Canonical scientific claim: A recovery phrase is a portable root secret: anyone who has the correct phrase and any required passphrase can derive the wallet's keys, while a device PIN cannot protect a copied backup.
The recovery words are a spare master key for the wallet. A PIN may lock one device, but it does not lock a copied backup.
Safety note: Never type a real recovery phrase or passphrase into this site or any untrusted webpage. Plentropy uses demonstrations only and does not recover wallets.
A recovery phrase—and any required passphrase—is not a hint about your wallet. Together they are enough information to rebuild its keys.
That is why the same words solve two opposite problems:
- If a signing device is lost or broken, the words can restore access.
- If someone else copies the words, they may be able to take control.
One root, many keys
A modern Bitcoin wallet normally does not store one recovery word for each address. It starts from one secret and derives a tree:
recovery phrase + optional passphrase → seed → master key → accounts → receiving and change addresses
This is useful because one carefully preserved backup can recover many past and future addresses. It also concentrates responsibility: the root backup matters more than any one address.
Four secrets that do different jobs
| Item | What it does | What it does not do |
|---|---|---|
| Recovery phrase | Recreates the wallet’s root secret when combined with any required passphrase | Lock a particular device |
| BIP39 passphrase | Derives a different wallet from the same words | Warn that a typo was entered |
| Device PIN | Restricts use of that physical device | Protect words copied elsewhere |
| Wallet-file password | May encrypt a file on one computer | Change the strength of the original seed |
Adding protections without naming the threat causes confusion. A longer PIN cannot rescue photographed words. More seed words cannot rescue a forgotten passphrase.
The words may not be the whole recovery record
The same root can be used with different wallet policies and derivation paths. Recovery software may also need to know the wallet format, account or script type, network, and whether a passphrase was used. If those details are wrong, a valid recovery can appear empty.
The first Plentropy rule is therefore simple:
Protect the root secret, and preserve enough non-secret recovery information to find the right wallet again.
The next chapter opens the phrase itself and shows which bits are uncertainty—and which are only a checksum.
Evidence reviewed 2026-08-06
- BIP 39 — Mnemonic code for generating deterministic keysprimary specification · deployed
- BIP 32 — Hierarchical Deterministic Walletsprimary specification · deployed