Racira Calculator

Cold Wallet Key Entropy Calculator

Cold Wallet Key Entropy Calculator

Effective Key Entropy
128.0 bits
Cryptographically Secure — a keyspace of 10^38.5 combinations
Classification
Cryptographically Secure
Seed Entropy
128 bits
vs 128-bit
+0 bits
Average Time to Exhaust Keyspace
3.91 × 10^8 times the current age of the universe
Assuming 10^12 guesses per second, sustained without interruption
Entropy ComponentValue
Generation MethodBIP-39 Mnemonic Words
Quantity (words)12
Entropy per Unit11.000 bits
Raw Wordlist / Symbol Bits132.0 bits
Checksum Bits Deducted4.0 bits
True Seed Entropy128.0 bits
Added Passphrase Entropy0.0 bits
KDF Stretching Equivalent0.0 bits
Effective Attacker Work Factor128.0 bits
Total Keyspace10^38.5 combinations
Security ClassificationCryptographically Secure
Margin vs 128-bit Standard+0.0 bits
Total Effective Entropy128.0 bits
Generation MethodBIP-39 Mnemonic Words
Quantity (words)12
Entropy per Unit11.000 bits
Raw Wordlist / Symbol Bits132.0 bits
Checksum Bits Deducted4.0 bits
True Seed Entropy128.0 bits
Added Passphrase Entropy0.0 bits
KDF Stretching Equivalent0.0 bits
Effective Attacker Work Factor128.0 bits
Total Keyspace10^38.5 combinations
Security ClassificationCryptographically Secure
Margin vs 128-bit Standard+0.0 bits

What Key Entropy Measures

Entropy is the number of genuinely unpredictable bits behind a key, and it is the only honest measure of how hard that key is to guess. A key with 128 bits of entropy can take any of 2^128 values, roughly 3.4 × 10^38 possibilities. Crucially, entropy counts randomness, not length. A 40-character passphrase copied from a song lyric has almost no entropy despite its length, while 50 dice rolls recorded honestly have about 129 bits. This calculator works from the generation method rather than the output, because that is where the randomness actually comes from.

Why 12 Words Equals 128 Bits, Not 132

BIP-39 wordlists contain exactly 2,048 entries, so each word encodes 11 bits and twelve words appear to carry 132. Four of those bits are a checksum computed from the other 128, which lets a wallet detect a mistyped word but adds no unpredictability. True entropy is therefore 128 bits. The same structure scales: a 24-word phrase carries 264 wordlist bits minus 8 checksum bits, giving exactly 256. Any calculator that reports 132 or 264 bits is counting the checksum as randomness, which it is not.

Why 128 Bits Cannot Be Brute Forced

The impossibility here is physical rather than merely economic. Landauer's principle sets a minimum energy of about 2.85 × 10^-21 joules to irreversibly flip a single bit at room temperature. Simply counting through a 128-bit keyspace, with no work done per candidate, would require more energy than is plausibly available to a civilisation on this planet, and 256 bits exceeds the output of the Sun over its remaining lifetime. Real cryptocurrency losses do not come from broken entropy. They come from photographed seed phrases, cloud backups, phishing, malicious wallet software, and keys generated by weak random number generators.

Generating Entropy You Can Verify

The advantage of dice is verification: you can see the randomness happen rather than trusting a chip you cannot audit. Casino-grade precision dice avoid the small bias introduced by drilled pips, and 50 rolls give 128 bits while 99 rolls give 256. Never choose words yourself, never derive a phrase from a book or lyric, and never enter a real seed phrase into any website, this one included. Enter only counts here. If you use a BIP-39 passphrase as a 25th word, add its entropy in Advanced Options to see the combined work factor, and remember that the passphrase is unrecoverable by design: losing it destroys access as completely as losing the seed itself.

Frequently Asked Questions

Related Calculators