Difference between revisions of "Seed phrase"

(Created page with "A '''seed phrase''', '''seed recovery phrase''' or '''backup seed phrase''' is a list of words which store all the information needed to recover a Bitcoin...")
 
Line 1: Line 1:
A '''seed phrase''', '''seed recovery phrase''' or '''backup seed phrase''' is a list of words which [[Storing bitcoins|store]] all the information needed to recover a Bitcoin wallet. Wallet software will typically generate a seed phrase and instruct the user to write it down on paper. If the user's computer breaks or their hard drive becomes corrupted, they can download the same wallet software again and use the paper backup to get their bitcoins back.
+
=DISCLAIMER=
 +
This article is a direct copy of the original https://en.bitcoin.it/wiki/Seed_phrase and has not been checked for correctness or edited.
 +
2 December 2019
 +
Expected review by: 15 December 2019
  
Anybody else who discovers the phrase can steal the bitcoins, so it must be kept safe like jewels or cash. For example, it must not be typed into any website.
+
Review BJL 20191202
  
Seed phrases are an excellent way of backing up and [[storing bitcoins]] and so they are used by almost all well-regarded wallets.<ref>[https://bitcoin.org/en/choose-your-wallet Bitcoin.org: Choose your wallet]</ref>
+
 
 +
 
 +
A '''seed phrase''', '''seed recovery phrase''' or '''backup seed phrase''' is a list of words which correspond to the master private key of a Bitcoin wallet. In typical usage, a wallet will generate a seed phrase and instruct the user to write it down on paper. If the user's computer breaks or their hard drive becomes corrupted, they can download the same wallet software again and use the paper backup to deterministically re-generate their wallet.
 +
 
 +
Anybody with access to the phrase can steal the bitcoins, so it must be kept safe.
 +
 
 +
Seed phrases are the most frequently encountered means of backing up Bitcoin wallets.
  
 
== Example ==
 
== Example ==
Line 12: Line 21:
  
 
The word order is important.
 
The word order is important.
 
[[File:Mnemonic-seed-still-life.jpg|300px|thumb|none|alt=An example seed phrase written on paper|Example seed phrase on paper.]]
 
  
 
== Explanation ==
 
== Explanation ==
  
A simplified explanation of how seed phrases work is that the wallet software has a list of words taken from a dictionary, with each word assigned to a number. The seed phrase can be converted to a number which is used as the seed integer to a [[Deterministic wallet|deterministic wallet]] that generates all the [[Private key|key pairs]] used in the wallet.
+
A simplified explanation of how seed phrases work is that the wallet software has a list of words taken from a dictionary, with each word assigned to a number. The words in the seed phrase are each converted to their corresponding number and concatenated to generate the seed integer to a [[Deterministic wallet|deterministic wallet]]. From this seed integer the wallet generates all [[Private key|key pairs]] used in the wallet.
 
 
The English-language wordlist for the BIP39 standard has 2048 words, so if the phrase contained only 12 random words, the number of possible combinations would be 2048^12 = 2^132 and the phrase would have 132 bits of security.  However, some of the data in a BIP39 phrase is not random,<ref>[https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki#Generating_the_mnemonic BIP39: Generating the mnemonic]</ref> so the actual security of a 12-word BIP39 seed phrase is only 128 bits.  This is approximately the same strength as all Bitcoin private keys, so most experts consider it to be sufficiently secure.<ref>[https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki#Security BIP32: Security]</ref>
 
  
It is not safe to invent your own seed phrase because humans are bad at generating randomnessThe best way is to allow the wallet software to generate a phrase which you write down.
+
The English-language wordlist for the BIP39 standard has 2048 words, so if the phrase contained only 12 random words, the number of possible combinations would be 2048^12 = 2^132 and the phrase would have 132 bits of securityHowever, some of the data in a BIP39 phrase is not random,<ref>[https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki#Generating_the_mnemonic BIP39: Generating the mnemonic]</ref> so the actual security of a 12-word BIP39 seed phrase is only 128 bits.
  
 
== Two-Factor Seed Phrases ==
 
== Two-Factor Seed Phrases ==
  
Seed phrases, like all backups, can store any amount of bitcoins. It's a concerning idea to possibly have enough money to purchase the entire building just sitting on a sheet of paper without any protection. For this reason many wallets make it possible to encrypt a seed phrase with a password.
+
Several wallets enable their users to generate seed phrases with an added layer of encryption to prevent someone who discovers the words from accessing the wallet. The password can be used to create a two-factor seed phrase where both ''"something you have"'' plus ''"something you know"'' is required to recover the wallet.
 
