Buy now

If you set up Electrum at any point in the last decade and wrote down the words it gave you, there's something about that Electrum wallet seed you may not know. It isn't a BIP-39 phrase. It looks like one, it's the same kind of word list, and it will be rejected or silently misread by nearly every hardware wallet you try it on. People discover this at the worst possible moment, which is when the laptop is dead and the words are all they have left.

What makes an Electrum seed different

Since version 2.0, Electrum has used its own seed version system rather than the BIP-39 standard the rest of the industry settled on. Both take your words and stretch them into a master key using PBKDF2 with 2048 iterations of HMAC-SHA512, so the machinery looks identical from a distance. The difference sits in one small input: BIP-39 salts the process with the string "mnemonic", and Electrum salts it with "electrum" plus any extension word you added.

Change the salt and you get a completely different master key from the same words. Electrum also encodes a version number inside the phrase itself, a few bits that tell the software which derivation scheme to apply, which is why an Electrum seed carries information a BIP-39 wallet has no idea what to do with.

There's a reason Electrum went its own way. BIP-39 has no built-in way to signal which address type a phrase belongs to, so recovering into the wrong wallet can leave you staring at an empty balance while your coins sit at addresses the software never checked. Electrum's version bits solve that. The cost of solving it alone was compatibility with everything else.

What happens when you type it into a hardware wallet

One of two things, and the second is worse than the first.

Most devices validate the phrase against the BIP-39 checksum, fail, and tell you the seed is invalid. Annoying, and at least it's unambiguous. The other outcome is that the words happen to pass the checksum, the device accepts them, and it derives a wallet that has nothing to do with your coins. You get a clean, working, completely empty wallet, and no error message anywhere tells you that your bitcoin is fine and sitting somewhere your new device will never look.

This runs the other direction too, though more forgivingly. Electrum can import a BIP-39 phrase from another wallet if you go looking for the option during restore, and it warns you that it's doing something outside its own standard. The traffic is one-way by design.

The move you can make, and the one you can't

You cannot convert an Electrum seed into a BIP-39 seed. The words are an input to a key derivation function, and there is no procedure that turns one standard's phrase into the other's while pointing at the same coins.

What you can do is move the coins.

  1. Set up the hardware wallet first and let it generate its own seed. Complete the whole setup while nothing is in motion.
  2. Get a receive address from the new device and check it on the device's own screen rather than trusting what the computer shows you.
  3. Open your Electrum wallet, send a small test amount, and wait for it to confirm and appear on the new device.
  4. Send the rest, then leave the Electrum wallet alone for a while rather than deleting it, in case an old address you'd forgotten receives something.

Ten minutes of work, one network fee, and your holdings end up under a standard that any BIP-39 wallet on earth can read.

The other Electrum question people ask

Search interest in whether Electrum is safe has a history behind it. Beginning on 27 December 2018, attackers stood up a large number of malicious servers on Electrum's open server network, and when a user's transaction happened to route through one, the server returned an error telling them to download an update from an attacker-controlled site. The fake client then harvested credentials and drained wallets. Reporting from the time put early losses at well over 771 BTC, around 4 million dollars, and the campaign kept running for years, with cumulative totals later estimated near 24 million dollars including a single victim who lost 1,400 BTC.

Electrum itself was never broken. The software is open source, well regarded, and still maintained. What the episode exposes is the exposure that comes with a wallet whose keys live on a general-purpose computer: the attack came through a message on a screen, and a screen is something malware controls. A hardware wallet moves the approval step onto a device that malware cannot redraw, which is why pairing Electrum with a signing device has always been the sensible way to run it.

Once you've moved, the backup is the whole job

Here's the thing nobody tells you at the end of a migration. You've swapped one problem for another: instead of worrying about which software understands your words, you now have to keep those words alive through fires, floods, house moves and decades of forgetting where you put them. Paper handles none of that well. A stamped steel plate handles the fire and the water, and it still leaves your entire position resting on one object staying intact, staying hidden from visitors, and staying findable by you.

TapSafe Recovery is our answer to the object problem. Recovery splits across a Recovery Tag holding half of what's needed and your paired phone holding the other half, encrypted into your own iCloud or Google Drive instead of sitting on the handset, so losing either piece alone costs you nothing and stealing either piece alone gets a thief nowhere. Recovery Contacts are optional, hold a quarter each, learn nothing about your balances, and are set up in person with a tap. Underneath it runs a custom implementation of Shamir's Secret Sharing, and your seed phrase stays available on the device as a last resort under the BIP-39 standard.

Why we stayed on the standard

The Ryder One generates BIP-39 phrases and imports them, so a 12 or 24-word phrase from another vendor comes across and you can layer TapSafe on top rather than starting over. That compatibility is a promise about the exit rather than the entrance: if we stop making devices tomorrow, your words work in whatever you choose next, and nothing about your coins depends on our company still existing.

Anyone still holding an Electrum seed as their only backup has a dependency worth removing this week. Get your Ryder One.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More