ShareTheSeeds.com

Laser engraving on stainless steel

Detailed shot: Precise laser engraving on A4 stainless steel

1. Your account, your autonomy – the scale of 2^256

Do you want to feel, think, and speak freely, without your account being subject to seizure?
No banker, no ideological screening, no credit scoring, no monthly maintenance fees - nothing stands in your way of setting up one account, or many.
Do you need a hundred accounts, a thousand accounts? It doesn't matter.
Set up as many accounts as you need - and can manage.

Can you imagine all this?
Oh, and there are no terms and conditions or fine print.
You don't need a OTP (One Time Password) generator, no authorization, no bank card (with an expiration date).
There are no transaction limits, no national borders, no negative interest on deposits ...
And yet, these self-created accounts are more secure than typical bank accounts!

They are even protected from yourself - in case you misplace, forget, or lose your access data.
That is the 'price of freedom' for these accounts - It is up to you to guard the 'key to the vault'.
Does that scare you, or do you love self-responsibility?

You can create a high-security account on your computer in seconds; or many, as many as you like...
You can even create account numbers by hand, in peace and at your leisure, using dice.
Real account numbers, mind you, onto which you can deposit as much wealth as you wish.
You can even deposit any number of different currencies into each account!

Do you prefer self-determination, self-responsibility, and autonomy over subservience and external control?

Does that sound too good to be true?

In the world of cryptocurrencies, this is exactly the standard. Your „digital vault“ is not based on a contract with a bank, but on simple mathematics.

The number that protects your assets is: 2 to the power of 256.

To understand why your digital property is so secure, we have to stretch our imagination. When we talk about security, we often think of locks, safes, or alarm systems. With cryptocurrencies, however, security is not a physical object, but a mathematical law of probability.

Why this number changes everything:

2 to the power of 256 is not just a big number. It is so large that it far exceeds the number of atoms in the observable universe.

Before diving deeper into the mathematics of the number 2 to the power of 256, I would like to share a few philosophical thoughts on the bigger picture:

Why Financial Decentralization Is Not a Luxury, but a Contribution to Securing Peace

For some people, the word "math" is a trigger because it brings back school days when an out-of-touch math teacher failed to connect abstract numbers to lived reality. For others, "cryptocurrency" is an allergen because they believe these coins are backed by nothing, making them economic bubbles that will burst sooner or later, causing investors to lose all their money.

To those who do not love mathematics - or do not love it yet - let it be said that numbers occur everywhere in creation; in other words, they are a divine reality. Mathematics is essentially the description of the world in numbers. All growth, from single-celled organisms to giant redwood trees, follows natural laws that run with precise mathematical order. This creates fascinating geometric patterns such as a sunflower or a nautilus shell.

And cryptocurrencies are indeed backed, even if nothing physical can be seen.

Before diving deeper into that, let us look at conventional currencies: currencies issued by princes, kings, and emperors - generally speaking, by authorities and royalties - have existed for millennia. These were practically always centrally organized and served as an expression of power and force. To maintain or expand power, these 'currencies' were frequently abused or deployed in the interest of the rulers: inflation, deflation, war financing, national debt, fraud, betrayal of savers, and much more. When these centralized currencies failed, dark chapters of humanity's history often followed. The price for state money monopolies, abusive debt management, and arbitrary devaluation has always ultimately been paid by people with their freedom and their lives - and, often overlooked, by animals and plants as well.

Even the darkest chapter of German history is directly linked to the conventional monetary system:
From the ruins of the Weimar hyperinflation of 1923 - well over 100 years ago - to the Great Depression beginning in 1929, the ground was laid for totalitarianism and extremism.
The resulting Nazi regime exploited this severe crisis, built its massive rearmament on covert shadow credit (MEFO bills), and ultimately looted the gold reserves and central banks of occupied nations to finance its wars.1

Currency crashes and famines, state currency devaluation, national bankruptcies, and ruthless imperialist predatory campaigns - right up to global economic crises and totalitarian wars driven, mind you, by financial motives - have over the course of millennia certainly cost hundreds of millions, if not over 1 billion, human lives. To this should be added the countless ancient and early modern wars fought to conquer gold, silver, and resource sources, or to exact crushing taxes. When one considers that every murdered person leaves behind a collective trauma in their complex family network, the ocean of human suffering left behind by central monetary systems based on coercion and power becomes immeasurably vast.

Furthermore, conventional currencies have massively influenced the transformation of agriculture over the past 150 years. Small-scale farming characterized by hedges, diverse biotopes, and — most importantly — a heart-connection between the farmer and the land has been pushed aside. It has given way to ever-larger operations utilizing ever-larger machines, more oppressive debts, and growing dependencies on subsidies. Instead of stabilizing the foundations of life for coming generations and perfecting the habitat, it was only about profit anymore. Without a heart-connection to the land, farmers were intent solely on reaping maximum financial gain, come what may, even if erosion increased and humus was lost.2

The massive, practically always subsidy-driven expansion of solar and wind power plants in the open countryside is also an expression of our monetary system, which is based on constantly new and rising debt (fiat money / debitism: the eternal search for a successor debtor). Climate protection, perhaps even well-intentioned in its beginnings many decades ago, has degenerated into yet another redistribution from the hardworking to the rich, into a further destruction of our means of subsistence, and into a desperate attempt to stall the systemically guaranteed state bankruptcy a little bit longer.

Since all life on Earth — plants, animals, and humans — is based on the existence and quality of humus, the large-scale destruction of the landscape is a concrete threat to life itself. It is not for nothing that the words 'human' and 'humus' share the same origin. We humans are 'earthlings'. Thus, centralist conventional fiat currencies not only destroyed millions of human lives as a consequence of their respective failures, but they are now also undermining the survival chance of humanity as a whole.

Compared to all this suffering and pain, the lost profits of individual pioneers in crypto investments are not even the itch of a mosquito bite.

Whoever decentralizes the financial base and breaks the coercion ultimately protects not only their savings, but also deprives industrial soil destruction of its foundation.

Because I am resolutely opposed to any life-hostile extremism, I have an open heart for problem-solving pioneer projects. For me, a decentralized, counterfeit-proof monetary system is not an object of speculation, but a crucial contribution toward preventing the repetition of such historical catastrophes. Whoever decouples means of payment from state arbitrariness and central power deprives totalitarian systems of their breeding ground.

Compared to conventional, centrally issued currencies, cryptocurrencies are a new phenomenon, a pioneer project.

The fact that shady characters in the crypto sphere are now also trying to lure weak minds into greed and hype with false promises of hope does nothing to change the groundbreaking foundation of the project itself. Some of these shady characters, through their flashy and aggressive manner, easily give newcomers the impression that everything to do with crypto is just about making a quick buck. That is by no means the case.

Bitcoin, the first cryptocurrency with a decentralized ledger system on a blockchain, started on January 3, 2009, with the generation of "Block 0", the so-called genesis block. The following message was immortalized in this code: "The Times 03/Jan/2009 Chancellor on brink of second bailout for banks" Its creator, Satoshi Nakamoto, wrote about it in February 2009: “The root problem with conventional currency is all the trust that's required to make it fiat work. The central bank must be trusted not to debase the currency, but the history of fiat currencies is full of breaches of that trust. Banks must be trusted to hold our money and transfer it electronically, but they lend it out in waves of credit bubbles with barely a fraction in reserve. We have to trust them with our privacy, trust them not to let identity thieves drain our accounts. Their massive overhead costs make micropayments impossible. [...] With e-currency based on cryptographic proof, without the need to trust a third party middleman, money can be secure and transactions effortless.” 3

Cryptocurrencies are thus clearly and recognizably backed by humanity's endeavor to free itself from the yoke of central banks, state fraud and manipulation, as well as warmongering and the destruction of the foundations of life. This immaterial backing is in my opinion more valuable than physical gold. Whoever invests seriously and long-term in cryptocurrencies trusts mathematics, creation, or - to put it directly: God.

This choice of words may seem surprising, but upon closer inspection, close parallels can be found between the conventional banking system and the church: credit and credo (creed); creditor and belief/faith (gläubiger / glaube); debts and confession of guilt (schulden / schuldgeständnis); money is "created/spawned" ("geschöpft") and the priest talks about the "story of creation" (Schöpfungsgeschichte)...

