Create a new BIP39 recovery phrase by drawing paper slips from a hat.

Mix the complete BIP39 vocabulary in a real hat, privately draw 11 or 23 folded slips with replacement, then complete the checksum and prove recovery before funds are deposited. The instructions, print files, checksums, and generator source are available freely.
Before you begin
This procedure creates a new wallet backup. It is not a method for inspecting, repairing, or transforming an existing live recovery phrase.
- You have a private, camera-free workspace.
- You can verify a complete, uniform 2,048-word English BIP39 set.
- You have a trusted offline device for checksum completion and recovery testing.
- You understand that anyone who obtains the completed phrase can control the wallet.
- You will not deposit meaningful funds until the wallet has been successfully recovery-tested.
What can fail
No physical method is secure by appearance alone. Each failure mode needs an explicit control.
| Failure mode | Required control |
|---|---|
| Biased or altered materials | Count all 2,048 unique words. Reject missing, duplicated, marked, damaged, or detectably different slips. |
| Observation during generation | Work alone in a camera-free room. Remove connected devices before any word is exposed. |
| Transcription or order error | Number every position, compare both paper copies, and verify spelling against the official list. |
| Compromised completion device | Use a documented offline path, verify firmware and instructions, and cross-check when practical. |
| Wrong recovered wallet | Reproduce the expected fingerprint or receive address and complete a small-value test before funding. |
| Correlated backup failure | Use separate physical locations and move at least one copy to durable storage. |
The complete workflow
Generation is only one part of the process. Verification and recovery testing are funding gates.

- 01
Define the wallet and threat model
Choose the wallet type, script policy, passphrase policy, and devices before generating anything.
- 02
Verify materials and devices
Inspect the complete word set and prepare a trusted offline device for checksum completion.
- 03
Prepare a private workspace
Remove cameras and connected electronics. Use a clean opaque container large enough to mix thoroughly.
- 04
Draw, record, replace, remix
Complete 11 cycles for a 12-word phrase or 23 cycles for a 24-word phrase.
- 05
Complete the final word offline
Apply the HAT39 lowest-index convention using a documented compatible path.
- 06
Record a verification reference
Record the wallet master fingerprint where available, or a known receive address and its exact configuration.
- 07
Prove recovery before funding
Recover in a controlled process, compare the reference, and complete a small-value transaction before moving meaningful funds.
- Draw
Select one folded slip without looking inside the container.
- Record
Write the word in the next numbered position on your private worksheet.
- Replace
Return the same slip to the container before the next selection.
- Remix
Mix thoroughly to approximate uniform selection on the next draw.
The randomness comes from the private draws
The figures below are structural capacities under ideal conditions. They assume complete untampered materials, equal detectability, thorough mixing, replacement, uniform selection, and independent draws.
| Procedure | Capacity | Assessment |
|---|---|---|
| 11 independent draws | 121 bits | Return and thoroughly remix after every draw. |
| 23 independent draws | 253 bits | The HAT39 first-valid ending adds no entropy. |
| 12 known words, order only | up to ~24.8 bits | Maximum with all words distinct, after checksum filtering. Repeats reduce it. Unsafe. |
| 24 known words, order only | up to ~71 bits | Maximum with all words distinct, after checksum filtering. Repeats reduce it. Below the intended level. |
Standard 12- and 24-word BIP39 constructions normally begin with 128 or 256 entropy bits. HAT39 deliberately fixes the remaining 7 or 3 entropy bits to zero, leaving 121 or 253 bits from the physical draws.
How the final word is completed
HAT39 chooses the checksum-valid ending with the lowest index in the official English BIP39 list. This is a HAT39 convention—not an extra BIP39 rule—and it adds no entropy.
12-word construction
Word positions 1–11 provide the known entropy.
24-word construction
Word positions 1–23 provide the known entropy.
Use a documented offline device path and cross-check the result when practical.
Verification before funding
A valid checksum does not prove correct spelling, order, derivation settings, passphrase, script policy, or wallet configuration.
- Complete the phrase on the intended trusted wallet or signer.
- Record its master fingerprint where supported, or a known first receive address with the exact wallet configuration.
- Perform the device’s built-in backup check or a controlled recovery on a dedicated device.
- Confirm the same fingerprint or receive address is reproduced.
- Complete a small-value receive and spend test before moving meaningful funds.
Do not fund the wallet and do not attempt to “repair” a phrase while funds are attached. Start again with a new phrase.
Paper is immediate storage, not necessarily durable storage
Keep independently verified copies in separate failure domains. Plan for fire, water, theft, fading, accidental disposal, inheritance, and periodic recovery-readiness checks.
- Never photograph, scan, email, message, or cloud-sync a phrase.
- Keep location and access instructions separate from the phrase where appropriate.
- Move at least one verified copy to a durable medium suited to your threat model.

