1. Your account, your autonomy – the scale of 2^256▴
Do you want to feel, think, and speak freely, without your account being subject to seizure?
No banker, no ideological screening, no credit scoring, no monthly maintenance fees - nothing stands in your way of setting up one account, or many.
Do you need a hundred accounts, a thousand accounts? It doesn't matter.
Set up as many accounts as you need - and can manage.
Can you imagine all this?
Oh, and there are no terms and conditions or fine print.
You don't need a OTP (One Time Password) generator, no authorization, no bank card (with an expiration date).
There are no transaction limits, no national borders, no negative interest on deposits ...
And yet, these self-created accounts are more secure than typical bank accounts!
They are even protected from yourself - in case you misplace, forget, or lose your access data.
That is the 'price of freedom' for these accounts - It is up to you to guard the 'key to the vault'.
Does that scare you, or do you love self-responsibility?
You can create a high-security account on your computer in seconds; or many, as many as you like...
You can even create account numbers by hand, in peace and at your leisure, using dice.
Real account numbers, mind you, onto which you can deposit as much wealth as you wish.
You can even deposit any number of different currencies into each account!
Do you prefer self-determination, self-responsibility, and autonomy over subservience and external control?
Does that sound too good to be true?
In the world of cryptocurrencies, this is exactly the standard. Your „digital vault“ is not based on a contract with a bank, but on simple mathematics.
The number that protects your assets is: 2 to the power of 256.
To understand why your digital property is so secure, we have to stretch our imagination. When we talk about security, we often think of locks, safes, or alarm systems. With cryptocurrencies, however, security is not a physical object, but a mathematical law of probability.
Why this number changes everything:
2 to the power of 256 is not just a big number. It is so large that it far exceeds the number of atoms in the observable universe.
Before diving deeper into the mathematics of the number 2 to the power of 256, I would like to share a few philosophical thoughts on the bigger picture:
Why Financial Decentralization Is Not a Luxury, but a Contribution to Securing Peace
For some people, the word "math" is a trigger because it brings back school days when an out-of-touch math teacher failed to connect abstract numbers to lived reality. For others, "cryptocurrency" is an allergen because they believe these coins are backed by nothing, making them economic bubbles that will burst sooner or later, causing investors to lose all their money.
To those who do not love mathematics - or do not love it yet - let it be said that numbers occur everywhere in creation; in other words, they are a divine reality. Mathematics is essentially the description of the world in numbers. All growth, from single-celled organisms to giant redwood trees, follows natural laws that run with precise mathematical order. This creates fascinating geometric patterns such as a sunflower or a nautilus shell.
And cryptocurrencies are indeed backed, even if nothing physical can be seen.
Before diving deeper into that, let us look at conventional currencies: currencies issued by princes, kings, and emperors - generally speaking, by authorities and royalties - have existed for millennia. These were practically always centrally organized and served as an expression of power and force. To maintain or expand power, these 'currencies' were frequently abused or deployed in the interest of the rulers: inflation, deflation, war financing, national debt, fraud, betrayal of savers, and much more. When these centralized currencies failed, dark chapters of humanity's history often followed. The price for state money monopolies, abusive debt management, and arbitrary devaluation has always ultimately been paid by people with their freedom and their lives - and, often overlooked, by animals and plants as well.
Even the darkest chapter of German history is directly linked to the conventional monetary system:
From the ruins of the Weimar hyperinflation of 1923 - well over 100 years ago - to the Great Depression beginning in 1929, the ground was laid for totalitarianism and extremism.
The resulting Nazi regime exploited this severe crisis, built its massive rearmament on covert shadow credit (MEFO bills), and ultimately looted the gold reserves and central banks of occupied nations to finance its wars.1
Currency crashes and famines, state currency devaluation, national bankruptcies, and ruthless imperialist predatory campaigns - right up to global economic crises and totalitarian wars driven, mind you, by financial motives - have over the course of millennia certainly cost hundreds of millions, if not over 1 billion, human lives. To this should be added the countless ancient and early modern wars fought to conquer gold, silver, and resource sources, or to exact crushing taxes. When one considers that every murdered person leaves behind a collective trauma in their complex family network, the ocean of human suffering left behind by central monetary systems based on coercion and power becomes immeasurably vast.
Furthermore, conventional currencies have massively influenced the transformation of agriculture over the past 150 years. Small-scale farming characterized by hedges, diverse biotopes, and — most importantly — a heart-connection between the farmer and the land has been pushed aside. It has given way to ever-larger operations utilizing ever-larger machines, more oppressive debts, and growing dependencies on subsidies. Instead of stabilizing the foundations of life for coming generations and perfecting the habitat, it was only about profit anymore. Without a heart-connection to the land, farmers were intent solely on reaping maximum financial gain, come what may, even if erosion increased and humus was lost.2
The massive, practically always subsidy-driven expansion of solar and wind power plants in the open countryside is also an expression of our monetary system, which is based on constantly new and rising debt (fiat money / debitism: the eternal search for a successor debtor). Climate protection, perhaps even well-intentioned in its beginnings many decades ago, has degenerated into yet another redistribution from the hardworking to the rich, into a further destruction of our means of subsistence, and into a desperate attempt to stall the systemically guaranteed state bankruptcy a little bit longer.
Since all life on Earth — plants, animals, and humans — is based on the existence and quality of humus, the large-scale destruction of the landscape is a concrete threat to life itself. It is not for nothing that the words 'human' and 'humus' share the same origin. We humans are 'earthlings'. Thus, centralist conventional fiat currencies not only destroyed millions of human lives as a consequence of their respective failures, but they are now also undermining the survival chance of humanity as a whole.
Compared to all this suffering and pain, the lost profits of individual pioneers in crypto investments are not even the itch of a mosquito bite.
Whoever decentralizes the financial base and breaks the coercion ultimately protects not only their savings, but also deprives industrial soil destruction of its foundation.
Because I am resolutely opposed to any life-hostile extremism, I have an open heart for problem-solving pioneer projects. For me, a decentralized, counterfeit-proof monetary system is not an object of speculation, but a crucial contribution toward preventing the repetition of such historical catastrophes. Whoever decouples means of payment from state arbitrariness and central power deprives totalitarian systems of their breeding ground.
Compared to conventional, centrally issued currencies, cryptocurrencies are a new phenomenon, a pioneer project.
The fact that shady characters in the crypto sphere are now also trying to lure weak minds into greed and hype with false promises of hope does nothing to change the groundbreaking foundation of the project itself. Some of these shady characters, through their flashy and aggressive manner, easily give newcomers the impression that everything to do with crypto is just about making a quick buck. That is by no means the case.
Bitcoin, the first cryptocurrency with a decentralized ledger system on a blockchain, started on January 3, 2009, with the generation of "Block 0", the so-called genesis block. The following message was immortalized in this code: "The Times 03/Jan/2009 Chancellor on brink of second bailout for banks" Its creator, Satoshi Nakamoto, wrote about it in February 2009: “The root problem with conventional currency is all the trust that's required to make it fiat work. The central bank must be trusted not to debase the currency, but the history of fiat currencies is full of breaches of that trust. Banks must be trusted to hold our money and transfer it electronically, but they lend it out in waves of credit bubbles with barely a fraction in reserve. We have to trust them with our privacy, trust them not to let identity thieves drain our accounts. Their massive overhead costs make micropayments impossible. [...] With e-currency based on cryptographic proof, without the need to trust a third party middleman, money can be secure and transactions effortless.” 3
Cryptocurrencies are thus clearly and recognizably backed by humanity's endeavor to free itself from the yoke of central banks, state fraud and manipulation, as well as warmongering and the destruction of the foundations of life. This immaterial backing is in my opinion more valuable than physical gold. Whoever invests seriously and long-term in cryptocurrencies trusts mathematics, creation, or - to put it directly: God.
This choice of words may seem surprising, but upon closer inspection, close parallels can be found between the conventional banking system and the church: credit and credo (creed); creditor and belief/faith (gläubiger / glaube); debts and confession of guilt (schulden / schuldgeständnis); money is "created/spawned" ("geschöpft") and the priest talks about the "story of creation" (Schöpfungsgeschichte)...
