If a BIP39 hardware wallet is lost, what exactly is recovered from the seed phrase?

If a BIP39 hardware wallet is lost, what exactly is recovered from the seed phrase?

Manage alerts

Loading saved threads...

user190472 · External communityPost link
External question — Bitcoin Stack Exchange Author: user190472 Original post: https://bitcoin.stackexchange.com/questions/130998 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. I’m trying to better understand the relationship between a hardware wallet, a BIP39 seed phrase, and the actual Bitcoin keys. Suppose a user initializes a hardware wallet, receives a 12- or 24-word recovery phrase, and later completely loses or destroys the physical device. If the recovery phrase is imported into another compatible wallet: What exactly is being reconstructed from those words? Are the same Bitcoin private keys and addresses deterministically regenerated? What additional information might still be required, such as a passphrase, derivation path, or wallet type? Are there situations where having the correct seed phrase alone would still not be enough to recover the expected Bitcoin wallet? I’m specifically interested in the Bitcoin/BIP32/BIP39/BIP44 side of this rather than device-specific recovery instructions.
Quote
Report
StackQsUp · External communityPost link
External answer — Bitcoin Stack Exchange Author: StackQsUp Original post: https://bitcoin.stackexchange.com/a/130999 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. BIP-39 is not strictly a hardware standard, it's a way to generate billions of Bitcoin addresses derived from a seed phrase ("mnemonic seed", which can be thought of as 'word seed'). The wallet (collection of addresses) that are generated from the seed is called a Hierarchal Deterministic Wallet, or HD Wallet for short. Hierarchal Deterministic is exactly what it sounds like, it follows a hierarchy, which means you can have accounts, addresses, even use the same seed phrase for multiple coins, and it's deterministic, which means that you will always generate the same addresses with the same seed. I will try to give more technical answers below: What exactly is being reconstructed from those words? Let's say you have a 12 word seed phrase. What Bitcoin wallet software does (or hardware wallet) is take that seed phrase, check if the checksum matches (the last word is a verification word, calculated from the previous words). If it matches it takes the seed phrase, runs it through a mathematical formula/computer instruction called PBKDF2, then takes that result, and runs it through another math formula called HMAC-SHA512. Then with that result, it then - basically - follows the derivation path to generate the keys and addresses. More on derivation path below. Are the same Bitcoin private keys and addresses deterministically regenerated? Yes. Every seed phrase will always generate the exact same private keys and address, assuming the exact same derivation path (see below). What additional information might still be required, such as a passphrase, derivation path, or wallet type? If a passphrase was used on the wallet, then yes, a passphrase would be required. Some hardware and software wallets have PIN codes and locks, these are not true seed phrase passphrase. These are just visual UI/device security locks that prevent someone from accessing the actual seed phrase. HD wallets can absolutely have a passphrase on the actual seed, so even if someone was able to get access to the words and word order, they would still need the passphrase to generate the correct addresses and keys. It's important to note that a passphrase does not replace safeguarding and keeping a seed phrase private, as most passphrases people use can be brute forced easily if someone has the seed phrase. Derivation paths are necessary for the wallet to know where to find the addresses. For software wallets, they usually automatically scan the chain for previously used addresses to find which derivation path to use. A derivation path is something like m/44'/0'/0'/0/0. That means: m is for the master key, the root key, where to start 44' is for purpose. IN this content, 44 means legacy address. If you wanted native segwit addresses, you'd use 84 The first 0' means coin type. 0' for bitcoin, 1' for testnet. The second 0' means account, you can have multiple accounts, for example, 0 can be main, 1 can be work, 2 can be investing, etc. The first 0 without a ' (3rd 0 from the left) means change. if it's a main address, it's 0. If it's a "change" address (where leftover coins are sent as part of a transaction), it's 1. The last 0 is the address index. So you can have address 0 for the first address, then 1, 2, 3, 4, 5 etc. Are there situations where having the correct seed phrase alone would still not be enough to recover the expected Bitcoin wallet? Yes, if it has a passphrase, it uses the wrong seed phrase type (Electrum vs BIP-39) or the wallet doesn't support it.
Quote
Report
Fab_Crypto_Recovers · External communityPost link
