A full, unknown 12-word BIP39 phrase has 128 bits of entropy — no rented GPU fleet touches that. The real risk lives in the shortcuts: a partly-remembered phrase, a scrambled word order, or a weak 25th-word passphrase. This walks through both, with the math shown.
This is the realistic breach: 4 words illegible or forgotten, 8 known and in order. Not all 204812 combinations — just 20484, filtered by the built-in checksum. See "missing words," below.
Unlike a website password hashed once with bcrypt, a BIP39 seed goes through several deliberate speed bumps before it becomes a usable wallet.
The mnemonic is run through PBKDF2-HMAC-SHA512 for 2,048 iterations before it becomes a seed. Every single guess costs 2,048 hash operations, not one — this is the BIP39 equivalent of bcrypt's cost factor.
An optional passphrase is mixed into the same PBKDF2 salt. It's not from the 2048-word list — it can be any string — and every passphrase produces a different, fully valid-looking wallet. Wrong guesses don't error, they just derive empty accounts.
Each surviving candidate still has to be run through the BIP32 derivation path to produce keys, and checked against a known address. This step is largely CPU-bound and doesn't parallelize on GPUs nearly as well as the hashing does.
Standard BIP39 lengths, entropy before the checksum is appended.
| Words | Entropy | Checksum | Keyspace |
|---|---|---|---|
| 12 | 128 bits | 4 bits | 2¹²⁸ ≈ 3.4×10³⁸ |
| 15 | 160 bits | 5 bits | 2¹⁶⁰ ≈ 1.5×10⁴⁸ |
| 18 | 192 bits | 6 bits | 2¹⁹² ≈ 6.3×10⁵⁷ |
| 21 | 224 bits | 7 bits | 2²²⁴ ≈ 2.7×10⁶⁷ |
| 24 | 256 bits | 8 bits | 2²⁵⁶ ≈ 1.2×10⁷⁷ |
Every one of those rows, fully unknown and brute forced at full derivation speed, lands somewhere past 10²⁴ years even on an optimistic GPU fleet. 12 words and 24 words are equally uncrackable from scratch. Length only matters once part of the phrase leaks — which is the scenario below.
Positions known, values forgotten or illegible — the most common real recovery case. Assumes a 12-word phrase, checksum-filtered, ~5×10⁶ candidates/sec (see assumptions).
| Words missing | Candidates | Time to exhaust |
|---|---|---|
| 1 | 128 | |
| 2 | 262,144 | |
| 3 | 5.4×10⁸ | |
| 4 | 1.1×10¹² | |
| 5 | 2.3×10¹⁵ | |
| 6 | 4.6×10¹⁸ | |
| 7 | 9.4×10²¹ |
You have every word, but the sequence is lost — permutations only, no wordlist search.
| Words | Permutations | Time to exhaust |
|---|---|---|
| 12 | 4.8×10⁸ | |
| 15 | 1.3×10¹² | |
| 18 | 6.4×10¹⁵ | |
| 21 | 5.1×10¹⁹ | |
| 24 | 6.2×10²³ |
Full seed phrase known, 25th-word passphrase forgotten — random string, ~70-character set.
| Length | Keyspace | Time to exhaust |
|---|---|---|
| 6 chars | 1.2×10¹¹ | |
| 8 chars | 5.8×10¹⁴ | |
| 10 chars | 2.8×10¹⁸ | |
| 12 chars | 1.4×10²² | |
| 16 chars | 3.3×10²⁹ |
Rough estimate, full keyspace, ~5×10⁶ candidates/sec (PBKDF2-HMAC-SHA512, 2,048 rounds). Character counts assume a ~70-character random set (≈6.1 bits/char) — same convention as the length table above, indexed by entropy instead.
| Entropy | ≈ Chars | Time to exhaust | Verdict |
|---|---|---|---|
| 40 bits | ~7 | 2.5 days | Cracked this week |
| 48 bits | ~8 | 1.8 years | Cracked in years |
| 56 bits | ~9 | 457 years | Weak — a serious fleet gets there |
| 64 bits | ~10 | 117,000 years | Getting there, still uncomfortable |
| 72 bits | ~12 | 3.0×10⁷ years | Comfortable margin |
| 80 bits | ~13 | 7.7×10⁹ years | Longer than the universe |
| 96 bits | ~16 | 5.0×10¹⁴ years | Solidly safe |
| 112 bits | ~18 | 3.3×10¹⁹ years | Solidly safe |
| 128 bits | ~21 | 2.2×10²⁴ years | Overkill — matches full seed entropy |
| 160 bits | ~26 | 9.3×10³³ years | Overkill |
| 192 bits | ~31 | 4.0×10⁴³ years | Overkill |
| 256 bits | ~42 | 7.3×10⁶² years | Overkill |