 
The password can be used to create a two-factor seed phrase where both ''"something you have"'' plus ''"something you know"'' is required to unlock the bitcoins.
 
  
 
This works by the wallet creating a seed phrase and asking the user for a password. Then both the seed phrase and extra word are required to recover the wallet. Electrum and some other wallets call the passphrase a '''"seed extension"''', '''"extension word"''' or '''"13th/25th word"'''. The BIP39 standard defines a way of passphrase-protecting a seed phrase. A similar scheme is also used in the Electrum standard. If a passphrase is not present, an empty string "" is used instead.
 
This works by the wallet creating a seed phrase and asking the user for a password. Then both the seed phrase and extra word are required to recover the wallet. Electrum and some other wallets call the passphrase a '''"seed extension"''', '''"extension word"''' or '''"13th/25th word"'''. The BIP39 standard defines a way of passphrase-protecting a seed phrase. A similar scheme is also used in the Electrum standard. If a passphrase is not present, an empty string "" is used instead.
 
'''Warning''': Forgetting this password will result in the bitcoin wallet and any contained money being lost. Do not overestimate your ability to remember passphrases especially when you may not use it very often.
 
 
'''Warning''': The seed phrase password should not be confused with the password used to encrypt the wallet file on disk. This is probably why many wallets call it an extension word instead of a password.
 
  
 
== Storing Seed Phrases for the Long Term ==  
 
== Storing Seed Phrases for the Long Term ==  
  
Most people write down phrases on paper but they can be stored in many other ways such as [[Brainwallet|memorizing]], engraving on metal, writing in the margins of a book, chiseling into a stone tablet or any other creative and inventive way.
+
Most people write down phrases on paper but they can be stored in many other ways such as [[Brainwallet|memorizing]], engraving on metal, writing in the margins of a book or any other creative and inventive way.
  
 
For storing on paper writing with pencil is much better than pen<ref>[http://www.joethorn.net/blog/2011/12/07/pencil-does-not-fade Pencil Does Not Fade]</ref><ref>[https://www.quora.com/How-do-I-maintain-a-paper-notebook-that-can-remain-for-years How do I maintain a paper notebook that can remain for years?]</ref>. Paper should be acid-free or archival paper, and stored in the dark avoiding extremes of heat and moisture<ref>[https://www.loc.gov/preservation/care/deterioratebrochure.html Essential facts about preservation of Paper]</ref><ref>[https://www.quora.com/If-I-write-with-a-pencil-on-my-notebook-will-the-writing-last-for-a-long-time-say-50-years-or-will-it-just-fade-away-gradually Writing in a notebook with pencil]</ref><ref>[http://copar.org/bulletin14.htm CoPAR: Creating records that will last]</ref>.
 
For storing on paper writing with pencil is much better than pen<ref>[http://www.joethorn.net/blog/2011/12/07/pencil-does-not-fade Pencil Does Not Fade]</ref><ref>[https://www.quora.com/How-do-I-maintain-a-paper-notebook-that-can-remain-for-years How do I maintain a paper notebook that can remain for years?]</ref>. Paper should be acid-free or archival paper, and stored in the dark avoiding extremes of heat and moisture<ref>[https://www.loc.gov/preservation/care/deterioratebrochure.html Essential facts about preservation of Paper]</ref><ref>[https://www.quora.com/If-I-write-with-a-pencil-on-my-notebook-will-the-writing-last-for-a-long-time-say-50-years-or-will-it-just-fade-away-gradually Writing in a notebook with pencil]</ref><ref>[http://copar.org/bulletin14.htm CoPAR: Creating records that will last]</ref>.
 
Some people get the idea to split up their phrases. Storing 6 words in one location and the other 6 words in another location. This is a bad idea and should not be done, because if one set of 6 words is discovered then it becomes easier to bruteforce the rest of the phrase. Storing bitcoins in multiple locations like this should be done via [[multisignature]] wallets instead.
 
 
Another bad idea is to add random decoy words that are somehow meaningful to you, and later remove them to be left only with the 12 word phrase. The phrase words come from a known dictionary (see next section), so anybody can use that dictionary to weed out the decoy words.
 