Conventional central banks share structural similarities with churches, right down to the Vatican. Decentralized cryptocurrencies, on the other hand, dispense with a central authority and are thus an expression of humanity's evolution toward self-responsibility and self-organization-the recognition that every individual is a co-creator of God.
Cryptocurrencies - in particular systems for absolute self-custody and physical data backup - currently fulfill an important function: They break the monopolies of centralized institutions and teach us how to handle value and sovereignty in the digital space with personal responsibility. They are, so to speak, the tool for a global, decentralized coming of age.
Of course, the development and operation of cryptocurrencies require electricity, meaning energy. They also need hardware: computers and the internet. However, conventional currencies also require energy and hardware, with all their bank towers, data centers, branches, etc. ... Furthermore, with the increasing liberation of the creativity of the human mind, there are continually new insights and inventions. Whether through highly efficient consensus mechanisms or completely novel protocol structures: It can be expected that there will be more and ever better new solution ideas the more suppression fades.
Though the monopolies do not want to be broken, their time has - in my view - run out: The more EU bureaucracy tries to shackle cryptocurrencies through increasingly totalitarian regulations and control over the central gateways (fiat exchanges), the more the effect will likely backfire: Freedom-loving people are likely to detach themselves further and further from the fiat system and begin operating directly and seamlessly in crypto, peer-to-peer, or other unregulatable payment methods, or to scale down their official economic output to the point where they no longer have a tax burden. Not that I would recommend the following, but it cannot be ruled out that some will go so far as to voluntarily and intentionally settle into state welfare until human- and business-friendly times arrive.
The old will pass away, the new will emerge. Let us now shift our focus away from the decay of the old and toward the mathematical foundation of the new — cryptocurrencies:
Let us return to the number that changes everything: 2 to the power of 256.
If someone wanted to try and guess one billion account numbers every second, it would take them longer than the universe has existed to check even a fraction of these combinations. This sheer size is the "fortress" in which your wealth lies. There is no hacker in the world, and no supercomputer - and there never will be - that could ever guess the "combination" to your vault. As long as you keep your access data highly confidential and do not make any mistakes, your accounts are secure, absolutely secure.
This sounds phenomenal! However, everything has its price: what is mathematically impossible to guess is just as impossible for humans to find again in the event of a loss. And since there are no bankers in the self-service bank who could reissue a lost debit or Visa card, everything is lost if you lose your access data to 2 to the power of 256 possible account numbers.
The number 2 to the power of 256 is a very large number. It is truly very, very large.
Let's start small, with the number 2:
All electronic digital devices use binary codes with the state '0' or '1'.
Here, '0' stands for 'no voltage' and '1' stands for voltage (usually 5 volts).
A binary code with multiple positions can have either the state '0' or '1' at each position.
A two-digit binary code has two positions, each of which can have two states (0 or 1).
Mathematically, this is called 2 to the power of 2.
A two-digit binary code can represent 4 different values:
00 01 10 11
A three-digit binary code can represent twice as many values:
2 * 2 * 2, or mathematically called '2 to the power of 3' (2³ = 8):
000 001 010 011 100 101 110 111
An 11-digit binary code is therefore the number 2 multiplied by itself 11 times:
2*2*2*2*2*2*2*2*2*2*2, mathematically called 2 to the power of 11 (2¹¹ = 2048):
The possible values begin like this:
00000000000 00000000001 00000000010 ...
and end like this:
... 11111111101 11111111110 11111111111
A chessboard has 8 * 8, so a total of 64 squares.
There is a story from Asia where a ruler wanted to do someone a favor. The person asked for grains of wheat: one grain on the first square of a chessboard, double that on each subsequent square... what looked like little at the beginning, just 64 grains at the end of the first row... the ruler probably laughed at first until the laughter faded... towards the end of the chessboard it becomes so large, it is simply no longer realizable because the corresponding amount of grain would be many thousands of times the world's annual production.
We have the doubling of possibilities with every additional position in binary codes as the number of positions grows, exactly the same. The difference, however, is that we start with the number 2 at the first square of the chessboard, because either '0' or '1' can also stand on this field. A binary code with 64 positions therefore has 2 to the power of 64 different possibilities.
Exponential growth (Chessboard squares 1–8)
Each step doubles the value. At square 64, the bar would be billions of kilometers long.
With 'only' two chessboards, i.e., 128 squares, every single grain of the many thousands of times the world's annual production would become an additional many thousands of times the world's annual production... mind you, from every single grain... This alone already exceeds the imagination of the human mind.
Four chessboards have a total of 4 times 64 = 256 squares.
A 256-digit binary code, and that is exactly what we are dealing with in cryptocurrencies (if it is a seed phrase with 24 words), has 2 to the power of 256 different possibilities. That goes absolutely into the astronomical, practically infinite.
To try and approach an idea of 2 to the power of 256, let's take practically the smallest thing we have in physical reality: An electron!
An electron is one of the most elementary particles of our universe. Unlike atoms or molecules, an electron, according to current quantum physics, has no measurable internal structure - it is considered "point-like." To be able to calculate with it, physicists use the so-called "classical electron radius" (also known as the Lorentz radius). This is the theoretical sphere of influence of an electron.
This radius is so unimaginably tiny that one can hardly write it down in millimeters:
• Diameter of an electron: 0.00000000000282 mm
(That is approximately 100,000 times smaller than an atom)
Now, we line up (virtually, of course) as many electrons in a row as there are possibilities in 2 to the power of 256...
You arrive at 3.265 times 10 to the power of 62 meters.
That is, again, a number that a human cannot grasp.
So let's take something really big: The distance of a light-year, i.e., the distance that light travels within one year!
A light-year is approximately 9.5 times 10 to the power of 15 meters long, which is far, far shorter than the mentioned 3.265 times 10 to the power of 62 meters.
Then let's take something ultimately big: The diameter of the visible universe:
93 billion light-years... Sounds really big, right?
But for the (virtual) row of electrons as an expression of the myriad combination possibilities of 2 to the power of 256, 93 billion light-years is still a trifle!
The (virtual) row of electrons would have to go multiple times across the entire visible universe, specifically 370 decillion times (a number with 35 digits before the decimal point).
And somewhere on this practically infinite stretch stands a single electron for your own cryptocurrency account connection, which you can ONLY access if you have the right passwords ready. ...
Does it now become visually understandable that one can no longer find a lost 'crypto account number'?
Has the importance of securing access data to the crypto account become drastically apparent?
I certainly hope so!
To conclude this chapter, I will provide the first and last two combinations of the binary code with 2 to the power of 256 possibilities.
It is a code with 256 positions, where a '0' or a '1' can stand at each position.
The possible values begin like this:
...
and end like this:
2. What is a seed?▴
Following the astronomical numbers in Chapter 1, we return to somewhat smaller figures... The "crypto account number," with its 256 zeros and ones, is rather unwieldy despite its comparative brevity and is mercilessly error-prone when typed out.
A few years after the introduction of Bitcoin (the first cryptocurrency), an improvement proposal was submitted in September 2013. It was the 39th proposal (BIP = Bitcoin Improvement Proposal), and it published a wordlist of 2048 words (2 to the power of 11). This list became the global standard for cryptocurrencies and is called the BIP39 wordlist. Each word represents an 11-digit binary code.
The words are selected in such a way that they can be clearly distinguished from one another and can be uniquely identified by their first four letters, even if the entire word is longer. For example, "ABAN" stands for "abandon" - it represents the binary code 00000000000, the first of the 2048 possibilities - and there is no other word in the list that starts with "aban." The next word is "ability," shortened to four characters and displayed in capital letters for better readability: ABIL, representing the binary code 00000000001.
Worth knowing: The BIP39 wordlist
The list comprises 2048 English words. The complete list can be looked up on GitHub.
For illustration, I provide the beginning of the list here:
A "seed" is a sequence of 24 words from the BIP39 wordlist!
