12 or 24? Anyone setting up a wallet faces this choice — and most decide by gut feeling: more must be better. True, but the difference is so absurdly large it breaks every intuition. To calculate along, use the seed security calculator: pick a word count, type an attacker rate, read off crack time in universe ages.
What entropy really measures
Entropy in bits measures true randomness — and it grows exponentially: every extra bit doubles the search space. Word count sets it, the rest is math:
| Words | Entropy | Keyspace |
|---|---|---|
| 12 | 128 bits | 3.4 × 10³⁸ |
| 15 | 160 bits | 1.5 × 10⁴⁸ |
| 18 | 192 bits | 6.3 × 10⁵⁷ |
| 21 | 224 bits | 2.7 × 10⁶⁷ |
| 24 | 256 bits | 1.2 × 10⁷⁷ |
Going from 12 to 24 words is not double protection but a 2¹²⁸-fold one — a factor with 39 digits. So the honest answer to "are 12 words enough": against brute force, yes, with astronomical margin. 24 words are reserve for decades — and for anyone who prefers to prepare for quantum computers sooner rather than later.
The math behind crack time
Assume an attacker guesses blindly at R guesses per second. On average they need half the keyspace: 2^(N−1) / R seconds. At 12 words and a billion guesses per second, that is about 5 × 10²¹ years — roughly 390 billion universe ages. At 24 words and a million guesses per second: about 10⁵³ universe ages, a number beyond everyday comparison.
And that is still the optimistic math for the attacker: every real seed-phrase guess additionally runs through PBKDF2 with 2048 rounds of key stretching — slowing things by roughly factor 2000. What the calculator shows is the lower bound; in reality it takes much longer.
What brute force does not break
Here is the uncomfortable truth: nobody cracks random seeds. The real attack paths are entirely different — and no word count helps against any of them:
- Phishing. Fake wallet sites and support scammers ask for the seed directly. Hand it over and everything is gone — whether 12 or 24 words.
- Malware. Keyloggers and clipboard hijackers read what you type and copy. Seed entry belongs on a clean, ideally separate device.
- Bad randomness. A seed is only as strong as its randomness. Serious wallets use system randomness (
window.crypto.getRandomValues()in browsers); self-invented "random" words are not entropy but a pattern — and patterns get cracked. - No or wrong backup. The most common loss cause is not theft but forgetting: seed on paper or steel, in two separate places, recovery tested once.
Bottom line: 12 for everyday, 24 for eternity
Both variants are immune to guessing — the difference is reserve. If you park your main reserve for decades, take 24 words and sleep better; for an everyday wallet with manageable amounts, 12 are perfectly fine, provided backup and environment are right. Calculate it yourself: seed security — and check a written-down phrase with the seed phrase validator before using it.
Sources:
Standards & practice
- BIP39: Mnemonic code for generating deterministic keys — entropy levels, checksum, PBKDF2 with 2048 rounds