Conventional central banks share structural similarities with churches, right down to the Vatican. Decentralized cryptocurrencies, on the other hand, dispense with a central authority and are thus an expression of humanity's evolution toward self-responsibility and self-organization-the recognition that every individual is a co-creator of God.

Cryptocurrencies - in particular systems for absolute self-custody and physical data backup - currently fulfill an important function: They break the monopolies of centralized institutions and teach us how to handle value and sovereignty in the digital space with personal responsibility. They are, so to speak, the tool for a global, decentralized coming of age.

Of course, the development and operation of cryptocurrencies require electricity, meaning energy. They also need hardware: computers and the internet. However, conventional currencies also require energy and hardware, with all their bank towers, data centers, branches, etc. ... Furthermore, with the increasing liberation of the creativity of the human mind, there are continually new insights and inventions. Whether through highly efficient consensus mechanisms or completely novel protocol structures: It can be expected that there will be more and ever better new solution ideas the more suppression fades.

Though the monopolies do not want to be broken, their time has - in my view - run out: The more EU bureaucracy tries to shackle cryptocurrencies through increasingly totalitarian regulations and control over the central gateways (fiat exchanges), the more the effect will likely backfire: Freedom-loving people are likely to detach themselves further and further from the fiat system and begin operating directly and seamlessly in crypto, peer-to-peer, or other unregulatable payment methods, or to scale down their official economic output to the point where they no longer have a tax burden. Not that I would recommend the following, but it cannot be ruled out that some will go so far as to voluntarily and intentionally settle into state welfare until human- and business-friendly times arrive.

The old will pass away, the new will emerge. Let us now shift our focus away from the decay of the old and toward the mathematical foundation of the new — cryptocurrencies:

Let us return to the number that changes everything: 2 to the power of 256.

If someone wanted to try and guess one billion account numbers every second, it would take them longer than the universe has existed to check even a fraction of these combinations. This sheer size is the "fortress" in which your wealth lies. There is no hacker in the world, and no supercomputer - and there never will be - that could ever guess the "combination" to your vault. As long as you keep your access data highly confidential and do not make any mistakes, your accounts are secure, absolutely secure.

This sounds phenomenal! However, everything has its price: what is mathematically impossible to guess is just as impossible for humans to find again in the event of a loss. And since there are no bankers in the self-service bank who could reissue a lost debit or Visa card, everything is lost if you lose your access data to 2 to the power of 256 possible account numbers.

The number 2 to the power of 256 is a very large number. It is truly very, very large.

Let's start small, with the number 2:
All electronic digital devices use binary codes with the state '0' or '1'.
Here, '0' stands for 'no voltage' and '1' stands for voltage (usually 5 volts).
A binary code with multiple positions can have either the state '0' or '1' at each position.

A two-digit binary code has two positions, each of which can have two states (0 or 1).
Mathematically, this is called 2 to the power of 2.

A two-digit binary code can represent 4 different values:

00
01
10
11

A three-digit binary code can represent twice as many values:
2 * 2 * 2, or mathematically called '2 to the power of 3' (2³ = 8):

000
001
010
011
100
101
110
111

An 11-digit binary code is therefore the number 2 multiplied by itself 11 times:
2*2*2*2*2*2*2*2*2*2*2, mathematically called 2 to the power of 11 (2¹¹ = 2048):

The possible values begin like this:

00000000000
00000000001
00000000010
...

and end like this:

...
11111111101
11111111110
11111111111

A chessboard has 8 * 8, so a total of 64 squares.

There is a story from Asia where a ruler wanted to do someone a favor. The person asked for grains of wheat: one grain on the first square of a chessboard, double that on each subsequent square... what looked like little at the beginning, just 64 grains at the end of the first row... the ruler probably laughed at first until the laughter faded... towards the end of the chessboard it becomes so large, it is simply no longer realizable because the corresponding amount of grain would be many thousands of times the world's annual production.

We have the doubling of possibilities with every additional position in binary codes as the number of positions grows, exactly the same. The difference, however, is that we start with the number 2 at the first square of the chessboard, because either '0' or '1' can also stand on this field. A binary code with 64 positions therefore has 2 to the power of 64 different possibilities.

Exponential growth (Chessboard squares 1–8)

SQ 1:
SQ 2:
SQ 3:
SQ 4:
SQ 5:
SQ 6:
SQ 7:
SQ 8:

Each step doubles the value. At square 64, the bar would be billions of kilometers long.

With 'only' two chessboards, i.e., 128 squares, every single grain of the many thousands of times the world's annual production would become an additional many thousands of times the world's annual production... mind you, from every single grain... This alone already exceeds the imagination of the human mind.

Four chessboards have a total of 4 times 64 = 256 squares.
A 256-digit binary code, and that is exactly what we are dealing with in cryptocurrencies (if it is a seed phrase with 24 words), has 2 to the power of 256 different possibilities. That goes absolutely into the astronomical, practically infinite.

To try and approach an idea of 2 to the power of 256, let's take practically the smallest thing we have in physical reality: An electron!

An electron is one of the most elementary particles of our universe. Unlike atoms or molecules, an electron, according to current quantum physics, has no measurable internal structure - it is considered "point-like." To be able to calculate with it, physicists use the so-called "classical electron radius" (also known as the Lorentz radius). This is the theoretical sphere of influence of an electron.

This radius is so unimaginably tiny that one can hardly write it down in millimeters:
• Diameter of an electron: 0.00000000000282 mm
(That is approximately 100,000 times smaller than an atom)

Now, we line up (virtually, of course) as many electrons in a row as there are possibilities in 2 to the power of 256...
You arrive at 3.265 times 10 to the power of 62 meters.

That is, again, a number that a human cannot grasp.
So let's take something really big: The distance of a light-year, i.e., the distance that light travels within one year!
A light-year is approximately 9.5 times 10 to the power of 15 meters long, which is far, far shorter than the mentioned 3.265 times 10 to the power of 62 meters.

Then let's take something ultimately big: The diameter of the visible universe:
93 billion light-years... Sounds really big, right?

But for the (virtual) row of electrons as an expression of the myriad combination possibilities of 2 to the power of 256, 93 billion light-years is still a trifle!

The (virtual) row of electrons would have to go multiple times across the entire visible universe, specifically 370 decillion times (a number with 35 digits before the decimal point).

And somewhere on this practically infinite stretch stands a single electron for your own cryptocurrency account connection, which you can ONLY access if you have the right passwords ready. ...

Does it now become visually understandable that one can no longer find a lost 'crypto account number'?

Has the importance of securing access data to the crypto account become drastically apparent?
I certainly hope so!

To conclude this chapter, I will provide the first and last two combinations of the binary code with 2 to the power of 256 possibilities.
It is a code with 256 positions, where a '0' or a '1' can stand at each position.

The possible values begin like this:

0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001

...
and end like this:

1111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111110
1111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111
Laser engraving on stainless steel

2. What is a seed?

Following the astronomical numbers in Chapter 1, we return to somewhat smaller figures... The "crypto account number," with its 256 zeros and ones, is rather unwieldy despite its comparative brevity and is mercilessly error-prone when typed out.

A few years after the introduction of Bitcoin (the first cryptocurrency), an improvement proposal was submitted in September 2013. It was the 39th proposal (BIP = Bitcoin Improvement Proposal), and it published a wordlist of 2048 words (2 to the power of 11). This list became the global standard for cryptocurrencies and is called the BIP39 wordlist. Each word represents an 11-digit binary code.

The words are selected in such a way that they can be clearly distinguished from one another and can be uniquely identified by their first four letters, even if the entire word is longer. For example, "ABAN" stands for "abandon" - it represents the binary code 00000000000, the first of the 2048 possibilities - and there is no other word in the list that starts with "aban." The next word is "ability," shortened to four characters and displayed in capital letters for better readability: ABIL, representing the binary code 00000000001.

Worth knowing: The BIP39 wordlist

The list comprises 2048 English words. The complete list can be looked up on GitHub.
For illustration, I provide the beginning of the list here:

0 00000000000 abandon 1 00000000001 ability 2 00000000010 able 3 00000000011 about 4 00000000100 above 5 00000000101 absent 6 00000000110 absorb 7 00000000111 abstract 8 00000001000 absurd 9 00000001001 abuse 10 00000001010 access 11 00000001011 accident 12 00000001100 account 13 00000001101 accuse 14 00000001110 achieve 15 00000001111 acid 16 00000010000 acoustic 17 00000010001 acquire ...