This sequence of words represents the corresponding 256-digit binary code.
However, there is a peculiarity with the 24th word of a seed: The first 23 words from the list can be chosen freely and randomly. These represent 23 times 2 to the power of 11, totaling 2 to the power of 253. To reach the total number of 2 to the power of 256, only 2 to the power of 3 = 8 combinations remain. This means: the 24th word can no longer be chosen arbitrarily from the 2048 words. Only 8 words from the list fit! When selecting this 24th word, a checksum is processed. Therefore, the 8 possible words for the 24th position can only be calculated cryptographically, or by using an appropriate tool.
In the form of 24 words-which are more accurately typed and, if necessary, easier to remember - the 256-digit crypto account numbers have become more manageable and suitable for everyday use.
However, anyone who thinks "it’s just a few words"... is gravely mistaken. If the paper with the seed (the 24 words) is gone, the account is gone. "Lost in space."
[In the past, and sometimes still today, 12-word sequences were also common. However, the significantly more secure 24-word sequences are increasingly becoming the standard.]
Worth knowing: What does HODL mean?
People new to cryptocurrencies won't know what to make of "HODL." "HODL" is not a word from the BIP39 wordlist, not even in an abbreviated form using the first four letters. On the other hand, precisely because it is four letters long, it fits perfectly as a placeholder for a real word of an active seed. Some providers of "seed-in-metal" storage solutions like to use "HODL" in their fields for demonstration purposes. I handle it the same way.
The origin is quite simply explained: In December 2013, a presumably drunk user wrote on a Bitcoin forum: “I AM HODLING,” while certainly meaning to write "HOLDING," meaning to "hold" or "hold on."
The term "hodling" or "HODL" quickly became the epitome of long-term investment rather than short-term profit seeking in the crypto scene.
3. Entropy (The true randomness)▴
In Chapter 2, I wrote: "The first 23 words from the list can be chosen freely and randomly."
But how does one achieve "true randomness"?
To create a 24-word seed, one usually uses a so-called "wallet" with a built-in random number generator. A wallet is software for managing access data to a crypto account - a digital keychain.
There are two fundamental types:
- Hot Wallet: Software that runs on an internet-enabled device (smartphone, computer).
- Cold Wallet: A standalone device where the seed is stored securely without transmitting it to a computer or the internet. This variant is significantly more secure but slightly more complex to operate.
When setting up a wallet, a valid seed is created via the built-in random number generator (with the 24th word being correctly calculated as a checksum). The words are displayed, and you are prompted to note them down - for example, by writing them down. But this is where the danger lurks: Anyone who saves the seed digitally, photographs it, or copies it to the clipboard opens the door to scammers. Many courses and videos on the topic of crypto, wallets, and seeds teach responsible handling: Do not save it digitally, but write it down on paper and then stamp it into metal-yet hardly anyone questions the generation of the seed itself.
The problem: Electronic randomness.
A computer "rolls" with logic - this is called pseudo-randomness. There are "reliable," "limited-reliability," and "low-reliability" generators. Can a layperson know which type is inside their own wallet? No. You have to trust the manufacturer, the brand, or the programmer.
So, you are supposed to trust a stranger?!?!?
Is it compatible with the philosophy of cryptocurrencies-self-responsibility, self-custody, independence - to leave the ultimate foundation of your account to an electronic black box, of all things?
For everyday wallets with amounts comparable to petty cash, that may be perfectly fine.
But for long-term wealth accumulation with HODL, i.e., holding assets over a long period, trust in a black box is not appropriate at all!
What to do? We turn to physics.
The solution: The dice
According to Wikipedia, "good physical methods for generating random numbers are rolling dice and drawing lottery numbers." To generate true randomness, we don't need expensive machines, just one die (or several).
A proven method:
- Eyes 1 to 3 stand for binary 0.
- Eyes 4 to 6 stand for binary 1.
- You roll 11 times for an 11-digit binary code and then look up the corresponding word in the BIP39 list.
To illustrate the process, click on the gray square (your die) 11 times:
Attribution: Michael Konstantin Haberer / ShareTheSeeds – www.sharetheseeds.com
Perfecting randomness:
Since standard dice have manufacturing tolerances and their pips influence their weight, my suggestion is:
Use dice from different manufacturers and sizes. Mix them in a container, reach in blindly, and roll the drawn die only 11 times-exactly for one word. Alternatively, you can draw a new die from the mix for every throw. This minimizes physical influences on the result and achieves the maximum possible true randomness.
By rolling several dice simultaneously, entropy can be increased even further:
- The addition method: The eyes of several dice are added together. If the sum is even, you count it as 0; if it is odd, as 1.
- The filter method: You roll several dice at once. A roll is only counted as valid if all dice show either small numbers (1, 2, 3) or all show large numbers (4, 5, 6). Rolls with mixed results are discarded and repeated.
It is important here to decide on a rule at the beginning and stick to it consistently.
If you want to take it to the extreme, get expensive new precision casino dice and a suitable felt pad. But that really isn't necessary. Much more important is the proper handling of the die: it is far better for entropy to let a simple game die roll and bounce across the table extensively until it comes to rest than to carefully and gently place an expensive precision die onto fine velvet.
And even more crucially: treat the self-created seed with full awareness and responsibility. No one should find out about the new seed - no one! (At least not in your lifetime.)
To roll 23 words, you need 253 rolls (23 times 11). Feel free to use further variability: roll alternately with your right and left hand, use different surfaces, or vary your rolling style - there are no limits to the imagination.
Worksheets File Download:
I have created a worksheet for you where you can enter the results of your dice rolls:
View Dice Recording Sheet in a new tab
Download Dice Recording Sheet
To convert the 11-digit binary numbers you have rolled into the corresponding words, you need the BIP39 wordlist. Although this list is easy to find on the internet, it is often not provided with binary codes. So I have created a BIP39 wordlist for you containing the binary codes for all 2048 words. I recommend printing this file (17 pages). Do not be tempted, out of convenience or habit, to type your rolled binary codes into a search field to find the word faster – and your data would no longer be secure...
View BIP39-wordlist.pdf in a new tab
Download BIP39-wordlist.pdf
4. The checksum - the 24th word▴
Now we come to a technical aspect:
The 24th word cannot be "rolled" with dice. The selection is narrowly limited to 8 possibilities and is mathematically tied to the preceding 23 words.
The misconception: Many believe there is only one single correct 24th word. That is incorrect. Since the first 23 words comprise 253 bits, 3 bits of "freedom" remain up to the 256-bit limit. Since 23 = 8, there are exactly 8 combinations that result in a valid checksum and thus define a valid wallet.
The manual vs. the mechanical way:
Theoretically, calculation by hand is possible - perhaps interesting for computer science students - but for practical use, it would be absurd to waste valuable lifetime on this. The effort of rolling the first 23 words with dice, however, is worthwhile because it forms the basis of a truly randomly generated and therefore secure seed.
The idea of rolling a seed myself came to me at the beginning of 2026. In February, I failed at the 24th word. I asked ChatGPT and quickly learned that one cannot roll the 24th word because it contains a checksum. I asked the AI how one could calculate this word. This led to a lengthy debate between me and ChatGPT, during which the AI offered me everything possible: from Python scripts and setting up a special offline computer just for this purpose, to weeks-long calculation problems, and much more.
ChatGPT on the attempt to calculate the 24th word by hand:
The hard fact
Without any form of computational aid, you cannot determine the 24th word.
Not slowly.
Not clumsily.
But fundamentally impractical.
The reason is exactly one step:
This step is not achievable by hand.
Why it was “easy” up to 23 words - and then abruptly ends
What you have done so far was:
- Rolling dice → bits ✔️
- Grouping bits → words ✔️
These are linear, mechanical steps.
The 24th word, however, requires:
- 64 rounds of bit operations
- Rotations
- Modulo additions
- Fixed constants
- State machines
This is built intentionally so that it cannot be calculated by humans.
