Canonical scientific claim: A 12-word BIP39 mnemonic encodes 128 bits of source entropy plus 4 checksum bits, while 24 words encode 256 plus 8; the checksum detects some errors but adds no unpredictability.
Most of the word pattern carries the secret randomness. A small checksum helps notice some mistakes, but it does not make the wallet harder to guess.
Safety note: All word diagrams are placeholders, not wallet material. Never paste a real mnemonic into a checksum checker or educational site.
BIP39 does not ask a person to invent a memorable sentence. It starts with generated bits and gives those bits a form that is easier to copy.
The bit budget
| BIP39 words | Source entropy | Checksum | Encoded total |
|---|---|---|---|
| 12 | 128 bits | 4 bits | 132 bits |
| 15 | 160 bits | 5 bits | 165 bits |
| 18 | 192 bits | 6 bits | 198 bits |
| 21 | 224 bits | 7 bits | 231 bits |
| 24 | 256 bits | 8 bits | 264 bits |
The encoded stream is divided into 11-bit numbers. Each number selects one entry from a 2,048-word list because (2^11=2,048).
That does not mean every word contributes 11 new bits of uncertainty. The checksum is calculated from the entropy, so an attacker does not need to guess it independently.
The last word is not “the checksum word”
For twelve words, the final 11-bit group contains seven entropy bits and four checksum bits. For twenty-four words, it contains three entropy bits and eight checksum bits.
The checksum can reject many incorrect combinations. It can help detect some transcription errors. It cannot:
- Prove the generator was unpredictable.
- Repair an unknown or damaged phrase by itself.
- Protect a phrase that someone copied.
- Add secret uncertainty to the source.
A familiar word count does not identify the format
Not every twelve-word wallet backup is BIP39. Electrum documents a different, versioned seed system. Other wallets may use other encodings or threshold-share formats.
Before attempting recovery, identify the format and original wallet behavior. Trying words in random online tools creates a much larger danger than choosing the wrong checksum explanation.
The important distinction
Encoding determines how generated secret material is written down. Entropy generation determines how hard that material is to predict.
A perfectly formatted BIP39 phrase can still be weak if it came from a tiny or predictable source. That is the subject of the next chapter.
Evidence reviewed 2026-08-06
- BIP 39 — Mnemonic code for generating deterministic keysprimary specification · deployed
- Electrum Seed Version Systemimplementation documentation · documented