Recommended generation method
Draw with replacement
- Draw one slip.
- Record the word by position.
- Replace the slip in the full set.
- Remix before drawing again.
- Repeated words
- Possible
- Draw distribution
- Independent when mixing and selection are uniform
- Remainder
- The complete vocabulary remains present
Temporary backup alternative
Tape slips without replacement
- Draw one slip.
- Set aside the selected slip.
- Stop after taping 11 or 23 entropy slips in order.
- Do not draw position 12 or 24.
- Calculate the final word separately and write it on a blank.
- Securely destroy the incomplete remainder.
- Repeated words
- Impossible
- Draw distribution
- Changes after every selection
- Remainder
- Missing vocabulary can identify selected words by subtraction
Documented final-word compatibility
Inclusion means a primary source documents local final-word calculation or checksum-valid selection. It is not a security endorsement or audit.
| Device or tool | 12 words | 24 words | HAT39 convention | Primary evidence |
|---|---|---|---|---|
| SeedSignerDIY signer | Yes | Yes | Native HAT39 first Tools → Calc final word → enter 11 or 23 words → choose Finalize with zeros. Method and offline postureOffers coin flips, word-selection entropy, or a deterministic Finalize with zeros path after 11 or 23 entries. Air-gapped Raspberry Pi Zero signer with no wireless hardware in the recommended build. | SeedSigner custody guide ↗Checked 2026-08-11 |
| COLDCARD Mk4 / QHardware wallet | Yes | Yes | Choose first manually Choose the candidate with the lowest official BIP39 index. Method and offline postureExposes every valid candidate after 11 or 23 entries; 12-word candidates are grouped by first letter. Can be operated without USB data; Q also supports QR and MicroSD workflows. | COLDCARD master-seed guide ↗Checked 2026-08-11 |
| KruxDIY signer | Yes | Yes | Choose first manually Manually choose the valid candidate with the lowest official list index. Method and offline postureRestricts the final-word keypad to valid candidates; leaving it blank selects a candidate randomly. Open-source signer firmware for standalone camera devices. | Krux mnemonic-generation guide ↗Checked 2026-08-11 |
| Passport CoreHardware wallet | Yes | Yes | Random final entropy Do not use Passport as the HAT39 final-word calculator. It can import a completed HAT39 phrase calculated elsewhere. Method and offline postureGenerate Final Word samples device noise and calculates one valid ending; retrying samples again. Designed for QR and microSD air-gapped operation. | Foundation Passport setup guide ↗Checked 2026-08-11 |
| Blockstream JadeHardware wallet | Yes | Yes | Choose first manually Do not accept the randomized default; choose the lowest-index valid candidate. Method and offline postureRestricts final-word entry to valid options; its starting keyboard letter and initial candidate are randomized. Jade Plus supports QR air-gap; other models can use a temporary signer workflow. | Blockstream final-word guide ↗Checked 2026-08-11 |
Print and inspect the materials yourself
The six-page unshifted word-slip set, two backup cards, SHA-256 files, and PDF generators are available without an order or account.

