Every word is a number from 0 to 2047. You need 11 of them for a 12-word phrase, or 23 for a 24-word phrase. The calculator works out the final word for you.
01011010110.(d1 × 1296) + (d2 × 216) + (d3 × 36) + (d4 × 6) + d5| marked d6 | d10 | d10 | d10 |
| THOUSANDS | HUNDREDS | TENS | UNITS |
| 0 1 2 | 0–9 | 0–9 | 0–9 |
| PLACE DIE HERE | PLACE DIE HERE | PLACE DIE HERE | PLACE DIE HERE |
| thousands — marked d6 | hundreds — colour ______ | tens — colour ______ | units — colour ______ |
Your 11 or 23 words do not fill the phrase exactly. A few entropy bits are left over, and the calculator will show you every word that could validly finish the phrase — one row per possible value of those leftover bits. Those bits are real entropy: generate them the same careful way, then use the number as the row.
| 12 words | 15 words | 18 words | 21 words | 24 words |
| 7 bits left over | 6 bits left over | 5 bits left over | 4 bits left over | 3 bits left over |
| rows 0–127 | rows 0–63 | rows 0–31 | rows 0–15 | rows 0–7 |
Never reduce a too-large roll with modulo, wrap it around, or simply pick a row that looks good. Discard and reroll.
Write each index in the column for the length you are building. The last word is never rolled — it carries the checksum and the calculator works it out from the words above it, which is why the tail of every column is dashed out. Write the numbers here if you must, never the finished phrase.
| Roll # | 12-word | 15-word | 18-word | 21-word | 24-word |
|---|---|---|---|---|---|
| 1 | |||||
| 2 | |||||
| 3 | |||||
| 4 | |||||
| 5 | |||||
| 6 | |||||
| 7 | |||||
| 8 | |||||
| 9 | |||||
| 10 | |||||
| 11 | |||||
| 12 | — | ||||
| 13 | — | ||||
| 14 | — | ||||
| 15 | — | — | |||
| 16 | — | — | |||
| 17 | — | — | |||
| 18 | — | — | — | ||
| 19 | — | — | — | ||
| 20 | — | — | — | ||
| 21 | — | — | — | — | |
| 22 | — | — | — | — | |
| 23 | — | — | — | — |
You shouldn't — not on this file's word. Nothing written on this page is evidence of its own honesty, because a tampered copy would say every word of it too. What you can do instead is check it, and most of the checks take a minute: compare its hash against one published somewhere else, make an unrelated program agree with its arithmetic, read the self-test it just ran, have your own browser confirm it asked the network for nothing, and read the code.
Opens in a separate window, with the exact commands for each operating system, the live results from this copy, and — for every check — what it proves and what it leaves open. All of it works offline.
You shouldn't. This window was drawn by the very file it is describing, so everything in it is the file's testimony about itself — which is exactly what a tampered copy would also offer. Below are seven checks that do not rest on taking its word: each one brings in something other than this file, and each one says plainly what it proves and what it leaves open. They all work with the network off. Use Cmd/Ctrl+F to search.
A cryptographic hash of the file is a short number that changes completely if a single character of it changes. Compute it yourself, then compare it against the value published at bip39toolbox.com/hash — deliberately a different page from the one offering the download, so that swapping the file would not be enough to fool you. Type that address in yourself; do not follow a link that travelled with the file.
shasum -a 256 bip39_checksum_calculator.htmlsha256sum bip39_checksum_calculator.htmlcertutil -hashfile bip39_checksum_calculator.html SHA256If you have never opened a terminal in the folder a file is saved in, the panel headed “Verifying this file wasn't tampered with” on the main page has the steps for your system, plus a command that makes the computer do the comparison instead of asking you to eyeball 64 hexadecimal characters — worth using, because a tampered file would be built to match the first and last few on purpose.
Proves: the bytes on your disk are the bytes that were published — if, and only if, the hash you compared against reached you by a different route than the file did.
Does not prove: anything, if the hash came bundled with the file. Whoever could alter the file could alter a hash sitting next to it just as easily.
BIP-39's checksum is not this file's invention, so a program that has never heard of this file has to produce the same answers. Two reference cases are small enough to check with software you almost certainly already have:
abandon can be completed only by about.abandon can be completed only by art.
