Will My Crypto
Early preview. This service is still in development and is not open for accounts.
The honest maths Prototype

How hard is it to crack?

Short answer: guessing a properly random 12 or 24 word recovery phrase is not realistic. Long answer: the numbers below, with every figure labelled as exact, estimated, or assumed. And the part that matters most: the real danger is almost never someone guessing a random seed.

The real risks are weak or reused passphrases, phishing and fake support, shares or backups that get lost, and mistakes. Big numbers protect random secrets. They do nothing for guessable ones.

The numbers

12-word recovery phrase
2128

≈ combinations. That is 128 bits of randomness; the last word also carries a checksum.

Show the math
  • 2128 = (exact calculation)
24-word recovery phrase
2256

≈ combinations. Every extra bit doubles the work, so 256 bits is not twice as hard as 128; it is 2128 times harder.

Show the math
  • 2256 = (exact calculation)
For scale
1078–82

Common estimates for the number of atoms in the observable universe. So 2256 is just a few powers of ten below that range. (Estimate, not exact.)

Picture it: one grain of sand

Estimates put the number of grains of sand on Earth at about 7.5 × 1018 (a popular estimate, not a precise count). Now imagine one of them is yours, and you must find it.

Each dot is a grain. The gold one is the secret. It keeps moving, because a guesser does not know where to look.

128 bits

The same as choosing one grain out of the sand on Earths.

Show the math
  • 2128 ÷ (7.5 × 1018) ≈ Earths

256 bits

The same as choosing one grain out of the sand on Earths.

Show the math
  • 2256 ÷ (7.5 × 1018) ≈ Earths

The guess machine

Give an attacker a computer and see how long a brute-force search would take. We compute it live from real numbers: the age of the universe (about 13.8 billion years), the size of the search, and the speed you choose. We show the average time, which is half the search, since on average you find the answer halfway through.

Bars use a log scale, so each step to the right is a billion billion times more. Honest caveats: this is the cost of guessing. Checking one wallet candidate takes thousands of operations, so real attackers are far slower than the raw figures. An exascale supercomputer does about a billion billion simple operations a second.

What actually goes wrong

Weak passphrases

Words, names, dates and small tweaks like Password1! fall in seconds. Our meter below shows how fast.

Phishing and fake support

Someone asks you, in a message or a convincing website, to type your seed phrase. The best encryption in the world cannot stop you handing it over.

Lost or gathered shares

If too many shares are lost, nobody can recover. If too many end up together, the split stops protecting you. Spread them out, and test.

Copies and mistakes

A photo of a recovery phrase, an old backup in cloud notes, a malware-infected computer. These beat any maths.

Passphrase strength meter

The encrypted letter is only as strong as its passphrase. The letter's key is derived with PBKDF2-SHA256 at 600,000 rounds, which makes every guess about 600,000 times more work than a plain hash. Even so, a weak passphrase falls fast. A long random one cannot be guessed.

Try a made-up passphrase, not your real one.This runs only in your browser and nothing is sent, but get in the habit of never typing real secrets into test boxes.
Try:

How the estimate works. It looks at length and variety, then deducts for patterns attackers try first: very common passwords, words with digits swapped in, years, repeats and sequences. It assumes a patient attacker with 1,000 powerful graphics cards, about 107 guesses per second against 600,000-round PBKDF2 (a rough figure: one top consumer card manages around 104 per second). It is an estimate, and a human-chosen phrase is usually weaker than any formula says.

What about quantum computers?

Quantum computers are a long-term consideration, mainly for some public-key algorithms such as the signatures many blockchains use today. For symmetric encryption such as the AES-256 used in the letter, the best known quantum attack is expected to cut the effective strength roughly in half (256 bits to about 128), which is still out of reach. Researchers and standards bodies are already preparing upgrades. This does not change the advice today: use a long random passphrase, keep shares apart, keep software updated, and review your plan every year.

Numbers and assumptions

  • Exact: 2128 ≈ 3.4 × 1038 and 2256 ≈ 1.16 × 1077.
  • Age of the universe: about 13.8 billion years (a measured estimate).
  • Atoms in the observable universe: commonly estimated between 1078 and 1082.
  • Grains of sand on Earth: about 7.5 × 1018 (a popular estimate).
  • Attacker speed: the slider is an assumption you choose, not a measurement. The graphics-card figure (about 104 guesses per second at 600,000 PBKDF2 rounds) is a rough estimate from public benchmarks.
  • The code that computes all of this is js/strength.js, with tests in tests/run.js.

This page is education, not a guarantee. A prototype tool and a passphrase estimate cannot promise your family will recover anything. See the disclaimer.

Lock a letter with a strong passphrase Try the whole flow