liberlume-content-v3 lang: en title: How big is «practically impossible»? summary: «It is practically impossible for someone else to generate your own seed» sounds like a way out, and anyone who does not buy it deserves an answer rather than reassurance. How big the space a Bitcoin wallet's seed comes from really is, why the right question is not whether someone guesses yours but whether two identical seeds will ever turn up among all the seeds ever generated, what it would cost a perfect machine just to count them, what difference twelve words instead of twenty-four actually makes, and what a passphrase adds. The fragile point is not the coincidence but the birth, which is to say the generator: the Android episode of 2013 and the Coldcard defect of July 2026. btc-anchor: 960990,0000000000000000000007c6cbdc6958d83fbfe12368e96f373a23a84ed45276 prev: sha256:dd7e330ac1d08c7d657a55db3e4746773242114f677a0d26dcfcb838364eb7ff --- body --- Anyone who comes near a Bitcoin wallet soon meets a sentence meant to reassure that usually does the opposite: it is *practically impossible* for someone else to generate your own seed. It sounds like a way out. It does not say impossible, it says practically, and the reader hears the difference: there is a chance, however small, and small things do happen to someone every now and then. Why should they not happen to me? The objection is a fair one and deserves an answer, not reassurance. What follows tries to give it in full: how big that number really is, how much the fear of colliding with someone else is worth, what it would cost any physical process at all just to cross that space, and finally where the reckoning really does break, because there is a fragile point and it is not the one it seems to be. With the figures in hand, the practical question everyone asks comes last: whether twelve words are enough or twenty-four are needed. There is then a second half of the matter that the figures do not touch: the procedures, the mechanisms and the tools by which those numbers are actually produced. A sound theoretical frame says how big the space is, it does not guarantee that whoever draws from it has used all of it. Working through the foundations is worth doing, but that confidence still hangs on a robust implementation and on the discipline these matters call for. ## A number, not a password The first thing to shift is the picture. A seed is not a password chosen by somebody: it is a number drawn by lot from a set of fixed size. Passwords resemble one another because a human head picks them, and human heads fish in the same tiny corner of proper names and dates. A seed generated properly fishes in no corner: it takes any value at all among those available, each equally likely. How many there are. A seed with 256 bits of entropy is worth ``` 2²⁵⁶ ≈ 1.16 × 10⁷⁷ ``` that is, a 116 followed by seventy-five zeros. The standard comparison is with the atoms in the observable universe, which are roughly 10⁸⁰: the space of seeds is about a thousandth of that number. Not «many»: beyond measure in experience. It should be said at once, because it comes back at the end, that not all seeds carry 256 bits. The twelve words that almost every wallet offers first carry 128, and the twenty-four carry 256. They are two different numbers and they support different reckonings. ## «Somebody does win the lottery, though» The real objection, the one intuition actually raises, is not that the thing is unlikely. It is that the jackpot comes out anyway, every year, and somebody gets it. If an event at one in six hundred million happens regularly, why should one in 10⁷⁷ be of another nature? Anyone reasoning this way is already doing the right sum, and it is worth granting that rather than correcting it. In the SuperEnalotto, the Italian national lottery, the possible combinations are ``` C(90, 6) = 622,614,630 ``` that is, a probability of about 1.6 × 10⁻⁹ per ticket. The jackpot comes out not because that number is large enough, but because tens of millions of tickets are played at every draw, and the draws have been repeating for decades. Intuition, in short, never looks at the probability on its own: it multiplies it by the number of attempts. That is exactly the correct method. The point is to apply it all the way in the other case too. ## The same reasoning, applied to seeds Applying it properly takes one piece of care. The question is not «somebody guesses my seed», which is a targeted search on a fixed target, far more costly, and which the [post on quantum computing](/en/bitcoin-and-quantum-computing/) deals with. The question is: among all the seeds that will ever be generated in the world, will there be two the same? This is the birthday problem, and it is the right