Both fall out of a single SHA-256 of a block of zero bytes. Eleven abandons
are 121 zero bits, so the phrase's entropy is 128 zero bits, and the last word's eleven
bits are seven zeros followed by the four checksum bits. That makes the last word's index
the checksum by itself — and the checksum is the first four bits of the hash of the
entropy, which is its first hexadecimal digit:
head -c 16 /dev/zero | shasum -a 256head -c 16 /dev/zero | sha256sumpython3 -c "import hashlib; print(hashlib.sha256(bytes(16)).hexdigest())"powershell -c "$b = New-Object byte[] 16; [BitConverter]::ToString([Security.Cryptography.SHA256]::Create().ComputeHash($b)).Replace('-','').ToLower()"
It starts 3747…. The first digit is 3, so the twelfth word is the
word at index 3 — counting from zero, so the fourth word in the list — and in
the official English list that word is about. For the 24-word case use 32 zero bytes
instead of 16: the hash starts 6668…, there are eight checksum bits this
time rather than four, 0x66 is 102 in decimal, and word 102 is
art.
Look those two indexes up in a copy of english.txt you got yourself — it is published in bitcoin/bips (BIP-39) and in trezor/python-mnemonic — rather than in the table on this page. Using this file to check this file is the one move that proves nothing.
The reference implementation is Trezor's python-mnemonic. With it
installed, Mnemonic("english").check(phrase) answers the same question this
tool's verify mode answers, in code written by other people years earlier. Ian Coleman's
BIP-39 tool is another long-standing offline cross-check; download it and open it from disk,
exactly as you did this one.
The check that exercises everything at once is a restore: take a phrase this file completed from throwaway words, load it into a wallet you are willing to discard, and see that it is accepted. Nothing else tests the word list, the index order and the checksum together, in the software that will actually have to read your backup one day.
Proves: the arithmetic in this file is BIP-39's arithmetic, not this file's opinion of it, and its word list agrees with the world's at the indexes you tested.
Does not prove: that this copy is unaltered elsewhere. Working math and honest math are different things — only check 1 speaks to the second.
Every time this file loads it recomputes both BIP-39 reference vectors through the same code path the calculator uses, and cross-checks its own from-scratch SHA-256 against the one built into your browser across a spread of byte lengths, including the block boundaries where a hand-written implementation goes wrong if it is going to. A genuine disagreement disables the calculator outright rather than warning you, because wrong math quietly producing a wrong final word is the worst thing this tool could do to you.
Half of that check is worth more than the other half: the reference vectors are this file testing itself, but your browser's SHA-256 is someone else's code, already on your machine, and it has no idea this file exists. Here is what it said a moment ago:
Proves: the hashing and checksum code in the copy you are running works, on your hardware, right now — not on the author's machine at some point in the past.
Does not prove: that the file is the published one, or that the word list is right, or that the interface puts your words where you think it does.
Better than any of that, watch it yourself. Open your browser's developer tools
(F12, or Cmd+Option+I on a Mac), select the Network tab, and reload the
page: the list stays empty. Then do the check that needs no tools at all — turn the
Wi-Fi off, or unplug the cable, and use the whole tool. Everything still works, because
there is nothing it could have been waiting for.
Proves: nothing you type here leaves the machine, and nothing this page shows you came from anywhere but the file.
Does not prove: that the machine itself is clean. A keylogger does not need this page's cooperation — see the last section.
A word's position in the list is its number, so a list with two words swapped would produce phrases that no wallet on earth could restore — and every check above would still pass. Rebuilding each official .txt from the list embedded here and hashing it catches a single reordered, dropped or altered word:
Proves: the embedded lists are word-for-word and order-for-order the official ones, if the values you compared against came from the BIP-39 repository rather than from this page.
Does not prove: much on its own if you read the expected values off this page, since a copy that altered a list could also alter what it claims to expect. What it reliably catches is damage; check 1 is what catches intent.
It is one file, with no build step, no minification and no dependencies, and the button
headed “Read this file's code” near the top of the page opens all of it as
inert text. Worth searching for: fetch, XMLHttpRequest,
WebSocket, src=, localStorage. Your browser's own
view-source shows you the same thing, and is one fewer piece of this file to trust.
Proves: that what the file claims to do is what its code does, to the extent you are able to read it — and you do not have to read all of it to search it.
Does not prove: that the file is genuine. A tampered copy displays its tampered code just as willingly. Reading is not verifying.
