官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

Technical reference

BIP-39 passphrases: the wrong phrase can open a different wallet

Recovery words and the optional passphrase are separate inputs to key generation.

Source-based reference · Updated 12 September 2026

研究文章和参考条目以英语发布。导航提供七种语言。

本文目录
  1. Two inputs, one seed
  2. Why recovery can look successful but be wrong
  3. Backups need a recovery test
  4. Sources

Two inputs, one seed

BIP-39 describes mnemonic words and a process that derives a seed from the mnemonic plus an optional passphrase. The mnemonic is not simply an account password checked by a recovery server. Different passphrases derive different seeds.

Why recovery can look successful but be wrong

A wallet may accept the words and a mistyped passphrase without reporting a failed login. It can instead derive a different set of keys and show no expected funds. The same symptom can also arise from a different derivation path or account selection. An empty balance alone does not distinguish these causes.

Backups need a recovery test

Keep any passphrase backup separate according to the threat model, but ensure that recovery does not depend solely on memory. Test recovery on a trusted device without typing secrets into a website or support chat. Never publish the words or passphrase as evidence in a public finding. A checksum on the mnemonic cannot validate the correctness of the separate passphrase.

Sources

相关阅读

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包