ENTROPÍA

Is a 12-word seed enough? 12 vs 24 words security

You got a wallet that showed you 12 words, and now you wonder if having only 12 instead of 24 means your bitcoin can be stolen.

**12 words are not insecure: nobody forces 2^128.**

What BIP-39 says about 12 and 24 words

BIP-39 defines seed phrases of 12 and 24 words. With 12 words you get 128 bits of entropy; with 24, 256. Source: BIP-39 (entropy by phrase length).

That difference sounds huge, but in practice it doesn't change what can happen to you.

Can someone brute-force a 12-word phrase?

No. Nobody forces 2^128. Even though 128 bits is half the number of bits as 256, both are so far beyond brute-force that the practical difference is zero.

This does not mean 24 words are wrong

Don't say 24 words is wrong or that it's the same in every way. Some devices only generate 24 and the standard defines both. The point is that 12 is NOT insecure, not that 24 is overkill.

This does not mean 24 words are wrong

Don't say 24 words is wrong or that it's the same in every way. Some devices only generate 24 and the standard defines both. The point is that 12 is NOT insecure, not that 24 is overkill.

Source: BIP-39 (entropía por largo de frase)