Hardware & services · procedures

Roll your own seed

Pick a method and this page becomes only that method. If you have not decided yet, or you are not sure what your device allows, start at where your seed's randomness comes from.

First, pick a method — the three below

They differ in how much of the randomness is yours and how much work that takes, and which of them your own hardware can do at all — each tab says so before you open it. Everything else follows from that choice, including how long your seed should be, which each procedure helps you decide once you are inside it. If you have not met these options before, or you are not sure what your device allows, start at where your seed's randomness comes from.

Something awkward, and we would rather say it than have you notice it

2 of these options — the ones where the device's own randomness plays no part or gets yours mixed in — can only be performed on Coinkite hardware. And on 6 August 2026 we stopped recommending those devices for purchase. So the strongest on-device forms of this procedure live on the one brand we are steering new buyers away from.

We have not removed them, because a lot of readers own a Coldcard and this is exactly the thing they should be doing with it. What changed is which option we point at by default: option 1, the printed table, where you pick every word yourself. It is the most work here by a distance and we are not pretending otherwise — it is the default because it is the strongest form that most devices can actually do.

🛑 This page will never ask what you rolled

There is no box to type your throws into, and there is not going to be one. The list of numbers you roll IS your seed, written in a different alphabet — anyone who has it has your coins. rule 07 says key material never touches anything digital, and we are not making an exception for our own page. Every real throw goes straight into your hardware wallet — or, on the option that uses a printed table, onto paper you will destroy afterwards. Never onto a screen, and never into this one.

You pick every word

The device never generates anything.

You roll for each word and read it off a printed table, then type all but the last word into the device. The device computes only the final word, which carries the checksum and cannot be worked out by hand. Your randomness never touches a machine.

Devices we rate that can do this Coldcard Q · Coldcard Mk5 · Jade · Jade Plus · Jade Core · BitBox02

What it costs you About 173 throws and 23 coin flips for 24 words (83 and 11 for 12), each read off a printed table by hand. Set aside an evening.

The steps

  1. Decide 12 words or 24 — before you print anything. Both are standard and every wallet worth owning takes either. This is not really a security decision: 24 words carries more randomness than 12, and both are already so far past anything that could be guessed that neither is the weak point in your setup. It is a decision about WORK, and by hand the difference is large. 24 words means 23 lookups and roughly 173 throws; 12 means 11 lookups and about 83. That is an evening against an hour — and every lookup is another chance to write a word on the wrong line, which is the way this procedure actually goes wrong. Our suggestion: if this is a stack you mean to leave alone for years and you are doing it by hand anyway, take 24; the extra margin costs one more page of rolling, once, ever. If it is your first time, or the amount is modest, 12 done carefully beats 24 done tired. Whichever you pick, print that worksheet and only that one.
  2. You roll every word but the last one. So a 24-word seed is 23 lookups and a 12-word seed is 11, not 24 and 12. This surprises everyone the first time and nothing has gone wrong. The final word is not free to be anything: it has to agree with all the words in front of it, and that agreement is what lets a wallet tell you when you have mistyped one of them years later. It cannot be worked out with a die and a printed table, so your hardware wallet works it out for you at the end. That is why your worksheet has one greyed row at the bottom marked "not rolled", and why its count stops one short of the length you picked.
  3. Print the BIP-39 word table, a worksheet, and read the method sheet first. Three separate things, and it matters which is which: the BIP-39 WORD TABLE is the reference you look words up in and it is public; the WORKSHEET is where you write, and it becomes your seed; the METHOD SHEET is the one-page instructions. There is a worksheet for each seed length — print only the one you are doing. The downloads are directly below this list of steps. Read the method before you throw anything — it is the part that says which throws map to which column, and that 5s and 6s are rerolled, which is why no entry on the table contains one. The table holds no secret and is safe to print, photograph or leave lying about: it is the standard word list in a fixed order, and anyone can regenerate it.
  4. Update the firmware, then wipe the device. Even though the device plays almost no part here, it still holds the finished seed at the end. Do this first, on a device with no coins on it. If it already holds a wallet you care about, stop and deal with that separately — this procedure starts from empty.
  5. Clear the room. Phones out of the room. Laptop lids shut. Nothing recording, nothing on a call, nobody behind you. Get the die, the coin, the table, the pen and the paper out before you start so you are not walking around mid-sequence.
  6. Fill in one row at a time — throws, flip, then the word. The worksheet has a row per word: 3 boxes for the throws that find your block, 2 for the ones that find the line inside it, one for the coin, and the word itself at the end. Complete a row before you throw for the next one. Rerolled 5s and 6s are the exception and do not go in a box — they do not count and are not recorded, which is why no entry in the table contains one. Do not roll several words ahead: the row bands every five rows are there because the mistake this sheet exists to prevent is a word written on the wrong line. AND FROM THE FIRST MARK YOU MAKE, THIS SHEET IS YOUR SEED — the throws alone already are it, in another alphabet, before a word is written beside them. Never photograph it, never type it up, never leave it out, and keep it in the room until you are done.
  7. Count your words before the device is switched on. You should have exactly 23 words in order (or 11), each one legible and spelled the way the table spells it. Check the count and the spelling now. Half the BIP-39 list looks like the other half at a glance, and a word you cannot read later is a seed you cannot restore.
  8. Now the device — and only for the last word. Use the device's IMPORT or RESTORE flow, not "create a new wallet". That reads oddly the first time and it is correct: you are not asking it to make a seed, you are handing it one and asking for the final word. Type your words in, and at the last position the device does the only thing it does in this procedure — it produces a valid final word. Some devices calculate one for you; some offer the valid options and let you choose. There are 8 of them for a 24-word seed and 128 for a 12-word one, because a few bits of your own randomness still live in that word alongside the checksum. Your exact menu path is below.
  9. Write the final word in the last row, then wipe and restore. The worksheet keeps a box for it on the row marked "not rolled" — it is as much a part of your seed as the ones you chose. Then wipe the device and restore it from the full written list, so you find out today rather than in five years whether you transcribed it correctly.
  10. Copy to metal, and check each word as you copy. This is the permanent backup, and it has to exist before the paper one goes. Read each word off the sheet and check it again on the metal — this is the second of the two transcriptions in this procedure, and both of them are places a seed goes quietly wrong.
  11. Only now, destroy the worksheet. Once the words are on their permanent backup and you have restored successfully from it, the sheet has done its job and is nothing but a liability. Burn or shred it; do not simply bin it. Destroying it any earlier means the only copy of your seed is a device you have not finished testing.
  12. Fund it — small first. Send a small amount, confirm it arrives, then send a spend back out to prove you can move it. Only after that does the rest follow.
Print the PDF for your seed length

Print the PDF, not this page. Printing from a browser depends on your own margins, headers and background-graphics setting — and that last one silently drops every shade the sheets use to show you where you are. Each PDF holds the method, the worksheet for that length, and all 2,048 words of the BIP-39 word table.

24-word seed — 6 pages 12-word seed — 6 pages Just the table — 4 pages

Prefer to read it on a second screen? the word table, in the same layout as the PDF. The table contains no secret — it is the standard wordlist in a fixed order, and anyone can regenerate it.

On your device

Blockstream Jade · Jade Plus

Setup Jade → Advanced Setup → Restore Wallet → 12/24 Words → Calculate

Options → Temporary Signer → 12/24 Words reaches the same screen without committing the device. Choose Calculate, not Existing: Existing is for when you already know your final word.

This is the one method here that does not use a six-sided die. If all you own is a d6, this procedure is not available to you as written. And note who it is documented for: Blockstream keeps a single Jade section in its help centre, but this article’s wording and screens are the Jade and the Jade Plus. There is no Jade Core documentation for it, so we are not going to tell you the menu is identical on a Jade Core — check on the device before you commit to an evening.

Blockstream — Create a recovery phrase using dice ↗

BitBox02

Restore from recovery words → 24 words → enter your 23 words → pick one of the valid final words

It runs through the RESTORE flow rather than a create-a-wallet flow, which reads oddly the first time. That is the supported route in BitBox’s own guide, not a workaround.

BitBox is blunt about the trade: the standard setup already blends five independent entropy sources, and doing this by hand introduces mistakes that setup cannot make. Their guidance is to follow one documented method start to finish rather than improvise partway through.

BitBox — Create a Bitcoin wallet with your own entropy ↗

Foundation Passport Corepartial — see note

Import Seed → 12 words or 24 words → enter your first 11 or 23 words → Generate Final Word

Firmware 2.3.0 and later.

Half a documented procedure. We list it because the device really does offer the final-word step, not because Foundation has published a way to get to it with dice.

Foundation — Passport Core setup ↗

Coldcard Q · Mk4 · Mk5

Import Existing → 12 / 18 / 24 Words

On a device with no seed on it. Type the words you chose; as you reach the last one the device narrows the keyboard to the finals that make a valid checksum, so you cannot enter an impossible word.

Coinkite — Master Seed ↗

Coldcard Mk3

Import Existing → 24 Words

Twenty-four words only on this model — there is no 12-word equivalent. It offers the eight valid final words and you choose one.

Coinkite — security advisory ↗

Rolling a passphrase

If your setup is a passphrase on top of your seed, build that the same way, with the same dice and the same table. It is the identical act — roll, look the word up, write it down — and it takes minutes, because you need far fewer words.

Do not think one up. BIP-39 stretches a passphrase with only 2,048 rounds of hashing, so anyone holding your seed backup can test guesses offline as fast as their hardware allows, with nothing to rate-limit them. The structure that makes a phrase memorable is exactly what a cracking rig tries first.

Write the words down exactly as the table gives them, separated by single spaces, with no space before the first or after the last — a stray space is invisible on paper and is part of the secret. Then back it up as carefully as the seed and keep it somewhere the seed is not. The full reasoning, and the traps, are on rung 2.

← Why, and what your device allows Your setup checklist

Last verified: August 6, 2026