Every release of bip39_checksum_calculator.html, newest first.
Current version
v2.1.1
Which version do you have? Two ways to tell, neither of which needs the file to
contact anything:
Open your copy and read the Version panel — it sits just above the
safety checklist and states the version and its date.
Or compute your file's SHA-256 and find it in the list below. Every release is
listed with its hash, so the hash identifies the version exactly.
v2.1.1 current
Released 2026-08-22 · 666,986 bytes
A search-engine fix with no effect on how the tool works. The printable working sheet's title was the first top-level heading in the file, so a search engine reading the page met "BIP-39 Seed Phrase -- Offline Working Sheet" before the name of the tool itself. It is now a second-level heading in the document outline while keeping exactly the same size and spacing when you print it, so the printed sheet is unchanged.
Nothing else in this release: no wording, no arithmetic, no dice, no checklist. If you are holding v2.1.0 there is no reason to replace it, and a phrase made with it needs nothing done to it.
The instructions for the final word's row number have been rewritten, and there is now a calculator for them. Those last few bits -- seven for a 12-word phrase, three for a 24-word one -- were the one part of the job the file still asked you to do arithmetic for, at the very end, when you are most likely to give up and pick a row that looks nice.
Flip a coin once per bit and tap the flips in: heads, tails, in the order you flipped. The box names the row and the word it gives you. Nothing on that route is ever discarded, because every result of those flips is one of the rows -- and it is the same number as the Binary column beside each candidate word.
No coin in the house? Any die with an even number of faces is one. Split its faces down the middle -- on a d6, 1, 2, 3 = 0 and 4, 5, 6 = 1; on a d10, 1 to 5 = 0 and 6 to 10 = 1 -- or read odd as 1 and even as 0. Both splits are exactly even, so a d6 you already own does this without being marked and without anything to work out.
That replaces the old three-dice base-6 recipe for this step: (d1 x 36) + (d2 x 6) + d3, discarded above 128 about 41% of the time. It was correct and it was unbiased -- a row produced that way with any earlier copy of this file needs nothing done to it -- but the same d6 read as a coin gives the row with no multiplying, no adding and nothing discarded at all.
If you would rather read a decimal number off the d10s you already use for Index Dice, the calculator takes that too: a die per place, fixed before you throw, and the number you read off them is the row. It tells you the range and how often a throw has to be binned -- and where that rate is high, it says outright that the coin route bins nothing and is the better tool at that length.
Every refusal there carries the same sentence the rest of the tool does: an invalid roll is not a failed roll. Throwing the whole thing away when it lands above the last row is what makes every row exactly as likely as every other.
The printed sheet now covers all five phrase lengths for this step instead of just 12 and 24, with the leftover bits and the row range for each, and the same two methods.
Every time the tool refuses a roll it now says why that is not a failure: an invalid roll is not a failed roll, and throwing away everything from 2048 up is what makes every valid BIP-39 index equally likely. That is the mathematical reason this method stays unbiased -- discarding is not the price of it, it is the method.
It appears on every refusal rather than in the prose somewhere: the first pair over 20, a four-digit throw over 2047, the five-dice discard at whichever cutoff you have chosen, both of the wizard's rerolls, and the rerolls the practice run deliberately walks you through. A red cross reads as "you did something wrong", and a reader who feels they failed is the one who quietly nudges a die instead of binning the throw -- which is the single move that actually biases a phrase.
It is also stated as the principle rather than only as reassurance: at the head of the entropy explanation, on the Index Dice card, and on the printed worksheet, which is the copy you actually have in front of you while you are throwing.
Your finished phrase is no longer put on the screen the moment you pick a row. It is held back behind a Show my phrase button, so it cannot be caught by a screen share you forgot about, a recording already running, or somebody glancing over at the wrong moment -- and Hide it again takes the words back out of the page rather than just covering them.
The warning above it is now a warning rather than a small grey line. It names screenshots first, says what is at stake in one sentence, and covers the things a checklist tick does not: photographing the screen, pasting it somewhere, reading it aloud, and being on a call or recording while you reveal it.
