Beware of impersonators - only trust emails from @cryptoassetrecovery.com. Report impersonator

Crypto Asset Recovery
← Knowledge center
Password Recovery

24-Word Recovery Phrase: How It Works & How to Store It

What a 24-word recovery (seed) phrase is, why the last word is a checksum, 12 vs 24 words, and how to store it safely. From wallet recovery specialists.

By · Published

24-Word Recovery Phrase: How It Works & How to Store It

A 24-word recovery phrase is the master key to a crypto wallet. Write those 24 words down correctly and you can lose your hardware wallet, your phone, or your laptop and still get every coin back. Lose them, or get one word wrong, and you may lose everything. We rebuild broken and incomplete recovery phrases for a living, so this guide explains how the 24 words actually work, why the last one is special, whether you need 24 words at all, and how to store them so you never need our help.

What is a 24-word recovery phrase?

A recovery phrase is a list of ordinary words that encodes the secret behind your wallet. Every private key and every address in the wallet is derived from it. Different wallets give it different names: seed phrase, mnemonic, Secret Recovery Phrase, secret key, or wallet backup. They all mean the same thing.

The phrase does two jobs:

  • It's your backup. Enter it into a compatible wallet and your accounts reappear, because your coins live on the blockchain, not in the device.
  • It's your ownership. Anyone who has the phrase can move your funds, from anywhere, without your password or your device.

Most wallets follow a standard called BIP39, which defines how the words are generated and checked. A 24-word phrase is the longest standard length; 12 words is the other common one.

What a 24-word recovery phrase looks like

Here's a real, valid 24-word phrase from the official BIP39 test data:

abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon art

It's public, which means anyone can open the wallet it creates. Never use it, or any phrase you find online, to hold funds. A real phrase is a random mix of 24 words like "ocean", "tribe", or "garment", written in a fixed order.

How your 24 words are generated

When a wallet creates a 24-word phrase, it works like this:

  1. It generates 256 random bits: the actual secret.
  2. It runs those bits through the SHA-256 hash function and takes the first 8 bits of the result as a checksum.
  3. It joins them into 264 bits and splits them into 24 groups of 11 bits.
  4. Each 11-bit group is a number from 0 to 2,047, which points to one word in the 2,048-word BIP39 list.

The same recipe works for every standard length:

WordsRandom bitsChecksum bitsValid last wordsPossible phrases
1212841282128 (about 3.4 × 1038)
151605642^160
181926322^192
212247162^224
24256882256 (about 1.2 × 1077)

Why the 24th word is different: the checksum

In a 24-word phrase, the last word carries only 3 bits of randomness. The other 8 bits are the checksum, calculated from everything before it. That has a surprising consequence: once the first 23 words are set, only 8 of the 2,048 words can be a valid 24th word.

Take the test phrase above. After 23 "abandon"s, the only valid final words are art, diesel, false, kite, organ, ready, surface, and trouble. Any other word makes the phrase invalid.

This is why wallets say "invalid recovery phrase" when you mistype a word, swap two words, or misread your handwriting: the checksum no longer matches. It's a useful safety net, but not a perfect one. About 1 in 256 random mistakes in a 24-word phrase still passes the checksum (1 in 16 for 12 words) and opens a perfectly valid wallet that happens to be empty.

From words to wallet: the seed and derivation paths

Your 24 words aren't used directly as a key. The wallet runs the phrase through a slow function (PBKDF2 with HMAC-SHA512, 2,048 rounds) to produce a 512-bit seed. From that seed it derives keys along derivation paths, a kind of address for each account, such as m/44'/0'/0'/0/0 for a first Bitcoin address.

This is behind one of the most alarming moments in crypto: you restore a correct phrase into a new app and see a zero balance. Usually nothing is lost. The new app is looking at different derivation paths, a different address type (legacy, SegWit, or Taproot for Bitcoin), or a different account number. The same 24 words can produce many sets of addresses, and wallets don't all check the same ones by default.

