๐ Learn how to create a seed phrase by hand in under 10 minutes! Penlock's solution is easy, fast, well-researched, and secure:
โ Works with any wallet
โ Video and illustrated guides available
โ No reliance on third-party tools or websites (OMG please don't do that ๐ซฃ!!)
โ Close to maximum entropy: paper tiles have a 1โ2% bias, better than basic dice (5โ10%) and coins (10โ20%)
Printable components + written guide: ๐

Penlock / Generate a Seed Phrase
Generate a new 12-word seed phrase using real-world, provable randomness.
Available in ๐ฌ๐ง English and ๐ฐ๐ท Korean (auto-detected). Please DM me on Nostr if you'd like to help with additional translations.
๐ฃ Feel free to share widely and across networks โ the tool is MIT licensed, and the video is public domain (CC0)!
Replies (16)
@profk Here's the video guide ;)
Yaharrr
Actually, the process itself takes less than 10 minutes, but since you need to learn, print and cut first it's going to be closer than 30.
I don't think other processes let you avoid printing a wordlist, or then you're using a digital wordlist which might not be the most secure thing in the world especially if you have to scroll that thing back and forth to find your words.
I call bias the net loss of entropy, which is what we care about, and not the deviation from the mean. In that sense, 51/49 is already a 2% bias, out of a big fat coin that's nothing like what you have in your pocket.
And no, it doesn't diminishes over turns: it's a whole 2% entropy loss on your final entropy: so you'd get 125,44 bits of entropy instead of 128.
Now, to be clear, even a 20% bias would lead you to an unbreakable seed phrase -- so in that sense, maybe it can appear negligible. In any case, my goal with Penlock was to create a fail-proof process, and while my number are rough estimate I stand by paper tiles having the both a better safety and entropy profile.
I should have written "up to x%-x%", please read it that way; I lost that nuance while tightening the text and unfortunately I can't edit it now but I definitely found about 8% bias on coins that weren't the absolute worst in my own series of throws.
That being said, I really invite you to try this method & I'm genuinely interested in your feedback about how long it took for you compared to others.
As a clarification, my bias figures are rough estimates of the worst-case scenario for coins, dice, and tiles under good shuffles/throws. Someone correctly pointed out that not every coin or die will be as bad; but it's also easy to underestimate biases because it's generally twice what you'd intuitively expect. (e.g., a 52/48 coin has a 4% bias and generates only ~96 bits of entropy over 100 throws.)
The reason tiles (and cards alike) have a much better safety profile is simple: low-quality coins/dice can be severely imbalanced, while the quality of a deck of tiles/cards has much less impact on the randomness of the draw. Moreover, the elements of a given deck are much easier to audit than the balance of a given coin or die.
Now, to be clear, even a 20% bias would still result in an unbreakable 12-word seed phrase. You'd still have 102.4 bits of entropy, plus 11 additional bits of security from BIP39 key stretching. But my goal with Penlock was to identify and deliver the method that best combines UX and security, and I believe paper tiles are it.
Would Von Neuman debiasing trick help here? ๐ค
after about an hour of retries maybe?
Let us know ๐โโ๏ธ๐
Alright yes, I get your point and I admit my entropy calculation was naive. Essentially, the biases I measured would result in a much lower loss of entropy than I initially thought because they are obviously non-deterministic, which means everything is more secure than I initially thought.
That being said, coins/dices can have significantly higher biases than you assume & I invite you to verify this by yourself (since ultimately, you can always default to doubting whatever I will say on Nostr). Try to compare good nice heavy coins with light ones or various shuffling method & you'll definitely find out that the theory is not meeting the practice.
On the other hand, the wash shuffle is an excellent randomizer is used in casinos all around the world. So when it comes to ranking our options, I am pretty sure tiles would come first in any proper study.
After generating the keys, entering them all into an app is safe??
Only enter them into the wallet that will secure/spend the fund -- in this video I'm using Coconut wallet, it's an application to recycle an old phone into an airgap wallet: the phone is meant to stay in plane mode forever after that.
To be clear, it is definitely be unsafe to enter your seed phrase into a third party application, and you shouldn't do so: this method works for any wallet, and you only need to enter the words in the wallet that'll secure the funds.
Coconut looks cool.
If you know them can you pass the message -
To have signed APK packages along with their releases on github or zapstore.
So people can download it with out depending on play store.
Yes I know them well, they are a Penlock sponsor along with
@Angor. But I don't think they'll want to do that because they are a selling that wallet as their main product. :)
Don't see pricing on the website.
Is it an in app purchase?
๐๐ฅLFG๐