Hardware & services · procedures
Roll your own seed
Pick a method and this page becomes only that method. If you have not decided yet, or you are not sure what your device allows, start at where your seed's randomness comes from.
They differ in how much of the randomness is yours and how much work that takes, and which of them your own hardware can do at all — each tab says so before you open it. Everything else follows from that choice, including how long your seed should be, which each procedure helps you decide once you are inside it. If you have not met these options before, or you are not sure what your device allows, start at where your seed's randomness comes from.
2 of these options — the ones where the device's own randomness plays no part or gets yours mixed in — can only be performed on Coinkite hardware. And on 6 August 2026 we stopped recommending those devices for purchase. So the strongest on-device forms of this procedure live on the one brand we are steering new buyers away from.
We have not removed them, because a lot of readers own a Coldcard and this is exactly the thing they should be doing with it. What changed is which option we point at by default: option 1, the printed table, where you pick every word yourself. It is the most work here by a distance and we are not pretending otherwise — it is the default because it is the strongest form that most devices can actually do.
There is no box to type your throws into, and there is not going to be one. The list of numbers you roll IS your seed, written in a different alphabet — anyone who has it has your coins. rule 07 says key material never touches anything digital, and we are not making an exception for our own page. Every real throw goes straight into your hardware wallet — or, on the option that uses a printed table, onto paper you will destroy afterwards. Never onto a screen, and never into this one.
You pick every word
The device never generates anything.
You roll for each word and read it off a printed table, then type all but the last word into the device. The device computes only the final word, which carries the checksum and cannot be worked out by hand. Your randomness never touches a machine.
The steps
- Decide 12 words or 24 — before you print anything. Both are standard and every wallet worth owning takes either. This is not really a security decision: 24 words carries more randomness than 12, and both are already so far past anything that could be guessed that neither is the weak point in your setup. It is a decision about WORK, and by hand the difference is large. 24 words means 23 lookups and roughly 173 throws; 12 means 11 lookups and about 83. That is an evening against an hour — and every lookup is another chance to write a word on the wrong line, which is the way this procedure actually goes wrong. Our suggestion: if this is a stack you mean to leave alone for years and you are doing it by hand anyway, take 24; the extra margin costs one more page of rolling, once, ever. If it is your first time, or the amount is modest, 12 done carefully beats 24 done tired. Whichever you pick, print that worksheet and only that one.
- You roll every word but the last one. So a 24-word seed is 23 lookups and a 12-word seed is 11, not 24 and 12. This surprises everyone the first time and nothing has gone wrong. The final word is not free to be anything: it has to agree with all the words in front of it, and that agreement is what lets a wallet tell you when you have mistyped one of them years later. It cannot be worked out with a die and a printed table, so your hardware wallet works it out for you at the end. That is why your worksheet has one greyed row at the bottom marked "not rolled", and why its count stops one short of the length you picked.
- Print the BIP-39 word table, a worksheet, and read the method sheet first. Three separate things, and it matters which is which: the BIP-39 WORD TABLE is the reference you look words up in and it is public; the WORKSHEET is where you write, and it becomes your seed; the METHOD SHEET is the one-page instructions. There is a worksheet for each seed length — print only the one you are doing. The downloads are directly below this list of steps. Read the method before you throw anything — it is the part that says which throws map to which column, and that 5s and 6s are rerolled, which is why no entry on the table contains one. The table holds no secret and is safe to print, photograph or leave lying about: it is the standard word list in a fixed order, and anyone can regenerate it.
- Update the firmware, then wipe the device. Even though the device plays almost no part here, it still holds the finished seed at the end. Do this first, on a device with no coins on it. If it already holds a wallet you care about, stop and deal with that separately — this procedure starts from empty.
- Clear the room. Phones out of the room. Laptop lids shut. Nothing recording, nothing on a call, nobody behind you. Get the die, the coin, the table, the pen and the paper out before you start so you are not walking around mid-sequence.
