Offline BIP-39 lab

Generate, validate, and derive receive addresses — English wordlist only.

Offline crypto Checking…
Air-gap recommended. Crypto stays in this tab. Progress/theme may be saved in the browser. Derived addresses go to Network only after explicit opt-in. Do not use a funded phrase here.

First hour 0 / 6

Create a practice 12-word card

  1. 1Generate 12-word
  2. 2Fill addresses
  3. 3Path playground
  4. 4Passphrase compare
  5. 5Network? optional
  6. 6Set Beginner

Mnemonic

English BIP-39 only. Optional passphrase is a BIP-39 extension (not a PIN).

About Seed QR, print, Network handoff

Seed QR and Print only work after the live phrase validates. Each asks you to confirm that you are showing or printing the full recovery phrase. Network handoff stores addresses only in sessionStorage, and only when you click Send addresses.

Mnemonic entropy —
Passphrase strength (estimate) Empty — no extra secret (not the 512-bit PBKDF2 seed size)

Updates as you type. Longer + mixed characters raise the estimate. This is not the BIP-39 seed’s fixed 512-bit PBKDF2 output size.

Why “512 bits” is not the passphrase strength

The BIP-39 seed is always 64 bytes from PBKDF2 — that is output size, not “512 bits of entropy.” Mnemonic entropy (e.g. 128 bits for 12 words) is BIP-39 ENT. Passphrase strength here is a local estimate only (Shannon + charset × length, capped) so you see empty vs weak vs longer secrets — not a guarantee against attack.

Chapter 1

Passphrase and entropy

Stronger passphrases come from more entropy. More entropy = stronger seed = stronger security.

Something you know Something you know
Randomness (entropy) Randomness (entropy)
Stronger seed Stronger seed
Too few dice 128 bits
0 / 4
  • Q1 passphrase Not yet
  • Q2 Shamir Not yet
  • Q3 too low Not yet
  • Q4 enough bits Not yet

Q1 Self-graded

Wrong passphrase → different vault Not yet

Test that a small change creates a completely different vault.

Not yet. Open compare, leave A empty and set B to test, run derive — addresses must differ.

Q2 Self-graded

Under-threshold Shamir fails Not yet

See what happens when you don’t have enough shares.

Not yet. Split 2-of-3, recombine with one share (fail), then M shares (succeed).

Q3 Self-graded

A few rolls = TOO LOW Not yet

Measure entropy with just a few dice rolls.

Not yet. Go try → roll d6 about 3 times → read TOO LOW.

Q4 Self-graded

Need ~128 bits (~50 d6) Not yet

Hit the target: generate ~128 bits with about 50 rolls.

Not yet. Keep rolling toward 128 bits, then mark passed.

Intermediate self-check Three splits + Tools depth 0 / 4

keys ≠ shares ≠ share-words

Multisig (keys)
Multisig (keys)
Shamir (edu)
Shamir (edu)
SLIP-39 (lab)
SLIP-39 (lab)

Keys ≠ shares ≠ share-words, plus PSBT inspect-only. Advanced stays off this face. Self-graded — Go try, then Mark passed when the idea is clear.

  • I1 keys Not yet
  • I2 shares Not yet
  • I3 words Not yet
  • I4 inspect Not yet

I1 — Multisig = keys, not shares Not yet

Several people each hold a key. Spend needs M-of-N signatures. That is not “shares of one secret blob.”

Not yet. Open Multisig, read that cosigners hold keys. Then mark passed.

I2 — Shamir edu = hex shares, not BIP-39 words Not yet

Educational Shamir splits a practice secret into hex shares. Not BIP-39 recovery words, not SLIP-39.

Not yet. Open Shamir, note hex share format. Then mark passed.

I3 — SLIP-39 lab = share words (not Suite, not funded) Not yet

SLIP-39 lab uses share mnemonics (Trezor-shaped). Lab only — not vendor Suite, not funded wallets.