This file states its own version and carries its whole change history, including the published hash of every earlier release. It never checks for updates: it makes no network requests at all, so it cannot know whether it is current. That comparison is yours to make, against bip39toolbox.com/versions, ideally while you are still connected and before you start.
Proves: what changed between the copy in your hand and any other, in plain language, so an old copy is a known quantity rather than a mystery.
Does not prove: that an old copy is unsafe. Every published release lists its own hash, so an older file can be verified exactly like a current one.
All seven checks are about the file. Not one of them is about the computer you are running it on. If that machine has a keylogger, a screen recorder or a clipboard watcher, every check on this page can pass and your phrase is gone the moment you type it. That is the entire reason the checklist at the top asks you to disconnect, and why doing this on a machine you have reason to trust matters more than anything written here.
Nor do they say anything about whether you should hold cryptocurrency, whether your wallet is a good one, or whether your backup is somewhere sensible. This file does arithmetic. It has no opinion about the rest, and a tool that offered one would be worth less, not more. The full disclaimer is at the foot of the main page, and it is worth the minute.
bip39toolbox.com
Did someone give you this file? If it reached you as an email attachment, a chat
message, a USB stick or a shared folder — anything other than you going to
bip39toolbox.com and downloading it yourself — then check
it before you type a real seed phrase into it. A single altered character could silently
hand your phrase to someone else.
For the best security, download it yourself from
bip39toolbox.com. That is the recommended way to get this
file, and it is the one case where an extra check is least likely to be needed. A copy
that passed through someone else's hands is where it matters most.
Opens the step-by-step instructions in a separate window. Everything runs on this machine; nothing is sent anywhere.
A single altered character in this file could silently hand your seed phrase to someone else. Checking the hash is how you catch that — but only if you check it the right way.
bip39toolbox.com/hash — deliberately on a different page
from the download itself. Navigate to that address yourself. Do not follow a link that
arrived alongside the file.
Every copy is worth checking, including one downloaded from that site. If you are obtaining this file for the first time, downloading it from the official site is better provenance than accepting a copy from someone else — but it is not a substitute for the check, and it is the weaker of the two cases:
You need a terminal open in the folder where this file is saved. If you have never done that, here is how:
Then run the command for your system:
shasum -a 256 bip39_checksum_calculator.htmlsha256sum bip39_checksum_calculator.htmlcertutil -hashfile bip39_checksum_calculator.html SHA256You'll get a 64-character hexadecimal string. That is this exact file's fingerprint: change one byte anywhere in it and the fingerprint changes completely.
The comparison is only meaningful if the hash reached you through a different channel than the file did. If the file came as an email attachment, get the hash by text message, phone call, printed note, or from a separate website you navigated to yourself.
Sixty-four characters is more than the eye reliably checks — and anyone who tampered with the file would make the first and last few match on purpose. Have the computer compare instead, pasting in the hash that reached you separately:
echo "PASTE_THE_HASH_YOU_RECEIVED bip39_checksum_calculator.html" | shasum -a 256 -cecho "PASTE_THE_HASH_YOU_RECEIVED bip39_checksum_calculator.html" | sha256sum -c(Get-FileHash .\bip39_checksum_calculator.html -Algorithm SHA256).Hash -eq "PASTE_THE_HASH_YOU_RECEIVED"
macOS and Linux print bip39_checksum_calculator.html: OK;
Windows prints True. Any other result is a mismatch.
The same rule applies in reverse, and it is your responsibility to follow it: send the file and its hash through two different channels, never the same one. Emailing someone the file with the hash pasted underneath gives them no protection at all. Send the file however is convenient, then send the hash a different way — a text, a call, in person, on paper.
A seed phrase checksum calculator, verifier, missing-word recovery tool and entropy converter in one HTML file — running entirely on your own machine, with the network off. No accounts, no server, no dependencies, nothing to install. Free, and small enough to read in a text editor.
A practice run walks you through making a word with four dice — the throws, the two rerolls that are legal, and the word that comes out — using numbers written into this page rather than any of your own. It is the one thing here that works on a website, precisely because you type nothing into it and there is nothing for a server to see.
Clearly labelled throughout, and the words it produces are the same for every reader — which is exactly why they must never be used for funds.
Two pages you can work from away from the screen: page one teaches the throw, page two is a slot per die and a 23-row grid to write your indexes into. Print it, sit down with four dice and a pen, and type nothing until the end.