Over many days, or rather weeks, I kept looking for ways to easily calculate this 24th word, or the 8 possible 24th words.
Towards the end of the debate, I remarked:
"The most ideal would be if software could input all 2000+ possibilities so one wouldn't have to type each word individually."
And ChatGPT answered:
Yes - that is objectively the best approach.
And it is technically correct, possible offline, and significantly more efficient than manual typing.
One just has to clearly distinguish what is realistically possible and what hardware wallets intentionally prevent.
1. Core idea (precise)
Software automatically tests all 2048 possible 24th words
and outputs only the valid result.
This is not guessing, but rather:
- Deterministic BIP39 checksum verification
- Exactly what a wallet does internally anyway
Mathematically clean, secure, complete.
I even contacted the manufacturer of a hardware wallet because, supposedly, some wallets could calculate the 24th word. But all efforts were in vain. Finally, I gave up.
About three months later, a simple solution suddenly appeared: an offline-capable HTML file that calculates the missing word, or the possibilities, in fractions of a second.
To find the 24th word without compromising the confidentiality of a seed, we therefore use exactly this specialized offline tool:
The BIP-39 CHECKSUM CALCULATOR by Sutterseba
A programmer who writes about himself: "Hey, I'm Sebastian, a 20-ish year old cybersecurity student from Germany," released the appropriate program for our purpose a few years ago.
To get to the offline version, you simply go to the site where the tool runs online:
https://sutterseba.de/bip39-checksum-calculator/
And right-click "Save as" or "Save page as..." (the phrasing varies slightly from browser to browser).
And just like that, you have the appropriate HTML file.
Attention! The programmer writes on GitHub about his tool:
Be careful
The implementation is very simple, may contain mistakes and was not designed with security in mind. It is meant for testing and learning purposes to offer a way to play around with mnemonic phrases. If you roll your own seed and want to complete your mnemonic phrase, there are hardware wallets allowing you to do just that in a more secure way.
If you insist on using this tool for your own keys, make sure to run it offline on a secure and isolated operating system!
Therefore, it is advisable to pay attention when entering the 24 words into the OMDP39 tool to see if the seed is recognized as valid, as OMDP39 is security-verified!
Security note:
For the calculation of the 8 possible words of the 24th position of the seed, we use a computer that has no connection to the internet, no hard drive, and no radio chips, and which starts from a live Linux USB stick where all entered and calculated data resides only in volatile memory (RAM) and physically disappears after switching it off.
What the computer does in the background:
To understand why we use the machine, a look at the process the computer executes in fractions of a second is helpful:
- The gap: We have 253 bits. 3 bits are missing to reach the 256 bits.
- The 8 variants: The computer tests all 8 possibilities of these 3 missing bits (000 to 111).
- The SHA-256 hash: For each variant, a cryptographic hash (SHA-256) is calculated. This is a complex mathematical procedure that extracts a checksum from the data.
- The completion: The first 8 bits of this hash serve as the checksum. This is appended, and the result is split into 11-bit blocks (words).
Composition of the 24th word (11 bits):
R R R | C C C C C C C C
[3 bits randomness] + [8 bits checksum] = 11 bits (1 word)
(The sequence of the 8 bits of checksum and 3 bits of randomness within the word can vary)
Conclusion:
We do not let the machine generate our key - we have done that ourselves by rolling dice. We only let the computer calculate the "mathematical signature" (the checksum) for our rolled numbers. The offline HTML file acts here as a deterministic calculation tool that - unlike a human - is free of errors during the complex hash calculation.
5. Self-responsibility and self-custody▴
Now we have our own seed. Created with the highest level of confidentiality through manual craftsmanship using true randomness and signed with a checksum.
And now what? How do we handle this treasure appropriately?
This question arises naturally, especially given the effort of rolling the dice, looking up the words, and setting up an offline computer with the appropriate checksum calculation...
If we make a mistake now, the entire effort was useless - a "sunk cost," so to speak. I like to compare it to a bathtub: it can be crafted as elegantly and nobly as you like, but if there is even a single hole in the bottom, you cannot fill it because everything will simply run right back out.
Regarding the seed, we must also learn to keep things "sealed." Only then can wealth be held stably on that seed (HODL). You should not show the seed to anyone, not photograph it, not save it in a password manager, not send it via email or messenger, not save it in the cloud, and so on and so forth. Simultaneously, we must learn to store the seed in such a way that unauthorized persons cannot penetrate the "seal" - for example, by securing the seed in a safe. But natural forces like fire, water, wind, and earthquakes can also make a piece of paper with a written-down seed disappear.
At this point, we must dive into the fundamental depths of value patterns and characteristics. The successful and sustainable use (HODL) of cryptocurrencies is directly linked to a corresponding development of consciousness regarding personal responsibility. Anyone who has the habit of always blaming other people or institutions first when something goes wrong, and who intends to keep that habit, will have a hard time with cryptocurrencies - or more accurately: a very hard time. To make this shift in consciousness toward self-responsibility easier, I dedicate an entire chapter to this topic.
Cryptocurrencies differ fundamentally from much of what we know from the current financial system. Therefore, it is important to me to shed light on the special characteristics of cryptos:
- Factual control over assets
With cryptocurrencies, practical power of disposal lies exclusively with the person who possesses the "seed phrase" (a series of English words). This seed phrase is the central password. It is used to calculate cryptographic keys that allow the signing of transactions on the blockchain. The balances are not stored in the wallet itself, but are publicly recorded on the blockchain. Whoever controls the password or the keys can move the coins; whoever does not have them has no access-regardless of who might formally claim the assets. - No central authority, no state assignment
Unlike bank accounts, there is no central institution that manages or can restore access. There is no name entry, no land registry, no executive branch that could restore the assets in the event of loss or dispute. The blockchain itself only knows addresses and balances, not the people behind them. - Self-responsibility instead of external determination
Self-custody represents a radical paradigm shift:- Traditional accounts: State and banks determine, manage, and protect access; the individual's power of disposal is externally determined, but legally protected.
- Cryptocurrencies: You alone are responsible. Security, backup, inheritance, or the transfer of access lie entirely in your hands.
- Separation of legal attribution and factual power of access
Even if authorities treat cryptocurrencies as "assets," this does not mean that the law can enforce practical access. The blockchain protects the coins through cryptographic control, not through state enforceability. Property in the classical sense - name, registration, recovery by executive authority - does not exist here. - Risk and freedom
- Those who keep their passwords and keys securely, without others being able to view them, have maximum control and independence. You can access your assets worldwide, even if your own phone, computer, or hardware wallet should break.
- Anyone who loses their passwords - whether through negligence, forgetfulness, accidents, fire, or flooding - loses access to the assets permanently and irretrievably. Anyone who makes the keys accessible to third parties enables them to gain access, without any way to prevent or reverse the misuse.
- This fundamentally distinguishes self-custody from all previous financial systems: Access = Power, not legal title.
- Philosophical essence
Self-custody is more than a technical concept: it is a system of absolute self-responsibility that breaks the millennia - old coupling of property, access, and institutional external determination. Whoever holds cryptocurrencies actively assumes responsibility for their assets - and all the consequences that follow.
Before using a new crypto account (address), you should make a plan of where to store the word list of the seed phrase securely, protected, and yet accessible to yourself.
And, very importantly: you should seriously ask yourself whether you are interested in, capable of, and prepared for absolute self-responsibility.
Those who wholeheartedly agree to self-responsibility can now tread the path of securely storing their freshly created seed. In doing so, however, one encounters a probabilistic paradox.
The Availability-Confidentiality Paradox
If you have only a single copy of the seed (even if it is "carved in stone" or stamped into steel), you are 100% dependent on this one treasure surviving everything that may come unharmed. Against natural forces, political upheavals, and even war and displacement, this one location must hold its own - and you must be able to find the object again in an emergency.
Since this demand for the absolute indestructibility of a single object in one location is hard to fulfill, the impulse arises: copy the seed multiple times and deposit them in different locations (possibly in other countries or on other continents). But this leads to the paradox: While you massively increase the probability of availability, you increase to the same extent the risk that an unauthorized person could gain access to one of these copies and clean out your assets.
