TL;DR
Both are safe against guessing. 12 words hold 128 bits of randomness, 24 words 256 bits; nobody can brute-force either. This guide uses 24 because all three devices support it and it keeps every backup the same.
What the words encode
A BIP39 seed is a random number written as words from a fixed list of 2,048. Each word stands for 11 bits. The last word also contains a small checksum, which is why a random typo usually makes a device reject the phrase.
| 12 words | 24 words | |
|---|---|---|
| Randomness | 128 bits | 256 bits |
| Can it be guessed? | No | No |
| Time to write on metal | Shorter | Twice as long |
| Supported by | Nearly all wallets | Nearly all wallets |
So why 24?
Mostly consistency and margin. The three devices in this guide create 24 words by default or as an option, so every backup looks the same. And if a device’s random generator is ever weaker than it should be, as with the Coldcard flaw disclosed in 2026, more words don’t fix the flaw but don’t hurt either.
The four-letter rule
Every word in the BIP39 list is unique by its first four letters. That’s why metal backups often store only four letters per word: tiles, punched or engraved.
Avoid other formats
Trezor’s default 20-word backup uses SLIP39, a different standard that your other devices can’t restore. Pick 24-word BIP39 during setup. More in BIP39 vs SLIP39.