It also says plainly what it cannot do. No web page can block a screenshot, a photo of your monitor, or a recording that was already going, so this one does not pretend to -- there is no fake protection here, because believing you are protected is worse than knowing you are not. What a screenshot actually costs is spelled out instead: your photo library, your cloud backup, your messaging app's cache, and your phone's recently-deleted folder.
New: the finished phrase now shows where every bit of it came from. For a 24-word phrase that is 253 bits from the words you rolled, 3 from the row you chose, and 8 checksum bits that are not entropy at all but arithmetic, and could not have been anything else. It ends with the sentence that answers the question people are really asking: this tool chose none of it.
Section 3 says the same thing where you actually decide it, before the list of candidate words rather than after: this tool has not chosen a word for you. It lists every word that can legally finish the phrase -- 8 of them for 24 words, 128 for 12 -- and which one becomes yours is the last few bits of randomness, which have to come from you.
Two new help answers cover both questions directly: what happens after the last word you roll and whether the tool created your phrase, and whether it will stop you screenshotting it.
The page now opens in a simple view. Four technical tools are folded away -- the entropy converter, the five-dice base-6 calculator, the full 2048-word list, and the inactivity safeguard -- so a first-time reader reaches the guided wizard without scrolling past machinery they do not need in order to make a phrase correctly.
Nothing is removed and nothing is disabled. Each folded tool still shows its heading and a line saying what it is, with a Show button beside it, and one button near the top of the tool unfolds all four at once. An expert who wants the word list and nothing else can open just that.
Nothing that matters to safety is ever folded. The warnings, the checklist, the load-time self-test, the file-integrity and tamper-check panels, the status bar, the version panel and the disclaimer are all on the page in both views -- as is the wizard itself, which is the simple path rather than an advanced one. Both test suites carry that list and fail if anything on it becomes foldable.
It resets to the simple view every time the file opens, on purpose: the only thing this file remembers about you is whether you chose light or dark, and a view preference is not worth weakening that for.
New: a security status bar pinned to the top of the screen at all times. It says one of three things -- ONLINE, DO NOT ENTER YOUR SEED in red; NO CONNECTION DETECTED, NOT CONFIRMED in amber; or OFFLINE, SAFE TO ENTER YOUR SEED in green -- and it updates the moment your connection changes, which is the case it is really for: a network that comes back while you are at word 17 and looking at the word grid.
It will not claim you are safe on the browser's word alone. A browser can only see whether a network interface is up, not whether anything is reachable, so "no connection detected" is amber and says outright that it is not proof. The green only appears once you have confirmed it yourself by ticking the first box of the checklist -- and even then it says so, because that assurance comes from you, not from anything this file can measure.
If the connection comes back mid-session the bar turns red immediately and a separate warning appears. Nothing you have entered is cleared: an "online" event can fire spuriously, and wiping a half-transcribed phrase over a false alarm would do more harm than the warning prevents. The warning says so, so you are not left wondering.
New: the wizard shows how much entropy you have actually collected -- "66 of 256 bits" -- counted from the words on your paper, at exactly 11 bits per word, because the list holds 2048 words and 2048 is 2 to the 11th.
And a full explanation of why the result is unbiased, opened from that line or from the Index Dice card. It counts the four dice out: 3 x 10 x 10 x 10 = 3000 equally likely throws, 2048 of them kept and each by exactly one route, so every word lands at exactly 1 in 2048 -- not approximately. It does the same for the split throw, shows what re-throwing a single die or clamping a high roll actually costs (1.25x, 2.3x, 28x, and ten words that could never appear at all), and ends on the thing none of it can check: whether your own dice are fair. This file receives numbers, never throws.
New: a practice run. "Never done this before? Try a practice run" sits on the safety checklist and needs nothing ticked -- practising is what you do before you are ready to commit. It clicks through making four words with four dice: the throws, the two rerolls that are legal, the word that comes out, and an index with leading zeros, which is the one that looks wrong and is not.
It is the only part of this tool that works on the website, and it works there because there is nothing to type into it. The throws are written into the page -- the same numbers and the same four words for every reader -- so there is nothing a server could see. Labelled PRACTICE, DO NOT USE FOR FUNDS at the top of the screen, pinned there so it cannot be scrolled past.