The optional passphrase (the "25th word")

Many wallets, including Ledger and Trezor, let you add an optional passphrase to your recovery phrase. It isn't a wordlist word; it can be any text you choose. People call it the "25th word".

Two things make it powerful and dangerous:

  • Every passphrase opens a different wallet. There's no "wrong passphrase" error. A typo silently opens a different, empty wallet.
  • A lost passphrase is not recoverable from the phrase. Trezor puts it plainly: passphrases can't be changed, removed, or recovered. Your 24 words without the right passphrase lead somewhere else.

One point of confusion: Pi Network calls its own 24-word phrase a "passphrase". That's Pi's name for the phrase itself, not the optional extra described here.

12 vs 24 words: which is more secure?

Both are effectively uncrackable. A 12-word phrase has 128 bits of randomness, and a 24-word phrase has 256. Even 2^128 possibilities is far beyond any computer that exists or is planned; Trezor describes 24 words as "vastly more than needed". Nobody is going to guess either one.

In practice, phrases are lost through very human problems:

  • Theft of a written copy, a photo, or a cloud note.
  • Phishing: typing the phrase into a fake website or handing it to fake support.
  • Transcription errors: a misspelled word, a missed word, or two words written in the wrong order.

Longer phrases mean more chances for that last kind of mistake. On the other hand, the 24-word checksum is stronger: if one word is missing from the end, only 8 candidates fit instead of 128. Choose whichever length your wallet uses, write it down carefully, and check it.

Which wallets use 24 words (and which use 12)?

WalletDefault phrase
Ledger (all models)24 words
Trezor Model One24 words (12 also supported)
Trezor Model T, and Safe 3 before June 202412 words
Trezor Safe 3 (from June 2024), Safe 5, Safe 720-word Shamir backup by default; 12 or 24 BIP39 words selectable
Exodus12 words, always
MetaMask12 words
Trust Wallet12 words
Phantom12 words
Coinbase Wallet12 words
ElectrumIts own format, usually 12 words (not BIP39)

Some phrases look like BIP39 but aren't, which is why a phrase sometimes "won't import" into another app:

  • Electrum seeds use the same word list but a different scheme with a built-in version number. Most BIP39 wallets can't restore them.
  • Trezor's 20-word and 33-word Shamir (SLIP-39) backups use a separate 1,024-word list and aren't compatible with BIP39.
  • Older Blockchain.com wallets used legacy phrases of unusual lengths. See our guide to recovering Blockchain.com legacy mnemonics.

For wallet-specific help, see our recovery phrase guides for MetaMask, Coinbase Wallet, and Solflare.

The BIP39 word list: why the first four letters are enough

The standard English list has exactly 2,048 words, chosen so that the first four letters identify each word (or the whole word, for the 103 words that are only three letters long, such as "act" and "zoo"). That's why some metal backups only stamp four letters per word, and why a smudged word can often be pinned down from its start. The list also avoids near-duplicates like "build" and "built".

You can check any word against the official BIP39 English list on GitHub. Other languages exist, but the standard discourages them, and most wallets only accept English.

How to store your 24-word recovery phrase safely

  • Write it on paper first, in order, numbered 1 to 24. Check every word against the list.
  • Move it to metal for the long term. Stamped or engraved steel survives fire and water far better than paper.
  • Never store it digitally. No photos, screenshots, notes apps, emails, password managers, or cloud drives. Trezor and Ledger both give the same rule.
  • Keep copies in two separate secure places, so one fire, flood, or burglary can't take everything.
  • Test your backup with your wallet's backup-check feature before you rely on it.
  • Don't split your phrase in half as a homemade safety measure. Each half gives away a lot, and losing either half loses everything. If you want split backups, use a real scheme such as Trezor's Shamir backup, where a set number of shares rebuilds the wallet and fewer shares reveal nothing. For large holdings, multisig (several keys, each with its own phrase) goes further.
  • Never type it into a website or give it to anyone who contacts you. No legitimate wallet or support team will ask.

For more on wallet types and safe setups, see our guide to hot vs cold and custodial vs non-custodial wallets.