A "seed" is a sequence of 24 words from the BIP39 wordlist!

This sequence of words represents the corresponding 256-digit binary code.

However, there is a peculiarity with the 24th word of a seed: The first 23 words from the list can be chosen freely and randomly. These represent 23 times 2 to the power of 11, totaling 2 to the power of 253. To reach the total number of 2 to the power of 256, only 2 to the power of 3 = 8 combinations remain. This means: the 24th word can no longer be chosen arbitrarily from the 2048 words. Only 8 words from the list fit! When selecting this 24th word, a checksum is processed. Therefore, the 8 possible words for the 24th position can only be calculated cryptographically, or by using an appropriate tool.

In the form of 24 words-which are more accurately typed and, if necessary, easier to remember - the 256-digit crypto account numbers have become more manageable and suitable for everyday use.

However, anyone who thinks "it’s just a few words"... is gravely mistaken. If the paper with the seed (the 24 words) is gone, the account is gone. "Lost in space."

[In the past, and sometimes still today, 12-word sequences were also common. However, the significantly more secure 24-word sequences are increasingly becoming the standard.]

Worth knowing: What does HODL mean?

People new to cryptocurrencies won't know what to make of "HODL." "HODL" is not a word from the BIP39 wordlist, not even in an abbreviated form using the first four letters. On the other hand, precisely because it is four letters long, it fits perfectly as a placeholder for a real word of an active seed. Some providers of "seed-in-metal" storage solutions like to use "HODL" in their fields for demonstration purposes. I handle it the same way.

The origin is quite simply explained: In December 2013, a presumably drunk user wrote on a Bitcoin forum: “I AM HODLING,” while certainly meaning to write "HOLDING," meaning to "hold" or "hold on."

The term "hodling" or "HODL" quickly became the epitome of long-term investment rather than short-term profit seeking in the crypto scene.

Laser engraving on stainless steel

3. Entropy (The true randomness)

In Chapter 2, I wrote: "The first 23 words from the list can be chosen freely and randomly."
But how does one achieve "true randomness"?

To create a 24-word seed, one usually uses a so-called "wallet" with a built-in random number generator. A wallet is software for managing access data to a crypto account - a digital keychain.

There are two fundamental types:

When setting up a wallet, a valid seed is created via the built-in random number generator (with the 24th word being correctly calculated as a checksum). The words are displayed, and you are prompted to note them down - for example, by writing them down. But this is where the danger lurks: Anyone who saves the seed digitally, photographs it, or copies it to the clipboard opens the door to scammers. Many courses and videos on the topic of crypto, wallets, and seeds teach responsible handling: Do not save it digitally, but write it down on paper and then stamp it into metal-yet hardly anyone questions the generation of the seed itself.

The problem: Electronic randomness.
A computer "rolls" with logic - this is called pseudo-randomness. There are "reliable," "limited-reliability," and "low-reliability" generators. Can a layperson know which type is inside their own wallet? No. You have to trust the manufacturer, the brand, or the programmer.

So, you are supposed to trust a stranger?!?!?

Is it compatible with the philosophy of cryptocurrencies-self-responsibility, self-custody, independence - to leave the ultimate foundation of your account to an electronic black box, of all things?
For everyday wallets with amounts comparable to petty cash, that may be perfectly fine.

But for long-term wealth accumulation with HODL, i.e., holding assets over a long period, trust in a black box is not appropriate at all!

What to do? We turn to physics.

The solution: The dice

According to Wikipedia, "good physical methods for generating random numbers are rolling dice and drawing lottery numbers." To generate true randomness, we don't need expensive machines, just one die (or several).

A proven method:

  • Eyes 1 to 3 stand for binary 0.
  • Eyes 4 to 6 stand for binary 1.
  • You roll 11 times for an 11-digit binary code and then look up the corresponding word in the BIP39 list.

To illustrate the process, click on the gray square (your die) 11 times:

word: -
This interactive visualization is licensed under CC BY-ND 4.0.
Attribution: Michael Konstantin Haberer / ShareTheSeedswww.sharetheseeds.com

Perfecting randomness:
Since standard dice have manufacturing tolerances and their pips influence their weight, my suggestion is:
Use dice from different manufacturers and sizes. Mix them in a container, reach in blindly, and roll the drawn die only 11 times-exactly for one word. Alternatively, you can draw a new die from the mix for every throw. This minimizes physical influences on the result and achieves the maximum possible true randomness.

By rolling several dice simultaneously, entropy can be increased even further:

It is important here to decide on a rule at the beginning and stick to it consistently.

If you want to take it to the extreme, get expensive new precision casino dice and a suitable felt pad. But that really isn't necessary. Much more important is the proper handling of the die: it is far better for entropy to let a simple game die roll and bounce across the table extensively until it comes to rest than to carefully and gently place an expensive precision die onto fine velvet.

And even more crucially: treat the self-created seed with full awareness and responsibility. No one should find out about the new seed - no one! (At least not in your lifetime.)

To roll 23 words, you need 253 rolls (23 times 11). Feel free to use further variability: roll alternately with your right and left hand, use different surfaces, or vary your rolling style - there are no limits to the imagination.

Worksheets    File Download:

I have created a worksheet for you where you can enter the results of your dice rolls:
View Dice Recording Sheet in a new tab
Download Dice Recording Sheet

To convert the 11-digit binary numbers you have rolled into the corresponding words, you need the BIP39 wordlist. Although this list is easy to find on the internet, it is often not provided with binary codes. So I have created a BIP39 wordlist for you containing the binary codes for all 2048 words. I recommend printing this file (17 pages). Do not be tempted, out of convenience or habit, to type your rolled binary codes into a search field to find the word faster – and your data would no longer be secure...
View BIP39-wordlist.pdf in a new tab
Download BIP39-wordlist.pdf

Laser engraving on stainless steel

4. The checksum - the 24th word

Now we come to a technical aspect:
The 24th word cannot be "rolled" with dice. The selection is narrowly limited to 8 possibilities and is mathematically tied to the preceding 23 words.

The misconception: Many believe there is only one single correct 24th word. That is incorrect. Since the first 23 words comprise 253 bits, 3 bits of "freedom" remain up to the 256-bit limit. Since 23 = 8, there are exactly 8 combinations that result in a valid checksum and thus define a valid wallet.

The manual vs. the mechanical way:
Theoretically, calculation by hand is possible - perhaps interesting for computer science students - but for practical use, it would be absurd to waste valuable lifetime on this. The effort of rolling the first 23 words with dice, however, is worthwhile because it forms the basis of a truly randomly generated and therefore secure seed.

The idea of rolling a seed myself came to me at the beginning of 2026. In February, I failed at the 24th word. I asked ChatGPT and quickly learned that one cannot roll the 24th word because it contains a checksum. I asked the AI how one could calculate this word. This led to a lengthy debate between me and ChatGPT, during which the AI offered me everything possible: from Python scripts and setting up a special offline computer just for this purpose, to weeks-long calculation problems, and much more.

ChatGPT on the attempt to calculate the 24th word by hand:

The hard fact

Without any form of computational aid, you cannot determine the 24th word.

Not slowly.
Not clumsily.
But fundamentally impractical.

The reason is exactly one step:

SHA-256 over 256 bits of entropy

This step is not achievable by hand.

Why it was “easy” up to 23 words - and then abruptly ends

What you have done so far was:

  • Rolling dice → bits ✔️
  • Grouping bits → words ✔️

These are linear, mechanical steps.

The 24th word, however, requires:

  • 64 rounds of bit operations
  • Rotations
  • Modulo additions
  • Fixed constants
  • State machines

This is built intentionally so that it cannot be calculated by humans.

Over many days, or rather weeks, I kept looking for ways to easily calculate this 24th word, or the 8 possible 24th words.

Towards the end of the debate, I remarked:

"The most ideal would be if software could input all 2000+ possibilities so one wouldn't have to type each word individually."

And ChatGPT answered:

Yes - that is objectively the best approach.
And it is technically correct, possible offline, and significantly more efficient than manual typing.
One just has to clearly distinguish what is realistically possible and what hardware wallets intentionally prevent.

