Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Bitcoin basics · Entry 192

12 versus 24 seed words: entropy, checksums and compatibility

Theme
Bitcoin basics
Sources
4 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for 12 versus 24 seed words: entropy, checksums and compatibility
FactDetailSource
12 words128 entropy bits + 4 checksum bits[1]
24 words256 entropy bits + 8 checksum bits[1]
CompatibilityCheck the mnemonic system, not only length[2]
01

Each BIP-39 word represents eleven encoded bits

The wordlist contains 2,048 entries, so each word represents an 11-bit index. For 12 words, 12 × 11 = 132 encoded bits; 128 are entropy and four are checksum. For 24 words, 24 × 11 = 264, split into 256 entropy and eight checksum bits.

The checksum is derived from the entropy. It helps detect some errors but does not add independent secret randomness and does not catch every invalid transcription.

02

A similar-looking phrase can use another system

Electrum documents a native seed-version system that signals derivation information. A BIP-39 phrase has its own rules and may still need the correct passphrase, paths and script conventions to locate the intended accounts.

Do not add or remove words to convert between formats. Those changes do not extend the original wallet; they alter or invalidate its recovery input. Use a supported migration transaction when changing wallet arrangements.

03

Protect the complete recovery arrangement

An attacker who obtains the necessary full recovery secret does not need to guess whether it originally had 128 or 256 bits of entropy. Storage, device authenticity and informed signing remain material risks for both lengths.

Use the format generated and supported by the chosen wallet, preserve any required passphrase and test recovery through its documented process. Neither phrase length makes a public address capable of recovering the missing words.

Direct answers

Questions people ask

Can I turn a 12-word wallet into the same wallet with 24 words?

Not by appending words. BIP-39 maps different valid mnemonic inputs through seed derivation; a longer newly generated phrase generally represents a different wallet. A transfer is needed to move funds between independent keys.

Does a valid checksum mean I restored the intended wallet?

No. It checks the mnemonic encoding. The wrong valid mnemonic, a different normalized passphrase or incompatible derivation settings can still produce a different wallet or an incomplete view.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

In BIP-39, a correctly generated 12-word mnemonic encodes 128 entropy bits plus a 4-bit checksum; 24 words encode 256 entropy bits plus an 8-bit checksum. More words increase that generated entropy, but they do not fix exposed backups or a compromised signer. Word count also does not identify the wallet format: Electrum’s native mnemonic system is different from BIP-39.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
12 words: 128 entropy bits + 4 checksum bits

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
24 words: 256 entropy bits + 8 checksum bits

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
Compatibility: Check the mnemonic system, not only length

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and separate automated verification.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Mnemonic code for generating deterministic keysBitcoin Improvement Proposals

    Entropy and checksum table, intended computer-generated randomness and NFKD seed derivation.

    Locator: Generating the mnemonic; From mnemonic to seed · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:54.120ZOpen source
  2. Seed Version SystemElectrum

    Electrum mnemonic format differs from BIP-39 and encodes a version indication.

    Locator: Electrum Seed Version System; Description; Motivation; Security implications · Retrieved: 2026-10-02T18:53:56.665ZOpen source
  3. Securing your walletBitcoin.org

    Backup scope, online exposure, offline signing, custody and software update practices.

    Locator: Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date · Retrieved: 2026-10-02T18:53:53.659ZOpen source
  4. Multi-Account Hierarchy for Deterministic WalletsBitcoin Improvement Proposals

    Hardened account paths and external-chain discovery gap rule.

    Locator: Path levels; Account discovery; Address gap limit · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:54.097ZOpen source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “12 versus 24 seed words: entropy, checksums and compatibility.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-12-vs-24-word-seed/