Bitcoin Forum
October 06, 2026, 03:00:15 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Electrum made me afraid of BIP39.  (Read 332 times)
nc50lc
Legendary
*
Offline

Activity: 3290
Merit: 9237


Self-proclaimed Genius


View Profile
October 02, 2026, 08:58:32 AM
Merited by ABCbits (1), DireWolfM14 (1)
 #21

4.  I'm not 100% sure I understand Thomas' concern here, so I'll pass.
I think he's talking about the difference between the two specs' checksum;
Where BIP39 just includes the checksum to the mnemonic (thus still use the indexed word list to verify it)
While Electrum hashes the mnemonic to check for a valid "version_number" which also acts as its checksum. (doesn't need a wordlist to check, just hash)

It's inconsistent because BIP39's checksum is also the last few bits of the mnemonic, so to get those bits, the word list is required to see the bits represented by the word.
While using pbkdf2_hmac on the "seed phrase" to generate the "binary seed" is implemented to not require a fixed word list in the first place.
Any word list could have been used since calculating the binary seed doesn't require to check the number represented by each word, just hash of the words itself.
But verifying the checksum needs it.

This point looks personal to me since he's the one suggested that to BIP39 specs as he mentioned, but it makes sense nonetheless.

DireWolfM14
Copper Member
Legendary
*
Offline

Activity: 3010
Merit: 5920



View Profile WWW
October 02, 2026, 12:06:44 PM
 #22

4.  I'm not 100% sure I understand Thomas' concern here, so I'll pass.
I think he's talking about the difference between the two specs' checksum;
Where BIP39 just includes the checksum to the mnemonic (thus still use the indexed word list to verify it)
While Electrum hashes the mnemonic to check for a valid "version_number" which also acts as its checksum. (doesn't need a wordlist to check, just hash)

It's inconsistent because BIP39's checksum is also the last few bits of the mnemonic, so to get those bits, the word list is required to see the bits represented by the word.
While using pbkdf2_hmac on the "seed phrase" to generate the "binary seed" is implemented to not require a fixed word list in the first place.
Any word list could have been used since calculating the binary seed doesn't require to check the number represented by each word, just hash of the words itself.
But verifying the checksum needs it.

This point looks personal to me since he's the one suggested that to BIP39 specs as he mentioned, but it makes sense nonetheless.

Thanks for your explanation.  I just went back and re-read Thomas' point and it made sense to me this time around.  Agreed, it's odd and inconsistent that the implantation uses a hash of the first 11 (or 23) words but then requires the word list for the 12th (or 24th) word to complete the checksum. 

It is indeed a good suggestion if the intent is to modify or grow the word list at some later time.  Again, I'm still not sure why that would need to be done.  Word lists are available in multiple languages, and adding or substituting words isn't necessary given the overwhelming number of combinations currently possible.

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!