The solution to this paradox lies in the mathematical splitting of the seed into cryptographic parts, so-called shares. These are individually worthless, but in a specific combination, they enable the reconstruction of the seed. How to use this to secure availability without compromising confidentiality is the subject of the following chapter.
6. The logic of splitting (SSS and OMDP39)▴
More than 40 years ago, Adi Shamir, an Israeli cryptology expert, developed a method to securely split secrets. Using this method, a secret can be broken down into several fragments, so-called shares, such that only a defined subset of these shares is required to reconstruct the secret. This method, developed in 1979, is called: Shamir’s Secret Sharing (SSS).
For decades, this method has been considered the gold standard for the secure storage and reconstruction of secrets - from industry, banking, and government to private security needs.
A "3-of-5" configuration is frequently used. This means the secret is split into 5 shares, and you need at least 3 of these shares to restore the original secret.
In practice, SSS is widely applied:
- Corporate security: Companies that operate critical digital infrastructure protect central code keys using SSS. Changes to sensitive systems then require the approval of several authorized employees.
- Government security: Encryption master passwords or access codes for sensitive databases are distributed among different ministries or agencies so that no single person (such as a corrupt official) can gain access to the entire system.
- Personal risk management: Private individuals use SSS to protect sensitive information against loss through "single points of failure." By splitting data into shares stored in geographically separate locations, critical data - such as medical records, emergency contacts, or safe deposit box data - is protected against local disasters without any single custodian ever having access to the entire secret.
- Master passwords for password managers: To prevent the total loss of digital access (in case of forgetting the master password or in the event of death), the master password is split into shares. This ensures access for authorized parties while the service provider never knows the password themselves.
- Highly sensitive digital documents: Protecting information whose loss or unauthorized disclosure would be existentially threatening (e.g., patents, sensitive research data, or private archives). The encryption key is managed via SSS in such a way that it can only be reconstructed by the defined minimum number of participants.
The proven method (SSS) is therefore perfectly suited to secure a valuable seed.
Splitting a seed into shares with OMDP39
While Shamir’s Secret Sharing (SSS) has been the gold standard as a general cryptographic principle for decades, for the user of BIP39 seeds, there was long a lack of a direct, highly secure, verifiable, offline-capable implementation that applies the method directly to the 11-bit word format while simultaneously bringing overlong shares down to a familiar length. This is exactly where OMDP39 comes in: it translates the mathematical principle of Shamir into the world of mnemonic words and makes it usable for the user in a way that is secure, simple, offline, and verifiable.
The shares are natively longer than the secret. A seed with 24 words becomes a series of 33 words. Since this is impractical for standard seed storage systems (which are usually designed for 24 words), OMDP39 includes an integrated conversion to Base24: 33 words become a series of 24 codes, each 4 characters long. Thus, the shares can be secured using the same methods as a classic seed.
The freely available tool OMDP39 is published by C&W Software Labs AG from Zug, Switzerland. It can be used online as well as offline, although for confidential applications, the offline version must obviously be used exclusively.
OMDP39 includes the following functional components:
- Seed management: Inputting an existing seed or generating a new, random seed.
- Configuration: Defining the number of shares and the necessary reconstruction threshold (recommended: 3-of-5).
- Fragmentation: Splitting the seed into several shares.
- Conversion: Converting 33-word shares into Base24 format and back.
- Reconstruction: Inputting the shares to restore the original seed.
- Tools: Integrated BIP39 word list for verification.
Important note on authenticity
In the world of cryptography, the integrity of tools is the highest good. As OMDP39 gains importance as a verifiable trust model for sensitive security applications, it inevitably becomes the focus of actors who might create imitator products or phishing sites to mislead users by using the well-known name.
Trust only the official sources:
Official repository: github.com/OmegaSoftwareLabs/omdp39-releases
Official websites:
www.omdp39.io,
www.omdp39.com,
www.sliceyourseed.com
You must verify every downloaded tool via the provided cryptographic signatures (minisig) and SHA-256 checksums in the official repository. Never use a copy whose origin cannot be unequivocally traced back to this repository.
OMDP39 is not a classic open-source project for free modification, but a verifiable security protocol. The focus is on the integrity of execution: cryptographic signatures ensure that what the user has in their hands was exactly certified by the manufacturer-without any blind trust in the provider. Every user can (and should) independently check the cryptographic signature and the hashes.
Security is not created by convenience, but by verification!
With Shamir 3-of-5, the seed is split into 5 shares.
The original seed is restored with at least 3 shares:
(Please click the gray shares #1 through #5)
Attribution: Michael Konstantin Haberer / ShareTheSeeds – www.sharetheseeds.com
7. The AirGap computer: From calculation to metal share▴
Basic Principle of Security
In the fourth chapter, I wrote about the computer used:
"For the calculation of the 8 possible words of the 24th position of the seed, we use a computer that has no connection to the internet, no hard drive, and no radio chips, and which starts from a live Linux USB stick where all entered and calculated data resides only in volatile memory (RAM) and physically disappears after switching it off."
For us, "AirGap" means: there is a complete physical separation of the device from the internet. It is not just a Wi-Fi switch being deactivated - the device simply no longer possesses any hardware components to establish a connection.
Since security at the software level (e.g., deactivating JavaScript) can be bypassed at any time through administrative rights, our AirGap concept relies exclusively on physical facts: missing wireless hardware, physically sealed interfaces, and an independent power supply rule out data transfer at a technical level. Here, the system does not rely on configurations, but on the absence of physical possibilities.
Now I will introduce the hardware used for this process:
- Lenovo ThinkPad X250: Compact, energy-efficient, perfectly sufficient for OMDP39.
- Lenovo ThinkPad T470: Larger screen, which significantly increases comfort when working with LightBurn.
Linux Mint (via USB stick) is used as the operating system. The software environment is configured so that after booting, Firefox (with the local OMDP39 HTML tools) and LightBurn (with the prepared laser design) start automatically.
Below are pictures of the "gutting" (the hardware modification) of the computers for final securing:
The Ports of the AirGap Computer Are Sealed
Please click on the image multiple times:
The ports are still open, here the SD card slot and LAN port.
Details for Experts: The Security Workflow
- The Hardware: A Lenovo T470 (backup: X250), a fiber laser (GWEIKE G2 Pro 30W), and a fume extractor are in use. The power supply is self-contained via a power station - this guarantees a stable quality of power supply during computing operations and lasering. It also prevents any potential data leakage through the power grid. The T470 has no hard drive and no wireless chips; unused ports are closed with hologram security seals, and the Linux USB stick is physically connected to the device via a tamper seal. After each use, the stick is removed, formatted, the system is reinstalled, and the stick is fixed to the device with a new tamper seal. Since a wireless chip inside the laser housing could not be technically removed, its antenna was removed and the entire device was placed in a grounded Faraday cage. With the Electrosmog Detector Acousticom 2, no wireless emission at all (0 to 0.01 V/m) could be measured even in the immediate vicinity.
- Browser Hardening: Firefox is strictly configured for "privacy without local storage"; no form entries or browsing histories are saved.
- Operator Briefing: After the system boots up, the process guide instructs the operator, who will laser their own seed onto metal themselves. Depending on the operator's situation and preferences (whether they have 23 or 24 words, etc.), process steps can be flexibly adapted to their individual level of knowledge or specific security configuration. Different layers can also be toggled on and off in the LightBurn design, depending on design preferences.
- Confidentiality with Guidance: From this point on, the operator must make the necessary entries and clicks themselves. Ideally, they are alone in the room. Each step of the action is clearly explained with laminated and labeled screenshots. It is also possible for the process guide to remain in the room to answer pressing questions and, if necessary, perform the more difficult actions (operating the design software, the laser, the fume extractor, etc.). It is always crucial that the process guide can under no circumstances see the confidential data of the seed and the shares!
- Seed Generation: The operator enters the 23 rolled words, evaluates the 8 possible variants for the 24th word, and makes the final selection.
