Free mnemonic checker for test phrases

BIP39 Mnemonic Validator & Last Word Finder

Check a seed phrase word by word, verify the BIP39 checksum, get spelling suggestions, and find every valid last word, all inside your browser.

No loginNothing sent or storedTest phrases only
BIP39 mnemonic validator checksA pasted phrase passes through three checks, word count, wordlist membership, and checksum, before a verdict.phraselegal winner …1. word count12 to 242. in wordlist2048 words3. checksumSHA256 bitsverdictvalidor the exact reason

Never paste a real wallet phrase here

Anyone who sees a seed phrase controls the funds behind it, and browser extensions can read what you type into any page. Use test vectors, throwaway phrases, or the samples below. This checker keeps the phrase in page memory only: it never writes it into the URL, never saves it, and never sends it over the network. Clear the box or close the tab and it is gone.

Input is normalized with NFKD, lowercased, and split on any whitespace, including the Japanese ideographic space.

Paste a 12, 15, 18, 21, or 24 word test phrase, or one word short of those counts to find the missing last word.

Why there is no share link

Other tools on this site encode inputs into the URL so a scenario can be shared. A seed phrase is a secret, so this checker never writes it into the address bar, browser history, or storage. To report a bug, share a public test vector instead of a phrase.

Show the spec behind the checks

Checks follow the BIP39 specification and use validateMnemonic and mnemonicToEntropy from @scure/bip39. Each word maps to an 11 bit index. The checksum is the first ENT/32 bits of SHA256 over the entropy, appended before the split into words.

About this tool

What this BIP39 mnemonic validator answers

This BIP39 mnemonic validator tells you whether a seed phrase is structurally valid: a correct word count, every word on the official 2048 word list, and a checksum that matches the entropy. When a phrase fails, it names the reason, suggests corrections for misspelled words, and lists every valid last word when the final word is missing or wrong.

It works as a mnemonic checker for wallet developers writing tests, support engineers triaging a recovery ticket, and anyone learning how the standard behaves. All ten BIP39 wordlists are supported, from English to Japanese and Traditional Chinese. Validation is structural only. A phrase can pass every check here and still open an empty wallet, because the checksum proves the words are consistent, not that they are yours.

How to use it

Pick the wordlist language first. English is loaded by default; any other language is fetched from this site the first time you select it. Then paste a test phrase into the box, or load one of the three samples: a valid public test vector, a phrase that fails the checksum, and an 11 word phrase that is one word short.

The result updates as you type. The seed phrase word count table highlights the matching row with its entropy and checksum sizes. The word table lists each position, the word, whether it is on the list, and up to three suggestions for unknown words. Click a suggestion to swap it in.

If the phrase has 11, 14, 17, 20, or 23 words, or if every word is valid but the checksum fails, press Find valid last words. Clicking a candidate completes the phrase. For a valid phrase you can reveal the entropy in hex behind a warning.

How the validation works

A mnemonic is a sequence of 12 to 24 wordlist words that encodes entropy plus a checksum. The entropy is the random part, from 128 to 256 bits. The BIP39 checksum is the first ENT/32 bits of the SHA256 hash of that entropy: 4 bits for 12 words, 8 bits for 24. Entropy and checksum are joined, split into 11 bit groups, and each group indexes a fixed wordlist of 2048 words.

Validation runs that process backwards. Input is normalized with NFKD, lowercased, and split on whitespace, which also covers the ideographic space used between Japanese words. Each word is looked up. Unknown words get suggestions from an exact four letter prefix match first, then the smallest Levenshtein distance. The phrase then goes to validateMnemonic from @scure/bip39, which decodes the indices and recomputes the checksum.

The BIP39 last word is special because it mixes entropy bits with checksum bits. In a 12 word phrase it holds 7 entropy bits and 4 checksum bits, so 128 of the 2048 words produce a valid phrase. In a 24 word phrase only 8 do. The finder tests all 2048 words and keeps the ones that pass.

Bit layout of a 12 word BIP39 phraseTwelve words of 11 bits hold 132 bits: 128 bits of entropy and a 4 bit checksum. The last word holds 7 entropy bits and the 4 checksum bits, so 128 of 2048 words can end a valid phrase.12 words × 11 bits = 132 bitsw1w2w3w4w5w6w7w8w9w10w11w12entropy: 128 bits4last word = 7 entropy + 4 checksum bits2^7 = 128 of 2048 words pass the checksum

Where the answer usually breaks down

A valid checksum is weak evidence of correctness. For a 12 word phrase, roughly 1 in 16 random word sequences passes, so a phrase with two swapped words can still validate. The checksum catches most single typos, not every mistake. Only the derived address confirms that a phrase is the one you wrote down.