One small HTML page, openable and printable offline forever, with no reader to install. Your print dialog will save it as a PDF if you would rather have one.
fetch, no XMLHttpRequest and no
WebSocket call anywhere, and a Content-Security-Policy of
default-src 'none' with no connect-src
blocks every outbound connection at the browser level regardless.fetch yourself.Downloading from here is better than accepting a copy from someone else, but it is not a substitute for checking. Compute the file's SHA-256 after downloading and compare it against the hash published at bip39toolbox.com/hash — deliberately a different page from this one, so that replacing the download would not be enough to fool the check. The file explains exactly how, for each operating system, once you open it.
Corrections, unclear wording, and anything that behaves wrongly in your browser are all worth reporting — this tool has been improved by exactly that kind of message. Write to suggestions@bip39toolbox.com.
Never send a seed phrase, part of one, or any wallet detail. Not to this address, not to anyone, ever. Anything that looks like a seed phrase is deleted without being read. Nobody who legitimately helps you will ever need those words.
Nobody from this site will ever email you first, or ever ask you for your phrase. The only mail that could ever come from here is a direct reply to a message you sent yourself — and there is no guarantee of one. Anything unsolicited, and anything asking you to "verify" or "confirm" or "restore" your wallet, is a fraud regardless of what the sender address appears to say.
One person, no support desk, no guaranteed reply — silence is the normal outcome, not a sign anything went wrong. It is read, but treat it as a suggestion box rather than a help line — the answers to most questions are already in the file itself, under Help.
Free, independently created, provided as-is with no warranty and no liability. Not affiliated with any wallet manufacturer, exchange, or the Bitcoin Improvement Proposals project. Verify results independently before relying on this for anything of real value. The full disclaimer is in the file.
New to this, or stuck? Start here.
What a seed phrase is, why the last word is not free to be anything, what to do when you cannot read one of your words, how to use every part of this tool — and what this file will not tell you.
Opens in a separate window. Every answer is already inside this file, so it works with the network off. Use your browser's find (Cmd/Ctrl+F) to search it.
Everything here is part of the file you are running. Nothing was fetched, and nothing you do on this page is sent anywhere. Use Cmd/Ctrl+F to search.
A list of 12 or 24 ordinary words that stands in for the master key to a cryptocurrency wallet. The words are not a password and they are not encrypted: anyone holding them holds the wallet. That is the whole reason this file refuses to run from a website and asks you to disconnect the machine.
Because 2048 is 211, so each word carries exactly 11 bits. Twelve words are 132 bits, twenty-four are 264. That clean arithmetic is the only reason the list is that length — there is nothing special about the words themselves.
The final word carries a checksum, computed from everything before it. Of 132 bits in a 12-word phrase, 128 are your entropy and 4 are that checksum; of 264 bits in a 24-word phrase, 256 are entropy and 8 are checksum. So the last word is partly determined by your earlier words, which is what this tool works out for you.
It depends on the length, and the pattern is clean: 128 words for a 12-word phrase, 64 for 15, 32 for 18, 16 for 21, and only 8 for 24. The reason is bit arithmetic: a phrase of n words carries n÷3 checksum bits, so the final word has 11 − n÷3 bits left free, and the count is 2 to that power. For 12 words your first 11 spend 121 of the 128 entropy bits, leaving 7 free, and 27 is 128. Any of those completions is equally valid — picking among them is a free choice, so make it with dice rather than by preference.
No. BIP-39 defines five lengths — 12, 15, 18, 21 and 24 words — carrying 128, 160, 192, 224 and 256 bits of entropy respectively. Most wallets only ever offer 12 or 24, which is why the other three are rarely seen, but they are entirely valid and this tool handles all five. If you have an 18-word phrase, it is not malformed; it is just uncommon.
Yes, completely. The same words in a different order are a different phrase and a different wallet. And you cannot invent words: every word must come from the official list, or no wallet can restore the phrase.
Out of scope here. BIP-39 allows an optional passphrase on top of the words, which produces an entirely different wallet. This file does not take one, does not derive keys or addresses, and is not a wallet. It works on the words and the checksum only. If you use a passphrase, this tool neither knows nor needs to know.
Because typing a real seed phrase into a page served by a website means trusting the server, the connection, and everyone in between. Opened from your own disk there is nothing left to trust but the file itself, which you can read. The refusal is a hard gate, not a warning you can dismiss.