question because it is the one that hands the attacker every possible pair instead of a single one. With N seeds generated and a space of k bits, the probability that any two coincide is roughly ``` p ≈ N² / 2^(k+1) ``` A declared N is needed. Let us take a generous one: a billion seeds ever created, which is more than all the wallets that have existed so far put together, counting the ones generated and thrown away as well. ``` N = 10⁹ k = 128 → p ≈ 1.5 × 10⁻²¹ N = 10⁹ k = 256 → p ≈ 4.3 × 10⁻⁶⁰ ``` Now those two numbers can be set against the lottery, which is the scale the reader has experience of. Winning the SuperEnalotto twice in a row sits at around 2.6 × 10⁻¹⁸. A collision among a billion 128-bit seeds is about one thousand seven hundred times rarer than that. With 256 bits it takes almost seven consecutive wins to reach the same order. And if a billion should seem like a number pulled out of the air, an absurd bound can be taken instead: every human being who ever lived, one hundred and seventeen billion people, each generating a thousand seeds. That makes 1.17 × 10¹⁴ seeds, and the probability of a collision somewhere in the whole history of the species becomes 2 × 10⁻¹¹ for 128-bit seeds and 6 × 10⁻⁵⁰ for 256-bit ones. The first of the two, it should be noted, is no longer an unpronounceable number: it is about one chance in fifty billion, which is to say a grotesque hypothesis that still carries a risk eighty times smaller than winning the SuperEnalotto on a single ticket. ## What it costs merely to count There is a way of making that number less abstract, and it does not go through cryptography. It goes through physics, and in particular through [Landauer's principle](/en/maxwells-demon/): erasing one bit of information has a minimum energy cost, which at room temperature is worth ``` k·T·ln2 ≈ 2.9 × 10⁻²¹ J ``` This is a lower bound, not an estimate of what it costs today: it is what it would cost a perfect machine, one that does not heat up, has no friction and wastes nothing. Nobody can do better. So let us take the most pointless operation imaginable, one that breaks nothing and proves nothing: counting. Running once through every possible value of a 256-bit seed, without even checking whether they correspond to anything. ``` 2²⁵⁶ × 2.9 × 10⁻²¹ J ≈ 3.3 × 10⁵⁶ J ``` The Sun, over its whole existence, from the first day to the last, will emit roughly 1.2 × 10⁴⁴ joules. The count asks for almost three thousand billion times as much. Not the energy available on Earth, not what humanity could manage to gather: three thousand billion stars like ours, spent entire, to do the most useless thing in the world. It is worth saying where the claim stops holding, too, because the boundary is often moved one step too far. Against the energy of the whole universe the sum does not hold: the ordinary matter of the observable universe alone is worth something like 10⁷⁰ joules, and 10⁵⁶ fits inside that comfortably. The exact sentence is that no process confined to a stellar system will ever cross that space, which is more than enough, and has the merit of being true. And this holds for 256 bits. At 128 bits the same sum would give 9.8 × 10¹⁷ joules, that is, about fourteen hours of world energy consumption: thermodynamics on its own proves nothing there. What protects 128 bits is not the ideal limit but the distance between the ideal and the real. The most efficient hardware ever built to repeat a single operation, the ASICs that grind hashes for mining, uses about 1.5 × 10⁻¹¹ joules per hash: five billion times the Landauer minimum. On that machine, 2¹²⁸ operations would cost 5 × 10²⁷ joules: eight million years of world energy consumption, where fourteen hours were enough for the perfect machine. This is not a limit of principle like the one before: it is a distance no conceivable budget covers, and the difference is worth stating. ## A bet already being made There remains the part the numbers do not touch, that is, the discomfort of leaning on something that is not forbidden but merely unlikely. And it is an already familiar condition. The air in a room, twenty-four hours a day, could gather entirely into one half, leaving the other empty. No law forbids it: the molecules move at random, and that configuration is one among many. In a room of thirty cubic metres the molecules are about 7 × 10²⁶, and the probability that they all sit in half the room is 2 to the minus that number, a value it makes no sense even to write out. [Maxwell's demon](/en/maxwells-demon/) tells at length why the second law works this way: it is statistical, not absolute. It serves to establish one thing only, and it is worth saying which: that «not forbidden but it does not happen» is not a quibble invented by