It looks like the real wizard on purpose: the same dice pictures, the same VALID and RE-ROLL badges, the same words. It ends on the four things that are different when it is real -- your own dice, the network off, one word on screen at a time, and a last word that is computed rather than thrown -- and says outright that the example words are worthless.
The printable dice kit is now a download on the homepage. Two pages: how to throw, and a slot per die with a 23-row grid to write your indexes into. It is a small HTML page rather than a PDF, so there is nothing to install, you can read every line of it, and your print dialog will save it as a PDF if you want one.
That sheet is generated from the same template the in-file worksheet uses, so the copy in your drawer and the copy on the screen cannot drift apart, and publishing refuses to go ahead if it does not come out as exactly two pages with its roll grid and its one unbreakable rule intact.
Every dice calculator now tells you whether the roll is usable before it tells you anything else: a green VALID with the number, or a red RE-ROLL with the number and the limit it broke -- "2050 - above 2047". The explanation is still there, underneath, where it is worth reading second.
The same words everywhere. The Index Dice boxes, the five-dice boxes and the wizard used to phrase the same verdict three different ways, one of them opening with "Index 1847" -- which is not the question anyone is asking with four dice in their hand.
One exception, deliberately: when the first two dice of a split throw come in at 20 or less, that reads IN RANGE rather than VALID. It is two digits of four, not a word, and the wizard says so -- telling you a roll is valid when you are halfway through it would be telling you that you have something you have not got.
The wizard now says how far through the phrase you are: "Word 7 of 23 - 26% done, 6 of 23 written down, 17 to go", with a bar. The percentage counts the words you have actually written on paper, not the one you are throwing, which is why word 7 of 23 reads 26% and not 30% -- six words are done at that point, and rounding it up would overstate the job by a whole word.
The wizard draws the dice. The D6 you marked is a square, the three D10s are kites in their three colours, and each one shows the number you tapped -- with the same number repeated underneath, which is the one you copy onto paper. Matching a picture on the screen to a die in your hand replaces working out which one "the hundreds die" means, and sorting four dice into the right places is where this method actually goes wrong.
The setup screen now pictures all four dice before you throw anything, with what each is for underneath, so you can lay them out in front of you and check you have the right ones.
The pictures make the two-stage throw visible rather than only described: while you are throwing the first pair the other two dice are drawn faded with a question mark, and once the pair is settled it dims and the tens and units light up. They are inline drawings, not images -- nothing is downloaded, and they re-colour with the light and dark themes.
New: a guided Index Dice wizard. "Walk me through it, one word at a time" on the Index Dice card opens one screen per word -- it names the dice to throw, you tap what each one landed on, and it gives you the word to write down. No arithmetic, no worksheet to read first, and nothing to hold in your head.
It shows one word at a time and clears it the moment you say you have written it down, so your phrase is never on the screen all at once. The words are typed into the boxes in section 2 as you go, so when the rolling is finished you press Calculate for the final word without retyping a thing -- check the boxes against your paper first, because a word copied down wrong is the one mistake dice cannot catch.
The wizard enforces the parts of the method that are easy to get wrong. It throws the marked D6 and the hundreds D10 on their own first, tells you to pick up exactly those two when they read 21 or higher, and will not offer to rethrow a single die to bring a number down -- the move that quietly makes some words likelier than others. On the rare throw that has to be binned outright it says so and names all four.
You can also tell it to throw all four dice at once, which is what this file taught before v2.1.0. It is equally correct and equally unbiased, just slower: about 31.7% of throws go in the bin instead of 2.5%. The recommended two-dice-first method is the default.
You tap the numbers rather than typing them, so the marked D6 offers only 0, 1 and 2 -- the value written on the face, never the original face number -- and each D10 offers 0 to 9 with a separate button for a die showing 10. The old confusion between the die's face and its value is not something the wizard can let you have.
The Master delete button and the inactivity timer both clear the wizard along with everything else, and the three D10 places are named in text as well as coloured, so a reader who cannot tell red from green can still keep them apart.
New: a panel headed "Why should I trust this?" sits under the self-test banner, and its button opens a window collecting every check you can actually run on this file. It answers the question the way the file has always meant to -- you should not trust it, you should check it -- and then hands you the checks.
Seven of them, in order of strength rather than convenience: compare its hash against the value published on a different page of the site; make an unrelated program reproduce its arithmetic; read the self-test it ran when it opened; have your own browser confirm it fetched nothing; rehash all ten word lists against their official values; read the code; and know which version you are holding.
Check 2 is the new one, and it needs nothing installed. Two shell commands hash a block of zero bytes, and the first digit of the answer IS the last word of the all-zeroes phrase -- so "eleven abandons can only be finished by about" becomes something you confirm in five seconds with software that has never heard of this tool. The full reasoning is spelled out, along with the reference implementation and Ian Coleman's tool for anyone who wants a whole second program, and the warning that a cross-check is done with throwaway words and never with your real phrase.
Every check in the window prints what it proves AND what it leaves open, and the window closes on the thing none of them prove: that the computer you are running it on is clean. A page listing only reassurances would read exactly the same whoever had written it, which is the reason for the format.
The numbers in that window are read off the live page as it opens rather than written into it -- the self-test's own words, the page hash, your browser's own list of what it loaded (zero), the word-list hashes recomputed on the spot. If a copy has been altered so that any of them is no longer true, the window says so instead of reassuring you.
Also new there: all ten embedded word lists are now rehashed in the page and shown against their official published values, so a single reordered or dropped word is visible. A word's position in the list is its number, so that is a mistake every other check would miss.
A new help answer covers the same ground for anyone who arrives through the Help window instead, and the feature strip and the website both describe it.
The decimal dice method is now called Index Dice. The old name described the notation; the new one describes what you get, which is the word's index itself. If you are holding a printed sheet that points at a "Decimal dice box", that is this box.
Index Dice now teaches a two-stage throw, and it is the method rather than a footnote: throw the marked D6 and the hundreds D10 on their own first, and if those two read 21 or higher throw just those two again. Only then throw the tens and units. Every index stays exactly as likely as every other -- the arithmetic for that is enumerated in the test suite, not argued -- and only about 2.5% of words have to be started over instead of 31.7%, for about 15% fewer dice thrown.
Throwing all four dice at once and rerolling on 2048 or higher is still described and still correct. It is the slower path, not the wrong one, so a phrase generated that way with any earlier copy of this file needs nothing done to it.
The dice box now judges the first two dice as soon as you have entered them, and names the two dice to throw again -- before you throw the other two, which is the only moment that advice is worth anything.
A new two-page worksheet for Index Dice opens from a button on that card and has its own Print button. Page one teaches the throw, page two is the die slots and a 23-row grid to write indexes into. It is markup inside this file rather than a PDF: nothing is downloaded and nothing is fetched, and your browser's print dialog will save it as a PDF if you want one.
The printed sheet's Method C and the on-screen card now carry the same rule in the same words, including the one sentence the old wording was missing: the two-dice reroll is legal only because the other two dice have not been thrown yet, and once all four are down, changing one of them to make the number fit biases the phrase.
The Help window covers all of this: how to throw Index Dice and why it starts with two dice, where the "Decimal dice" box on an older printed sheet went, and where the worksheet is. It also states how many answers it holds as a number the tests count rather than a phrase nobody rechecks -- it had been claiming twenty-six while carrying twenty-nine.
The four entropy methods are laid out with coin flips and the five-dice rule down the left and Index Dice, now the longest of them, in a column of its own.
The decimal dice method now uses a d6 you mark yourself -- two faces 0, two faces 1, two faces 2 -- instead of reading an unmarked die through a 1,2=0 3,4=1 5,6=2 table. Nothing is looked up or worked out any more: you throw four dice and read the index off them.
BREAKING: the d6 box in that calculator now takes the value 0, 1 or 2, not the face 1 to 6. If you are used to typing the face, 3 and up are now refused outright -- but 1 and 2 are valid values as well as faces, so check what you are entering. No pen? The old mapping is still printed beside the box; convert once and enter the 0, 1 or 2.