External answer — Bitcoin Stack Exchange Author: Fab_Crypto_Recovers Original post: https://bitcoin.stackexchange.com/a/131050 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. The answer above covers the derivation side well. Adding the practical cases where the words are correct but the restore still looks wrong, since that was your third question: Are there situations where having the correct seed phrase alone would still not be enough to recover the expected Bitcoin wallet? Right seed, zero balance is the common one. Restore into a wallet that defaults to a different address type than the original, and your coins won't show. Same seed, same private keys underneath, but legacy (addresses starting with 1), P2SH (starting with 3) and native segwit (bc1) each sit on a different derivation path. The wallet only displays the paths it scans. The fix is to restore into a wallet that lets you set the path or the account type, or try each type until the balance appears. Right seed, still zero, right address type: Check the gap limit. Wallets stop scanning after a run of empty addresses, which is 20 by default. If you once sent funds to, say, the 40th address and the ones before it are empty, the wallet gives up before it reaches yours. Raise the gap limit and rescan. The passphrase has no wrong answer. If a passphrase (the BIP39 "25th word") was set, every passphrase you type produces a valid, empty wallet with no error. There is no "incorrect passphrase" message, because each one derives a real but different set of keys. So a forgotten passphrase behaves exactly like a wallet with no funds. Worth knowing before you conclude the seed is bad. One correction worth flagging: a PIN and the BIP39 passphrase are different things, as the answer above notes. Losing the PIN is fine, the seed alone rebuilds everything. Losing the passphrase is not, because it feeds into the key derivation itself.
Quote
Report
Keystoner · External communityPost link
External answer — Bitcoin Stack Exchange Author: Keystoner Original post: https://bitcoin.stackexchange.com/a/131065 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. Taking the sub-questions in order, and refining one point in the existing answers. WHAT THE WORDS ARE The mnemonic is entropy plus a checksum, not entropy plus a "verification word". BIP-39 sets CS = ENT / 32 and MS = (ENT + CS) / 11. A 12-word phrase is 128 bits of entropy and 4 checksum bits; a 24-word phrase is 256 and 8. Since 11 words carry 121 bits, the twelfth word carries 7 entropy bits alongside those 4 checksum bits: it is not derived from the other eleven. Two consequences worth knowing. A random 12-word sequence passes the checksum once in 16 tries, and a 24-word one once in 256, so the check rejects most corruptions but validates plenty of wrong phrases. And given the first 11 words of a 12-word phrase, exactly 128 of the 2048 words are valid in the last position (8 of 2048 for a 24-word phrase). The checksum tells you something is wrong; it never tells you where. WHAT THE WORDS BECOME Two separate steps, and only the first is BIP-39. PBKDF2 with HMAC-SHA512, 2048 iterations, the mnemonic (NFKD) as the password and the string "mnemonic" + passphrase (NFKD) as the salt, producing 512 bits. That output is then the BIP-32 seed S, and the master key is I = HMAC-SHA512(Key = "Bitcoin seed", Data = S), with I_L the master private key and I_R the chain code. Everything below that is deterministic, so yes: same words, same passphrase, same path, same keys, forever. WHY A PASSPHRASE CANNOT BE CHECKED Because it enters as part of the PBKDF2 salt, not as a credential that anything verifies. BIP-39 states it plainly: "every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available." There is no failure path. A forgotten passphrase is indistinguishable from an empty wallet, and there is nothing to test candidates against unless you already know an address or xpub the wallet is supposed to produce. WHAT THE SEED DOES NOT CARRY The seed fixes the keys. It says nothing about which of them a wallet will look at. Script type and purpose: 44' (1...), 49' (3...), 84' (bc1q), 86' (bc1p). Same keys, four different sets of addresses. Account index, and the discovery rule that stops at the first account with no history on its external chain. Funds parked in account 2 with account 1 empty will not be found. The BIP-44 address gap limit of 20. And the case neither answer covers: multisig. For a 2-of-3, your seed is one of three secrets, and it is not sufficient even in principle. Reconstructing the script requires every cosigner's xpub, the policy, the script type (BIP-48 uses 1' for p2sh-p2wsh and 2' for p2wsh) and each key's origin fingerprint and path. Without the other xpubs you cannot compute your own addresses, let alone spend. This is the strongest argument for backing up the output descriptor alongside the words: the descriptor carries exactly the information the mnemonic omits.
Quote
Report

Post Reply

Checking account access…
If a BIP39 hardware wallet is lost, what exactly is recovered from the seed phrase? | Forex.com.bd