cryptographers to avoid answering. It is a category as old as physics, and one lives inside it without noticing. The gas measures nothing of what concerns seeds: its improbability is of another order, incomparably more remote, and anyone using it as a yardstick would be saying something false. The measure, if anything, is to be looked for on the opposite side, among the things that happen *more* often than a collision and that nobody treats as a reason to change their life. Being struck by lightning, over the course of a lifetime, sits at around one chance in tens of thousands: more than sixteen orders of magnitude above the collision in question, and nobody is reported to stay indoors on that account. The difference between 10⁻⁵ and 10⁻²¹ cannot be felt, but it is the same one that separates watching out for a thunderstorm from worrying that the air will leave the room. The useful comparison, then, is with the near risks rather than the remote ones. Losing the words, writing them down in a way that will not be legible in ten years, keeping them on a device that is already compromised, dying without anyone knowing where they are: these are all enormously more likely than a coincidence, and they are the ones worth spending attention on. The collision is not the first risk on the list. It is not the last one either: it is off the list. ## The point where the reckoning can break Everything above rests on one condition, never stated until now: that the draw was a real draw. The probability 1/2²⁵⁶ is not a property of the seed, it is a property of the way it was born. If the generator was not truly random, the values it could produce are not 2²⁵⁶ but as many as its defect allowed, and every sum on this page has to be redone with that number in place of the other. This is not a textbook hypothesis. In August 2013 a defect in Android's random number generator hit the Bitcoin wallets running on those phones: the keys were born from a space far smaller than the nominal one. The same faulty component spoiled things at two distinct points, the birth of the keys and the signing of transactions, and the thefts that followed came mostly from the second, the [repetition of the nonce](/en/signature-nonce/). At the end of July 2026 the maker of the Coldcard hardware wallet published a security advisory concerning exactly this point. The defect goes back to March 2021 and sits in a line of code that has nothing to do with cryptography: a preprocessor directive checked whether an option was *defined* instead of checking that it was set to *yes*. The option was defined as zero, because that device uses its own connection to the hardware generator, and the result is that the firmware bound itself to the hardware generator at one point and compiled a software fallback at the other. That fallback was started once only, from the chip's serial number and the state of the internal clock, and after that gathered nothing further: from then on every value followed from the previous one by pure arithmetic. The bits left, according to the preliminary estimates of the maker and of the researchers who reconstructed the fault, were around forty on the older models and about seventy on the recent ones, in place of the 128 of a twelve-word seed. These are numbers that change everything: 2⁴⁰ is worth about 1.1 × 10¹², that is, a space a machine runs through entire. No lock had to be attacked, and no device was touched: more than a thousand wallets were emptied in under an hour, by reconstructing the keys from outside. In confirmation that the problem seems tied to the entropy of the number source: those who had added dice rolls of their own to the generation, at least fifty or so, or a solid passphrase, were not exposed. Which models and which versions are affected is set out in the advisory, linked at the foot of this page. It is worth pausing on what did not happen. No collision, no unlucky coincidence, nothing resembling the fear this page starts from. The earlier sum, the one not even the Sun is enough to pay for, concerns a set of 2²⁵⁶ elements. Here the set had 2⁴⁰ of them, and the rest of the mathematics was intact: cryptography went on working exactly as promised, over a space someone else had already emptied. The risk, in short, is not the coincidence. It is the birth. And that is good news, because a coincidence cannot be controlled whereas the way a seed is generated can: it is a choice of tool, and it is documented. ## Twelve words or twenty-four Here the point left open at the beginning comes back, because it is where the most confusion circulates, condensed into a sentence heard everywhere: twelve words are enough, «it is the same thing anyway». It is worth taking the matter one piece at a time. The choice