Not yet. Open SLIP-39 lab, read the lab-only warning. Then mark passed.

I4 — PSBT inspect-only (no sign / no broadcast) Not yet

Tools PSBT card parses structure offline. It never signs, never finalizes, never broadcasts.

Not yet. Open Tools → PSBT inspector; confirm inspect-only copy. Then mark passed.

BIP-85 — child seeds (advanced, educational)

Idea: one master mnemonic can derive many application child mnemonics (different index → different app). This lab teaches the mental model. Demo below is not full BIP-85 crypto yet — practice only.

Raise Level to Advanced, put a practice phrase on Lab, then click Explain.

Ops — private Knots / seed-scan

Private balances and educational hash-only seed scans use a local Bitcoin Knots/Core node (Pi checklist), not this public website. Never expose RPC to the internet.

  • Pi / node checklist: see repo docs/BITCOIN_KNOTS.md
  • Educational scan CLI: scripts/seed_scan_educational.py --preflight-only
  • Public Network page remains mempool fees/balances with leak ack only

master → child keys

This site is not a wallet.

master key to three child keys. This site is not a wallet.

Advanced self-check Ops mind offline 0 / 4

Master → child keys. This site is not a wallet. BIP-85 idea, watch-only handoff, Knots limits, and what this lab is not. Self-graded — experiment, then mark passed.

  • A1 BIP-85 Not yet
  • A2 watch-only Not yet
  • A3 Knots Not yet
  • A4 is-not Not yet

A1 — BIP-85 idea (master → app children) Not yet

One master mnemonic can conceptually yield many application child mnemonics by index. Lab demo is educational — not full BIP-85 crypto yet.

Not yet. Open BIP-85 card, run Explain (practice phrase). Then mark passed.

A2 — Watch-only export (no xprv on page) Not yet

Lab watch-only export is public material (zpub/xpub style). No private keys / xprv for wallet spend.

Not yet. Generate a practice phrase, open watch-only panel, confirm no xprv. Then mark passed.

A3 — Knots limits (local node, not public farm) Not yet

Private balance / educational seed-scan work belongs on a local Knots/Core node. This website is not a bulk seed lottery or public RPC.

Not yet. Read the Ops card (Knots + seed-scan CLI). Then mark passed.

A4 — What this lab is / isn’t Not yet

Orientation table: practice lab, offline crypto, not a funded wallet, not a seed farm.

Not yet. Re-read “What this is / isn’t” on Lab. Then mark passed.

Receive addresses

Offline “account numbers” from your phrase. Crypto stays in this tab. Progress/theme may be saved in the browser. Addresses go to Network only after explicit opt-in.

Bank vault metaphor

Think of your recovery phrase as the master key to a bank vault. From that one key, wallets create many different “account numbers” (addresses) so you can receive bitcoin without reusing the same number every time.

Address type (one at a time)

BIP-86 Taproot (bc1p…) — default modern receive style in this lab — set by these tabs. Path m/86'/….

What each type means (simple)
  • # — address number in the sequence (0, 1, 2…). Same phrase + same settings always gives the same list.
  • BIP86 Taproot (bc1p…) — newest common format. Path m/86'/0'/account'/change/index.
  • BIP84 native segwit (bc1q…) — widely used. Path m/84'/….
  • BIP49 nested (3…) — older compatibility style. Path m/49'/….
  • BIP44 legacy (1…) — oldest style. Path m/44'/….

What this is: public receive numbers only (safe to share when you want payment).
What this is not: not your recovery phrase, not a private key, not a balance.

Copy & QR tips

Click Copy to put an address on the clipboard (like an IBAN). The button shows Copied briefly. Use QR for a scannable code offline. Only the address is copied — never the recovery phrase.

Watch-only export

Watch-only key type (one at a time)

BIP84 zpub — usual Sparrow / mobile watch-only import for native segwit.

Generate or paste a valid phrase, then refresh (or wait for auto-derive).