold your coins.

From Bits to Words

The random bits plus the checksum are split into chunks of 11 bits. Each chunk is a number from 0 to 2,047, and that number picks one word.

Entropy (bits)Checksum (bits)Total (bits)Word count
128413212
160516515
192619818
224723121
256826424

Twelve words means 128 bits of randomness, and 24 words means 256. Most phone and browser wallets give you 12, and Ledger usually gives you 24. The 15-, 18-, and 21-word lengths are uncommon. Our guide to how crypto wallet security works covers how those words become the keys that spend the coins.

How the 2,048 Words Were Chosen

BIP39 sets rules so a person copying a phrase onto paper makes fewer mistakes.

The First Four Letters

Every English word on the list can be identified from its first four letters. “abandon” and “ability” split at the fourth letter, which is how a wallet finishes the word as you type.

No Near-Duplicate Words

The list leaves out pairs that are easy to mix up. “build” is on the list and “built” isn’t. Same with “woman” and “women,” and “quick” and “quickly.”

Is the Word List Only in English?

No. There are also lists for Spanish, French, Italian, Portuguese, Czech, Japanese, Korean, and Chinese in both simplified and traditional forms. English is the one to use. Most wallets only ship that list, and the spec strongly discourages the others.

The seed is built from the words as written. Rewriting the phrase with another language’s list produces a different wallet.

What Keeps a BIP39 Phrase Safe

The words themselves are public, and anyone can download the list. What keeps the wallet safe is how many ways those words can be arranged.

A 12-word phrase has 2,048 choices in each position. That’s about 5.4 times 10 to the 39th power. The checksum throws most of those strings out, and what remains is 2^128 valid phrases. A billion guesses every second for a billion years still wouldn’t get you anywhere close. A 24-word phrase is 2^256 valid combinations, which is a much bigger set.

What can actually go wrong is someone getting hold of the copy you wrote down. Anyone with those words can move the coins, and they don’t need your phone, your PIN, or the device that created the wallet.

Why One List Works Across Wallets

A 12- or 24-word BIP39 phrase can usually be restored in a different wallet, for example a MetaMask phrase can go onto a Ledger. The new app rebuilds the same keys from those words, so the coins don’t move. Someone else who has the words can do the same thing.

A 20-word backup isn’t BIP39. It’s SLIP39, Trezor’s Single-share Backup, from a different word list. That’s the default on the Trezor Safe 3 from June 2024 and on the Safe 5 and Safe 7. MetaMask and Ledger will reject it, so you’ll usually need another Trezor to restore those words. Rabby, Electrum, Sparrow, and BlueWallet can import SLIP39 as well.

Trezor still supports BIP39 in full. The Model T defaults to a 12-word BIP39 phrase and can also do SLIP39. The Model One is BIP39 only. If you chose 12 or 24 words when you set the wallet up, that backup is BIP39. The two standards don’t convert, so switching means a new wallet and a transfer of your crypto to the new wallet addresses.

Electrum’s own seed isn’t BIP39. The app can still import a BIP39 phrase if you tell it to. A real BIP39 phrase can also show a zero balance if the wallet is looking at the wrong account, the wrong Bitcoin address type, or a hidden passphrase. A zero balance on the screen doesn’t mean your coins are gone.

The BIP39 Passphrase, or 25th Word

The “25th word” is a passphrase you create and add on top of the seed phrase. Spaces and capitals count, and it doesn’t need to be one of the 2,048 words. Leave it blank and you get the normal wallet. Anything else opens a different wallet from the same words.

Every passphrase produces a valid wallet, and only the right one holds the funds. A wrong passphrase doesn’t throw an error, so you just get an empty wallet. People sometimes add one as a security measure, so that someone who finds the seed phrase still can’t open the hidden wallet.

If you lose the passphrase, the seed phrase alone won’t open that wallet. You’ll get a different set of addresses instead. If you remember nothing about the extra secret, those funds stay out of reach. If you remember part of it, start with our guide to recovering a wallet password or passphrase.

How to Store Your Seed Words

Anyone who has the phrase can spend the coins, so where you keep it matters as much as how it was made. Whether the wallet is hot or cold, the written phrase is what you still have if the device dies or disappears. Our comparison of hot and cold wallets goes further on that split.

Where to keep your seed phrase

Cloud Storage and Notes Apps

Don’t put the phrase in email, a notes app, Google Drive, or a password manager that syncs. If someone gets into that account, they get the seed phrase and can access your cryptocurrency funds.

A Paper Backup

Handwrite the words in order and keep the paper in a safe or a lockbox. If a word smudges, you may not be able to tell what it said when you need it.

Photos and Screenshots

Don’t photograph the phrase, and don’t take a screenshot of it. Phone cameras sync to iCloud or Google Photos by default, so the photo can still be backed up long after you’ve gotten rid of the phone. A stolen or resold phone can hand over the whole library. If the paper is fading, transcribe what you can make out by hand and leave the original alone.

Never enter your seed phrase into a website, a support form, or a message to anyone. That includes so-called online recovery tools, wallet support chats, and strangers offering to walk you through a restore.

A Metal Backup

A steel plate you stamp or engrave holds up to fire and water better than paper does.

Some of these are plates you punch the letters into yourself. Others are a steel case with letter tiles you slide into place, like a Cryptosteel or a Billfodl. Our guide to metal seed phrase backups goes through the main ones and how they differ.

Copies in More Than One Place

If your only copy is in the house and there’s a fire, that backup is gone. Keep another full copy in a different place, such as a safe deposit box. That other spot has to be secure too.

If you used a hardware wallet device and it breaks, as long as the phrase is still readable you can usually restore onto a new hardware device. Our guide to a broken hardware wallet covers the device side. Do not factory-reset a device you aren’t sure you can restore.

Summing It Up

What you’re left with is 2,048 words, and the copy you wrote down is the part you have to protect.

If the coins have already been sent to someone else, this isn’t a seed-phrase problem. Once a transaction confirms, it can’t be reversed. No recovery service can pull those coins back, PCR included.

An incomplete phrase, a rejected one, or a passphrase you only partly remember is worth a careful look rather than guesswork in a live wallet. Seed phrase recovery starts from whatever you still have. Our fees are 18% of recovered assets, this is success-based and has no upfront cost. It’s taken from the recovered asset.

Request an assessment or call 1 (800) 645-1893. An assessment is a look at what remains, not a promise of access.

Frequently Asked Questions

Does every wallet use this word list?

Most self-custody wallets do. That includes MetaMask, Ledger, and a 12- or 24-word Trezor backup. A 20-word Trezor backup is SLIP39, and Electrum’s own seed isn’t BIP39 either. An exchange holds the keys itself.

What happens if I forget the 25th word?

The seed opens the wallet with no passphrase. The hidden wallet stays closed unless that extra secret matches, capitals and spaces included. If you remember nothing about it, those funds stay out of reach.

I typed my seed phrase into a website. Can the coins be recovered?

If the coins have already been sent, no recovery service can pull them back, PCR included. Report it to law enforcement. If they’re still at your addresses, move them to a new wallet and stop using the exposed phrase.

Will PCR ask for my seed phrase?

No. We don’t need a seed phrase or private keys to start a conversation. Anyone who asks you to type the phrase into a website or a message isn’t a legitimate recovery specialist. You can request an assessment or call 1 (800) 645-1893.

Julia Burlingham
Owner & Recovery Specialist

Julia is the founder of Professional Crypto Recovery and has over 20 years of experience in IT, software development, and data recovery. She works directly with every client using advanced tools and air-gapped systems to recover lost cryptocurrency wallets safely and securely.

Related Posts