between twelve and twenty-four words is made before the draw, and it fixes how much is drawn: twelve words write 128 bits taken by lot, twenty-four write 256. There is no conversion, in either direction: choosing twelve words is not compressing a 256-bit draw, it is making a smaller one; and no later step reduces the twenty-four to 128. The word lists also carry a few check bits, which serve to catch a transcription error and add no entropy, so they enter none of these sums. Part of the misunderstanding comes from a name. After the words, the protocol turns them, together with any passphrase, into a much longer number, 512 bits, and that is what the specification calls the «seed»; from there descend all the wallet's keys. But that step creates no unpredictability: the long number can take only the values the initial draw allowed. With twelve words the whole tree of keys, however vast, remains reachable from 2¹²⁸ starting points; with twenty-four, from 2²⁵⁶. So it is not the same thing: they are two different spaces, and between them sits a factor of 2¹²⁸. The right question is then whether 128 bits are enough. For accidental collision the answer lies in the sums already done, and no realistic scenario dents that margin. For a targeted search there is a fact that «it is the same thing anyway» almost always leaves out, and it concerns another target: someone with a single wallet in their sights is not obliged to look for the seed, they can go for the key that descends from it, and that road has a cost of its own which does not depend on the size of the draw. The mathematics Bitcoin signs with offers the best known classical attack a labour of about 2¹²⁸ operations per key, whether it is twelve words or twenty-four. That number is a square root once again: attacking a key does not mean trying them all one by one, but pushing a computation until it falls back on a value already met, and in a space of 2²⁵⁶ a coincidence of that kind arrives after about 2¹²⁸ steps. It is the birthday problem again, applied this time inside the attack on a single target. The chain, that is, already has a 128-bit link, and it sits downstream of both draws: twelve words line the first link up with the one that exists anyway, twenty-four strengthen the first and leave the other where it was. This holds as long as the public key is visible, which is the commonest case: on [certain outputs](/en/bitcoin-locks/) it stands in the clear from the first moment, on all the others it appears at the first spend, because spending means showing it. As long as it stays covered by a fingerprint that link sits higher, at around the 2¹⁶⁰ of the fingerprint itself, and there the twenty-four words do add a margin; a margin that shifts nothing in practice, because even the lower of the two numbers is out of reach. Choosing twenty-four words is therefore not correcting a weakness: it is buying margin against the future, that is, against advances nobody today can foresee (the quantum ones are the subject of the [dedicated post](/en/bitcoin-and-quantum-computing/)), and the cost is only memory. Twelve words are sufficient with ample margin; that does not make them equivalent to twenty-four. Neither form, however, buys any defence against a badly made generator, and that is where the cases on record have always turned. The tool counts for more than the length. ## The extra word There is a lever that is neither the length nor the tool. To the twelve or twenty-four one can add a **passphrase**, a secret that does not appear in the words and that the wallet asks for separately: words and passphrase go together into the transformation that produces the long number from which the keys descend. The natural question is whether this increases the entropy of the seed or is merely a protection placed around a seed that stays the same as before. It is worth answering by separating the two, because the answer is neither one nor the other in full. It is not a padlock applied on top. Different passphrases produce different wallets, all equally valid: getting one letter wrong does not yield an error, it yields another wallet, an empty one. The device has no way of saying that one is wrong, because it does not know the right one and keeps it nowhere. Of entropy, on the other hand, it adds exactly its own, and not one bit more. The point lies in when those bits are needed. If the draw was a real draw they are not: 128 were already out of reach, and adding more shifts nothing concrete. If the draw was not a real one they are the only thing left standing, and that is what happened with the defect described above: the words could be reconstructed from outside, the passphrase could not, because it had not passed through the generator. The exact way to