Each one is a thing that has actually cost people their money: staying connected, trusting a screenshot or a photo instead of writing the words down by hand, and working where a camera or another person can see the screen. The tool stays disabled until all three are ticked because reading them is the point.
With dice or coins, using the helpers on this page. Do not let a website, a phone app, or this file choose your entropy for you if you can avoid it — physical randomness you generated yourself is the one source you can fully account for. The helpers read out indexes rather than computing them behind your back.
Four ways are offered and none is more correct than another. Eleven coin flips per word is the simplest and wastes nothing. Eleven dice read odd = 1, even = 0 do the same job with no coin. Five six-sided dice give a base-6 number the page adds up for you. Index Dice is the one that needs no arithmetic at all: a D6 you mark 0 0 1 1 2 2 plus three D10s in three different colours, read left to right as a four-digit number that is the word's index.
Throw the marked D6 and the hundreds D10 on their own first. If those two read 21 or higher, pick up just those two and throw them again — no word can start 21 or more, because the highest index is 2047. Then throw the tens and units and read all four digits. If the whole number still comes out 2048 or higher, throw all four again.
Starting with two dice is not a trick to make some result likelier; it is the same rejection done earlier and cheaper. Every index from 0 to 2047 stays exactly as likely as every other, and only about 2.5% of words have to be started over instead of 31.7%. It is safe only because the last two dice have not been thrown yet — you are throwing a fresh pair, not steering a result you have already seen. Once all four dice are on the table, never change just one of them to make the number fit: that makes some words 1.25 times likelier than others, and nothing on the paper would show it happened.
Throwing all four at once and rerolling on 2048 or higher is still perfectly correct, just slower. If that is how you made a phrase with an older copy of this file, it needs nothing done to it.
Yes. On the Index Dice card, “Walk me through it, one word at a time” opens a wizard that does the deciding for you. It draws the dice — the D6 you marked as a square, the three D10s as coloured kites — so you can match the picture on the screen to the die in your hand instead of working out which one “the hundreds die” means. You tap what each one landed on, the number appears both on the die and beneath it, and it gives you the word to write down. It knows which throws have to be repeated and which dice to pick up, so you never have to hold the 21-or-higher rule in your head, and it will not let you fix a bad number by rethrowing a single die — the mistake that quietly biases a phrase.
It shows one word at a time and clears it once you say you have written it down, so the phrase is never on the screen all at once. The words are typed into the boxes in section 2 as you go, which means when the rolling is done you press Calculate for the final word without retyping anything — and check what is in those boxes against your paper before you do, because a word copied down wrong is the one mistake dice cannot catch. Either throwing style works in it: the two-dice-first method it recommends, or all four at once if that is what you are used to.
It is the Index Dice box — the same four dice and the same numbers, renamed in v2.1.0. "Decimal" described the notation; "index" describes what you actually get. The one thing worth re-reading on an older sheet is the throw: from v2.1.0 the marked D6 and the hundreds D10 go first, on their own. A sheet that tells you to throw all four at once is not wrong, only slower.
No, and the arithmetic is worth following because it is the difference between a backup you own and one you have been handed. Your rolled words fix all but a few bits of the entropy. The checksum then rules out every word that cannot legally finish the phrase — for a 24-word phrase that leaves 8 candidates, for a 12-word phrase 128. The tool lists them. It does not pick one.
Which of them becomes yours is the last few bits of randomness, and they have to come from you: roll for the row number, do not choose the word that reads nicely. Choosing by eye throws away the last of your entropy at the very last step.
There is no arithmetic to do for it. Flip a coin once per leftover bit — seven times for a 12-word phrase, three for a 24-word one — heads = 1, tails = 0, in the order you flipped, and that binary number is the row. It is the same number as the Binary column beside each candidate. No coin in the house? Any die with an even number of faces is one: split its faces down the middle, so on a d6 1, 2, 3 = 0 and 4, 5, 6 = 1, or read odd = 1 and even = 0. Both splits are exactly even, and nothing on this route is ever discarded — every result is a row. Tap the flips into the box under the card and it names the row and the word; if you would rather read a decimal number off d10s it takes that too, and tells you when a throw has to be binned.
The final word's own bits are not random at all: they are the checksum, computed from everything before them, and they could not have been anything else. That is what makes the phrase restorable by a wallet that has never heard of this file — given the same rolled words and the same row, any correct BIP-39 implementation produces the identical phrase. Nothing here was invented; it was worked out. The finished phrase shows you that breakdown, bit for bit, and the entropy explainer shows the whole accounting.
It cannot, and neither can any other web page. There is no way for a page in a browser to block a screen capture, a photograph of your monitor, or a recording that was already running — so nothing here pretends to, because a reader who believes they are protected is worse off than one who knows they are not.
What it does instead: the finished phrase is not put on the screen until you ask for it, so it cannot be caught by a screen share, a recording, or somebody glancing over at the wrong moment; there is a Hide it again button that takes the words back out of the page rather than merely covering them; and the warning beside it names screenshots first rather than burying them in a list. Write the words on paper, by hand. A screenshot goes to your photo library, your cloud backup, your messaging app's cache and your phone's recently-deleted folder, and it will outlive your memory of taking it.
Yes — that is verify mode. Enter all 12 or 24 words and it tells you whether the checksum is valid, and if not, which word is the problem.
Often, yes. The missing-word recovery takes the words you do have, with a gap anywhere in the phrase, and lists every word that produces a valid phrase in that position. For a 12-word phrase expect a handful of candidates; you then need another way to tell which is yours, usually by restoring each in a wallet and looking at the addresses. Two gaps also work, provided you can read a few letters of at least one of them.
This is a different problem from a lost word, and a better one to have — the letters you can make out are information, and you should not throw them away by treating the word as missing. Faded ink, poor handwriting, a water-damaged card and a badly struck steel plate all land here.
First: type the characters you can read into the word box. The suggestion list narrows as you type. In English, bra leaves five possible words and brav leaves exactly one.
How many characters is enough? Every word in a list is uniquely identified by a short prefix, but how short depends on the language — the widely repeated rule that "the first four letters are always enough" is false for four of the ten official lists. These figures are computed from the lists embedded in this file:
So in Spanish, ámba is not enough — ámbar and ámbito both start that way. In French you need six characters before the word is certain.
If you cannot make out even that many characters, treat the word as missing, list the candidates, and then narrow them by eye using whatever letters you can see.
If you are torn between two similar words and you have the rest of the phrase, verify mode will often decide it for you: enter each candidate and see which one passes. But know the limit — the checksum is only 4 bits on a 12-word phrase, so roughly one wrong candidate in 16 passes by chance (one in 256 for 24 words). If more than one candidate passes, the checksum cannot tell them apart and this file can take you no further; the only way left is to restore each in a wallet and compare addresses.
Two unreadable words can now be solved, but only if you can read a little of at least one of them. Leave two boxes blank in recovery mode and type whatever letters you can make out for each. Three characters from each is usually enough to leave a single answer.
With nothing readable from either word, it is not solvable and the tool refuses rather than pretending: 2048 × 2048 is over four million combinations, and on a 12-word phrase roughly a quarter of a million of them would pass the checksum. That is not an answer, it is a haystack. Three or more unreadable words is worse again and is not attempted.
That the checksum does not match, so at least one word is wrong or the order is. The tool does three things rather than leaving you with "invalid":
A valid checksum is not proof the phrase is yours — only that it is well-formed.
Then the words are probably in the wrong order, and the usual cause is a grid. Wallets display a phrase in columns — 2 × 6, 3 × 4, 4 × 6 — and it is very easy to copy the words down the columns when the wallet meant them read across the rows, or the reverse. Every word is then correct and only the sequence is wrong, which looks identical to a corrupted phrase.
When verification fails, this tool re-reads your words as each standard grid shape and checks those orders too. If one passes, it tells you which grid and which direction, and prints the phrase in the correct order. Nothing was lost — it was a transcription error, not a damaged backup.
They flag patterns a human would notice in words you entered — repeats, runs, obvious sequences. They are a sanity check on obviously weak input, not a measure of randomness. Entropy that looks fine to them can still be poor if the source was poor, which is why the dice method matters more than the hint does.
The page opens in its simple view, which folds away four technical tools: the entropy ↔ phrase converter, the five-dice base-6 calculator, the full 2048-word list, and the inactivity safeguard. Nothing is removed and nothing is disabled — each one still shows its heading and a line saying what it is, with a Show button beside it, and the bar near the top of the tool has a single button that unfolds all four at once.
It resets to the simple view every time the file opens. That is deliberate: the only thing this file remembers about you is whether you chose light or dark, and a view preference is not worth weakening that for. Nothing that matters to safety is ever folded away — the warnings, the checklist, the load-time self-test, the file-integrity and tamper-check panels, the status bar and the disclaimer are on the page in both views, by design and with tests that say so.
Yes, and the print sheet never contains your words — only the checklist and the dice guide. It exists so you can work from paper while the machine is offline. Write the phrase itself by hand.
There is also a two-page Index Dice worksheet, from the button on that card. It opens in its own window and carries its own Print button: page one is how to throw, page two is the die slots and a grid to write up to 23 indexes into. It is part of this file rather than a download, so nothing is fetched and nothing leaves the machine — if you want a PDF, choose Save as PDF in your browser's print dialog.
The master delete button empties every field, across both modes and every language, and then verifies they are empty. An idle timer does the same if you walk away. Honestly stated: that clears the fields this page controls, and it cannot scrub every copy your browser or operating system may have made in memory or swap. Closing the browser and, if it truly matters, restarting the machine is the reliable end of a session.
Nothing but your light/dark preference. No cookies, no trackers, no counters, no server logs, nothing in local storage. Your words are never written anywhere by this file.
You should not, and the file does not ask you to. Every reassuring sentence on the page is a sentence a tampered copy would also carry, so the useful question is not whether to believe it but what you can check. The panel headed Why should I trust this?, just under the self-test banner on the main page, opens a window listing seven checks: the hash comparison below, making an unrelated program reproduce the arithmetic from a single command, the self-test the file ran when it opened, your browser's own confirmation that nothing was fetched, the ten word lists rehashed against their official values, reading the code, and knowing which version you hold. Each one is printed with what it proves and what it leaves open, and the window ends with the thing none of them prove — that the computer you are running it on is clean.
Compute its SHA-256 and compare it against the hash published at bip39toolbox.com/hash — deliberately a different page from the download, so replacing the file would not be enough to fool the check. The panel on the main page walks through the commands for each operating system. This matters most when the file reached you from someone else.
Your version is stated at the top of this page, and the full history with every release's changes and hash is in section F below. The Version panel on the main page says the same thing. To find out whether it is the latest, compare it against bip39toolbox.com/versions. This file never checks for updates by itself — it makes no network requests at all — so the comparison is yours to make, ideally while you are still connected.
Yes, and you are encouraged to: it is one file, no build step, no dependencies, no minification. The code viewer shows it to you as inert text. Reading it is worth doing, but reading it is not a hash check — you are reading what the page says it is, and only the hash tells you the bytes on disk match what was published.
That the checksum implementation in the copy you are running still reproduces the official BIP-39 reference vectors, and that its SHA-256 agrees with your browser's own. If it fails, the tool locks itself. What it does not prove is that the file is unmodified — working math and honest math are different things, and only the published hash speaks to the second.
Because BIP-39 defines exactly ten official lists, and those ten are embedded here. There is no official German list. A phrase built against a list that is not official is restorable by no wallet — which makes it not a backup but a loss with extra steps. English is always the default when the file opens.
This file does not say, and will not. It has no affiliations and nothing to sell. Choice of wallet is a question for sources that will still be accountable to you afterwards.
Not a question this file answers. It says nothing about prices, taxes, timing, or whether any of this is a good idea. It converts words to checksums and back, and that is the entirety of its opinion.
No. It derives no keys, no addresses, and no balances, and it cannot see any wallet. If your phrase is genuinely lost rather than partly unreadable, this tool cannot help and neither can anyone else who is honest with you.
No. The specification is the authority and is linked on the main page, alongside the official word list sources. This file also carries a full disclaimer: it is provided as-is, with no warranty and no liability, and results should be verified independently before anything of real value depends on them.
Write to suggestions@bip39toolbox.com. Corrections, unclear wording, and anything that behaves wrongly in your browser are genuinely welcome — this tool has been improved by exactly that kind of message.
Two practical notes. You are meant to be reading this with the network off, so writing is something to do afterwards, from a connected machine. And this file may outlive the address: it is one file that keeps working for years, wherever it was copied to. If mail to it bounces, check bip39toolbox.com for the current address rather than assuming the project is gone.
Never send a seed phrase, part of one, or any wallet detail — not to that address, not to anyone, ever. Nobody who legitimately helps you will ever need those words.
