# Brainwallets versus seed phrases: why a memorable sentence is different

A brainwallet commonly derives spending keys from a phrase chosen by a person. A BIP-39 mnemonic instead encodes generated randomness plus a checksum, then derives a seed. A memorable quotation or personally meaningful sentence can be much easier to guess than randomly generated recovery words. Length alone is not entropy, and BIP-39 explicitly says it is not designed to turn user-created sentences into secure wallet seeds.

Evidence: [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [Securing your wallet](https://bitcoin.org/en/secure-your-wallet)

Canonical: https://degreesofsatoshi.com/encyclopedia/bitcoin-brainwallets/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:29:20.637Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Mnemonic purpose:** Human-readable encoding of generated randomness ([Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki))
- **Brainwallet risk:** Human choice can make candidates predictable ([Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [Securing your wallet](https://bitcoin.org/en/secure-your-wallet))
- **Checksum:** Consistency check, not proof of randomness ([Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki))

## Ask how the words were selected

The BIP-39 process starts with entropy and appends a checksum before mapping groups of bits to words. Its familiar words help people transcribe a generated secret; they are not an invitation to invent a sentence.

A phrase can be long, grammatical and emotionally meaningful while still belonging to a small set an attacker might try. The security question is the uncertainty before seeing the phrase, not the number of characters on paper.

Evidence: [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki)

## A restricted choice has a restricted search space

Consider a deliberately simple illustration: choosing one favorite phrase from a known list of 100 gives at most 100 possibilities, however many words each phrase contains. Encoding 128 random bits starts from a vastly larger possibility space. The example compares selection methods, not real people’s exact entropy.

Passing a mnemonic checksum does not prove the words came from a secure generator. A badly generated or deliberately chosen phrase can still satisfy a format rule.

Evidence: [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki)

## Memory is an additional dependency

A person can forget even a once-familiar phrase or make a transcription error. A secure, documented backup avoids relying on memory as the only recovery path. Protection from theft and recovery after loss both matter.

If funds already depend on a potentially predictable secret, use the wallet’s supported process to move them under independently generated keys you control. Merely changing an application password does not change the old on-chain spending authority.

Evidence: [Securing your wallet](https://bitcoin.org/en/secure-your-wallet); [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki)

## Questions

### Does adding more personally chosen words make a phrase equivalent to 24 random words?

No. Predictable selection can leave far less uncertainty than independently generated entropy. A longer story or quotation does not inherit the entropy claimed for a correctly generated BIP-39 mnemonic.

Evidence: [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki)

### Is a mnemonic passphrase the same as a brainwallet?

No. In BIP-39 it is an additional input combined with the mnemonic after normalization. Its strength and recoverability still matter, but it does not replace the need for properly generated mnemonic entropy.

Evidence: [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [Securing your wallet](https://bitcoin.org/en/secure-your-wallet)

## Claims and scope

### bitcoin-brainwallets-quick-answer

A brainwallet commonly derives spending keys from a phrase chosen by a person. A BIP-39 mnemonic instead encodes generated randomness plus a checksum, then derives a seed. A memorable quotation or personally meaningful sentence can be much easier to guess than randomly generated recovery words. Length alone is not entropy, and BIP-39 explicitly says it is not designed to turn user-created sentences into secure wallet seeds.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-brainwallets-fact-mnemonic-purpose

Mnemonic purpose: Human-readable encoding of generated randomness

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-brainwallets-fact-brainwallet-risk

Brainwallet risk: Human choice can make candidates predictable

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-brainwallets-fact-checksum

Checksum: Consistency check, not proof of randomness

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki) — Bitcoin Improvement Proposals. Entropy and checksum table, intended computer-generated randomness and NFKD seed derivation. Locator: Generating the mnemonic; From mnemonic to seed. Retrieved: 2026-10-02T18:53:54.120Z.
- [Securing your wallet](https://bitcoin.org/en/secure-your-wallet) — Bitcoin.org. Backup scope, online exposure, offline signing, custody and software update practices. Locator: Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date. Retrieved: 2026-10-02T18:53:53.659Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Brainwallets versus seed phrases: why a memorable sentence is different.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-brainwallets/
