Bitcoin Entropy Lab

Make uncertainty visible.

Entropy is uncertainty that an attacker must guess. A wallet needs enough unpredictable entropy to create private keys no one else can reproduce.

2128 possible starting values
01

What it looks like

Random entropy is simply bits: unpredictable zeroes and ones. Sixteen random bytes give 128 bits, enough for a 12-word BIP39 phrase after adding a checksum.

02

What can go wrong

Dates, quotations, repeated patterns, biased coins, and human-chosen words occupy tiny, guessable corners of the possible range. More characters do not automatically mean more entropy.

03

How wallets do it

Good wallets use a cryptographically secure random-number generator, ideally with hardware randomness and health checks. Generate keys in a trusted wallet or signing device, never on this page.

Interactive microscope

Build and inspect uncertainty

Learning only. Never use entropy shown by a website to protect real bitcoin.

Ask the operating system

The browser requests cryptographically secure bytes from your device. Regenerating should change roughly half the squares.

Secure device128 / 128 bits
Cryptographic source
Recorded
128 bits
Balance
Checking…
Longest run
Checking…
Average guess
Checking…
Hexadecimal view

Under the hood

Entropy becomes word indexes

BIP39 does not pick twelve words independently. It starts with entropy, appends checksum bits derived from SHA-256, then cuts the result into 11-bit indexes for a 2,048-word list.

128entropy bits
4checksum bits
12BIP39 words

Attacker's view

Small bit counts collapse quickly

Move the control to change the search space. This assumes an unrealistically favorable attacker trying one trillion guesses every second.

Possible values2^32Average guessing timeless than a second