What differs? BIP-39 · educational Shamir · SLIP-39
Three different backup models. This lab shell names the SLIP-39 word format so you can feel the difference — product promise stays lab, not “restore my Trezor.”
| Topic | BIP-39 (Lab) | Educational Shamir | SLIP-39 (this lab) |
|---|---|---|---|
| Wordlist | 2048 English words | No wordlist — share:index:hex |
1024 SLIP-39 English words |
| Backup unit | One recovery phrase | N hex share lines | N share mnemonics (threshold M) |
| Checksum | CS bits in last word | Demo-only structure | Per-share checksum / identifier |
| Passphrase | Optional “25th word” on seed | N/A on hex demo | Passphrase at combine (wrong → different/fail) |
| Groups | None | Single secret split | Groups + member thresholds |
| Downstream | PBKDF2 seed → BIP32 | Practice bytes only | Master secret (lab stops here) |
Demo — single group split / combine
Offline SLIP-39-compatible split/combine for a practice master secret (hex only). Never auto-imports Lab BIP-39. Defaults: 2-of-3 or 3-of-5. Lab only — not a funded-wallet restore tool.
—
Combine shares
—
—
Groups & passphrase (teach)
Production SLIP-39 can require group thresholds (e.g. need group A and any 2 of group B). Wrong passphrase at combine yields a different master secret (or recovery error) — not BIP-39’s optional “25th word” on seed derivation alone.
- Group 1: 1-of-1 “owner” share
- Group 2: 2-of-3 “heirs” shares
- Recover needs the owner share and any 2 heir shares (group threshold = 2). Wrong passphrase at combine → mismatch / different secret (no silent wallet unlock). Not BIP-39’s optional 25th word.
Demo splits with passphrase correct, combines with wrong,
and shows mismatch vs the practice secret. Lab only.