Are 24-word phrase generators safe?

No. Websites that generate recovery phrases for you, or promise "seed phrases with a balance", are either pointless or scams. With 2^256 possible phrases, nobody will ever randomly land on a funded wallet. And any phrase a website generates has been seen by that website, so treat it as already stolen. Create your phrase only on your own wallet or hardware device.

If part of your 24-word phrase is missing or wrong

This is where the maths above turns in your favor. With a 24-word phrase:

  • One missing word, position known: 2,048 candidates, and only about 8 pass the checksum. Checking them takes moments.
  • One missing word, position unknown: about 49,000 candidates, a few hundred valid. Still quick.
  • Two missing words: about 4.2 million candidates if you know where they go, around a billion if you don't. A real search, but very doable.
  • Three missing words: billions of candidates. Hard, but often still possible, especially with any partial memory of the missing words.
  • Words in the wrong order: if most positions are known, often recoverable. A completely scrambled 24-word order (about 6 × 10^23 possibilities) generally isn't.
  • The whole phrase gone: unrecoverable. 2^256 is not a search anyone can run.

Every search also needs a way to recognize the right wallet, usually an address you know the wallet used. For the step-by-step version, read our guide to recovering a missing word from your seed phrase.

If you're missing words or your phrase says invalid, this is exactly what we do. Crypto Asset Recovery reconstructs incomplete and invalid recovery phrases offline, testing every valid combination against your wallet's addresses on air-gapped machines. You only pay if we succeed.

Start your recovery →

Seed recovery means working with the words you still have, so you'll share your partial phrase with us. Share it only with a recovery service you've verified, never with anyone who contacts you first.

Why Choose Crypto Asset Recovery?

  • Secure, offline recovery. Searches run on air-gapped, offline machines, so your keys are never exposed online.
  • Thousands of wallets recovered across MetaMask, Trust Wallet, Blockchain.com, and more.
  • Success-based pricing. You only pay if we get you back in.
  • Talk to a real person. We're a registered New Hampshire company, and you can get on a Zoom with our founders, the father-and-son team Chris and Charles.
  • Featured in BBC, Forbes, Vice, The Block, and Business Insider.

Frequently asked questions

Can you give me an example of a recovery phrase? The official BIP39 test phrase is "abandon" repeated 23 times followed by "art". It's valid but public, so it must never hold funds. A real phrase is 12 or 24 random words from the 2,048-word BIP39 list.

What is a 24-word passphrase? Usually, people mean one of two things. Some wallets, such as Pi Network, call the 24-word phrase itself a "passphrase". Others mean the optional extra passphrase, or "25th word", that you can add on top of your recovery phrase; every passphrase opens a different wallet.

Should I use a 12- or 24-word seed phrase? Either is secure. 12 words gives 128 bits of security and 24 words gives 256, and both are far beyond brute force. Use what your wallet offers and focus on storing it well; mistakes and theft are the real risks.

How long would it take to crack a 12- or 24-word seed phrase? Longer than the age of the universe, with any computer that exists. A 12-word phrase has about 3.4 × 1038 possibilities, and a 24-word phrase about 1.2 × 1077. Brute force only becomes practical when most of the phrase is already known, which is how missing-word recovery works.

Can I change my 24-word recovery phrase? Not on the same wallet. The phrase is the wallet. To get a new phrase, create a new wallet and move your funds to it.

What happens if I lose my 24-word recovery phrase? If your wallet still opens (for example, your hardware wallet works and you know the PIN), write down a new backup or move your funds to a new wallet right away. If you've lost both the phrase and access to the wallet, the funds usually can't be recovered.

Is a 20-word Trezor backup the same as a seed phrase? It does the same job, but it isn't BIP39. Trezor's 20-word backups use the SLIP-39 Shamir standard with a different word list, so they only restore in wallets that support SLIP-39.

Wallet recovery guidance, in your inbox.

Occasional practical notes from the team that helps people get back into their wallets.

By subscribing, you agree to our privacy policy. Unsubscribe anytime.