BIP 39 (standard for seed words)
The widely used standard that turns random data into 12 to 24 words from a fixed list of 2,048 words. Your wallet calculates all its keys from these words – BIP 39 is behind most seed phrases.
AlsoBIP39BIP-39mnemonic codeBIP 39 word listword list
On the learning path: Stage 5 · Step 3 – Backing up your seed phrase
BIP 39 is an improvement proposal (BIPGlossaryBIP (Bitcoin Improvement Proposal)A publicly documented proposal for Bitcoin – for example for new rules, standards or processes. A BIP is not a decision: whether it gets used is up to users, wallets and node operators themselves.In the glossary →) from 2013. It defines how a wallet turns a random number into ordinary words – your seed phraseGlossarySeed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary →. Words are easier to copy down correctly than numbers. Because so many wallets use the standard, you can usually restore your words in a different wallet too.
How it works
- 128 bits of randomness give 12 words, 256 bits give 24.
- A short checksum in the last word catches most copying mistakes, but not all, and doesn’t correct any.
- The list has 2,048 words. The first four letters are enough to identify each word unambiguously.[1]
What this means for you
- English words are normal. BIP 39 strongly discourages other languages, because most wallets only support the English list.
- Never make up words yourself. The standard advises against it – invented words are far easier to guess than real randomness.[1]
- Not every wallet uses BIP 39. Electrum, for example, generates its own seed phrases.[2] So note which wallet you used to create your backup.
Dive deeperFrom words to key
The words are not yet the key. The wallet turns them – together with an optional passphraseGlossaryPassphrase (the ‘25th word’)An extra word of your choice added to your seed phrase. The same words then produce a completely different wallet. This protects you if someone finds your words – but if you forget the passphrase, access is lost for good.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary → – into a 512-bit seed using PBKDF2. From this seed, all private keys are created according to BIP 32, each along a derivation pathGlossaryDerivation pathThe route a wallet follows to calculate individual keys from your seed phrase, for example m/84'/0'/0'. If another wallet uses a different path when you restore, it looks empty – even though nothing has been lost.In the glossary →. Every passphrase produces a valid but different wallet.[1]
Related terms
These terms are closely connected.
- This termBIP 39(standard for seed words)
- Seed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.
- Passphrase (the ‘25th word’)An extra word of your choice added to your seed phrase. The same words then produce a completely different wallet. This protects you if someone finds your words – but if you forget the passphrase, access is lost for good.
- Derivation pathThe route a wallet follows to calculate individual keys from your seed phrase, for example m/84'/0'/0'. If another wallet uses a different path when you restore, it looks empty – even though nothing has been lost.
- BIP (Bitcoin Improvement Proposal)A publicly documented proposal for Bitcoin – for example for new rules, standards or processes. A BIP is not a decision: whether it gets used is up to users, wallets and node operators themselves.
- Private keyA secret, randomly generated number that you use to sign transactions and so control your bitcoin. Anyone who knows the private key can spend the bitcoin that belongs to it – it must never fall into anyone else’s hands.
Explained in depth
These articles go into more detail:
- Deep dive · Stage 5Keys & addressesPrivate key, public key, address and seed phrase: how they fit together, why the path only runs one way and what 1, 3, bc1q and bc1p mean.
- Stage 5 · Step 3Backing up your seed phraseHow to back up your seed phrase for the long term: why never digitally, when paper is enough, how metal backups fare in a stress test and where to keep them.
- Deep dive · Stage 5Testing recoveryHow to check that your wallet backup works when it matters, why a restored wallet can look empty and what you can do if you lose access.
More from „Wallets & security“
Sources2 sources · 2 publishers
The superscript numbers in the text refer to these sources.
- BIP 39: Mnemonic code for generating deterministic keys – Bitcoin Improvement Proposals (Palatinus, Rusnak, Voisine, Bowe), 10.09.2013 (accessed 28/09/2026)
- Electrum Seed Version System – Electrum documentation (accessed 28/09/2026)
This entry is for education only and is not investment, tax or legal advice.