- Transfer: The 24 words are transferred into the OMDP39 page via copy/paste.
- Private Details: The operator has the option to enter the following private details into a prepared script: Name / nickname of the seed (important if managing multiple seeds) / date / free text (optional) in four text blocks of 96, 81, 68, 56 characters - meaning a maximum of 301 keystrokes in total (German umlauts count as 2 keystrokes each). This free text is intended to be lasered onto a separate metal plate ("Path to the Treasure"). This could be, for example, a reminder of where you hid the 5 shares yourself, though the description should be vague enough to only help you, not a stranger. A riddle for the heirs could also be written down here.
- Internal Processing: OMDP39 calculates the 5 shares as well as the Base24 conversion. A custom script writes the Base24 data of the 5 shares - along with the personal details - directly as a table into
/dev/shm, a RAM disk whose contents are immediately and irretrievably erased in the event of a power loss or reboot. - Design with Recovery Instructions: To ensure the long-term recovery of the seed, even if the OMDP39 tool should one day no longer be available, the type of encoding and recovery is permanently burned onto each share plate. With these details, a computer scientist or cryptologist can restore the data in an emergency without having to use the OMDP39 tool: ALPHABET: 0123456789ABCDEFGHJKMNPR (BASE24) [EXCLUDING: I(INDIA), L(LIMA), O(OSCAR), Q(QUEBEC)] | SYSTEM: OMDP39.COM (SHAMIR 3/5) | RECOVERY: 96-CHAR BASE24 -> 33 WORDS -> BIP39 SEED | BASE24 MAP: 0=0 | 9=9 | 10=A | 17=H | 18=J | 19=K | 20=M | 21=N | 22=P | 23=R
- Laser Safety Goggles: To protect against reflections, the operator (and the process guide, if in the room) wears certified safety goggles (850–1300nm OD6+).
- Laser Production: LightBurn imports the data directly from this volatile RAM disk into the production design and burns the data onto stainless steel within a few minutes!
- Metal Plates: As a storage medium, we use specially stamped metal plates made of acid-resistant A4 stainless steel, 7 cm in diameter, with a practically indestructible material thickness of 5 mm!
- QR Codes of Derived Addresses: For advanced users: using Ian Coleman's Mnemonic Code Converter (included on the Linux system), the operator can display the corresponding derived addresses, private keys, and public keys for Bitcoin, Ethereum, Monero, and other currencies as a QR code and photograph them with a digital camera or phone. Warning: Do not under any circumstances take photos of the lasered metal plates or the seed entered into the Coleman tool!! Use of this tool is strictly for advanced users and at their own risk!
- Traceless Work: After the process is finished and the system is shut down, no cryptographically relevant data remains on the device.
- Cleaning the Metal: After lasering, the metal plates undergo a multi-stage cleaning process, including the use of ultrasound, to remove soot marks and minimize potential signs of corrosion.
- Archiving: After cleaning, the lasered metal plates are placed in sealed containers with a controlled atmosphere. Depending on preference, the containers can also be heavy-duty to withstand particularly severe mechanical or thermal impacts. There are also proven designs for long-term underground burial.
8. Demo Seed▴
To illustrate the individual steps, we will use a demo seed. While this is a "valid" seed, it was not generated by chance.
Using logic created specifically for this purpose, I selected 23 words from the BIP39 list: starting with 'A', I took the first word that is exactly 4 letters long.
For words starting with 'A', it is the word 'able'. For the next letter, 'B', the first word with exactly 4 letters is 'baby'.
Picked out in this manner, the first 23 words are:
able baby cage damp earn face gain hair icon jazz keen lady maid name obey pact quit race safe tail ugly vast wait
I enter these 23 words into the 'Checksum Calculator' program and receive the 8 possible variants for the 24th word:
book, cliff, garment, inform, mistake, power, supply, want
From these, I take the first word with exactly 4 letters again: "book"
And there is a valid seed: able baby cage damp earn face gain hair icon jazz keen lady maid name obey pact quit race safe tail ugly vast wait book
I enter the demo seed into OMDP39 (www.omdp39.com) and verify that it is valid:
Then I click on "Generate Shares":
As a result, 5 shares with 33 words each are displayed. Here is the image of Share 1 of 5:
In the corresponding order, the 33 words are (you can easily insert them elsewhere by clicking "copy" in the top right):
cause quote city thing army shallow father insect control husband skull wine save hood giggle leaf amazing avoid unveil clip harbor raven until upgrade stable pupil toward panther update fault bargain length abandon
Alternatively, you can click on "Show BASE24" to get this view:
Below the already visible 33 words, 24 blocks of 4 characters each have been added. This is the BASE24 code.
Here is the result after clicking 'Copy as 24 x 4':
Share 2: 0RCD 1BAR D14C 9C62 4RFP 86JC 9NJF 6NCH HABA 8BA1 J4A9 HA2P H8EA DN7C D20J 5C49 A918 D7HG ARAA 8F41 8GFM PDR6 42M5 7B70
Share 3: 0RCD 1BAR D14C 9C64 1P73 9DEC DRNM 14J8 CF1R PM26 GF80 N2KH 6H7R M390 JN09 DG9D FK15 BBPH 8CF1 6ACH DNDM 8PJ3 8DCN GB70
Share 4: 0RCD 1BAR D14C 9C7G PF81 AB3C 6F4H D4FD JF8E DBE6 HRC8 HF10 FF14 6FD6 FCJ4 PBD7 88DE R53A GJP2 P2NN GAP7 G0R9 M6KD J848
Share 5: 0RCD 1BAR D14C 9C7J RRK9 N8FN PJMK PJCB 5JBE BK1F N310 3ADK 64N3 PBKB 3J6K MHHM M4JH R078 PCF4 H8KJ E242 4E5H JPHR 6H1G
Using the script I developed, the codes for the seed and the shares are written temporarily into a table and can thus be imported by the LightBurn software.
Before we immortalize the code in metal, we verify that the reconstruction of the seed works:
To do this, we first go to the BASE24 menu item in OMDP39:
Then we scroll down a bit to the point: "96 Base24 characters → 33 words" and enter the 96 characters of a share. We ensure that it says "96 valid characters" below the field to the right, which indicates there are no typos.
Here in the image, the BASE24 characters of Share 1 have been entered:
Then we click on "Convert back to words" and receive the notice: "33 words · OMDP39 share verified against header and checksum" as well as the 33 words, which can be easily pasted elsewhere by clicking "copy words":
We repeat this process with all shares (or in real life, with the recovered, salvaged, or unearthed shares - at least 3 out of 5) and receive 5 x 33 words:
Share 2: cause quote city thing around goose behind robot train mesh caution sort bargain rule sense sport lunar awake work prepare belt meat property ancient soda tube wink tourist cheap future south length abandon
Share 3: cause quote city thing around payment exile taste fault educate shop bread off tribe office awkward develop drip fold sing razor usage bounce decrease infant cradle govern library embody just leave abandon abandon
Share 4: cause quote city thing arrange indoor body sentence dance dinosaur mountain enrich rose middle what episode truly cotton entry local pill curve spice catalog eight genius loyal brass physical truth various length abandon
Share 5: cause quote city thing arrange renew duck plunge lonely veteran income paper dawn summer phone maze extend glow uncover token action fatigue guide banner wine roast bottom lemon sniff tree agree length abandon
Next, we go to the "Restore Secret" menu item in OMDP39:
Now we enter any three of the 33-word lists. Since only two input fields are displayed initially, you must click on "Add another share" once.
Clicking on the lower red bar labeled "Restore Secret" restores the original seed, but for security reasons, it is displayed in a blurred, illegible state. The security notice is legible: Sensitive: Anyone who knows this seed has full access to your wallet. Close this tab after use and avoid taking screenshots.
Hovering the mouse pointer over the seed field makes the seed visible. Clicking on "Show permanently" keeps them visible regardless of the mouse pointer's position:
At this point, the ability to copy the full seed with a click is missing (for security reasons - the seed should be stored physically and not end up in the electronic clipboard). However, for this demonstration, I can copy the words of the seed using copy/paste (Ctrl+C / Ctrl+V):
Earlier in the text, in the 'Security Workflow' section, I wrote:
"The operator has the option to enter the following private details into a prepared script: Name / nickname of the seed (important if managing multiple seeds) / date / free text (optional) in four text blocks of 96, 81, 68, 56 characters - meaning a maximum of 301 keystrokes in total (German umlauts count as 2 keystrokes each). This free text is intended to be lasered onto a separate metal plate ('Path to the Treasure'). This could be, for example, a reminder of where you hid the 5 shares yourself, though the description should be vague enough to only help you, not a stranger. A riddle for the heirs could also be written down here.
OMDP39 calculates the 5 shares as well as the Base24 conversion. A custom script writes the Base24 data of the 5 shares - along with the personal details - directly as a table into /dev/shm, a RAM disk whose contents are immediately and irretrievably erased in the event of a power loss or reboot."
Once this table is imported into LightBurn, the fields for variable text stored in the design are replaced with the details from the table.
The preview image of metal plates Share 1 through Share 4 from LightBurn looks like this: (the thin lines are the laser's travel paths)
The freshly lasered shares look like this:
(the blurriness is partly due to soot)
For metal plates 5 through 8, I made the following selection in this example:
- 1x Share 5
- 1x Free text
- 2x Seed (unsplit)
The preview image then looks like this:
This plate set looks like this when freshly lasered:
The word SAFE in a close-up:
After lasering, the engravings undergo a multi-stage cleaning program, including ultrasonic cleaning. The word SAFE then looks like this:
In even higher magnification, the difference is very visible:
Before (with soot)
After (cleaned)
A cleaned SHARE plate looks like this:
A cleaned SEED plate looks like this:
9. The Lasering Process (Video)▴
In the following video, you can see the process of lasering a demo share plate. The process takes about 2 minutes.
Usually, four plates (e.g., Share #1 to Share #4) are lasered in one pass (duration approx. 8 minutes).
10. Cleaning the Metal Plates▴
After lasering, the metal plates undergo a multi-stage cleaning process, including the use of ultrasound, to remove soot marks and minimize potential signs of corrosion.
Pore-deep cleaning is essential for corrosion protection during long-term storage. Lasering releases various metallic and chemical compounds or creates new ones as reaction products due to the intense energy applied to the metal. Over decades of storage, these soot residues could trigger corrosion even on acid-resistant A4 stainless steel. To prevent this, a multi-stage intensive cleaning process was developed.
A view of the utensils:
Shown are:
- Silicone table mat with edge
- Pack of disposable towels
- Paper towels
- GN 1/6 stainless steel container with resting plate holder
- Two special toothbrushes
- Vinegar spray bottle
- Dispenser with self-made cleaning paste
- Ultrasonic cleaner with cleaner bottle (plus measuring cup)
- GN 1/6 stainless steel container for intermediate cleaning
- Spray bottle with distilled water
- Second ultrasonic cleaner
- GN 1/6 stainless steel container with resting plate holder and 8 plates
- Spray bottle with 99.9% isopropanol
Details for the Interested: The Cleaning Workflow
- Personal Protective Equipment: The first step is to put on special disposable protective gloves. To protect against the finest metal particles and chemicals, we use extra-thick nitrile gloves (double strength). The non-slip, diamond-shaped 3D structure on the entire palm ensures excellent grip.
- Coarse Cleaning: Using vinegar from the spray bottle and a toothbrush with extra-hard bristles (so-called smoker's toothbrush), the soot on the plate is dissolved and loosened.
- Coarse Rinsing: The metal plate is held over the GN container, and with a few sprays of vinegar, the loosened soot components are rinsed off.
- Intensive Cleaning: A specially formulated cleaning paste is applied to the metal plate. The mixture consists of 10 parts of the finest chalk and 2 parts each of glycerin and propylene glycol. The combination provides a synergistic effect: while the glycerin serves as a stable carrier for the chalk particles due to its high viscosity, the thinner propylene glycol reduces surface tension. This improves the wetting of the engraving grooves and ensures that the mixture penetrates into the smallest recesses, reliably keeping the loosened soot in suspension. Since the mixture is formulated to be water-free and immediately absorbs any penetrating atmospheric moisture thanks to the glycerin, no preservatives are required. Cleaning is performed using a special sonic toothbrush with 40,000 vibrations per minute. Because the plate was pre-cleaned with vinegar and is therefore still coated with it, a controlled foaming occurs when the cleaning paste is applied: the reaction of the acetic acid with the calcium carbonate in the chalk releases carbon dioxide, which literally lifts the soot out of the engravings through this microscopic "foaming effect" and further promotes the loosening of deposits.
- Pre-rinsing: The metal plate is freed of the cleaning paste and dissolved soot residues over the GN container using sprays of distilled water.
- Ultrasonic Main Cleaning: The ultrasonic cleaner contains distilled water with 1% ultrasonic cleaner. At 55 °C (131 °F), up to 8 plates are cleaned simultaneously for 10 minutes at 40,000 vibrations per second to remove soot and cleaner residues.
- Intermediate Cleaning: The carrier with the 8 metal plates is placed on the GN container, and the plates are rinsed with several sprays of distilled water so that cleaner residues can run off completely.
- Ultrasonic Post-Cleaning: This ultrasonic cleaner contains distilled water (without added cleaner). At 30 °C (86 °F), the plates are cleaned for 2 minutes to remove the last traces.
- Final Rinsing: Finally, the metal plates are sprayed with 99.9% isopropanol. The alcohol creeps into the engravings, infiltrates the water, displaces it into the GN container, and subsequently evaporates without leaving any residue. After this, the metal plates are clean, dry, and ready for packaging in numbered safe bags, including silica gel/Tyvek pouches for permanent preservation.
In the following image series, you can see the cleaning step-by-step.
Please click on the image multiple times:
Freshly lasered, there is a lot of soot on the metal.
11. Verification of Durability▴
The intention behind all the effort of lasering the seed and shares onto metal is to ensure the most stable long-term durability of the data possible - whatever may happen.
We can confidently ignore ultimate catastrophic extremes such as meteorite impacts, bomb explosions, liquid magma, or sinkholes. Such events are not only highly improbable, but we have also prepared for the loss of individual shares through distributed storage (Shamir 3-of-5). This only applies, however, if these 5 shares (plus potentially one or more plates containing the seed) are stored in physically separate locations. If up to two shares were to disappear completely, the data - the seed - could still be fully restored from the remaining plates.
What we should focus on regarding durability is the verification of events that are more probable and could occur at multiple locations simultaneously.
We must consider: Fire, water, corrosion, and mechanical impact.
We use acid-resistant A4 stainless steel. This is a proven material from the shipping industry, resistant to water, saltwater, and many acids. This eliminates half of the dangers right away.
We must test the durability of the plate and the engraving under exposure to heat (house fire) including sudden quenching (fire department extinguishing), as well as any potential mechanical stress on the plate (scratches, impacts, etc., in the event of building collapse or accidents).
In the first test, I subjected two A4 stainless steel plates to a significant heat test.
Two stainless steel plates were placed on top of each other so that an unlasered plate covered the engraving. The duo was then wrapped in aluminum foil. Additionally, the package was placed in a plastic safety bag. The plastic will certainly melt together and likely burn, depending on the temperature. The melting point of aluminum is 660 °C (1220 °F), a temperature that can certainly be reached in an oven. Even if remnants of the aluminum foil survived the fire, they would likely offer no structural stability anymore.
Initial state before thermal exposure.
The test setup simulated the conditions of a residential fire.




As you can see, the plates physically survived the extreme heat of the oven. The aluminum foil had crumbled. The duo-pack of the two plates was easy to open:
The result – data fully preserved.
The reddish discoloration indicates a temperature range of 600 to 700 °C (1112 to 1292 °F).
In the second test, I subjected an A4 stainless steel plate to a severe mechanical abrasion test.
