‹ CHAPTER 15, ALL LESSONS

MASTER · CHAPTER 15 · LESSON 3 OF 5

Advanced custody

Entropy and dice

How random is your seed, and can you check it? 5 min

A seed is only as safe as the randomness used to make it. A 12 word seed holds 128 bits of entropy, a 24 word seed 256. If the device that generated it had a faulty or tampered random number generator, an attacker might be able to guess it.

This has happened

Weak generators have emptied wallets in the past: tools that used predictable seeds, websites that turned a chosen phrase into a key, and libraries with too little randomness. Humans are worse still: a sentence you think of yourself is never random.

Rolling your own

Some hardware wallets let you add your own entropy with dice. A six sided die gives about 2.58 bits per roll, so about 50 rolls cover a 12 word seed and about 99 cover a 24 word one. The device then computes the words, including the checksum word.

What to remember

  • 12 words hold 128 bits of entropy, 24 words 256.
  • Weak randomness has caused real losses.
  • Dice rolls can add entropy you control.

Quick check

Why is a phrase you think up yourself a bad seed?

About how many rolls of a six sided die give 256 bits of entropy?