Nobody from this site will ever email you first, or ever ask you for your phrase. The one exception is narrow and worth knowing so it cannot be used against you: if you write in, you may get a direct reply to your own message. Nothing else. Any mail you did not start, and any mail asking you to "verify", "confirm" or "restore" a wallet, is a fraud, no matter what the sender address appears to say.
There is no support desk. One person, no staffing, no guaranteed reply — silence is the normal outcome and means nothing went wrong. If something here is wrong, the source is readable and the specification is public — those are the two authorities, and they outrank this page.
Every release of this file, newest first, with what changed and the SHA-256 that identifies it. This list is part of the copy you are holding, so it cannot know about anything released after it — the complete list is always at bip39toolbox.com/versions.
This section is last on purpose: it only ever gets longer, and pushing everything else further down the page to make room for it would be the wrong trade.
BIP-39 has 2,048 words. Four dice give you a four-digit number, and that number is the word — no adding, no multiplying, no table. Because the first index is 0000, the highest valid one is 2047, not 2048. Type the number straight into the word boxes, or into the Index Dice box on the page.
1× D6, re-labelled two faces 0, two faces 1, two faces 2 — two per value, never three and three. The value is what you write down, never the original face.
3× D10 in three different colours, read 10 as 0. Decide which colour is hundreds, which is tens and which is units before the first throw and keep it for the whole phrase — identical dice leave you choosing the order after they land, and a die read in the wrong place is a different word.
Same result as throwing all four — but only 2.5% of words have to be started over instead of 31.7%, and you throw 15% fewer dice.
Discarding everything from 2048 up is what makes every valid index equally likely. It is not the method going wrong — it is the method.
Once all four dice are on the table, never change just one of them to make the number fit.
Rerolling only the units die when you get 2100 looks harmless and is not: it makes some words 1.25× likelier than others, and 2.3× if you reroll the tens die too when the units die cannot save it. It is quiet: nothing on the paper shows it happened. There are exactly two legal rerolls — the first two dice before the other two are thrown (step 2), and all four together (step 4).
| Example | Roll 1 · D6 | Roll 2 · D10 | Roll 3 · D10 | Roll 4 · D10 | Read left to right |
|---|---|---|---|---|---|
| Caught early first two read 23 |
2 | 3 | ? | ? | 23…✗ throw those two again |
| Good first two read 14 |
1 | 4 | 7 | 2 | 1472✓ valid index |
| Bin it first two read 20, still too high |
2 | 0 | 6 | 1 | 2061✗ over 2047 — all four again |
Throw Rolls 1 and 2 first — 21 or higher, throw those two again. Then throw Rolls 3 and 4 and read all four left to right. That four-digit number is the word's index.
| D6 0,1,2 | D10 | D10 | D10 |
| ROLL 1 | ROLL 2 | ROLL 3 | ROLL 4 |
| THROW THESE TWO FIRST | 21+ → THROW BOTH AGAIN | THEN THESE TWO | |
| THOUSANDS | HUNDREDS | TENS | UNITS |
| 0 1 2 | 0 – 9 | 0 – 9 | 0 – 9 |
| value, not the face | read 10 as 0 | read 10 as 0 | read 10 as 0 |
Rolls 1–2 read 21+ → throw those two again. All four read 2048+ → throw all four again.
Never trim a high number to fit, and never change a single die once all four are down — that biases the phrase, silently. With the two-dice start, only about 2.5% of words have to start over.
| PLACE DIE HERE | PLACE DIE HERE | PLACE DIE HERE | PLACE DIE HERE |
| Roll 1 — thousands · first | Roll 2 — hundreds · first · colour ______ | Roll 3 — tens · colour ______ | Roll 4 — units · colour ______ |
—not rolled. The last word of any phrase is never rolled — it carries the checksum and the calculator works it out from the others.
Index Dice was called Decimal dice up to v2.0.0; an older sheet pointing at a "Decimal dice box" means this one. Keep this sheet offline and destroy it after use.
This file never checks for updates by itself — it makes no network requests
at all, which is the whole point of it. To find out whether a newer version exists, open
bip39toolbox.com/versions and compare it against the version
number above. Do that while this machine is still connected, before you disconnect
it to work on a real wallet: once it is offline the button cannot reach the page, and the
address is written out above so you can check it from a phone instead.