An engraved stainless steel plate was clamped into a lathe. Care was taken to ensure it was clamped slightly out of alignment (at an angle). This causes the lathe tool to start at the highest point, and after turning off a defined feed, the material is fully removed at the formerly highest point, while at the previously deepest point, ideally, nothing has been removed yet. You can then clearly see how deep the engraving went based on the progression from "no removal" to "full removal."
After initial tests, we realized that 0.2 mm of full removal is exactly right. At the formerly highest point, where 0.2 mm was turned off, the text is just no longer visible, and at the formerly deepest point, the engraving is already turned flat - meaning the bead of metal that had pushed out of the engraving groove has just been removed.
It is interesting to note that the mechanical engraving depth is recognizably less than 0.2 mm, but the metal was altered deep within its structure, making the writing clearly legible at all depths down to the 0.2 mm limit.
A typical scratch in metal might have a depth of 0.01 mm. It is even less for A4, because A4 stainless steel is particularly tough; leaving deep scratches there without heavy machinery is practically impossible.
Plate clamped slightly out of alignment.
The test setup simulated the conditions of severe mechanical impact.


As is clearly visible, you can still see the data well even where the plate was heavily turned down - deeper than would ever be expected from a scratch!
In the third test, two A4 stainless steel plates were exposed to more than 1000°C (1832°F), followed immediately by quenching in water.
An electric kiln served as a tool for the third stress test. An engraved plate was placed together with a non-engraved plate and bundled tightly with stainless steel wire. The kiln was operated for 2 hours; after one hour, approx. 600°C (1112°F) was reached, and after 2 hours, I was able to measure a maximum temperature of 1033°C (1891°F). Then, the glowing hot package of the two plates was quenched directly in water.
The following images show this experiment:
12. Long-term storage▴
To keep the laser-engraved plates safe over long periods of time, several aspects need to be considered. One point is easy accessibility for oneself, while unauthorized persons should not be able to find the plates.
Long-term storage in the ground has proven very effective; one simply buries the plates. The material can handle this easily. A4 stainless steel is not only rust-resistant but also acid-resistant, making it stable against humic acids in the soil. However, the criteria "easy to reach" and "hard to find for unauthorized persons" conflict with each other. Common metal detectors easily find metal plates if they are buried only a few centimeters deep. To deposit the metal deeper than the detection range, one must go down at least half a meter. Then, in turn, one does not dig up the metal as quickly when one wants to access it oneself. And if one has not hit the exact spot, there is a major excavation operation...
An easily overlooked point is the heirs' search for the metal plates. In the worst case, they know nothing about the treasure and want to erect a building or create a garden pond exactly in that area of the garden, and an excavator arrives... In many cases, the heirs know that something was buried, but not where. Then a excavator helps with the search... if it is a matter of potential millions, one can dare to turn the garden upside down... And if an excavator tooth strikes the metal plate containing the seed with full hydraulic power, the data should remain intact!
I will not elaborate on the "where exactly." Everyone is asked to look within themselves and find a suitable solution. However, I strongly advise keeping at least 50 cm distance from fast-growing trees. In a few decades, even a freshly planted tree can easily reach more than 50 cm in trunk diameter if the location suits it. And it would be a shame to have to fell a tree just to get to the metal plates, which might then have grown into the roots... and anyone who has ever tried to split root wood knows why I strongly advise against proximity to trees.
I will also not elaborate in detail on the "where" regarding the transmission to the heirs. There are so many possibilities, from photos of the burial site to GPS coordinates, depositing a map in a sealed envelope with a notary, etc.; everyone is called upon to find the solution that feels individually appropriate.
I will now discuss an elegantly combined physical design for underground storage that possesses the desired properties.
The solution to the challenge I propose looks as follows:
With an earth auger / hole spade, one digs a round hole 12 to 15 cm in diameter. The depth depends on the soil conditions and the available tools. In any case, one should reach a depth of 60 cm. If digging is easy, a depth of more than a meter is even better. In soils with large stones, this is sometimes not possible with reasonable effort.
Into the hole, one places a soil and waste pipe (PP, HDPE, or PVC) with an internal diameter of 9 to 11 cm (approx. 4 inches), with the socket facing upwards. The bottom of the pipe remains open so that any water entering can drain out at the bottom. The seal is removed from the socket. A pipe plug is placed on top, resting loosely in the socket of the pipe. One could now easily let the metal plates "disappear" into the pipe, put the plug on, add 5 cm of soil, a stone, leaves, ... and that's it.
No, that would not be good! The plates would be deep enough not to be found by a metal detector. The big BUT, however, is retrieving the metal plates. Especially at a depth of one meter, arm length is never enough... And one must consider that in the soil, there is the 'the local underground construction crew' specifically voles and other burrowing animals. Ants alone can move entire mountains, grain by grain, over time...
Also, metal plates simply thrown down into the pipe would only be minimally protected from an excavator tooth. The plastic pipe is quickly broken, and the excavator tooth leaves a deep scratch on the plate...
My recommendation, therefore, is an additional metal plate covering the engraving, both slid onto the thread of an M24 V4A stainless steel eye bolt and screwed tight with an M24 V4A hex nut. Such a package of eye bolt, two metal plates, and a nut weighs a good kilogram. Such a chunk easily withstands an excavator tooth! The metal plates may get a few scratches on the outside, but inside, everything remains untouched. (Incidentally, one can also easily screw three engraved metal plates plus an additional plate into one package)
Now all that is needed is a connection between the pipe plug and the eye bolt: In the center of the pipe plug, drill a 3 mm hole and thread a 2 mm Dyneema rope through it. On the top side of the pipe plug, make a knot. The rope goes down, almost to the end of the pipe. At this end of the rope, tie the eye bolt so tightly that it hovers above the ground. A Dyneema rope with a 2 mm diameter has a breaking load of over 400 kg and a maximum elongation of 1%. Furthermore, this material is absolutely long-term stable, even in the presence of moisture, snail slime, and fungal mycelium. Since Dyneema has a smooth surface, a bowline knot is recommended at both ends of the rope.
To retrieve the metal plates, clear the pipe plug, lift the pipe plug, and pull the eye bolt with the intact seed into the daylight using the rope.
Those who want to optimize further can take the following selection as inspiration, depending on their own security needs:
- Under the lower pipe end, place gravel or an A4 stainless steel mesh against burrowing animals.
- Before screwing them together, bees wax is spread between the metal plates so that no water can penetrate to the engraving.
- The metal share package is placed inside a numbered safety bag and sealed. When recovering an intact bag, it is guaranteed that no one has retrieved, inspected, or returned the share. A single share is worthless to a thief – they need three out of five parts to reconstruct the seed. If a bag is found to be damaged during inspection, regardless of whether the metal plate is still present or has been removed, the situation is critical: in this case, all four remaining associated shares should be retrieved immediately and replaced with a completely new 5-share set.
Important note: A newly created 5-share set is cryptographically completely different from the previous one – even with an identical seed. The old shares are incompatible with the new ones. A thief in possession of one or two old fragments holds nothing but scrap metal once the remaining three shares of the old set have been destroyed. Nevertheless, the following applies: Any hiding spot where a safety bag has been opened is considered 'burned' and must never be used again. - The safety bag can be wrapped in aluminum foil to prevent snails from dissolving the film.
- Vibration security: A spring washer (split ring) reliably secures the bolted connection. This is particularly essential for hiding spots located near sources of vibration, such as railway lines or heavily traveled roads. Self-locking nuts are an equally suitable alternative.
- Preventing cold welding (galling): A thin layer of ceramic paste (alternatively copper paste) can be applied to the threads of the A4 stainless steel bolts. This prevents the cold welding of the stainless steel caused by long-term pressure and ensures that the bolt can be loosened without difficulty even after decades in the ground
- Add a comprehensive layer of zeolite to the ground at the bottom open end of the pipe. This will slow down or even prevent ants from colonizing the cavity inside the pipe.
In the following film, you can see the retrieval of a laser-engraved metal plate: