Buy now

Set up a Ledger and you get twenty-four words. Set up MetaMask and you get twelve. Both are standard, both are correct, and the difference between them is smaller than almost anyone assumes. If you've been staring at a 24-word recovery phrase wondering whether the wallet that gave you twelve shortchanged you, the answer involves one piece of arithmetic and one much more useful question about where those words are going to live.

Where the number comes from

Your words aren't chosen by the wallet in any meaningful sense. They're an encoding of a random number, converted into language by a standard called BIP-39, which exists so that a backup made on one brand of wallet restores on another.

The mechanics are tidier than they look. BIP-39 defines a fixed list of 2,048 words, and since 2,048 is two to the eleventh power, each word carries exactly eleven bits. A wallet generating a phrase starts with raw randomness, takes a SHA-256 hash of it, appends the first few bits of that hash as a checksum, then slices the result into eleven-bit chunks and reads off the matching words. Twelve words means 128 bits of randomness plus a 4-bit checksum. Twenty-four means 256 bits plus an 8-bit checksum. The standard also allows 15, 18 and 21 words, which almost nothing uses.

That checksum is why typing a phrase with one word wrong usually produces an error rather than silently opening an empty wallet. It catches most transcription mistakes, though it can't catch all of them.

Does 24 words make you twice as secure?

No, and the gap isn't close to two times anything. Both numbers describe how many possible wallets exist, and both are past the point where guessing is a strategy.

Consider what 128 bits means as a quantity. It's roughly 340 undecillion, a 3 followed by 38 digits. An attacker running every computer on earth for the remaining lifespan of the sun does not make a dent in a number that size, because the energy required to merely count that high exceeds what's available. Going to 256 bits takes something already impossible and makes it more impossible, which changes nothing about your risk today.

Nobody has ever lost coins to a brute-forced 12-word phrase generated with proper randomness. The losses come from phrases that were written down where someone found them, typed into a website, stored in a photo library, or generated badly in the first place. The Coldcard exploit in 2026 drained roughly 116 million dollars from devices whose seeds were produced with a software random number generator instead of the hardware one, which is a failure of the randomness rather than the word count. Twenty-four weak words are worse than twelve strong ones.

The argument for 24 that does hold up

There's one technical case worth stating fairly. Grover's algorithm, a quantum search method, would cut the effective difficulty of brute-forcing a secret to roughly its square root, which turns 256 bits into about 128 and 128 bits into about 64. A 64-bit search is not comfortable in the way a 128-bit search is. Whether that ever becomes a practical concern depends on hardware that doesn't exist, and the more immediate quantum question in Bitcoin concerns exposed public keys rather than seed entropy, but if you want the extra margin, this is the reason to want it.

For most holders it's a rounding error compared to the risk of losing the paper.

What the extra twelve words cost you

Here's the trade nobody puts on the box. Twenty-four words is twice as much to transcribe by hand, twice as many chances to write an ambiguous letter, twice as much to verify, and twice as much to read back under stress years later. Handwriting errors and misread characters are among the most common reasons a restore fails, and the failure mode is discovering it at the worst possible moment.

Length also does nothing about the exposure that empties wallets in practice. A longer phrase is not harder to photograph, harder to find in a desk, or harder to phish out of someone who believes they're talking to support.

The question worth asking instead of 12 versus 24, and what your recovery should do

Word count is a distraction from the structure underneath it. Whether yours runs to twelve words or twenty-four, it's one secret, written on one object, and everything you own depends on that object surviving fires, floods, house moves, and your own filing decisions while staying unread by everyone who passes through the room.

Paper fails in obvious ways. Steel plates answer durability and are the sensible upgrade from paper, though the shape of the exposure is unchanged: one item still holds the whole thing. TapSafe Recovery takes a different route by splitting the dependency. A Recovery Tag holds half of what's needed, your paired phone holds the other half encrypted into your own iCloud or Google Drive rather than on the handset itself, and optional Recovery Contacts hold a quarter each while seeing nothing about your balances. No single object is worth stealing, and losing any one piece leaves you recoverable. It runs on a custom implementation of Shamir's Secret Sharing, and restores happen by tapping objects together instead of typing words into a screen.

The BIP-39 seed phrase stays on the device as a last resort, so you keep the standard and the freedom to restore anywhere.

If you already hold a phrase

Whatever length yours is, the useful checks are the same. Confirm it restores before you trust it with a balance you care about, keep it off anything with a camera roll or a cloud sync, and never type it into a site or an app because something told you your wallet needed validating.

The Ryder One imports an existing 12 or 24-word phrase and layers TapSafe on top, so moving across doesn't mean starting over. Keys are generated inside an EAL6+ certified secure element and never leave it, the device communicates over NFC alone, and every transaction is drawn in full on the 1.6-inch AMOLED screen before you approve it. Setup runs three taps and finishes in under a minute, and the Starter Combo is 149 USD with the Recovery Tag, wireless charger and pouch included. Get your Ryder One.


Meta description: Why a 24-word recovery phrase exists, how BIP-39 turns randomness into words, whether 12 words is less safe, and the question that matters more than length.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More