Independent technical reference

Create a new BIP39 recovery phrase by drawing paper slips from a hat.

Overhead technical illustration of an upside-down felt hat with its interior head opening and sweatband visible, filled with folded slips as one slip is drawn
Figure 1 — One private physical draw from the hat’s interior head opening. Security depends on indistinguishable slips, thorough mixing, private selection, and replacement after every draw.

Mix the complete BIP39 vocabulary in a real hat, privately draw 11 or 23 folded slips with replacement, then complete the checksum and prove recovery before funds are deposited. The instructions, print files, checksums, and generator source are available freely.

Suitability gate

Before you begin

This procedure creates a new wallet backup. It is not a method for inspecting, repairing, or transforming an existing live recovery phrase.

  • You have a private, camera-free workspace.
  • You can verify a complete, uniform 2,048-word English BIP39 set.
  • You have a trusted offline device for checksum completion and recovery testing.
  • You understand that anyone who obtains the completed phrase can control the wallet.
  • You will not deposit meaningful funds until the wallet has been successfully recovery-tested.

Threat model

What can fail

No physical method is secure by appearance alone. Each failure mode needs an explicit control.

Failure modeRequired control
Biased or altered materialsCount all 2,048 unique words. Reject missing, duplicated, marked, damaged, or detectably different slips.
Observation during generationWork alone in a camera-free room. Remove connected devices before any word is exposed.
Transcription or order errorNumber every position, compare both paper copies, and verify spelling against the official list.
Compromised completion deviceUse a documented offline path, verify firmware and instructions, and cross-check when practical.
Wrong recovered walletReproduce the expected fingerprint or receive address and complete a small-value test before funding.
Correlated backup failureUse separate physical locations and move at least one copy to durable storage.

Operational sequence

The complete workflow

Generation is only one part of the process. Verification and recovery testing are funding gates.

Overhead technical illustration of an upside-down felt hat with its interior head opening visible while folded slips are mixed and one is drawn beside a numbered worksheet
Figure 2 — Mix, draw, record, replace, remix. Return the selected slip before every remix so all 2,048 outcomes remain possible on the next draw.
  1. 01

    Define the wallet and threat model

    Choose the wallet type, script policy, passphrase policy, and devices before generating anything.

  2. 02

    Verify materials and devices

    Inspect the complete word set and prepare a trusted offline device for checksum completion.

  3. 03

    Prepare a private workspace

    Remove cameras and connected electronics. Use a clean opaque container large enough to mix thoroughly.

  4. 04

    Draw, record, replace, remix

    Complete 11 cycles for a 12-word phrase or 23 cycles for a 24-word phrase.

  5. 05

    Complete the final word offline

    Apply the HAT39 lowest-index convention using a documented compatible path.

  6. 06

    Record a verification reference

    Record the wallet master fingerprint where available, or a known receive address and its exact configuration.

  7. 07

    Prove recovery before funding

    Recover in a controlled process, compare the reference, and complete a small-value transaction before moving meaningful funds.

  1. Draw

    Select one folded slip without looking inside the container.

  2. Record

    Write the word in the next numbered position on your private worksheet.

  3. Replace

    Return the same slip to the container before the next selection.

  4. Remix

    Mix thoroughly to approximate uniform selection on the next draw.

Repeat the complete cycle for every entropy word. Replacing the slip permits repeated words and allows independent draws under the stated uniform-selection assumptions.

Open the detailed procedure →

Entropy assumptions

The randomness comes from the private draws

The figures below are structural capacities under ideal conditions. They assume complete untampered materials, equal detectability, thorough mixing, replacement, uniform selection, and independent draws.

ProcedureCapacityAssessment
11 independent draws121 bitsReturn and thoroughly remix after every draw.
23 independent draws253 bitsThe HAT39 first-valid ending adds no entropy.
12 known words, order onlyup to ~24.8 bitsMaximum with all words distinct, after checksum filtering. Repeats reduce it. Unsafe.
24 known words, order onlyup to ~71 bitsMaximum with all words distinct, after checksum filtering. Repeats reduce it. Below the intended level.

Standard 12- and 24-word BIP39 constructions normally begin with 128 or 256 entropy bits. HAT39 deliberately fixes the remaining 7 or 3 entropy bits to zero, leaving 121 or 253 bits from the physical draws.

Deterministic completion

How the final word is completed

HAT39 chooses the checksum-valid ending with the lowest index in the official English BIP39 list. This is a HAT39 convention—not an extra BIP39 rule—and it adds no entropy.

12-word construction

Word positions 1–11 provide the known entropy.

