LibraryPrivacy2013Design paperCorpus record
Mnemonic Code for Generating Deterministic Keys
BIP 39. Marek Palatinus, Pavol Rusnak, Aaron Voisine and Sean Bowe.
Encode entropy as a word list with a checksum, then stretch the words with a passphrase into a seed. The words are the backup. The passphrase is an extra secret, often empty.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A recovery flow that asks for twelve words and never asks whether there was a passphrase will restore the wrong wallet and call it empty.
The five-minute read
The defect
A seed that is a random hex string is not something a person can write down without errors.
The rule
Encode entropy as a word list with a checksum, then stretch the words with a passphrase into a seed. The words are the backup. The passphrase is an extra secret, often empty.
How it is put together
The word list is an encoding, not an account. The checksum catches some typos, not all mistakes of meaning. PBKDF2 stretches the mnemonic into a seed.
Where the claim stops
The standard does not say which derivation path. That is BIP 44 and cousins.
One action, walked through
- Draw entropy.
- Map it to words and a checksum.
- Derive the seed. BIP 32 then derives keys.
- How many words, and which list?
The argument, unpacked
Why it is still on the desk
A recovery flow that asks for twelve words and never asks whether there was a passphrase will restore the wrong wallet and call it empty.
After the text
The word list became the default backup. The passphrase is the part users do not know they set.
What has to be true
- The standard does not say which derivation path. That is BIP 44 and cousins.
- A passphrase that nobody recorded is a lost wallet.
- The words are not encrypted because they were written on paper.
What happened after the paper
The word list became the default backup. The passphrase is the part users do not know they set.
What to check before you use the idea
- How many words, and which list?
- Is there a passphrase beyond the words?
- Which derivation path turns the seed into addresses?
Terms
- Mnemonic
- Words that encode the entropy and a checksum.
- Passphrase
- An optional extra secret mixed into the seed.
The problem the paper names
A seed that is a random hex string is not something a person can write down without errors.
What the design proposes
- The word list is an encoding, not an account.
- The checksum catches some typos, not all mistakes of meaning.
- PBKDF2 stretches the mnemonic into a seed.
How the mechanism is specified
- Draw entropy.
- Map it to words and a checksum.
- Derive the seed. BIP 32 then derives keys.
What this page does not treat as proven
- The standard does not say which derivation path. That is BIP 44 and cousins.
- A passphrase that nobody recorded is a lost wallet.
- The words are not encrypted because they were written on paper.
Why a venture studio still reads it
A recovery flow that asks for twelve words and never asks whether there was a passphrase will restore the wrong wallet and call it empty.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
