SLIP-39 lab

Trezor-shaped share mnemonics · offline · educational

Offline crypto Checking…

What differs? BIP-39 · educational Shamir · SLIP-39

Three different backup models. This lab shell names the SLIP-39 word format so you can feel the difference — product promise stays lab, not “restore my Trezor.”

Topic BIP-39 (Lab) Educational Shamir SLIP-39 (this lab)
Wordlist 2048 English words No wordlist — share:index:hex 1024 SLIP-39 English words
Backup unit One recovery phrase N hex share lines N share mnemonics (threshold M)
Checksum CS bits in last word Demo-only structure Per-share checksum / identifier
Passphrase Optional “25th word” on seed N/A on hex demo Passphrase at combine (wrong → different/fail)
Groups None Single secret split Groups + member thresholds
Downstream PBKDF2 seed → BIP32 Practice bytes only Master secret (lab stops here)

Demo — single group split / combine

Offline SLIP-39-compatible split/combine for a practice master secret (hex only). Never auto-imports Lab BIP-39. Defaults: 2-of-3 or 3-of-5. Lab only — not a funded-wallet restore tool.

—

Combine shares

—

—

Groups & passphrase (teach)

Production SLIP-39 can require group thresholds (e.g. need group A and any 2 of group B). Wrong passphrase at combine yields a different master secret (or recovery error) — not BIP-39’s optional “25th word” on seed derivation alone.

Demo splits with passphrase correct, combines with wrong, and shows mismatch vs the practice secret. Lab only.