- Fill in one row at a time — throws, flip, then the word. The worksheet has a row per word: 3 boxes for the throws that find your block, 2 for the ones that find the line inside it, one for the coin, and the word itself at the end. Complete a row before you throw for the next one. Rerolled 5s and 6s are the exception and do not go in a box — they do not count and are not recorded, which is why no entry in the table contains one. Do not roll several words ahead: the row bands every five rows are there because the mistake this sheet exists to prevent is a word written on the wrong line. AND FROM THE FIRST MARK YOU MAKE, THIS SHEET IS YOUR SEED — the throws alone already are it, in another alphabet, before a word is written beside them. Never photograph it, never type it up, never leave it out, and keep it in the room until you are done.
- Count your words before the device is switched on. You should have exactly 23 words in order (or 11), each one legible and spelled the way the table spells it. Check the count and the spelling now. Half the BIP-39 list looks like the other half at a glance, and a word you cannot read later is a seed you cannot restore.
- Now the device — and only for the last word. Use the device's IMPORT or RESTORE flow, not "create a new wallet". That reads oddly the first time and it is correct: you are not asking it to make a seed, you are handing it one and asking for the final word. Type your words in, and at the last position the device does the only thing it does in this procedure — it produces a valid final word. Some devices calculate one for you; some offer the valid options and let you choose. There are 8 of them for a 24-word seed and 128 for a 12-word one, because a few bits of your own randomness still live in that word alongside the checksum. Your exact menu path is below.
- Write the final word in the last row, then wipe and restore. The worksheet keeps a box for it on the row marked "not rolled" — it is as much a part of your seed as the ones you chose. Then wipe the device and restore it from the full written list, so you find out today rather than in five years whether you transcribed it correctly.
- Copy to metal, and check each word as you copy. This is the permanent backup, and it has to exist before the paper one goes. Read each word off the sheet and check it again on the metal — this is the second of the two transcriptions in this procedure, and both of them are places a seed goes quietly wrong.
- Only now, destroy the worksheet. Once the words are on their permanent backup and you have restored successfully from it, the sheet has done its job and is nothing but a liability. Burn or shred it; do not simply bin it. Destroying it any earlier means the only copy of your seed is a device you have not finished testing.
- Fund it — small first. Send a small amount, confirm it arrives, then send a spend back out to prove you can move it. Only after that does the rest follow.
Print the PDF, not this page. Printing from a browser depends on your own margins, headers and background-graphics setting — and that last one silently drops every shade the sheets use to show you where you are. Each PDF holds the method, the worksheet for that length, and all 2,048 words of the BIP-39 word table.
24-word seed — 6 pages 12-word seed — 6 pages Just the table — 4 pages
Prefer to read it on a second screen? the word table, in the same layout as the PDF. The table contains no secret — it is the standard wordlist in a fixed order, and anyone can regenerate it.
On your device
Blockstream Jade · Jade Plus
Setup Jade → Advanced Setup → Restore Wallet → 12/24 Words → Calculate
Options → Temporary Signer → 12/24 Words reaches the same screen without committing the device. Choose Calculate, not Existing: Existing is for when you already know your final word.
This is the one method here that does not use a six-sided die. If all you own is a d6, this procedure is not available to you as written. And note who it is documented for: Blockstream keeps a single Jade section in its help centre, but this article’s wording and screens are the Jade and the Jade Plus. There is no Jade Core documentation for it, so we are not going to tell you the menu is identical on a Jade Core — check on the device before you commit to an evening.
BitBox02
Restore from recovery words → 24 words → enter your 23 words → pick one of the valid final words
It runs through the RESTORE flow rather than a create-a-wallet flow, which reads oddly the first time. That is the supported route in BitBox’s own guide, not a workaround.
BitBox is blunt about the trade: the standard setup already blends five independent entropy sources, and doing this by hand introduces mistakes that setup cannot make. Their guidance is to follow one documented method start to finish rather than improvise partway through.
Foundation Passport Corepartial — see note
Import Seed → 12 words or 24 words → enter your first 11 or 23 words → Generate Final Word
Firmware 2.3.0 and later.
Half a documented procedure. We list it because the device really does offer the final-word step, not because Foundation has published a way to get to it with dice.
Coldcard Q · Mk4 · Mk5
Import Existing → 12 / 18 / 24 Words
On a device with no seed on it. Type the words you chose; as you reach the last one the device narrows the keyboard to the finals that make a valid checksum, so you cannot enter an impossible word.
Coldcard Mk3
Import Existing → 24 Words
Twenty-four words only on this model — there is no 12-word equivalent. It offers the eight valid final words and you choose one.
Your rolls, hashed by the device
Its random number generator plays no part.
You press each roll into the device as it happens. It hashes the sequence and turns that into your words. None of its own randomness is mixed in.
The steps
- Decide 12 words or 24, and a roll target. Pick the length first — it is the menu item you choose on the device, so you need it before you touch anything. Then pick how many times you will roll. 100 throws for a 24-word seed is our recommendation and 50 for a 12-word one; those are the counts at which your own dice alone carry the full strength of the seed, and Coinkite's own minimums sit just underneath them. The device counts for you and will not let you finish short, so the number is a target to head for rather than something to keep track of. It goes quicker than it sounds: roll, press, roll, press.
- Update the firmware, then wipe the device. Do this before anything else, on a device with no coins on it — and do it now, while you still have a computer and the internet to hand, because the next step shuts all of that down. A dice seed generated on old firmware is still a seed generated on old firmware. If the device already holds a wallet you care about, stop and deal with that separately: this procedure starts from empty.
- Clear the room. Phones out of the room. Laptop lids shut. Nothing recording, nothing on a call, nobody behind you. Get the die out before you start so you are not walking around mid-sequence.
- Find the dice screen on your device. Get to the exact screen before you throw anything. The menu path is below and it is different on every make; on at least one it has moved between firmware versions. This is not the moment to be hunting.
- Roll and enter, one at a time. Throw the die, read it, press it, throw again. Do not throw a handful and read them off, and do not roll ahead while entering — the moment you are working from a short list you have written down, that list is your seed sitting on a table. The device shows its own count as you go, so there is nothing for you to record.
- Keep going until you pass your target. Watch the count on the screen and stop when it is past the number you picked. Overshooting costs you nothing and removes the only question you cannot answer later, so if you lose track, keep rolling rather than guessing — more throws than you think is fine, fewer is not.
- Write the words down, on paper, by hand. Read them off the device screen. Not a photo, not a QR code into anything, not read aloud. Check the spelling of each word against the device before moving on — half the BIP-39 list looks like the other half at a glance.
- Wipe the device and restore from your written words. Before anything goes in. This is the step that tells you today, rather than in five years, whether what you wrote down actually rebuilds the wallet. If it does not restore, you have lost nothing yet.
- Copy the words to metal, and check each one as you copy. Paper survives a drawer; it does not survive a fire or a flood. Read each word off your sheet and check it again on the metal — this is the second of the two times you transcribe your seed, and both are places one goes quietly wrong.
- Fund it — small first. Send a small amount, confirm it arrives, then send a spend back out to prove you can move it. Only after that does the rest follow.
On your device
Coldcard Q · Mk4 · Mk5
New Seed Words → Advanced → 12 Word Dice Roll or 24 Word Dice Roll
On a device with no seed on it yet. This is the route on current Q, Mk4 and Mk5 firmware — the Mk3 is a different menu entirely, and has its own entry below.
Coldcard Mk3
Import Existing → Dice Rolls
On an empty Mk3 running firmware 4.2.0 or later — update first, or the device you are about to trust is the one with the defect. Coinkite calls this an advanced procedure and says so plainly; the ordinary New Wallet flow on 4.2.0 is already fixed and is the safer choice unless you specifically want the device to have no hand in your entropy.
Your rolls added to the device’s own
Belt and braces.
The device generates as usual, and you add as many rolls as you like on top. The two are combined.
The steps
- Decide 12 words or 24. Pick 12 or 24 words as usual; longer is the easy answer since the effort is the same either way. There is no roll target on this option — the device has already produced a full-strength seed on its own and yours is being added on top, so any number of throws is an improvement and none of them is a threshold.
- Update the firmware, then wipe the device. Do this before anything else, on a device with no coins on it — and do it now, while you still have a computer and the internet to hand, because the next step shuts all of that down. A dice seed generated on old firmware is still a seed generated on old firmware. If the device already holds a wallet you care about, stop and deal with that separately: this procedure starts from empty.
- Clear the room. Phones out of the room. Laptop lids shut. Nothing recording, nothing on a call, nobody behind you. Get the die out before you start so you are not walking around mid-sequence.
- Find the dice screen on your device. Get to the exact screen before you throw anything. The menu path is below and it is different on every make; on at least one it has moved between firmware versions. This is not the moment to be hunting.
- Roll and enter, one at a time. Throw the die, read it, press it, throw again. Do not throw a handful and read them off, and do not roll ahead while entering — the moment you are working from a short list you have written down, that list is your seed sitting on a table. The device shows its own count as you go, so there is nothing for you to record.
- Stop whenever you want to. Ten throws are better than none and a hundred are better than ten, but nothing happens at any particular number and nothing is waiting to be satisfied. This is the step that costs you the least in the whole procedure, and it is why this is the option we suggest by default.
- Write the words down, on paper, by hand. Read them off the device screen. Not a photo, not a QR code into anything, not read aloud. Check the spelling of each word against the device before moving on — half the BIP-39 list looks like the other half at a glance.
- Wipe the device and restore from your written words. Before anything goes in. This is the step that tells you today, rather than in five years, whether what you wrote down actually rebuilds the wallet. If it does not restore, you have lost nothing yet.
- Copy the words to metal, and check each one as you copy. Paper survives a drawer; it does not survive a fire or a flood. Read each word off your sheet and check it again on the metal — this is the second of the two times you transcribe your seed, and both are places one goes quietly wrong.
- Fund it — small first. Send a small amount, confirm it arrives, then send a spend back out to prove you can move it. Only after that does the rest follow.
On your device
Coldcard Q · Mk4 · Mk5
New Seed Words → Advanced → 12 Word Dice Roll or 24 Word Dice Roll
On a device with no seed on it yet. This is the route on current Q, Mk4 and Mk5 firmware — the Mk3 is a different menu entirely, and has its own entry below.
Coldcard Mk3
Import Existing → Dice Rolls
On an empty Mk3 running firmware 4.2.0 or later — update first, or the device you are about to trust is the one with the defect. Coinkite calls this an advanced procedure and says so plainly; the ordinary New Wallet flow on 4.2.0 is already fixed and is the safer choice unless you specifically want the device to have no hand in your entropy.
Rolling a passphrase
If your setup is a passphrase on top of your seed, build that the same way, with the same dice and the same table. It is the identical act — roll, look the word up, write it down — and it takes minutes, because you need far fewer words.
Do not think one up. BIP-39 stretches a passphrase with only 2,048 rounds of hashing, so anyone holding your seed backup can test guesses offline as fast as their hardware allows, with nothing to rate-limit them. The structure that makes a phrase memorable is exactly what a cracking rig tries first.
- Six words — 66 bits, 30 throws and 6 coin flips. The floor for any passphrase worth having.
- Eight words — 88 bits, 40 throws and 8 coin flips. For savings, or anything you would not want to explain losing.
Write the words down exactly as the table gives them, separated by single spaces, with no space before the first or after the last — a stray space is invisible on paper and is part of the secret. Then back it up as carefully as the seed and keep it somewhere the seed is not. The full reasoning, and the traps, are on rung 2.
✓ Last verified: August 6, 2026