1. Core idea (precise)

Software automatically tests all 2048 possible 24th words
and outputs only the valid result.

This is not guessing, but rather:

- Deterministic BIP39 checksum verification
- Exactly what a wallet does internally anyway

Mathematically clean, secure, complete.

I even contacted the manufacturer of a hardware wallet because, supposedly, some wallets could calculate the 24th word. But all efforts were in vain. Finally, I gave up.

About three months later, a simple solution suddenly appeared: an offline-capable HTML file that calculates the missing word, or the possibilities, in fractions of a second.

To find the 24th word without compromising the confidentiality of a seed, we therefore use exactly this specialized offline tool:

The BIP-39 CHECKSUM CALCULATOR by Sutterseba

A programmer who writes about himself: "Hey, I'm Sebastian, a 20-ish year old cybersecurity student from Germany," released the appropriate program for our purpose a few years ago.

To get to the offline version, you simply go to the site where the tool runs online:

https://sutterseba.de/bip39-checksum-calculator/

And right-click "Save as" or "Save page as..." (the phrasing varies slightly from browser to browser).

And just like that, you have the appropriate HTML file.

Attention! The programmer writes on GitHub about his tool:

Be careful
The implementation is very simple, may contain mistakes and was not designed with security in mind. It is meant for testing and learning purposes to offer a way to play around with mnemonic phrases. If you roll your own seed and want to complete your mnemonic phrase, there are hardware wallets allowing you to do just that in a more secure way.

If you insist on using this tool for your own keys, make sure to run it offline on a secure and isolated operating system!

Therefore, it is advisable to pay attention when entering the 24 words into the OMDP39 tool to see if the seed is recognized as valid, as OMDP39 is security-verified!

Security note:

For the calculation of the 8 possible words of the 24th position of the seed, we use a computer that has no connection to the internet, no hard drive, and no radio chips, and which starts from a live Linux USB stick where all entered and calculated data resides only in volatile memory (RAM) and physically disappears after switching it off.

What the computer does in the background:
To understand why we use the machine, a look at the process the computer executes in fractions of a second is helpful:

Composition of the 24th word (11 bits):

R R R | C C C C C C C C

[3 bits randomness] + [8 bits checksum] = 11 bits (1 word)
(The sequence of the 8 bits of checksum and 3 bits of randomness within the word can vary)

Conclusion:
We do not let the machine generate our key - we have done that ourselves by rolling dice. We only let the computer calculate the "mathematical signature" (the checksum) for our rolled numbers. The offline HTML file acts here as a deterministic calculation tool that - unlike a human - is free of errors during the complex hash calculation.

Laser engraving on stainless steel

5. Self-responsibility and self-custody

Now we have our own seed. Created with the highest level of confidentiality through manual craftsmanship using true randomness and signed with a checksum.

And now what? How do we handle this treasure appropriately?

This question arises naturally, especially given the effort of rolling the dice, looking up the words, and setting up an offline computer with the appropriate checksum calculation...

If we make a mistake now, the entire effort was useless - a "sunk cost," so to speak. I like to compare it to a bathtub: it can be crafted as elegantly and nobly as you like, but if there is even a single hole in the bottom, you cannot fill it because everything will simply run right back out.

Regarding the seed, we must also learn to keep things "sealed." Only then can wealth be held stably on that seed (HODL). You should not show the seed to anyone, not photograph it, not save it in a password manager, not send it via email or messenger, not save it in the cloud, and so on and so forth. Simultaneously, we must learn to store the seed in such a way that unauthorized persons cannot penetrate the "seal" - for example, by securing the seed in a safe. But natural forces like fire, water, wind, and earthquakes can also make a piece of paper with a written-down seed disappear.

At this point, we must dive into the fundamental depths of value patterns and characteristics. The successful and sustainable use (HODL) of cryptocurrencies is directly linked to a corresponding development of consciousness regarding personal responsibility. Anyone who has the habit of always blaming other people or institutions first when something goes wrong, and who intends to keep that habit, will have a hard time with cryptocurrencies - or more accurately: a very hard time. To make this shift in consciousness toward self-responsibility easier, I dedicate an entire chapter to this topic.

Cryptocurrencies differ fundamentally from much of what we know from the current financial system. Therefore, it is important to me to shed light on the special characteristics of cryptos:

  1. Factual control over assets
    With cryptocurrencies, practical power of disposal lies exclusively with the person who possesses the "seed phrase" (a series of English words). This seed phrase is the central password. It is used to calculate cryptographic keys that allow the signing of transactions on the blockchain. The balances are not stored in the wallet itself, but are publicly recorded on the blockchain. Whoever controls the password or the keys can move the coins; whoever does not have them has no access-regardless of who might formally claim the assets.
  2. No central authority, no state assignment
    Unlike bank accounts, there is no central institution that manages or can restore access. There is no name entry, no land registry, no executive branch that could restore the assets in the event of loss or dispute. The blockchain itself only knows addresses and balances, not the people behind them.
  3. Self-responsibility instead of external determination
    Self-custody represents a radical paradigm shift:
    • Traditional accounts: State and banks determine, manage, and protect access; the individual's power of disposal is externally determined, but legally protected.
    • Cryptocurrencies: You alone are responsible. Security, backup, inheritance, or the transfer of access lie entirely in your hands.
  4. Separation of legal attribution and factual power of access
    Even if authorities treat cryptocurrencies as "assets," this does not mean that the law can enforce practical access. The blockchain protects the coins through cryptographic control, not through state enforceability. Property in the classical sense - name, registration, recovery by executive authority - does not exist here.
  5. Risk and freedom
    • Those who keep their passwords and keys securely, without others being able to view them, have maximum control and independence. You can access your assets worldwide, even if your own phone, computer, or hardware wallet should break.
    • Anyone who loses their passwords - whether through negligence, forgetfulness, accidents, fire, or flooding - loses access to the assets permanently and irretrievably. Anyone who makes the keys accessible to third parties enables them to gain access, without any way to prevent or reverse the misuse.
    • This fundamentally distinguishes self-custody from all previous financial systems: Access = Power, not legal title.
  6. Philosophical essence
    Self-custody is more than a technical concept: it is a system of absolute self-responsibility that breaks the millennia - old coupling of property, access, and institutional external determination. Whoever holds cryptocurrencies actively assumes responsibility for their assets - and all the consequences that follow.

Before using a new crypto account (address), you should make a plan of where to store the word list of the seed phrase securely, protected, and yet accessible to yourself.

And, very importantly: you should seriously ask yourself whether you are interested in, capable of, and prepared for absolute self-responsibility.

Those who wholeheartedly agree to self-responsibility can now tread the path of securely storing their freshly created seed. In doing so, however, one encounters a probabilistic paradox.

The Availability-Confidentiality Paradox

If you have only a single copy of the seed (even if it is "carved in stone" or stamped into steel), you are 100% dependent on this one treasure surviving everything that may come unharmed. Against natural forces, political upheavals, and even war and displacement, this one location must hold its own - and you must be able to find the object again in an emergency.

Since this demand for the absolute indestructibility of a single object in one location is hard to fulfill, the impulse arises: copy the seed multiple times and deposit them in different locations (possibly in other countries or on other continents). But this leads to the paradox: While you massively increase the probability of availability, you increase to the same extent the risk that an unauthorized person could gain access to one of these copies and clean out your assets.

The solution to this paradox lies in the mathematical splitting of the seed into cryptographic parts, so-called shares. These are individually worthless, but in a specific combination, they enable the reconstruction of the seed. How to use this to secure availability without compromising confidentiality is the subject of the following chapter.

Laser engraving on stainless steel

6. The logic of splitting (SSS and OMDP39)

More than 40 years ago, Adi Shamir, an Israeli cryptology expert, developed a method to securely split secrets. Using this method, a secret can be broken down into several fragments, so-called shares, such that only a defined subset of these shares is required to reconstruct the secret. This method, developed in 1979, is called: Shamir’s Secret Sharing (SSS).

For decades, this method has been considered the gold standard for the secure storage and reconstruction of secrets - from industry, banking, and government to private security needs.

A "3-of-5" configuration is frequently used. This means the secret is split into 5 shares, and you need at least 3 of these shares to restore the original secret.

