Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu
Lesson 03 / 21 · Expert

Entropy, mnemonics and passphrase tradeoffs

Understand recovery inputs without improvising cryptography.

14 MIN WITH PRACTICEREAD → TRY → REFLECTNO WALLET NEEDED

By the end, you’ll be able to…

  • Distinguish a mnemonic from an optional passphrase.
  • Explain how extra secrecy can create recovery failure.
Your learning map

Three questions to carry into this lesson.

01Distinguish a mnemonic from an optional passphrase.
02Explain how extra secrecy can create recovery failure.
Use these goals to guide your reading. Try the paper exercise, then explain the result in your own words.

Words encode carefully generated material

BIP 39 describes a mnemonic representation derived from entropy with a checksum and a process for deriving a seed. Choosing memorable words yourself is not equivalent to following a wallet’s secure generation process. A checksum helps detect certain mistakes; it is not proof that the underlying randomness was strong or privately generated.

An additional passphrase changes the result

In BIP 39, an optional passphrase participates in seed derivation. Different passphrases produce different results; a typo may lead to an apparently empty wallet rather than a helpful error. This can strengthen a particular design but also create a new loss path if the intended passphrase is forgotten or omitted from recovery planning.

Avoid home-made backup experiments

Do not split words casually among people, invent a brainwallet or enter existing recovery material into a website to see what happens. Different schemes have different security and compatibility properties. A classroom exercise can represent inputs as symbols: mnemonic M and passphrase P produce seed S. The real system should follow documented wallet behavior and be tested with an isolated, nonvaluable setup before anyone depends on it.

Your turn / A paper experiment

Practice on paper

A fictional recovery package contains a mnemonic but the wallet originally used an additional passphrase that nobody recorded. Why might the package fail?

I’ve tried it — show the worked answer

The intended seed depends on both inputs. Omitting or mistyping the passphrase can derive a different wallet. The existence of valid words alone does not establish recoverability of the intended funds.

Want to explore with buttons and instant feedback? Try the practice lab ↗

Think it through

Make a choice. Discover why.

Choose an answer and check the explanation. You can retry as often as you like. These are practice questions, not a test of mastery; answers are not saved or sent.

1. Is a mnemonic checksum proof of strong random generation?
  • Yes
  • No
Read the explanation

No. It checks structure, not the quality or secrecy of generation.

2. Must a wrong BIP 39 passphrase produce an error?
  • Yes
  • No
Read the explanation

No. It can derive a different valid seed.

One idea to take with you

Additional secrets need an equally deliberate recovery plan.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.