Canonical scientific claim: A recovery phrase can be no stronger than the unpredictability of the process that created its source entropy; longer output, hashing, and statistical appearance cannot manufacture missing entropy.
A machine can turn a small secret into many random-looking words, but it cannot hide that the starting secret was small. Strength begins at the source.
Safety note: Do not use a browser experiment to generate a real wallet. Dice examples here use prepared data and never request or retain actual rolls.
Random-looking is an output style. Unpredictable to an attacker is a security property.
A strong phrase begins before the first word appears:
physical or operating-system source → conservative entropy claim → conditioning → cryptographic generator → BIP39 encoding
If a failure near the start leaves only a small set of possibilities, later stages cannot erase that fact from an attacker who knows how the system worked.
Why human invention is a weak source
People reuse language, dates, names, keyboard shapes, and familiar sequences. BIP39 explicitly describes a way to transport computer-generated randomness; it is not a recipe for converting a sentence someone invented into a secure wallet.
Adding more human-chosen words may make a phrase longer while leaving it inside a highly predictable family.
What hashing can and cannot do
A cryptographic hash can mix uneven input into output that looks balanced. That is valuable conditioning. But if only (2^32) possible inputs existed, the attacker can hash those same (2^32) inputs.
Statistical tests have the same boundary. They can reveal obvious failures such as stuck or heavily biased output. Passing them cannot prove that an attacker lacks the generator state, observed the source, or can reproduce the process.
Device generation and manual dice
Neither label is a proof by itself.
A wallet device may combine physical noise, operating-system facilities, health checks, conditioning, and a cryptographic generator. Evaluating it means examining the complete documented path, not only the final words.
Dice can provide a source that a person can see, but the model assumes honest, independent rolls, unobserved results, accurate transcription, and a correct conversion method. Manual work trades some device trust for more procedural responsibility.
For one ideal fair six-sided roll, the maximum is log2(6) ≈ 2.585 bits.
- 50 ideal independent rolls: at most about 129.25 bits.
- 99 ideal independent rolls: at most about 255.91 bits.
- 100 ideal independent rolls: at most about 258.50 bits.
Those are mathematical maxima under assumptions, not measurements of a real session. Bias, dependence, observation, or a faulty conversion can reduce the defensible amount. Follow a vetted device-specific process rather than selecting words or inventing a mapping.
The goal is not a perfect source story. It is a source with a conservative margin large enough that guessing ceases to be the realistic failure.
Evidence reviewed 2026-08-06
- BIP 39 — Mnemonic code for generating deterministic keysprimary specification · deployed
- NIST SP 800-90B — Entropy Sources Used for Random Bit Generationgovernment standard · final
- RFC 4086 — Randomness Requirements for Securityinternet best practice · published