In practice, SSS is widely applied:

The proven method (SSS) is therefore perfectly suited to secure a valuable seed.

Splitting a seed into shares with OMDP39

While Shamir’s Secret Sharing (SSS) has been the gold standard as a general cryptographic principle for decades, for the user of BIP39 seeds, there was long a lack of a direct, highly secure, verifiable, offline-capable implementation that applies the method directly to the 11-bit word format while simultaneously bringing overlong shares down to a familiar length. This is exactly where OMDP39 comes in: it translates the mathematical principle of Shamir into the world of mnemonic words and makes it usable for the user in a way that is secure, simple, offline, and verifiable.

The shares are natively longer than the secret. A seed with 24 words becomes a series of 33 words. Since this is impractical for standard seed storage systems (which are usually designed for 24 words), OMDP39 includes an integrated conversion to Base24: 33 words become a series of 24 codes, each 4 characters long. Thus, the shares can be secured using the same methods as a classic seed.

The freely available tool OMDP39 is published by C&W Software Labs AG from Zug, Switzerland. It can be used online as well as offline, although for confidential applications, the offline version must obviously be used exclusively.

OMDP39 includes the following functional components:

  • Seed management: Inputting an existing seed or generating a new, random seed.
  • Configuration: Defining the number of shares and the necessary reconstruction threshold (recommended: 3-of-5).
  • Fragmentation: Splitting the seed into several shares.
  • Conversion: Converting 33-word shares into Base24 format and back.
  • Reconstruction: Inputting the shares to restore the original seed.
  • Tools: Integrated BIP39 word list for verification.

Important note on authenticity

In the world of cryptography, the integrity of tools is the highest good. As OMDP39 gains importance as a verifiable trust model for sensitive security applications, it inevitably becomes the focus of actors who might create imitator products or phishing sites to mislead users by using the well-known name.

Trust only the official sources:

Official repository: github.com/OmegaSoftwareLabs/omdp39-releases
Official websites: www.omdp39.io, www.omdp39.com, www.sliceyourseed.com

You must verify every downloaded tool via the provided cryptographic signatures (minisig) and SHA-256 checksums in the official repository. Never use a copy whose origin cannot be unequivocally traced back to this repository.

OMDP39 is not a classic open-source project for free modification, but a verifiable security protocol. The focus is on the integrity of execution: cryptographic signatures ensure that what the user has in their hands was exactly certified by the manufacturer-without any blind trust in the provider. Every user can (and should) independently check the cryptographic signature and the hashes.

Security is not created by convenience, but by verification!

With Shamir 3-of-5, the seed is split into 5 shares.
The original seed is restored with at least 3 shares:
(Please click the gray shares #1 through #5)

This interactive visualization is licensed under CC BY-ND 4.0.
Attribution: Michael Konstantin Haberer / ShareTheSeedswww.sharetheseeds.com
Laser engraving on stainless steel

7. The AirGap computer: From calculation to metal share

Basic Principle of Security

In the fourth chapter, I wrote about the computer used:
"For the calculation of the 8 possible words of the 24th position of the seed, we use a computer that has no connection to the internet, no hard drive, and no radio chips, and which starts from a live Linux USB stick where all entered and calculated data resides only in volatile memory (RAM) and physically disappears after switching it off."

For us, "AirGap" means: there is a complete physical separation of the device from the internet. It is not just a Wi-Fi switch being deactivated - the device simply no longer possesses any hardware components to establish a connection.

Since security at the software level (e.g., deactivating JavaScript) can be bypassed at any time through administrative rights, our AirGap concept relies exclusively on physical facts: missing wireless hardware, physically sealed interfaces, and an independent power supply rule out data transfer at a technical level. Here, the system does not rely on configurations, but on the absence of physical possibilities.

Now I will introduce the hardware used for this process:

Linux Mint (via USB stick) is used as the operating system. The software environment is configured so that after booting, Firefox (with the local OMDP39 HTML tools) and LightBurn (with the prepared laser design) start automatically.

Below are pictures of the "gutting" (the hardware modification) of the computers for final securing:

Lenovo X250 during the removal of the hard drive and the first wireless chip
Lenovo X250: Beginning of the hardware modification by removing the storage drive and a wireless chip.
Lenovo X250 with hard drive and two wireless chips removed
X250 after the physical elimination of both wireless chips and the hard drive.
Lenovo T470 before the modification
Lenovo T470: The base computer before the hardening process.
Lenovo T470 without wireless and without hard drive
Lenovo T470: The base computer is now clean (free of wireless and hard drive).
Lenovo T470 details
Lenovo T470, detailed close-up: The ends of the antenna cables are taped down securely with insulation.
Laser before modification
Fiber laser: Original condition before being retrofitted into a security-critical unit. The approx. 1 x 3 cm orange area on the right side of the image is the antenna. The corresponding black cable is the antenna cable.
Laser without antenna with internal shielding
Laser modification: Removal of the antenna (right side of the image) and application of the internal shielding with the housing opened (left side of the image).
Laser sealed and stamped
Securing: The housing is physically sealed and tamper-sealed against unauthorized opening.
Acousticom 2 measurement on the wireless-free laser setup
Verification of the shielding: The Acousticom 2 shows no measurable wireless emission (0 V/m) during active laser operation inside the Faraday cage.

The Ports of the AirGap Computer Are Sealed

Please click on the image multiple times:

The ports are still open, here the SD card slot and LAN port.

Details for Experts: The Security Workflow

  • The Hardware: A Lenovo T470 (backup: X250), a fiber laser (GWEIKE G2 Pro 30W), and a fume extractor are in use. The power supply is self-contained via a power station - this guarantees a stable quality of power supply during computing operations and lasering. It also prevents any potential data leakage through the power grid. The T470 has no hard drive and no wireless chips; unused ports are closed with hologram security seals, and the Linux USB stick is physically connected to the device via a tamper seal. After each use, the stick is removed, formatted, the system is reinstalled, and the stick is fixed to the device with a new tamper seal. Since a wireless chip inside the laser housing could not be technically removed, its antenna was removed and the entire device was placed in a grounded Faraday cage. With the Electrosmog Detector Acousticom 2, no wireless emission at all (0 to 0.01 V/m) could be measured even in the immediate vicinity.
  • Browser Hardening: Firefox is strictly configured for "privacy without local storage"; no form entries or browsing histories are saved.
  • Operator Briefing: After the system boots up, the process guide instructs the operator, who will laser their own seed onto metal themselves. Depending on the operator's situation and preferences (whether they have 23 or 24 words, etc.), process steps can be flexibly adapted to their individual level of knowledge or specific security configuration. Different layers can also be toggled on and off in the LightBurn design, depending on design preferences.
  • Confidentiality with Guidance: From this point on, the operator must make the necessary entries and clicks themselves. Ideally, they are alone in the room. Each step of the action is clearly explained with laminated and labeled screenshots. It is also possible for the process guide to remain in the room to answer pressing questions and, if necessary, perform the more difficult actions (operating the design software, the laser, the fume extractor, etc.). It is always crucial that the process guide can under no circumstances see the confidential data of the seed and the shares!
  • Seed Generation: The operator enters the 23 rolled words, evaluates the 8 possible variants for the 24th word, and makes the final selection.
  • Transfer: The 24 words are transferred into the OMDP39 page via copy/paste.
  • Private Details: The operator has the option to enter the following private details into a prepared script: Name / nickname of the seed (important if managing multiple seeds) / date / free text (optional) in four text blocks of 96, 81, 68, 56 characters - meaning a maximum of 301 keystrokes in total (German umlauts count as 2 keystrokes each). This free text is intended to be lasered onto a separate metal plate ("Path to the Treasure"). This could be, for example, a reminder of where you hid the 5 shares yourself, though the description should be vague enough to only help you, not a stranger. A riddle for the heirs could also be written down here.
  • Internal Processing: OMDP39 calculates the 5 shares as well as the Base24 conversion. A custom script writes the Base24 data of the 5 shares - along with the personal details - directly as a table into /dev/shm, a RAM disk whose contents are immediately and irretrievably erased in the event of a power loss or reboot.
  • Design with Recovery Instructions: To ensure the long-term recovery of the seed, even if the OMDP39 tool should one day no longer be available, the type of encoding and recovery is permanently burned onto each share plate. With these details, a computer scientist or cryptologist can restore the data in an emergency without having to use the OMDP39 tool: ALPHABET: 0123456789ABCDEFGHJKMNPR (BASE24) [EXCLUDING: I(INDIA), L(LIMA), O(OSCAR), Q(QUEBEC)] | SYSTEM: OMDP39.COM (SHAMIR 3/5) | RECOVERY: 96-CHAR BASE24 -> 33 WORDS -> BIP39 SEED | BASE24 MAP: 0=0 | 9=9 | 10=A | 17=H | 18=J | 19=K | 20=M | 21=N | 22=P | 23=R
  • Laser Safety Goggles: To protect against reflections, the operator (and the process guide, if in the room) wears certified safety goggles (850–1300nm OD6+).
  • Laser Production: LightBurn imports the data directly from this volatile RAM disk into the production design and burns the data onto stainless steel within a few minutes!
  • Metal Plates: As a storage medium, we use specially stamped metal plates made of acid-resistant A4 stainless steel, 7 cm in diameter, with a practically indestructible material thickness of 5 mm!
  • QR Codes of Derived Addresses: For advanced users: using Ian Coleman's Mnemonic Code Converter (included on the Linux system), the operator can display the corresponding derived addresses, private keys, and public keys for Bitcoin, Ethereum, Monero, and other currencies as a QR code and photograph them with a digital camera or phone. Warning: Do not under any circumstances take photos of the lasered metal plates or the seed entered into the Coleman tool!! Use of this tool is strictly for advanced users and at their own risk!
  • Traceless Work: After the process is finished and the system is shut down, no cryptographically relevant data remains on the device.
  • Cleaning the Metal: After lasering, the metal plates undergo a multi-stage cleaning process, including the use of ultrasound, to remove soot marks and minimize potential signs of corrosion.
  • Archiving: After cleaning, the lasered metal plates are placed in sealed containers with a controlled atmosphere. Depending on preference, the containers can also be heavy-duty to withstand particularly severe mechanical or thermal impacts. There are also proven designs for long-term underground burial.
Laser engraving on stainless steel

8. Demo Seed

To illustrate the individual steps, we will use a demo seed. While this is a "valid" seed, it was not generated by chance.

Using logic created specifically for this purpose, I selected 23 words from the BIP39 list: starting with 'A', I took the first word that is exactly 4 letters long.

For words starting with 'A', it is the word 'able'. For the next letter, 'B', the first word with exactly 4 letters is 'baby'.

Picked out in this manner, the first 23 words are:

able baby cage damp earn face gain hair icon jazz keen lady maid name obey pact quit race safe tail ugly vast wait

I enter these 23 words into the 'Checksum Calculator' program and receive the 8 possible variants for the 24th word:

Checksum Calculator result

book, cliff, garment, inform, mistake, power, supply, want

From these, I take the first word with exactly 4 letters again: "book"

And there is a valid seed: able baby cage damp earn face gain hair icon jazz keen lady maid name obey pact quit race safe tail ugly vast wait book

⚠️ Important Note: Please create a real seed only by using dice and not in the way I describe here. I am only presenting this word-selection logic to show how I arrived at a demo seed that looks much more authentic than "aban aban aban aben..." or using words like 'HODL', which do not appear in the BIP39 list at all.

I enter the demo seed into OMDP39 (www.omdp39.com) and verify that it is valid:

OMDP39 Verification
⚠️ Important Note: Please use ONLY the offline tool from OMDP39.com for real seeds and NOT the online function directly on the website!

Then I click on "Generate Shares":

Generate shares

As a result, 5 shares with 33 words each are displayed. Here is the image of Share 1 of 5:

Share 1 of 5

In the corresponding order, the 33 words are (you can easily insert them elsewhere by clicking "copy" in the top right):

cause quote city thing army shallow father insect control husband skull wine save hood giggle leaf amazing avoid unveil clip harbor raven until upgrade stable pupil toward panther update fault bargain length abandon

Alternatively, you can click on "Show BASE24" to get this view:

BASE24 view

Below the already visible 33 words, 24 blocks of 4 characters each have been added. This is the BASE24 code.

Here is the result after clicking 'Copy as 24 x 4':

Share 1: 0RCD 1BAR D14C 9C4E MPG0 9PJD M1RN CE3J ARM3 54FK JKCB FR5R 3DKR RF35 0JDJ 6BF3 M90M HBDB F90E C53K BCGP K14J 9FE2 K29G

Share 2: 0RCD 1BAR D14C 9C62 4RFP 86JC 9NJF 6NCH HABA 8BA1 J4A9 HA2P H8EA DN7C D20J 5C49 A918 D7HG ARAA 8F41 8GFM PDR6 42M5 7B70

Share 3: 0RCD 1BAR D14C 9C64 1P73 9DEC DRNM 14J8 CF1R PM26 GF80 N2KH 6H7R M390 JN09 DG9D FK15 BBPH 8CF1 6ACH DNDM 8PJ3 8DCN GB70

Share 4: 0RCD 1BAR D14C 9C7G PF81 AB3C 6F4H D4FD JF8E DBE6 HRC8 HF10 FF14 6FD6 FCJ4 PBD7 88DE R53A GJP2 P2NN GAP7 G0R9 M6KD J848

Share 5: 0RCD 1BAR D14C 9C7J RRK9 N8FN PJMK PJCB 5JBE BK1F N310 3ADK 64N3 PBKB 3J6K MHHM M4JH R078 PCF4 H8KJ E242 4E5H JPHR 6H1G

Using the script I developed, the codes for the seed and the shares are written temporarily into a table and can thus be imported by the LightBurn software.

Before we immortalize the code in metal, we verify that the reconstruction of the seed works:

To do this, we first go to the BASE24 menu item in OMDP39:

BASE24 in menu

Then we scroll down a bit to the point: "96 Base24 characters → 33 words" and enter the 96 characters of a share. We ensure that it says "96 valid characters" below the field to the right, which indicates there are no typos.

Here in the image, the BASE24 characters of Share 1 have been entered:

96 Base24 characters → 33 words

Then we click on "Convert back to words" and receive the notice: "33 words · OMDP39 share verified against header and checksum" as well as the 33 words, which can be easily pasted elsewhere by clicking "copy words":

33 words

We repeat this process with all shares (or in real life, with the recovered, salvaged, or unearthed shares - at least 3 out of 5) and receive 5 x 33 words:

Share 1: cause quote city thing army shallow father insect control husband skull wine save hood giggle leaf amazing avoid unveil clip harbor raven until upgrade stable pupil toward panther update fault bargain length abandon

Share 2: cause quote city thing around goose behind robot train mesh caution sort bargain rule sense sport lunar awake work prepare belt meat property ancient soda tube wink tourist cheap future south length abandon

Share 3: cause quote city thing around payment exile taste fault educate shop bread off tribe office awkward develop drip fold sing razor usage bounce decrease infant cradle govern library embody just leave abandon abandon

Share 4: cause quote city thing arrange indoor body sentence dance dinosaur mountain enrich rose middle what episode truly cotton entry local pill curve spice catalog eight genius loyal brass physical truth various length abandon

Share 5: cause quote city thing arrange renew duck plunge lonely veteran income paper dawn summer phone maze extend glow uncover token action fatigue guide banner wine roast bottom lemon sniff tree agree length abandon

Next, we go to the "Restore Secret" menu item in OMDP39:

Restore secret

Now we enter any three of the 33-word lists. Since only two input fields are displayed initially, you must click on "Add another share" once.

enter three shares

Clicking on the lower red bar labeled "Restore Secret" restores the original seed, but for security reasons, it is displayed in a blurred, illegible state. The security notice is legible: Sensitive: Anyone who knows this seed has full access to your wallet. Close this tab after use and avoid taking screenshots.

Seed is back, but blurred

Hovering the mouse pointer over the seed field makes the seed visible. Clicking on "Show permanently" keeps them visible regardless of the mouse pointer's position:

Seed is legible again

At this point, the ability to copy the full seed with a click is missing (for security reasons - the seed should be stored physically and not end up in the electronic clipboard). However, for this demonstration, I can copy the words of the seed using copy/paste (Ctrl+C / Ctrl+V):

1 able 2 baby 3 cage 4 damp 5 earn 6 face 7 gain 8 hair 9 icon 10 jazz 11 keen 12 lady 13 maid 14 name 15 obey 16 pact 17 quit 18 race 19 safe 20 tail 21 ugly 22 vast 23 wait 24 book
⚠️ Important Note: If you repeat the process of forming 5 shares from a seed, the shares will always look different. You must only combine shares from the same session when restoring. If you mistakenly mix shares (even if they originate from the same seed), this error message appears: "The shares do not belong to the same set. All shares must originate from a single create-shares call."

Earlier in the text, in the 'Security Workflow' section, I wrote:

"The operator has the option to enter the following private details into a prepared script: Name / nickname of the seed (important if managing multiple seeds) / date / free text (optional) in four text blocks of 96, 81, 68, 56 characters - meaning a maximum of 301 keystrokes in total (German umlauts count as 2 keystrokes each). This free text is intended to be lasered onto a separate metal plate ('Path to the Treasure'). This could be, for example, a reminder of where you hid the 5 shares yourself, though the description should be vague enough to only help you, not a stranger. A riddle for the heirs could also be written down here.

OMDP39 calculates the 5 shares as well as the Base24 conversion. A custom script writes the Base24 data of the 5 shares - along with the personal details - directly as a table into /dev/shm, a RAM disk whose contents are immediately and irretrievably erased in the event of a power loss or reboot."

Once this table is imported into LightBurn, the fields for variable text stored in the design are replaced with the details from the table.

The preview image of metal plates Share 1 through Share 4 from LightBurn looks like this: (the thin lines are the laser's travel paths)

Preview of Shares 1 to 4

The freshly lasered shares look like this:
(the blurriness is partly due to soot)

Preview of Shares 1 to 4

For metal plates 5 through 8, I made the following selection in this example:

The preview image then looks like this:

Preview of Shares 1 to 4

This plate set looks like this when freshly lasered:

Preview of Shares 1 to 4

The word SAFE in a close-up:

SAFE lasered

After lasering, the engravings undergo a multi-stage cleaning program, including ultrasonic cleaning. The word SAFE then looks like this:

SAFE cleaned

In even higher magnification, the difference is very visible:

A with soot

Before (with soot)

A cleaned

After (cleaned)

A cleaned SHARE plate looks like this:

Preview of Shares 1 to 4

A cleaned SEED plate looks like this:

Preview of Shares 1 to 4
Laser engraving on stainless steel

9. The Lasering Process (Video)

In the following video, you can see the process of lasering a demo share plate. The process takes about 2 minutes.

Usually, four plates (e.g., Share #1 to Share #4) are lasered in one pass (duration approx. 8 minutes).

Laser engraving on stainless steel

10. Cleaning the Metal Plates

After lasering, the metal plates undergo a multi-stage cleaning process, including the use of ultrasound, to remove soot marks and minimize potential signs of corrosion.

Pore-deep cleaning is essential for corrosion protection during long-term storage. Lasering releases various metallic and chemical compounds or creates new ones as reaction products due to the intense energy applied to the metal. Over decades of storage, these soot residues could trigger corrosion even on acid-resistant A4 stainless steel. To prevent this, a multi-stage intensive cleaning process was developed.

A view of the utensils:

Cleaning table

Shown are:

Details for the Interested: The Cleaning Workflow

  • Personal Protective Equipment: The first step is to put on special disposable protective gloves. To protect against the finest metal particles and chemicals, we use extra-thick nitrile gloves (double strength). The non-slip, diamond-shaped 3D structure on the entire palm ensures excellent grip.
  • Coarse Cleaning: Using vinegar from the spray bottle and a toothbrush with extra-hard bristles (so-called smoker's toothbrush), the soot on the plate is dissolved and loosened.
  • Coarse Rinsing: The metal plate is held over the GN container, and with a few sprays of vinegar, the loosened soot components are rinsed off.
  • Intensive Cleaning: A specially formulated cleaning paste is applied to the metal plate. The mixture consists of 10 parts of the finest chalk and 2 parts each of glycerin and propylene glycol. The combination provides a synergistic effect: while the glycerin serves as a stable carrier for the chalk particles due to its high viscosity, the thinner propylene glycol reduces surface tension. This improves the wetting of the engraving grooves and ensures that the mixture penetrates into the smallest recesses, reliably keeping the loosened soot in suspension. Since the mixture is formulated to be water-free and immediately absorbs any penetrating atmospheric moisture thanks to the glycerin, no preservatives are required. Cleaning is performed using a special sonic toothbrush with 40,000 vibrations per minute. Because the plate was pre-cleaned with vinegar and is therefore still coated with it, a controlled foaming occurs when the cleaning paste is applied: the reaction of the acetic acid with the calcium carbonate in the chalk releases carbon dioxide, which literally lifts the soot out of the engravings through this microscopic "foaming effect" and further promotes the loosening of deposits.
  • Pre-rinsing: The metal plate is freed of the cleaning paste and dissolved soot residues over the GN container using sprays of distilled water.
  • Ultrasonic Main Cleaning: The ultrasonic cleaner contains distilled water with 1% ultrasonic cleaner. At 55 °C (131 °F), up to 8 plates are cleaned simultaneously for 10 minutes at 40,000 vibrations per second to remove soot and cleaner residues.
  • Intermediate Cleaning: The carrier with the 8 metal plates is placed on the GN container, and the plates are rinsed with several sprays of distilled water so that cleaner residues can run off completely.
  • Ultrasonic Post-Cleaning: This ultrasonic cleaner contains distilled water (without added cleaner). At 30 °C (86 °F), the plates are cleaned for 2 minutes to remove the last traces.
  • Final Rinsing: Finally, the metal plates are sprayed with 99.9% isopropanol. The alcohol creeps into the engravings, infiltrates the water, displaces it into the GN container, and subsequently evaporates without leaving any residue. After this, the metal plates are clean, dry, and ready for packaging in numbered safe bags, including silica gel/Tyvek pouches for permanent preservation.

In the following image series, you can see the cleaning step-by-step.
Please click on the image multiple times:

Freshly lasered, there is a lot of soot on the metal.

Laser engraving on stainless steel

11. Verification of Durability

The intention behind all the effort of lasering the seed and shares onto metal is to ensure the most stable long-term durability of the data possible - whatever may happen.

We can confidently ignore ultimate catastrophic extremes such as meteorite impacts, bomb explosions, liquid magma, or sinkholes. Such events are not only highly improbable, but we have also prepared for the loss of individual shares through distributed storage (Shamir 3-of-5). This only applies, however, if these 5 shares (plus potentially one or more plates containing the seed) are stored in physically separate locations. If up to two shares were to disappear completely, the data - the seed - could still be fully restored from the remaining plates.

What we should focus on regarding durability is the verification of events that are more probable and could occur at multiple locations simultaneously.

We must consider: Fire, water, corrosion, and mechanical impact.

We use acid-resistant A4 stainless steel. This is a proven material from the shipping industry, resistant to water, saltwater, and many acids. This eliminates half of the dangers right away.

We must test the durability of the plate and the engraving under exposure to heat (house fire) including sudden quenching (fire department extinguishing), as well as any potential mechanical stress on the plate (scratches, impacts, etc., in the event of building collapse or accidents).

In the first test, I subjected two A4 stainless steel plates to a significant heat test.

Two stainless steel plates were placed on top of each other so that an unlasered plate covered the engraving. The duo was then wrapped in aluminum foil. Additionally, the package was placed in a plastic safety bag. The plastic will certainly melt together and likely burn, depending on the temperature. The melting point of aluminum is 660 °C (1220 °F), a temperature that can certainly be reached in an oven. Even if remnants of the aluminum foil survived the fire, they would likely offer no structural stability anymore.

Initial state

Initial state before thermal exposure.


The test setup simulated the conditions of a residential fire.

Preparation: Plates wrapped in aluminum foil
Preparation: Plates wrapped in aluminum foil
The plates in the safety bag inside the oven
The plates in the safety bag inside the oven
Full blaze
Full blaze
Something bright can be seen in the ashes
Something bright can be seen in the ashes

As you can see, the plates physically survived the extreme heat of the oven. The aluminum foil had crumbled. The duo-pack of the two plates was easy to open:

The result – data fully preserved.

The result – data fully preserved.
The reddish discoloration indicates a temperature range of 600 to 700 °C (1112 to 1292 °F).

