Just wrapped up some heavy lifting on cracking BIP-39 phrases, specifically how to recover more than 4 missing words. It’s something all those wallet recovery companies shy away from because it costs a ton.
BIP-39 Recovery Techniques and Insights
16 replies 424 views
I'll get into the details here, share proofs of concept, and outline some cool tech insights. My code utilizes OpenCL for GPU speed-ups and Python for overall management.
So, some brute-force tools like Hashcat are using wNAF-4 bits for calculating public keys on the secp256k1 curve, which is a big deal in Bitcoin.
Definitely the PBKDF2-HMAC-SHA512 is the choke point in breaking BIP-39. It limits even high-end GPUs to about 3-4 million attempts per second. But we’ve crafted a super parallel kernel to speed things up.
gwei_blockNewbie
Posts: 185 · Reputation: 37
#5Jan 26, 2026, 07:37 AM
Hold on, before I get too caught up in this… how effective are your methods? Like, how long would it take to recover, say, 5 or 6 missing words from a 12-word phrase?
Good question. How can we run your code on our own rigs for BIP-39 recovery?
falcon2019Full Member
Posts: 90 · Reputation: 425
#7Jan 26, 2026, 06:34 PM
I think we should clarify that this tool is meant for cracking a limited number of missing words from mnemonics. Checked out the GitHub but not sure if everything there is ready for public use.
For those looking to try this at home, I’ve been gathering different versions during my research. More optimizations pop up regularly.
Right now, you’ll only get about 1.2 million seeds per second on average hardware, but the results for recovering up to 5 missing words look really promising.
What’s up with your mention of speed? You said billions per second, but isn't that misleading? Because using Kangaroo also hits that range.
Exactly! Your project is working with random points on the curve, which is different from Kangaroo. But it is a bit slower due to needing more calculations.
Just a quick tip for anyone running this on Windows: WDDM and TDR can mess things up. If possible, run it where the driver isn’t hovering over everything.
falcon2019Full Member
Posts: 90 · Reputation: 425
#13Jan 27, 2026, 07:44 PM
Also, should we include Electrum 2FA versions in the discussions? It could help if users at least remember one address for checking!
I’ve been playing around with PBKDF optimizations too. Found a neat trick with reusing values in the SHA-512 processing that really improves things.
ben.matrixNewbie
Posts: 3523 · Reputation: 35
#15Jan 29, 2026, 07:28 PM
Nice! That kind of optimization can make a real difference. 2.3 million seeds/sec on a powerful GPU is impressive, but for full recovery, it still takes ages.
ben.matrixNewbie
Posts: 3523 · Reputation: 35
#16Jan 31, 2026, 09:38 AM
Does this help with recovering master keys if we know the wallet hash? Brute-forcing passwords is the main way to go.
ben.matrixNewbie
Posts: 3523 · Reputation: 35
#17Jan 31, 2026, 10:29 AM
In testing, you'll see how many iterations are needed for a smoother operation. We’re seeing crack times of months for 5 missing words, but for 6 you’ll need some clues.
Related topics
- Making BIP-39 Seeds More Compact 17
- Issues with ripemd160 on Ubuntu 22 9
- New Bitcoin Improvement Proposal with $100 Reward 9
- Clipboard Vulnerabilities in Cryptocurrency Transactions 8
- Understanding the Differences Between Traditional and Simplified Chinese Mnemonics 6
- Running Bitcoin Core on a Laptop with Limited Storage 20