Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

12 or 24 words: which seed length?

TL;DR

Both are safe against guessing. 12 words hold 128 bits of randomness, 24 words 256 bits; nobody can brute-force either. This guide uses 24 because all three devices support it and it keeps every backup the same.

What the words encode

A BIP39 seed is a random number written as words from a fixed list of 2,048. Each word stands for 11 bits. The last word also contains a small checksum, which is why a random typo usually makes a device reject the phrase.

12 words24 words
Randomness128 bits256 bits
Can it be guessed?NoNo
Time to write on metalShorterTwice as long
Supported byNearly all walletsNearly all wallets

So why 24?

Mostly consistency and margin. The three devices in this guide create 24 words by default or as an option, so every backup looks the same. And if a device’s random generator is ever weaker than it should be, as with the Coldcard flaw disclosed in 2026, more words don’t fix the flaw but don’t hurt either.

The four-letter rule

Every word in the BIP39 list is unique by its first four letters. That’s why metal backups often store only four letters per word: tiles, punched or engraved.

Avoid other formats

Trezor’s default 20-word backup uses SLIP39, a different standard that your other devices can’t restore. Pick 24-word BIP39 during setup. More in BIP39 vs SLIP39.