How 12 words become a Bitcoin address

Your recovery words are not a password to an account somewhere. They are a number, and every key and address in your wallet is calculated from that number by a fixed recipe. This page follows one example through that recipe, one step at a time.

  1. Words
  2. Seed
  3. Master key
  4. Your key
  5. Public key
  6. Address

Keep secret: anyone with this can spendSafe to share

Example only. This page uses a famous public test phrase that anyone can look up, so every value below is real but worthless. Never type your own words into any website, including this kind of page.

STEP 1

The words are a number

Keep secret

What is actually written on your backup?

The wallet uses a fixed list of 2,048 English words. Each word is really its position on that list, a number from 0 to 2047. Twelve of those numbers written together make one very large random number. That number is your wallet.

  1. abandon#0
  2. abandon#0
  3. abandon#0
  4. abandon#0
  5. abandon#0
  6. abandon#0
  7. abandon#0
  8. abandon#0
  9. abandon#0
  10. abandon#0
  11. abandon#0
  12. about#3

The small number under each word is its position on the list, counting from 0.

Why all "abandon"? "Abandon" is word 0 on the list, so this phrase is what you get when the random number is all zeros. A real wallet's words look random, like turtle orbit guilt. The last word is partly a checksum: 4 of its bits are calculated from the other words, so a wallet can usually tell you've made a typo.

Technical name: BIP39 mnemonic. 12 words × 11 bits = 132 bits: 128 random bits plus a 4-bit checksum. A 24-word phrase holds 256 random bits.

STEP 2

The words are scrambled into a seed

Keep secret

What does the wallet do with the words?

The wallet feeds the words through a one-way scrambler 2,048 times in a row. What comes out is the seed: 64 bytes that look like noise. "One-way" means you can go from words to seed in a fraction of a second, but nobody can go from the seed back to the words.

In
abandon abandon … about
Out: seed
5eb00bbddcf069084889a8ab9155568165f5c453ccb85e70811aaed6f6da5fc19a5ac40b389cd370d086206dec8aa6c43daea6690f20ad3d8d48b2d2ce9e38e4

The optional passphrase goes in here. Some wallets let you add an extra passphrase (sometimes called a "25th word"). It gets mixed into this scramble, so the same 12 words with a different passphrase make a completely different seed, and so a completely different wallet with different addresses. There is no "wrong passphrase" error: every passphrase opens a wallet.

Technical name: BIP39 seed. PBKDF2-HMAC-SHA512, 2,048 iterations, salt "mnemonic" + passphrase. The example uses no passphrase.

STEP 3

The seed becomes a master key

Keep secret

How does a seed turn into a key?

The seed is hashed once more and the result is cut in half. The first half is the master private key. The second half, the chain code, is extra randomness the wallet needs in the next step to make child keys. Together they are the top of your wallet: every other key comes from here.

In
the seed from step 2
Master private key
1837c1be8e2995ec11cda2b066151be2cfb48adf9e47b151d46adab3a21cdf67
Chain code
7923408dadd3c7b56eed15567707ae5e5dca089de972e07f3b860450e2a3b70e

Technical name: BIP32 master key. HMAC-SHA512 of the seed with the key "Bitcoin seed"; left 32 bytes are the key, right 32 bytes are the chain code.

STEP 4

A path picks one key out of billions

Keep secret

How does one master key become many keys?

Any key can make child keys, numbered 0, 1, 2 and so on, and each child can make its own children. Wallets agree on a route through that family tree, written as a derivation path. Read it left to right like a street address: each number means "take this child".

m / 84' / 0' / 0' / 0 / 0

PartMeansIn this example
mStart at the master keyThe key from step 3
84'Which address style84 = modern "native SegWit" addresses starting bc1q
0'Which coin0 = Bitcoin (1 = test network)
0'Which account0 = your first account
0Receiving or change0 = addresses you give out (1 = change the wallet sends back to itself)
0Which address0 = the first one
In
master key + path m/84'/0'/0'/0/0
Out: private key
4604b4b710fe91f584fff084e1a9159fe4f8408fff380596a604948474ce4fa3

This private key is what actually spends the coins sent to the address we're about to build. You never have to back it up, because the wallet can recompute it from your words at any time.

Technical names: BIP32 child derivation; path layout from BIP44, purpose 84 from BIP84. The apostrophe marks a "hardened" step, an extra-isolated child that can only be computed with the private key.

STEP 5

The private key makes a public key

Safe to share

What part can other people see?

A bit of elliptic-curve math turns the private key into a public key. Like the scramble in step 2, it's one-way: anyone can check a signature against the public key, but nobody can work backwards from it to the private key.

In
the private key from step 4
Out: public key
0330d54fd0dd420a6e5f8d3624f5f3482cae350f79d5f0753bf5beef9c2d91af3c

Technical name: secp256k1 compressed public key (33 bytes). This is where the chain of secrets ends: everything from here down can be shown to others.

STEP 6

The public key becomes an address

Safe to share

Where does the address you paste into an exchange come from?

The public key is hashed down to a short 20-byte fingerprint. That fingerprint is then written out in a typo-resistant format that starts with bc1q and ends in a built-in checksum. The result is the address you share to get paid.

In
the public key from step 5
Fingerprint
c0cebcd6c3d3ca8c75dc5ec62ebe55330ef910e2
Out: address
bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu

Technical names: HASH160 (SHA-256 then RIPEMD-160), native SegWit (P2WPKH) output, Bech32 encoding (BIP173). This exact address is the published BIP84 test vector for these words.

Change the last number, get the next address

Your wallet doesn't store addresses. When you ask for a new one, it walks the same path and adds 1 to the final number. The same 12 words always produce the same list, in the same order, on any wallet that follows the same path.

PathAddress
m/84'/0'/0'/0/0bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu
m/84'/0'/0'/0/1bc1qnjg0jd8228aq7egyzacy8cys3knf9xvrerkf9g
m/84'/0'/0'/0/2bc1qp59yckz4ae5c4efgw2s5wfyvrz0ala7rgvuz8z
m/84'/0'/0'/0/3bc1qgl5vlg0zdl7yvprgxj9fevsc6q6x5dmcyk3cn3
m/84'/0'/0'/1/0bc1q8c6fshw2dlwun7ekn9qwf37cu2rn755upcp6el

Highlighted row: the address built in steps 1 to 6. The last row is on the change branch (fourth number = 1).

What this means for you

Go deeper

David Veksler is a Principal AI Engineer in Denver. He leads agentic AI engineering at Antech, a Mars company, and builds AI platforms for regulated financial firms. This page was produced by a governed, multi-agent Claude Code pipeline with a git audit trail. How it's built Case studies