 
It could be a good idea to write some words of explanation on the same paper as the seed phrase. If storing for the long term you may forget what a phrase is how it should be treated. A sample explanation that can be adapted is:
 
 
<blockquote>These twelve words have control over BITCOINS. Keep this paper safe and secret, like cash or jewelry. The bitcoin information on this paper is encrypted with a passphrase. It is part of a multisignature wallet and was made by Electrum bitcoin wallet software on 1/1/2012.</blockquote>
 
  
 
== Word Lists ==
 
== Word Lists ==
Line 72: Line 63:
 
* [[Deterministic wallet]]  
 
* [[Deterministic wallet]]  
 
* [[Storing bitcoins]]  
 
* [[Storing bitcoins]]  
* [[Brainwallet]] - Put link to CSW article
+
* [[Brainwallet]]
 
* [https://github.com/6102bitcoin/FAQ/blob/master/seed.md FAQ regarding bitcoin seeds] - Look if this is good
 
* [https://github.com/6102bitcoin/FAQ/blob/master/seed.md FAQ regarding bitcoin seeds] - Look if this is good
 
==References==
 
<references />
 
 
 
[[Category:Technical]]
 

Revision as of 02:56, 2 December 2019

DISCLAIMER

This article is a direct copy of the original https://en.bitcoin.it/wiki/Seed_phrase and has not been checked for correctness or edited. 2 December 2019 Expected review by: 15 December 2019

Review BJL 20191202


A seed phrase, seed recovery phrase or backup seed phrase is a list of words which correspond to the master private key of a Bitcoin wallet. In typical usage, a wallet will generate a seed phrase and instruct the user to write it down on paper. If the user's computer breaks or their hard drive becomes corrupted, they can download the same wallet software again and use the paper backup to deterministically re-generate their wallet.

Anybody with access to the phrase can steal the bitcoins, so it must be kept safe.

Seed phrases are the most frequently encountered means of backing up Bitcoin wallets.

Example

An example of a seed phrase is:

   witch collapse practice feed shame open despair creek road again ice least

The word order is important.

Explanation

A simplified explanation of how seed phrases work is that the wallet software has a list of words taken from a dictionary, with each word assigned to a number. The words in the seed phrase are each converted to their corresponding number and concatenated to generate the seed integer to a deterministic wallet. From this seed integer the wallet generates all key pairs used in the wallet.

The English-language wordlist for the BIP39 standard has 2048 words, so if the phrase contained only 12 random words, the number of possible combinations would be 2048^12 = 2^132 and the phrase would have 132 bits of security. However, some of the data in a BIP39 phrase is not random,<ref>BIP39: Generating the mnemonic</ref> so the actual security of a 12-word BIP39 seed phrase is only 128 bits.

Two-Factor Seed Phrases

Several wallets enable their users to generate seed phrases with an added layer of encryption to prevent someone who discovers the words from accessing the wallet. The password can be used to create a two-factor seed phrase where both "something you have" plus "something you know" is required to recover the wallet.

This works by the wallet creating a seed phrase and asking the user for a password. Then both the seed phrase and extra word are required to recover the wallet. Electrum and some other wallets call the passphrase a "seed extension", "extension word" or "13th/25th word". The BIP39 standard defines a way of passphrase-protecting a seed phrase. A similar scheme is also used in the Electrum standard. If a passphrase is not present, an empty string "" is used instead.

Storing Seed Phrases for the Long Term

Most people write down phrases on paper but they can be stored in many other ways such as memorizing, engraving on metal, writing in the margins of a book or any other creative and inventive way.

For storing on paper writing with pencil is much better than pen<ref>Pencil Does Not Fade</ref><ref>How do I maintain a paper notebook that can remain for years?</ref>. Paper should be acid-free or archival paper, and stored in the dark avoiding extremes of heat and moisture<ref>Essential facts about preservation of Paper</ref><ref>Writing in a notebook with pencil</ref><ref>CoPAR: Creating records that will last</ref>.

Word Lists

Generally a seed phrase only works with the same wallet software that created it. If storing for a long period of time it's a good idea to write the name of the wallet too.

The BIP39 English word list has each word being uniquely identified by the first four letters, which can be useful when space to write them is scarce.

Alternative name "Mnemonic Phrase"

Seed phrases are sometimes called "mnemonic phrases" especially in older literature. This is a bad name because the word mnemonic implies that the phrase should be memorized. It is less misleading to call them seed phrases.

The power of backups

An especially interesting aspect in the power of paper backups is allowing your money to be two places at once. At the London Inside Bitcoin conference the keynote speaker showed 25 paper backups they were carrying -- all password-protected. With that one can carry $100,000 which can instantly be moved to a phone or transferred yet with total security. If it's stolen then there is no risk because it is backed up elsewhere. That is powerful.<ref>https://www.reddit.com/r/Bitcoin/comments/2hmnru/poll_do_you_use_paper_wallets_why_why_not_what/</ref>

See Also