The three d10s are thrown together and placed in order rather than one die rolled three times, so the dice sit in front of you spelling out the index. Use three different colours and fix which colour is hundreds, tens and units before you throw -- three identical dice leave you choosing the digit order after you can already see the digits.
The printed sheet now carries the decimal method as Method C, with a slot for each die, a shortcut for the throws that cannot possibly land in range, and a pointer back to the on-screen dice box for anyone who would rather type the four numbers than work on paper.
The contact rules no longer contradict themselves. They said nobody from this site will ever email you, and also that there is no guaranteed reply -- but a reply is an email. It now says nobody will ever email you FIRST, names the one exception (a direct reply to a message you sent), and says silence is the normal outcome rather than a sign something went wrong.
The printed sheet's roll tally is now a grid: 23 numbered rows against all five phrase lengths, with the rows you must not roll struck out, because the last word of a phrase always comes from the calculator.
Every feature now has a real description rather than a one-line label: what it does, and what mistake it catches. Both the list inside the file and the one on the website.
The website's feature list was still describing the original release -- it now covers all five phrase lengths, the wrong-order detection, two-word recovery and the built-in help.
All five BIP-39 phrase lengths are now supported: 12, 15, 18, 21 and 24 words. Previously only 12 and 24 worked, so an 18-word phrase could not be checked at all.
Verify mode now tries every pair of words swapped, not just neighbouring ones -- so 'I swapped words 3 and 9' is now reported instead of just 'invalid'.
New: detects grid transcription errors. If your wallet showed the phrase in columns and you copied it down instead of across, every word is right and only the order is wrong -- the tool now spots that and prints the correct order.
Recovery now solves TWO unreadable words, not just one, provided you can read a few letters of at least one of them.
Corrected two things the help used to say: that only 12 and 24 words were supported, and that two unreadable words could not be solved.
Contact now has its own section in the Help contents, and sits above the version history instead of below it -- the history only ever gets longer, and it was pushing Contact toward the bottom of the page.
The suggestions address is now printed in the Help window itself, so you can find it while working offline instead of having to go back to the website.
Help notes that this file may outlive the address: if mail bounces, check bip39toolbox.com for the current one rather than assuming the project has gone.
Added an address for suggestions and bug reports, on the website: corrections, unclear wording and browser problems are welcome.
Never send a seed phrase, or any part of one, to that address or to anyone else. Anything resembling a phrase is deleted unread.
Nobody from this site will ever email you or ask for your phrase. Any message claiming otherwise is a fraud, whatever the sender address appears to say.
The domain now publishes SPF and DMARC records so forged mail pretending to come from bip39toolbox.com is rejected before it reaches anyone.
Added a Help button fixed in the top-right corner, beside the light/dark toggle, so help is one click away from any scroll position instead of only from the panel above the checklist.
Both help buttons open exactly the same answers -- there is no second copy of the text to fall out of step.
The button is absent from the printed sheet and present on the website, both without special-casing.
Added an offline Help section: 26 questions and answers covering what a seed phrase is, how to use every part of this tool, how to check you can trust the file, and what this file deliberately will not tell you.
Added a full answer for the case where you cannot READ one of your words, as distinct from having lost one -- including the shortest prefix that identifies a word uniquely in each of the ten official lists.
That prefix is NOT four characters in every language: it is 5 in Spanish, Japanese and Korean, 6 in French, and 1 in both Chinese lists. The widely repeated 'first four letters are always enough' rule is wrong for four of the ten lists.
The help works with the network off, like the rest of the file, and is searchable with your browser's own find.
The file never checks for updates by itself. It makes no network requests at all
— that is the property that makes it safe to type a real seed phrase into, and an
update check would cost exactly that. So the comparison is yours to make, on this page,
whenever you choose. Nothing expires and nothing stops working: an old copy keeps
calculating correctly, it just will not have whatever was added later.
Do this before you disconnect the machine to work on a real wallet. Once it is
offline it cannot reach this page — which is the point.