put it is this: the passphrase does not strengthen a number that was already enough, it covers the case where that number was not there. Here, though, the password this page started from comes back. The passphrase is chosen by a human head, so what counts is how unpredictable it is to whoever is looking for it, not how long it is; and anyone holding the words can try as many as they like on their own, all the more so since the transformation repeats the same operation only a few thousand times, which is not enough to make an attempt expensive. The rest are the near risks, and here they are larger. A forgotten passphrase cannot be recovered in any way, and it leaves no trace: there is no medium to be found again, and those left behind do not even know what to look for. ## Pairs that get confused - **accidental collision ≠ targeted search**: the first plays on every possible pair and costs the square root of the space, the second has a fixed target and costs the whole space of the seed, assuming it is the seed being looked for; - **unlikely ≠ forbidden**: no law of physics forbids the coincidence, and none is needed; - **random ≠ unpredictable**: numbers that look random can be reproduced by someone who knows the starting point; - **deterministic ≠ predictable**: a fixed rule applied to a secret produces values that stay out of reach of anyone without that secret; - **entropy of the seed ≠ length of the phrase**: what counts is the bits drawn, not how many words it takes to write them down; - **drawn seed ≠ derived seed**: the specification also calls «seed» the long number obtained from the words, but the unpredictability remains that of the initial draw; - **drawn entropy ≠ chosen secret**: the first is uniform by construction, the second is worth as much as it is unpredictable to whoever is looking for it, and that is the difference between a seed and a passphrase; - **impossible in cryptography ≠ impossible in logic**: here it has always meant «outside any conceivable budget», and it is better to know that than to suspect it. ## In short The space a seed is drawn from is as large as a thousandth of the atoms in the observable universe, and the right question is not whether someone could guess one seed in particular, but whether two identical ones will turn up among all the seeds ever generated. The sum can be done, and with a generous number of wallets ever created it stays rarer than winning the SuperEnalotto twice in a row; inflating the assumptions to the point of the grotesque, it stays eighty times less likely than a single win. This is not a convention: crossing that space, breaking nothing and merely to count it, would cost a perfect machine thousands of billions of times all the energy the Sun will emit in its lifetime. There remains the discomfort of leaning on something that is not forbidden but merely unlikely: it is the same condition one is in every time one breathes in a room, and the risks accepted daily without a thought are sixteen orders of magnitude more likely than this one. Between twelve words and twenty-four, moreover, the same entropy does not run, whatever one hears: 128 drawn bits run against 256, and the first are amply enough without the two forms being equivalent. The fragile point is another and lies earlier: those sums hold if the draw was real, and whenever something has gone wrong it has always gone wrong there. ## References - BIP 39, *Mnemonic code for generating deterministic keys*: [github.com/bitcoin/bips/blob/master/bip-0039.mediawiki](https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki) - R. Landauer, *Irreversibility and Heat Generation in the Computing Process*, IBM Journal of Research and Development, 1961: [doi.org/10.1147/rd.53.0183](https://doi.org/10.1147/rd.53.0183) - NIST SP 800-90A/B/C, recommendations on random number generators: [csrc.nist.gov/publications/detail/sp/800-90a/rev-1/final](https://csrc.nist.gov/publications/detail/sp/800-90a/rev-1/final) - Bitcoin.org, security advisory on Android wallets (August 2013): [bitcoin.org/en/alert/2013-08-11-android](https://bitcoin.org/en/alert/2013-08-11-android) - Coinkite, security advisory on Coldcard seed generation (July 2026): [blog.coinkite.com/coldcard-mk3-seed-generation-warning](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/), with the [technical backgrounder on entropy](https://blog.coinkite.com/entropy-technical-backgrounder/) - Block Engineering, *Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware*: [engineering.block.xyz](https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware) - NASA's Sun Fact Sheet, for the solar luminosity: [nssdc.gsfc.nasa.gov/planetary/factsheet/sunfact.html](https://nssdc.gsfc.nasa.gov/planetary/factsheet/sunfact.html)