BIP39 appends the first ENT/32 bits of the entropy’s SHA-256 to ENT bits of entropy. The result is split into 11-bit wordlist indices. These check bits are publicly derivable and add no secret entropy.
BIP39 allows ENT = 128, 160, 192, 224 or 256 bits. The corresponding checksum lengths are 4, 5, 6, 7 or 8 bits, producing 12, 15, 18, 21 or 24 words. Each 11-bit group selects an index 0‑2047 in the applicable list of 2048 words. [BIP39 — Mnemonic generation and seed conversion]
For 128 bits, 128 + 4 = 132 = 12 × 11. The last word carries 7 entropy bits and 4 checksum bits. With 24 words, it carries 3 entropy bits and 8 checksum bits. You therefore cannot simply replace the last word with one universal check word. [BIP39 — Mnemonic generation and seed conversion]
Among uniformly random sequences of valid words, a fraction of 1/16 passes for 12 words and 1/256 for 24 words. This is a ratio across all possible sequences of that length, not a guarantee of detecting a particular typo or moved word. Some incorrect backups remain valid. [BIP39 — Mnemonic generation and seed conversion]
A validator maps words to bits using the correct wordlist, separates the entropy and compares the attached bits with its SHA-256. An attacker can calculate a valid checksum too. Weak or public input can therefore pass; the checksum is neither authentication nor a general error-correction algorithm. [BIP39 — Mnemonic generation and seed conversion]
The word checksum does not verify a BIP39 passphrase. Converting the phrase and passphrase with PBKDF2-HMAC-SHA512 produces a 512-bit seed separately from word validation. A valid phrase therefore does not confirm recovery of the original wallet. Preserve the exact words, their order and any required passphrase; translating the backup into another wordlist changes the seed. [BIP39 — Mnemonic generation and seed conversion]
Test implementations with public test vectors instead of your secret backup. Public vectors are not safe wallets for receiving funds. For recovery, follow your wallet’s trusted procedure; do not submit real words to an unknown web checker. A successful checksum check does not prove the application did not steal the words. [BIP39 — Mnemonic generation and seed conversion]
For the clearest picture, read this entry together with BIP 39, Seed Generation, BIP39 passphrase, Cryptographic Entropy. The reverse links also lead from BIP 39, BIP39 passphrase, COLDCARD RNG Incident (2026).