Shamir Secret Sharing is a construction published by Adi Shamir in 1979. It encodes a secret as the constant of a random polynomial over a finite field; it neither cuts up a phrase nor constitutes a signing protocol by itself.
A k-of-n scheme permits recovery from any k valid, distinct shares of the same set. It tolerates losing n−k shares, but also allows k cooperating holders to obtain the secret. For example, 3-of-5 tolerates two losses, not three. The threshold trades off availability against the size of a group capable of recovery. [Adi Shamir — How to Share a Secret (1979)]
For secret S, choose f(x)=S+a1*x+…+a(k−1)*x^(k−1). Coefficients other than S are independent, uniformly random field elements. A share is a pair (x,f(x)) with a distinct nonzero x; x=0 would reveal S outright. Lagrange interpolation from k points determines f(0). Two copies of the same point add no extra equation. [Adi Shamir — How to Share a Secret (1979)]
For teaching only, take S=5 and f(x)=5+3*x mod 17. Three shares are (1,8), (2,11), (3,14). The first two give slope 3 and constant 8−3=5; all three pairs recover 5. The single point (1,8) fits every S from 0 to 16 when a=8−S mod 17. This tiny field is not a wallet design. [Adi Shamir — How to Share a Secret (1979)]
In the ideal scheme, fewer than k complete shares provide no information about S, even to an attacker with unlimited computation. This assumes properly chosen independent coefficients and the specified observation model. Weak randomness, reused coefficients, side channels or additional checking data require separate analysis. Sharing cannot strengthen a weak secret guessable through other means. [Adi Shamir — How to Share a Secret (1979)] [SLIP-0039 — Shamir Secret-Sharing for Mnemonic Codes]
Recovery needs the same field, value encoding, indices and set identity. A prime field GF(p) uses modular inverses, not decimal division; GF(256) has different operations from arithmetic modulo 256. SLIP-39 adds a specific wordlist, metadata, groups, encryption and checks. Two programs labeled Shamir therefore need not have compatible shares. [Adi Shamir — How to Share a Secret (1979)] [SLIP-0039 — Shamir Secret-Sharing for Mnemonic Codes]
Basic interpolation authenticates neither a share's origin nor the distributor's honesty. A damaged point can return another secret rather than merely report insufficiency. Detection, error correction and verifiable secret sharing are additional constructions with their own assumptions. SLIP-39, for example, adds a checksum and digest; these additions cannot automatically be attributed to all Shamir Secret Sharing. [SLIP-0039 — Shamir Secret-Sharing for Mnemonic Codes] [NIST — Multi-Party Threshold Cryptography]
Ordinary recovery exposes the complete S in one environment, which can leak it. Unlike Multisig, Shamir Secret Sharing does not establish multiple independent on-chain signing keys. Threshold signing can use an additional MPC protocol to operate on shares without assembling the key, as NIST distinguishes. Simply splitting and later combining does not provide this property. [NIST — Multi-Party Threshold Cryptography]
Five files in one account do not separate loss or compromise risk. Record parameters and verify recovery on a trusted device. A new random polynomial with the same S creates another set whose shares should not be mixed with the old set. A sufficient old set still recovers S; resharing alone does not invalidate previously obtained shares or a leaked secret. [Adi Shamir — How to Share a Secret (1979)] [Trezor — Multi-share Backup]
For the clearest picture, read this entry together with SLIP-39, Multisig, Seed Phrase, Private Key, Bitcoin Inheritance Plan. The reverse links also lead from SLIP-39, FROST.