In the second test, I subjected an A4 stainless steel plate to a severe mechanical abrasion test.

An engraved stainless steel plate was clamped into a lathe. Care was taken to ensure it was clamped slightly out of alignment (at an angle). This causes the lathe tool to start at the highest point, and after turning off a defined feed, the material is fully removed at the formerly highest point, while at the previously deepest point, ideally, nothing has been removed yet. You can then clearly see how deep the engraving went based on the progression from "no removal" to "full removal."

After initial tests, we realized that 0.2 mm of full removal is exactly right. At the formerly highest point, where 0.2 mm was turned off, the text is just no longer visible, and at the formerly deepest point, the engraving is already turned flat - meaning the bead of metal that had pushed out of the engraving groove has just been removed.

It is interesting to note that the mechanical engraving depth is recognizably less than 0.2 mm, but the metal was altered deep within its structure, making the writing clearly legible at all depths down to the 0.2 mm limit.

A typical scratch in metal might have a depth of 0.01 mm. It is even less for A4, because A4 stainless steel is particularly tough; leaving deep scratches there without heavy machinery is practically impossible.

plate clamped

Plate clamped slightly out of alignment.


The test setup simulated the conditions of severe mechanical impact.

During turning
During turning
Two tenths removed
Two tenths (mm) removed

As is clearly visible, you can still see the data well even where the plate was heavily turned down - deeper than would ever be expected from a scratch!

In the third test, two A4 stainless steel plates were exposed to more than 1000°C (1832°F), followed immediately by quenching in water.

An electric kiln served as a tool for the third stress test. An engraved plate was placed together with a non-engraved plate and bundled tightly with stainless steel wire. The kiln was operated for 2 hours; after one hour, approx. 600°C (1112°F) was reached, and after 2 hours, I was able to measure a maximum temperature of 1033°C (1891°F). Then, the glowing hot package of the two plates was quenched directly in water.

The following images show this experiment:

The two plates before the test
The two plates (one of them with an engraved demo seed) before the stress test

The two plates bundled as a package
The two plates were bundled as a package with stainless steel wire
The plates glowing in the oven
The package of the two A4 stainless steel plates glowing in the kiln.
The oven is hotter than 550°C
The infrared camera is overwhelmed by the heat and shows only > 550°C (1022°F)
The infrared thermometer shows 970° C
The infrared thermometer shows 930°C (1706°F) at a max. of 970°C (1778°F) – I measured the actual peak of 1033°C (1891°F) shortly after taking this photo, right before I removed the plates from the kiln and quenched them in water.
The glowing plates are coming from the kiln into the water!
The two plates after quenching
The two plates after quenching

At first glance the data is gone
The wire is removed, the plate package is opened. Data is barely visible anymore.

With water and the right light you can see the data
When wetting the plate, the surface dries faster than the engraving, and for a while, you can see a contrast and read the data.

Vinegar and cleaning paste do nothing
Vinegar and cleaning paste do not change anything; the plate remains very dark and the data is difficult to read.

Under the microscope you can clearly see the data
Under the microscope, the data is clearly visible.

A brass brush cleans the plate
A brass brush is the tool of choice: The plate shines again and the data is very legible.

The data is now very legible
Under the microscope, the writing is now very legible.

At maximum magnification you can see the undamaged engraving
At full microscope magnification, the fine lines of the engraving are perfectly visible. Neither the heat nor the quenching left any damage.
Laser engraving on stainless steel

12. Long-term storage

To keep the laser-engraved plates safe over long periods of time, several aspects need to be considered. One point is easy accessibility for oneself, while unauthorized persons should not be able to find the plates.

Long-term storage in the ground has proven very effective; one simply buries the plates. The material can handle this easily. A4 stainless steel is not only rust-resistant but also acid-resistant, making it stable against humic acids in the soil. However, the criteria "easy to reach" and "hard to find for unauthorized persons" conflict with each other. Common metal detectors easily find metal plates if they are buried only a few centimeters deep. To deposit the metal deeper than the detection range, one must go down at least half a meter. Then, in turn, one does not dig up the metal as quickly when one wants to access it oneself. And if one has not hit the exact spot, there is a major excavation operation...

An easily overlooked point is the heirs' search for the metal plates. In the worst case, they know nothing about the treasure and want to erect a building or create a garden pond exactly in that area of the garden, and an excavator arrives... In many cases, the heirs know that something was buried, but not where. Then a excavator helps with the search... if it is a matter of potential millions, one can dare to turn the garden upside down... And if an excavator tooth strikes the metal plate containing the seed with full hydraulic power, the data should remain intact!

I will not elaborate on the "where exactly." Everyone is asked to look within themselves and find a suitable solution. However, I strongly advise keeping at least 50 cm distance from fast-growing trees. In a few decades, even a freshly planted tree can easily reach more than 50 cm in trunk diameter if the location suits it. And it would be a shame to have to fell a tree just to get to the metal plates, which might then have grown into the roots... and anyone who has ever tried to split root wood knows why I strongly advise against proximity to trees.

I will also not elaborate in detail on the "where" regarding the transmission to the heirs. There are so many possibilities, from photos of the burial site to GPS coordinates, depositing a map in a sealed envelope with a notary, etc.; everyone is called upon to find the solution that feels individually appropriate.

I will now discuss an elegantly combined physical design for underground storage that possesses the desired properties.

The solution to the challenge I propose looks as follows:

With an earth auger / hole spade, one digs a round hole 12 to 15 cm in diameter. The depth depends on the soil conditions and the available tools. In any case, one should reach a depth of 60 cm. If digging is easy, a depth of more than a meter is even better. In soils with large stones, this is sometimes not possible with reasonable effort.

Into the hole, one places a soil and waste pipe (PP, HDPE, or PVC) with an internal diameter of 9 to 11 cm (approx. 4 inches), with the socket facing upwards. The bottom of the pipe remains open so that any water entering can drain out at the bottom. The seal is removed from the socket. A pipe plug is placed on top, resting loosely in the socket of the pipe. One could now easily let the metal plates "disappear" into the pipe, put the plug on, add 5 cm of soil, a stone, leaves, ... and that's it.

No, that would not be good! The plates would be deep enough not to be found by a metal detector. The big BUT, however, is retrieving the metal plates. Especially at a depth of one meter, arm length is never enough... And one must consider that in the soil, there is the 'the local underground construction crew' specifically voles and other burrowing animals. Ants alone can move entire mountains, grain by grain, over time...

Also, metal plates simply thrown down into the pipe would only be minimally protected from an excavator tooth. The plastic pipe is quickly broken, and the excavator tooth leaves a deep scratch on the plate...

My recommendation, therefore, is an additional metal plate covering the engraving, both slid onto the thread of an M24 V4A stainless steel eye bolt and screwed tight with an M24 V4A hex nut. Such a package of eye bolt, two metal plates, and a nut weighs a good kilogram. Such a chunk easily withstands an excavator tooth! The metal plates may get a few scratches on the outside, but inside, everything remains untouched. (Incidentally, one can also easily screw three engraved metal plates plus an additional plate into one package)

Now all that is needed is a connection between the pipe plug and the eye bolt: In the center of the pipe plug, drill a 3 mm hole and thread a 2 mm Dyneema rope through it. On the top side of the pipe plug, make a knot. The rope goes down, almost to the end of the pipe. At this end of the rope, tie the eye bolt so tightly that it hovers above the ground. A Dyneema rope with a 2 mm diameter has a breaking load of over 400 kg and a maximum elongation of 1%. Furthermore, this material is absolutely long-term stable, even in the presence of moisture, snail slime, and fungal mycelium. Since Dyneema has a smooth surface, a bowline knot is recommended at both ends of the rope.

To retrieve the metal plates, clear the pipe plug, lift the pipe plug, and pull the eye bolt with the intact seed into the daylight using the rope.

Pipe plug-Dyneema-Eye bolt
The pipe plug is connected to the metal bolt via a Dyneema rope. On the packaging of the Dyneema rope, there is a picture of a bowline knot to always know which knot works very well with this material.

Those who want to optimize further can take the following selection as inspiration, depending on their own security needs:


In the following film, you can see the retrieval of a laser-engraved metal plate:

Back to topics – click the grey triangle: