CatBitcoin
Two small steel plates resting on a dark shelf, one stamped with words, the other with a shorter string, soft daylight from a window.

Custody mechanics, again

Passphrase: the second key to your box

Updated 6 October 2026

That is a passphrase. It is not a password.

A seed is a tree, a passphrase is a forest

BIP-39 turns twelve or twenty-four words into a 512-bit seed through PBKDF2. Wallets stretch that seed into a near-infinite set of keys, then into addresses, which we call boxes on this site. Strip out the optional passphrase and the math gives you a single tree. With a passphrase, the same words stretch into a different seed, and a different tree, every time.

Change a single character and the tree vanishes. The original boxes are still there in memory, but unreachable, because nothing in the world points to them.

An open notebook on a wooden desk with a single short handwritten line, a pen beside it, morning light across the page.

Why wallets treat it as optional

Most wallet software lets you add a passphrase through a checkbox labelled something like "advanced", "25th word", or "hidden wallet". The wording matters less than the effect. Without a tick, the wallet uses the empty passphrase and shows you the boxes a thief would see if they copied your words. With a tick, a different set of boxes appears, hidden behind a string the thief does not have.

This is also why a passphrase is dangerous as a default. Lose the string and there is no reset link, no support email, and no recovery phrase that brings the second tree back. The words on paper remain valid. The boxes they unlock simply are not the boxes you wanted.

What the maths actually does

The function is the same PBKDF2 used on the words, run 2048 more times with the passphrase concatenated. The output is a 64-byte seed. SHA-512 inside HMAC, then fed into the BIP-32 master node. From there, the derivation path looks identical to a seed with no passphrase. A scanner reading the seed bytes off a hardware device would not see the passphrase, only the final tree.

That is by design. A passphrase is a property of the holder, not of the seed. The seed is the part you can write down and store. The passphrase is the part you keep in your head, or on a separate sheet, or in a different safe. Mixing the two on one piece of paper collapses the second lock back into the first.

The watch-only trap

Watch-only wallets import an xpub, never a seed. That is the point. They can see boxes, label them, and build transactions, but they cannot sign. The rule is rigid because the alternative is a single field that, if pasted into the wrong form, hands over the key to every box on the tree.

A passphrase is not a password manager

Passwords can be reset by email. A passphrase cannot, because there is no server. It is a string of bytes fed into a one-way function, with no record kept anywhere on the chain. The boxes it opens are private in the strict sense: only the holder knows they exist.

Backing up a second key

The safe way is two separate media. Seed on steel, passphrase on paper in a different room, or better, memorised and rehearsed until it survives a year of not being written down. Splitting the storage means a single fire, a single thief, or a single curious visitor cannot reconstruct the second tree.

A duress passphrase, a different string that opens a small decoy tree, is a step further. It is not a feature every wallet supports, and it adds a third secret to track. Treat it as an advanced option, not a default.

The closing line

A passphrase is the cleanest second lock Bitcoin offers. It is also the lock most likely to be forgotten, mistyped, or written on the same sheet as the first. Treat it as a separate secret, stored separately, and rehearsed like a phone number you cannot afford to forget. Never paste a seed into a watch-only field.

Quick answers

Does a passphrase change my seed words?
No. The twelve or twenty-four words are unchanged. The passphrase is added inside the stretching function and produces a different seed from the same words.
Can a wallet recover my passphrase if I forget it?
No. The passphrase is not stored, hashed on a server, or written to the chain. Forgetting it is identical to losing the coins, because the boxes it opens are unreachable.
Is a passphrase the same as a wallet password?
No. A wallet password locks the app on your phone. A passphrase is part of the key itself, and unlocks a different set of boxes that the seed alone cannot reach.