Wrong standard is the second trap. Electrum seeds use their own version scheme and Monero seeds use their own wordlist, so both fail here even when correct. A BIP39 passphrase, sometimes called the 25th word, never appears in the mnemonic, so the validator cannot see it, and a valid phrase without the right passphrase opens a different, empty wallet. Suggestions are spelling help, not recovery: a misheard word may not be among the three closest matches.

When the answer is real and when it is not

The result is reliable for structural questions: is the seed phrase word count valid, is every word on the list, does the checksum hold, and which words can complete a phrase that is one word short. Those answers come straight from the spec and do not depend on any wallet.

It is not the right tool for recovering a real wallet. A missing word in an unknown position, several missing words, or a phrase you suspect is out of order all need an offline recovery tool that derives addresses and compares them with a known address. Do that on an air gapped machine, never in a browser tab.

How this tool differs from other mnemonic checkers

Many online checkers stop at valid or invalid. This one explains the failure, shows the bit budget for each word count, ranks spelling fixes, and runs the last word search on the same page. Full derivation tools such as a mnemonic code converter go further and derive keys; this page deliberately stops at validation. It also drops the share link found on the other tools here, because a secret should never travel in a URL.

The rules come from the BIP39 specification and the official English wordlist in the bitcoin/bips repository. Validation, entropy decoding, and the ten wordlists come from @scure/bip39, an audited JavaScript implementation by Paul Miller.

Recovering a wallet or building one?

Seed phrase handling is the highest risk boundary in a wallet product. Bring your recovery flow or key management design for a focused review.

Book a wallet security review

Frequently asked questions

How does a BIP39 mnemonic validator check a seed phrase?
A BIP39 mnemonic validator runs three checks in order. It confirms the phrase has 12, 15, 18, 21, or 24 words, confirms every word appears in the chosen 2048 word list, and recomputes the checksum from the entropy those words encode. A phrase is valid only when all three pass. This page also explains which check failed and suggests a fix.
What seed phrase word counts are valid under BIP39?
BIP39 allows 12, 15, 18, 21, and 24 words. Those lengths carry 128, 160, 192, 224, and 256 bits of entropy, plus a checksum of 4 to 8 bits. Any other count is invalid by definition. Most wallets use 12 or 24 words; Ledger devices default to 24, while many software wallets default to 12. An 11 or 23 word phrase is one word short.
Why does my seed phrase fail the checksum when every word is valid?
Every word can be on the list while the combination is still wrong. The final word must carry checksum bits that match a SHA256 hash of the entropy, so one substituted word, two swapped words, or a wrong word order breaks it. Check the words against the original backup in order, and confirm you picked the right wordlist language before editing anything.
How many valid last words exist for a 12 or 24 word phrase?
For a 12 word phrase, 128 of the 2048 words produce a valid checksum, because the last word holds 7 entropy bits and 4 checksum bits. For 24 words only 8 words pass, since 8 of the 11 bits are checksum. Phrases of 15, 18, and 21 words have 64, 32, and 16 valid last words. The finder on this page lists all of them.
Can I recover a seed phrase with one missing word?
If the missing word is the last one, the search space is small: at most 128 candidates for 12 words and 8 for 24. Each candidate is checksum valid, so you still need to derive addresses and match a known address to find the right one. A missing word in an unknown position multiplies the work and needs an offline recovery tool, not a browser.
Does a valid checksum prove the phrase opens my wallet?
No. The checksum only proves the words are internally consistent. Around 1 in 16 random 12 word combinations passes, so a phrase with a swapped pair can still validate. A wallet also depends on the optional passphrase and the derivation path. The only proof is deriving the address with the correct settings and confirming it matches the wallet you expect.
Is it safe to paste a seed phrase into an online mnemonic checker?
Not for a real wallet. Even when a page sends nothing, browser extensions, clipboard managers, and malware can read what you type. This checker keeps the phrase in page memory, writes nothing to the URL or storage, and makes no network request with it, but those protections cannot cover your device. Use it with test vectors and throwaway phrases only.
Do I only need the first four letters of each BIP39 word?
In the English list, yes. The BIP39 wordlist was chosen so the first four letters identify every word uniquely, which is why some metal backup plates store only four letters. This validator uses the same property: type a four letter abbreviation and the full word appears as the top suggestion. Words shorter than four letters, such as zoo, are stored whole.

Related services and reading

Wallet keys, seed phrases, and address checks.

Author: Mudassir Khan. Last updated October 8, 2026. Wordlists and checksum logic from @scure/bip39 1.6, matching the BIP39 reference lists.