Threat model · BIP39 / bcrypt comparison

Your seed phrase was never going to be brute forced whole.
Here's what actually breaks it.

A full, unknown 12-word BIP39 phrase has 128 bits of entropy — no rented GPU fleet touches that. The real risk lives in the shortcuts: a partly-remembered phrase, a scrambled word order, or a weak 25th-word passphrase. This walks through both, with the math shown.

Recovery card — 12 of 12 words4 unreadable

This is the realistic breach: 4 words illegible or forgotten, 8 known and in order. Not all 204812 combinations — just 20484, filtered by the built-in checksum. See "missing words," below.

Three things slow an attacker down

Unlike a website password hashed once with bcrypt, a BIP39 seed goes through several deliberate speed bumps before it becomes a usable wallet.

Key stretching
×2,048

The mnemonic is run through PBKDF2-HMAC-SHA512 for 2,048 iterations before it becomes a seed. Every single guess costs 2,048 hash operations, not one — this is the BIP39 equivalent of bcrypt's cost factor.

Optional passphrase
25th word

An optional passphrase is mixed into the same PBKDF2 salt. It's not from the 2048-word list — it can be any string — and every passphrase produces a different, fully valid-looking wallet. Wrong guesses don't error, they just derive empty accounts.

Derivation + match
BIP32/44

Each surviving candidate still has to be run through the BIP32 derivation path to produce keys, and checked against a known address. This step is largely CPU-bound and doesn't parallelize on GPUs nearly as well as the hashing does.

Entropy by phrase length

Standard BIP39 lengths, entropy before the checksum is appended.

WordsEntropyChecksumKeyspace
12128 bits4 bits2¹²⁸ ≈ 3.4×10³⁸
15160 bits5 bits2¹⁶⁰ ≈ 1.5×10⁴⁸
18192 bits6 bits2¹⁹² ≈ 6.3×10⁵⁷
21224 bits7 bits2²²⁴ ≈ 2.7×10⁶⁷
24256 bits8 bits2²⁵⁶ ≈ 1.2×10⁷⁷
10²⁴+ yrs

Every one of those rows, fully unknown and brute forced at full derivation speed, lands somewhere past 10²⁴ years even on an optimistic GPU fleet. 12 words and 24 words are equally uncrackable from scratch. Length only matters once part of the phrase leaks — which is the scenario below.

Realistic scenario: some words missing

Positions known, values forgotten or illegible — the most common real recovery case. Assumes a 12-word phrase, checksum-filtered, ~5×10⁶ candidates/sec (see assumptions).

Words missingCandidatesTime to exhaust
1128
instant
2262,144
< 1 second
35.4×10⁸
~2 minutes
41.1×10¹²
~2.5 days
52.3×10¹⁵
~14 years
64.6×10¹⁸
~29,000 years
79.4×10²¹
~60 million years

Realistic scenario: correct words, wrong order

You have every word, but the sequence is lost — permutations only, no wordlist search.

WordsPermutationsTime to exhaust
124.8×10⁸
~1.5 minutes
151.3×10¹²
~3 days
186.4×10¹⁵
~41 years
215.1×10¹⁹
~324,000 years
246.2×10²³
~3.9 billion years

Realistic scenario: forgotten passphrase

Full seed phrase known, 25th-word passphrase forgotten — random string, ~70-character set.

LengthKeyspaceTime to exhaust
6 chars1.2×10¹¹
~6.5 hours
8 chars5.8×10¹⁴
~3.7 years
10 chars2.8×10¹⁸
~17,900 years
12 chars1.4×10²²
~88 million years
16 chars3.3×10²⁹
~2.1×10¹⁵ years

Passphrase strength by entropy

Rough estimate, full keyspace, ~5×10⁶ candidates/sec (PBKDF2-HMAC-SHA512, 2,048 rounds). Character counts assume a ~70-character random set (≈6.1 bits/char) — same convention as the length table above, indexed by entropy instead.

Entropy≈ CharsTime to exhaustVerdict
40 bits~72.5 days Cracked this week
48 bits~81.8 years Cracked in years
56 bits~9457 years Weak — a serious fleet gets there
64 bits~10117,000 years Getting there, still uncomfortable
72 bits~123.0×10⁷ years Comfortable margin
80 bits~137.7×10⁹ years Longer than the universe
96 bits~165.0×10¹⁴ years Solidly safe
112 bits~183.3×10¹⁹ years Solidly safe
128 bits~212.2×10²⁴ years Overkill — matches full seed entropy
160 bits~269.3×10³³ years Overkill
192 bits~314.0×10⁴³ years Overkill
256 bits~427.3×10⁶² years Overkill
Methodology & honesty check

Assumptions