The words are a number
Keep secretWhat is actually written on your backup?
The wallet uses a fixed list of 2,048 English words. Each word is really its position on that list, a number from 0 to 2047. Twelve of those numbers written together make one very large random number. That number is your wallet.
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- abandon#0
- about#3
The small number under each word is its position on the list, counting from 0.
Why all "abandon"? "Abandon" is word 0 on the list, so this phrase is what you get when the random number is all zeros. A real wallet's words look random, like turtle orbit guilt. The last word is partly a checksum: 4 of its bits are calculated from the other words, so a wallet can usually tell you've made a typo.
Technical name: BIP39 mnemonic. 12 words × 11 bits = 132 bits: 128 random bits plus a 4-bit checksum. A 24-word phrase holds 256 random bits.
The words are scrambled into a seed
Keep secretWhat does the wallet do with the words?
The wallet feeds the words through a one-way scrambler 2,048 times in a row. What comes out is the seed: 64 bytes that look like noise. "One-way" means you can go from words to seed in a fraction of a second, but nobody can go from the seed back to the words.
- In
- abandon abandon … about
- Out: seed
- 5eb00bbddcf069084889a8ab9155568165f5c453ccb85e70811aaed6f6da5fc19a5ac40b389cd370d086206dec8aa6c43daea6690f20ad3d8d48b2d2ce9e38e4
The optional passphrase goes in here. Some wallets let you add an extra passphrase (sometimes called a "25th word"). It gets mixed into this scramble, so the same 12 words with a different passphrase make a completely different seed, and so a completely different wallet with different addresses. There is no "wrong passphrase" error: every passphrase opens a wallet.
Technical name: BIP39 seed. PBKDF2-HMAC-SHA512, 2,048 iterations, salt "mnemonic" + passphrase. The example uses no passphrase.
The seed becomes a master key
Keep secretHow does a seed turn into a key?
The seed is hashed once more and the result is cut in half. The first half is the master private key. The second half, the chain code, is extra randomness the wallet needs in the next step to make child keys. Together they are the top of your wallet: every other key comes from here.
- In
- the seed from step 2
- Master private key
- 1837c1be8e2995ec11cda2b066151be2cfb48adf9e47b151d46adab3a21cdf67
- Chain code
- 7923408dadd3c7b56eed15567707ae5e5dca089de972e07f3b860450e2a3b70e
Technical name: BIP32 master key. HMAC-SHA512 of the seed with the key "Bitcoin seed"; left 32 bytes are the key, right 32 bytes are the chain code.
A path picks one key out of billions
Keep secretHow does one master key become many keys?
Any key can make child keys, numbered 0, 1, 2 and so on, and each child can make its own children. Wallets agree on a route through that family tree, written as a derivation path. Read it left to right like a street address: each number means "take this child".
m / 84' / 0' / 0' / 0 / 0
| Part | Means | In this example |
|---|---|---|
m | Start at the master key | The key from step 3 |
84' | Which address style | 84 = modern "native SegWit" addresses starting bc1q |
0' | Which coin | 0 = Bitcoin (1 = test network) |
0' | Which account | 0 = your first account |
0 | Receiving or change | 0 = addresses you give out (1 = change the wallet sends back to itself) |
0 | Which address | 0 = the first one |
- In
- master key + path m/84'/0'/0'/0/0
- Out: private key
- 4604b4b710fe91f584fff084e1a9159fe4f8408fff380596a604948474ce4fa3
This private key is what actually spends the coins sent to the address we're about to build. You never have to back it up, because the wallet can recompute it from your words at any time.
Technical names: BIP32 child derivation; path layout from BIP44, purpose 84 from BIP84. The apostrophe marks a "hardened" step, an extra-isolated child that can only be computed with the private key.
The private key makes a public key
Safe to shareWhat part can other people see?
A bit of elliptic-curve math turns the private key into a public key. Like the scramble in step 2, it's one-way: anyone can check a signature against the public key, but nobody can work backwards from it to the private key.
- In
- the private key from step 4
- Out: public key
- 0330d54fd0dd420a6e5f8d3624f5f3482cae350f79d5f0753bf5beef9c2d91af3c
Technical name: secp256k1 compressed public key (33 bytes). This is where the chain of secrets ends: everything from here down can be shown to others.
The public key becomes an address
Safe to shareWhere does the address you paste into an exchange come from?
The public key is hashed down to a short 20-byte fingerprint. That fingerprint is then written out in a typo-resistant format that starts with bc1q and ends in a built-in checksum. The result is the address you share to get paid.
- In
- the public key from step 5
- Fingerprint
- c0cebcd6c3d3ca8c75dc5ec62ebe55330ef910e2
- Out: address
- bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu
Technical names: HASH160 (SHA-256 then RIPEMD-160), native SegWit (P2WPKH) output, Bech32 encoding (BIP173). This exact address is the published BIP84 test vector for these words.
Change the last number, get the next address
Your wallet doesn't store addresses. When you ask for a new one, it walks the same path and adds 1 to the final number. The same 12 words always produce the same list, in the same order, on any wallet that follows the same path.
| Path | Address |
|---|---|
m/84'/0'/0'/0/0 | bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu |
m/84'/0'/0'/0/1 | bc1qnjg0jd8228aq7egyzacy8cys3knf9xvrerkf9g |
m/84'/0'/0'/0/2 | bc1qp59yckz4ae5c4efgw2s5wfyvrz0ala7rgvuz8z |
m/84'/0'/0'/0/3 | bc1qgl5vlg0zdl7yvprgxj9fevsc6q6x5dmcyk3cn3 |
m/84'/0'/0'/1/0 | bc1q8c6fshw2dlwun7ekn9qwf37cu2rn755upcp6el |
Highlighted row: the address built in steps 1 to 6. The last row is on the change branch (fourth number = 1).
What this means for you
- The words are the wallet. Everything above is calculated, not stored. Lose the device and keep the words, and you lose nothing. Lose the words and the device, and nobody can rebuild it.
- Anyone who sees your words can make every key. Steps 1 to 4 are secret. That's why the words never go into a website, a photo, or a cloud note.
- A passphrase makes a different wallet. Same words plus a different (or forgotten) passphrase gives a different seed in step 2, so different addresses, often an empty-looking wallet.
- A different path shows different addresses. If a wallet restores your words but uses path 44 or 86 instead of 84, it computes different addresses and may show a zero balance even though your coins are safe. Changing the path setting fixes it.
- Addresses are safe to share, but not private. An address can only receive. Anyone can see its history on the public blockchain, which is why wallets hand you a fresh one each time.
Go deeper
- Bitcoin self-custody guide: how to store the words and choose a passphrase
- Wallet recovery forensics: what to do when a restored wallet shows the wrong balance
- Bitcoin wallets compared: hardware and software wallets
- The specs: BIP39 (words and seed), BIP32 (key tree), BIP44 (path layout), BIP84 (bc1q addresses and this example's test vector)