Skip to main content
Loading …
AS Albert Schaper
  • 01Home
  • 02About
  • 03Expertise
  • 04Projects
  • 05Contact
  • 06Insights
  • 07Tools
AS

Albert Schaper

01Home 02About 03Expertise 04Projects 05Contact 06Insights 07Tools

AI · Finance · Entrepreneur

Home / Insights / How Safe Is Your Seed: 12 or 24 Words?
Insights

How Safe Is Your Seed: 12 or 24 Words?

12 words mean 128 bits of randomness, 24 words 256 bits — but what is that in years? Why brute force is hopeless, PBKDF2 slows attackers further, and what no word count on earth protects against.

24 September 2026 · 3 min read CryptoWeb3 Auf Deutsch lesen Share on LinkedInShare on X
Contents
  • What entropy really measures
  • The math behind crack time
  • What brute force does not break
  • Bottom line: 12 for everyday, 24 for eternity

12 or 24? Anyone setting up a wallet faces this choice — and most decide by gut feeling: more must be better. True, but the difference is so absurdly large it breaks every intuition. To calculate along, use the seed security calculator: pick a word count, type an attacker rate, read off crack time in universe ages.

What entropy really measures

Entropy in bits measures true randomness — and it grows exponentially: every extra bit doubles the search space. Word count sets it, the rest is math:

Words Entropy Keyspace
12 128 bits 3.4 × 10³⁸
15 160 bits 1.5 × 10⁴⁸
18 192 bits 6.3 × 10⁵⁷
21 224 bits 2.7 × 10⁶⁷
24 256 bits 1.2 × 10⁷⁷

Going from 12 to 24 words is not double protection but a 2¹²⁸-fold one — a factor with 39 digits. So the honest answer to "are 12 words enough": against brute force, yes, with astronomical margin. 24 words are reserve for decades — and for anyone who prefers to prepare for quantum computers sooner rather than later.

The math behind crack time

Assume an attacker guesses blindly at R guesses per second. On average they need half the keyspace: 2^(N−1) / R seconds. At 12 words and a billion guesses per second, that is about 5 × 10²¹ years — roughly 390 billion universe ages. At 24 words and a million guesses per second: about 10⁵³ universe ages, a number beyond everyday comparison.

And that is still the optimistic math for the attacker: every real seed-phrase guess additionally runs through PBKDF2 with 2048 rounds of key stretching — slowing things by roughly factor 2000. What the calculator shows is the lower bound; in reality it takes much longer.

What brute force does not break

Here is the uncomfortable truth: nobody cracks random seeds. The real attack paths are entirely different — and no word count helps against any of them:

  1. Phishing. Fake wallet sites and support scammers ask for the seed directly. Hand it over and everything is gone — whether 12 or 24 words.
  2. Malware. Keyloggers and clipboard hijackers read what you type and copy. Seed entry belongs on a clean, ideally separate device.
  3. Bad randomness. A seed is only as strong as its randomness. Serious wallets use system randomness (window.crypto.getRandomValues() in browsers); self-invented "random" words are not entropy but a pattern — and patterns get cracked.
  4. No or wrong backup. The most common loss cause is not theft but forgetting: seed on paper or steel, in two separate places, recovery tested once.

Bottom line: 12 for everyday, 24 for eternity

Both variants are immune to guessing — the difference is reserve. If you park your main reserve for decades, take 24 words and sleep better; for an everyday wallet with manageable amounts, 12 are perfectly fine, provided backup and environment are right. Calculate it yourself: seed security — and check a written-down phrase with the seed phrase validator before using it.


Sources:

Standards & practice

  • BIP39: Mnemonic code for generating deterministic keys — entropy levels, checksum, PBKDF2 with 2048 rounds

More on this site

  • Bitcoin & Web3 Basics — overview
  • Seed security — try it
  • How a wallet actually works
  • Self-custody checklist
More Insights
  • Crypto

    Why Anonymous Bitcoin Trading Ends in 2026 — and What Stays Private Anyway

    Binance had to halt its EU operations on July 1, 2026. The company blames postponed regulatory meetings; the Wall Street Journal points to compliance concerns instead. Four new rules kick in simultaneously in 2026. What they actually change, and what self-custody still explicitly protects.

  • Crypto

    Bitcoin & Web3 Basics: The Beginner's Learning Path

    Nine articles, one learning path: how wallets come to exist, how transactions actually work, and what matters for your own security — three modules, ~28 minutes, with a progress tracker and the matching tools to try it yourself.

  • Crypto

    Vanity Addresses: Expensive Fun That Costs Almost Nothing

    Addresses like sol...8888 are no coincidence but compute: thousands of keypairs per second until the prefix matches. How vanity grinding works, what it costs (time instead of money), why security holds — and where the privacy catch is.

Albert Schaper
About the author

AI expert, entrepreneur, and founder with a finance background and a focus on execution. I build companies, invest in ventures, and advise teams on putting AI to work. LinkedIn

← All Insights
AS

AI · Finance · Entrepreneur

Navigation

Home About Expertise Projects Contact Insights Tools

Projects

Best-AI.org BitAutor Geld 2.0 ASCANUS Health

© Albert Schaper. All rights reserved.

Privacy / Imprint