BIP39 Checksum

The checksum is the first ENT/32 bits of SHA-256(entropy), stored in the last word. Follow each step below with an official test vector.

Or random test entropy

Source: Test vector #1 This page never asks for your own mnemonic.

  1. Entropy: 128 random bits

    Hex
    00000000000000000000000000000000
    00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
    Explain

    BIP39 starts from 128 bits of entropy (ENT). Allowed sizes are 128 to 256 bits in steps of 32. Here the 32 hex characters are shown as 128 bits, 8 per byte.

  2. Hash the entropy with SHA-256

    SHA-256(entropy)
    374708fff7719dd5979ec875d56cd2286f6d3cf7ec317a3b25632aab28ec37bb

    First 4 bits of the hash: 0011 → checksum 0011

    Explain

    The checksum length is CS = ENT / 32 = 128 / 32 = 4 bits. They are the first 4 bits of the SHA-256 hash of the raw entropy bytes (not of the hex text).

  3. Append the 4 checksum bits

    00000000000 00000000000 00000000000 00000000000 00000000000 00000000000 00000000000 00000000000 00000000000 00000000000 00000000000 00000000011

    Entropy (128 bits)Checksum (4 bits)

    Explain

    Entropy + checksum = 128 + 4 = 132 bits, which divides exactly into 11-bit groups: (ENT + CS) / 11 = 12 words.

  4. Split into 12 groups of 11 bits

    Explain

    Each 11-bit group is a number from 0 to 2047 — an index into the 2048-word list. Only the last group contains checksum bits, which is why the last word cannot be chosen freely.

  5. Map each index to a word

    Mnemonic · 12 words
    1. 01abandon
    2. 02abandon
    3. 03abandon
    4. 04abandon
    5. 05abandon
    6. 06abandon
    7. 07abandon
    8. 08abandon
    9. 09abandon
    10. 10abandon
    11. 11abandon
    12. 12about
    Explain

    Index 0 is abandon and index 2047 is zoo. The words are joined with a single space to form the mnemonic.

How the BIP39 checksum works

BIP39 defines two formulas:

CS = ENT / 32 MS = (ENT + CS) / 11

ENT is the entropy length in bits, CS the checksum length in bits, and MS the mnemonic length in words. Taking the first CS bits of the SHA-256 hash and appending them to the entropy makes the total a multiple of 11, so it splits exactly into word indexes.

ENTCSENT + CSWords (MS)Checksum bits in last word
1284132124 of 11
1605165155 of 11
1926198186 of 11
2247231217 of 11
2568264248 of 11

What the checksum is for

The checksum catches most transcription mistakes: a wrong word, a swapped pair, a missing word. Wallets refuse to import a mnemonic whose checksum fails, which prevents silently restoring the wrong wallet from a typo.

It is not encryption and adds no security. Anyone with the words can recompute it.

Implementation notes

  • Hash the entropy bytes, not the hex string.
  • Take bits from the most significant bit of the first hash byte.
  • Read 11-bit groups big-endian: the first bit is the most significant bit of the index.
  • Check your implementation against all 24 English vectors in the official test vectors. You can step through each of them above.

To check a complete mnemonic, use the validator. To produce new test mnemonics, use the generator.

Frequently asked questions

Why is the last word of a mnemonic not random?

Part of the last word’s 11 bits are checksum bits calculated from all the other bits. For 12 words, 7 bits of the last word are entropy and 4 are checksum, so only 128 of the 2048 words are valid in that position for any given first 11 words.

Can I calculate the last word of my own phrase here?

No. This page only uses official test vectors or fresh random test entropy. Choosing words yourself and computing a last word produces weak, human-chosen entropy. A dedicated last-word tool may be added later as an offline-only feature.

Is the checksum hashed from the hex text or the bytes?

From the raw entropy bytes. Hashing the hex string is a common implementation bug; the test vectors on this page let you check your code.

How strong is the checksum?

It is a typo check, not a security feature: 4 bits for 12 words (1 in 16 chance a random error passes) up to 8 bits for 24 words (1 in 256).