24-word construction

Word positions 1–23 provide the known entropy.

The zero suffix selects the lowest-index checksum-valid final word. It adds no entropy: the 12-word method has 121 known entropy bits and the 24-word method has 253.
Never calculate a live final word on this website.

Use a documented offline device path and cross-check the result when practical.

Funding gate

Verification before funding

A valid checksum does not prove correct spelling, order, derivation settings, passphrase, script policy, or wallet configuration.

  1. Complete the phrase on the intended trusted wallet or signer.
  2. Record its master fingerprint where supported, or a known first receive address with the exact wallet configuration.
  3. Perform the device’s built-in backup check or a controlled recovery on a dedicated device.
  4. Confirm the same fingerprint or receive address is reproduced.
  5. Complete a small-value receive and spend test before moving meaningful funds.
If anything differs, stop.

Do not fund the wallet and do not attempt to “repair” a phrase while funds are attached. Start again with a new phrase.

Recovery readiness

Paper is immediate storage, not necessarily durable storage

Keep independently verified copies in separate failure domains. Plan for fire, water, theft, fading, accidental disposal, inheritance, and periodic recovery-readiness checks.

  • Never photograph, scan, email, message, or cloud-sync a phrase.
  • Keep location and access instructions separate from the phrase where appropriate.
  • Move at least one verified copy to a durable medium suited to your threat model.
Technical line illustration of a blank numbered paper backup beside generic durable metal backup material
Illustration only. Select durable media and storage locations according to your own threat model.

Temporary backup alternative

Tape slips without replacement

  1. Draw one slip.
  2. Set aside the selected slip.
  3. Stop after taping 11 or 23 entropy slips in order.
  4. Do not draw position 12 or 24.
  5. Calculate the final word separately and write it on a blank.
  6. Securely destroy the incomplete remainder.
Repeated words
Impossible
Draw distribution
Changes after every selection
Remainder
Missing vocabulary can identify selected words by subtraction
Use the physical set primarily as a source of entropy. Taped slips are an immediate backup option only when their limitations and the leftover-set risk are understood.

Evidence reviewed August 11, 2026

Documented final-word compatibility

Inclusion means a primary source documents local final-word calculation or checksum-valid selection. It is not a security endorsement or audit.

Device or tool12 words24 wordsHAT39 conventionPrimary evidence
SeedSignerDIY signerYesYesNative HAT39 first

Tools → Calc final word → enter 11 or 23 words → choose Finalize with zeros.

Method and offline posture

Offers coin flips, word-selection entropy, or a deterministic Finalize with zeros path after 11 or 23 entries.

Air-gapped Raspberry Pi Zero signer with no wireless hardware in the recommended build.

SeedSigner custody guide ↗Checked 2026-08-11
COLDCARD Mk4 / QHardware walletYesYesChoose first manually

Choose the candidate with the lowest official BIP39 index.

Method and offline posture

Exposes every valid candidate after 11 or 23 entries; 12-word candidates are grouped by first letter.

Can be operated without USB data; Q also supports QR and MicroSD workflows.

COLDCARD master-seed guide ↗Checked 2026-08-11
KruxDIY signerYesYesChoose first manually

Manually choose the valid candidate with the lowest official list index.

Method and offline posture

Restricts the final-word keypad to valid candidates; leaving it blank selects a candidate randomly.

Open-source signer firmware for standalone camera devices.

Krux mnemonic-generation guide ↗Checked 2026-08-11
Passport CoreHardware walletYesYesRandom final entropy

Do not use Passport as the HAT39 final-word calculator. It can import a completed HAT39 phrase calculated elsewhere.

Method and offline posture

Generate Final Word samples device noise and calculates one valid ending; retrying samples again.

Designed for QR and microSD air-gapped operation.

Foundation Passport setup guide ↗Checked 2026-08-11
Blockstream JadeHardware walletYesYesChoose first manually

Do not accept the randomized default; choose the lowest-index valid candidate.

Method and offline posture

Restricts final-word entry to valid options; its starting keyboard letter and initial candidate are randomized.

Jade Plus supports QR air-gap; other models can use a temporary signer workflow.

Blockstream final-word guide ↗Checked 2026-08-11
Review all compatibility records →

Open materials

Print and inspect the materials yourself

The six-page unshifted word-slip set, two backup cards, SHA-256 files, and PDF generators are available without an order or account.

Review downloads and checksums

Straight-on preview of page one of the downloadable BIP39 word-slip PDFStraight-on preview of the downloadable HAT39 backup-card PDF