Seed phrases explained
Twelve ordinary words can rebuild every key in a wallet. That makes them the most valuable thing you own in crypto, and the most targeted.

On this page
- What is a seed phrase, in plain terms?
- How do 12 words turn into your private keys?
- Seed phrase, private key, PIN or passphrase: what does each one protect?
- Why is a partly exposed seed phrase almost as bad as a full leak?
- How should you store a seed phrase?
- What mistakes do beginners make with seed phrases?
- Questions readers ask
- Sources
- A seed phrase is a list of 12 to 24 words that encodes the random number your wallet uses to create all of its private keys.
- Anyone who has the words can rebuild the wallet on any device and move the funds; no password or company can stop them.
- Under the BIP-39 standard each word stands for 11 bits, picked from a fixed list of 2,048 words.
- Write the phrase down offline. A screenshot or cloud note can sync to servers that attackers can reach.
- No real wallet, exchange or support agent will ever ask you for your seed phrase.
A seed phrase (also called a recovery or secret recovery phrase) is a list of 12 to 24 words that encodes the master secret of a crypto wallet. From those words, wallet software can regenerate every private key and address. Whoever holds the words controls the funds.
What is a seed phrase, in plain terms?
Every crypto account is controlled by a private key: a very large secret number that signs transactions. Many wallets do not ask you to back up that number directly. Instead they show you a short list of everyday words once, at setup, and ask you to write it down. That list is the seed phrase.
The words are not a password that unlocks a company account. They are the secret itself, written in a form people can copy by hand. Ethereum's official security guide calls the recovery phrase the master key to your wallet. Feed the same words into compatible wallet software on any phone or computer, and it will rebuild the same keys and show the same balances.
This is also why a wallet app is not where your coins live. As ethereum.org puts it, a wallet is a tool for using your keys; the assets sit on the blockchain. If you are new to wallets, start with crypto wallets explained.
How do 12 words turn into your private keys?
Many wallets follow BIP-39, a Bitcoin Improvement Proposal created in 2013 and now marked as deployed. The process runs in one direction only:
Random number. The wallet generates 128 to 256 random bits, called entropy. For a 12-word phrase it is 128 bits.
Checksum. It hashes that number with SHA-256 and adds the first few bits of the result (4 bits for 12 words). This lets software catch a mistyped word.
Words. The 132 bits are cut into 12 groups of 11 bits. Each group is a number from 0 to 2,047 that points to one word in the official list.
Seed. The words, plus an optional passphrase, go through a key-stretching function (PBKDF2 with 2,048 rounds) to produce a 512-bit seed.
Keys. From that seed the wallet derives as many private keys and addresses as it needs, always in the same order.
Two details are useful in practice. The BIP-39 wordlist was chosen so that the first four letters identify each word, so a smudged ending is often still readable. And because the last word carries the checksum, you cannot simply invent 12 words of your own: most random combinations fail the check, and the standard advises against phrases not generated this way.

Seed phrase, private key, PIN or passphrase: what does each one protect?
Beginners often mix up the secrets a wallet uses. They protect very different things, and losing each has very different consequences.
| Secret | What it controls | If someone else gets it | If you lose it |
|---|---|---|---|
| Seed phrase | Every key and address in the wallet | They can rebuild the wallet anywhere and take everything | You cannot restore the wallet if the device also fails |
| Single private key | One account or address | They can move that account's funds | Recoverable from the seed phrase, if you have it |
| App password or device PIN | Access to the wallet on one phone, computer or device | Risky only if they also hold the device | Restore the wallet on a new device from the seed phrase |
| Optional BIP-39 passphrase | Which wallet the seed phrase opens | Useless on its own without the words | The words alone open a different, empty wallet |
Why is a partly exposed seed phrase almost as bad as a full leak?
Twelve words drawn from 2,048 options give 2,04812 possible sequences. Only one in 16 of them passes the checksum, which still leaves 2128 valid phrases, roughly 3.4 × 1038. Nobody can guess a properly generated phrase from scratch. The protection collapses, though, once most of the words are known.
The same arithmetic explains why splitting a phrase into two halves and storing them in different drawers is weaker than it sounds. A thief who finds six of the 12 words cuts the search from about 3.4 × 1038 phrases to about 4.6 × 1018 (2,0486 ÷ 16), and finding the second drawer ends it. If you need protection against a single stolen backup, a passphrase or a multisig setup is designed for that job.
How should you store a seed phrase?
The official guidance from ethereum.org and bitcoin.org points the same way: keep the words offline, keep more than one copy, and keep them where only you, or people you trust with your estate, can reach them.
- Write it by hand. Copy the words in order, numbered, and check every spelling against the screen before you confirm.
- Never photograph it. Ethereum's security guide warns that screenshots can sync to cloud storage, where attackers may reach them. The same goes for notes apps, email drafts and chat messages to yourself.
- Keep at least two copies in separate places. Bitcoin.org recommends multiple backups in different secure locations, so a single fire, flood or move does not wipe you out.
- Plan for your family. Bitcoin.org also suggests a backup plan for relatives. Funds nobody can find are lost for good.
A seed phrase on paper is a form of cold storage, but the device you type it into matters too. Our guide to hardware vs software wallets explains where the words should be entered, and where they never should.

What mistakes do beginners make with seed phrases?
- Typing the words into a website. A page asking you to "validate", "sync" or "restore" your wallet by entering your phrase is a phishing page. Ethereum.org is blunt: no legitimate service, support agent or website will ever ask for it.
- Sharing it with "support". Scammers pose as helpdesk staff in private messages and on social media. Our guide to common crypto scams shows the scripts they use.
- Storing it digitally "just for now". Cloud photos, password-protected documents and email drafts are all online copies.
- Skipping the double-check. One misspelled or out-of-order word can make the backup useless when you need it most. Compare each numbered word against the screen before you confirm, and fix unclear handwriting while you still can.
- Forgetting the passphrase exists. If you add one, back it up separately. Without it the words open a different wallet.
Questions readers ask
Is a 24-word seed phrase safer than a 12-word one?
Both are far beyond guessing: 12 words carry 128 random bits and 24 words carry 256 under BIP-39. The real risk for either is someone seeing or stealing the words, not brute force.
Can I change my seed phrase?
Not for an existing wallet, because the phrase is the wallet's root secret. To replace it, create a new wallet with a new phrase and send your funds to its addresses.
Does a seed phrase work in other wallet apps?
Usually, if both apps follow BIP-39 and the same key-derivation rules. Restore only on a device you trust, never on a website.
What should I do if someone asks for my seed phrase?
Refuse and end the conversation. Anyone asking for it, whatever reason they give, is trying to take your funds. See common crypto scams.
A seed phrase is not a login. It is the wallet itself, written in words. Generate it on a trusted wallet, write it down offline, keep two copies in separate safe places and never type it anywhere but a wallet you are restoring yourself. Everything else in crypto security builds on that habit.
Sources
- Bitcoin Improvement Proposals (Palatinus, Rusnak, Voisine, Bowe), BIP-39: Mnemonic code for generating deterministic keys (2013)Primary source
- ethereum.org, Ethereum security and scam prevention (2026)Primary source
- ethereum.org, Ethereum wallets (2026)Primary source
- ethereum.org, Ethereum accounts (2026)Primary source
- bitcoin.org, Securing your walletPrimary source
Educational content only — not financial, investment, legal or tax advice. Crypto-assets are high-risk and you could lose all the money you put in. Rules differ by country; check with your national regulator. See our risk disclosure and editorial policy.



