SeedGrid 32×64
Physical randomness. Deterministic lookup.
No flips. No rolls. Strong entropy — anyone can do it!
Generate a BIP-39 seed phrase fully offline: two bags of numbered tokens — chits or housie coins — and a printed grid. Two physical draws select one of 2,048 words, and the mapping is simple enough to audit in minutes — no website, no computer, and no device for the entropy words.
32 × 64 = 2,048
TL;DR / ELI5 — generating a seed in one glance
Two draws out of two bags, a printed grid, and you have a seed phrase. That is the whole method. Here it is step by step, in plain English.
- Print the grid. The large grid PDF is colour, A4 landscape, eight readable sheets — or use the compact grid (2 pages, best on A3). See the printing instructions.
- Make two bags of numbered tokens. Bag A holds 64 identical tokens numbered 1–64. Bag B holds 32 identical tokens numbered 1–32. Home-made paper chits or commercial housie/Tambola coins both work.
- Draw your first word. Shake Bag A well, draw one token — that number is A. Shake Bag B well, draw one token — that number is B. Put both tokens back before the next draw.
- Look up cell (A, B). On the grid, go to row A and column B. The word written in that cell is one seed word.
- Repeat until you have your words. Do this 12 times for a standard 12-word seed (or 24 times for a 24-word seed). Write the words down, in order, on paper — the 12-word draw record sheet or the 24-word draw record sheet has a row for each draw and a slot for each final word.
- Only the last word needs a device. The 12th (or 24th) word is a checksum. Compute it with an air-gapped tool such as SeedSigner's "Calculate word 12/24" — never type your whole phrase into a website.
No website generates your entropy. The randomness comes from the physical bags; the grid only performs a deterministic lookup, exactly like a phone book from coordinates to words. The result is a seed phrase you can audit by hand in a few minutes.
1 · What SeedGrid is
BIP-39 is the standard that turns a human-readable sequence of words into a Bitcoin wallet's entropy. The English BIP-39 word list contains exactly 2,048 words.
SeedGrid 32×64 exploits a coincidence that makes physical entropy generation easy to understand:
2,048 = 32 × 64
You prepare two bags of numbered tokens — home-made chits or commercial housie/Tambola coins. Bag A holds 64 tokens numbered 1–64. Bag B holds 32 tokens numbered 1–32. After thoroughly mixing each bag, you draw one token from each. The pair (A, B) points to one cell in a 64-row × 32-column grid, and that cell is assigned one BIP-39 word.
The physical randomness comes from the bags. The grid — whether on paper or on this page — only performs a deterministic lookup. This is the design philosophy of the project:
The philosophy
Don't trust the website to generate your entropy. Generate randomness physically. Use software only for deterministic mapping and verification.
2 · Why 32×64?
BIP-39 has 2,048 words. Rather than rolling dice, flipping coins, or relying on a website to pick words, SeedGrid uses two independent, equally simple physical sources and a lookup grid that covers the word list exactly.
Why this decomposition?
- 32 and 64 are factors of 2,048, so every coordinate pair maps to a valid word and no word is left out.
- Two small bags are easy to prepare and mix well. A 2,048-token barrel is not.
- The grid is rectangular and legible. Rows and columns make the mapping visual and auditable.
- No arithmetic bias is possible. There is exactly one pair per word, and one word per pair.
SeedGrid is not mathematically superior to dice or coin flips. It is an alternative physical entropy mechanism designed to make the mapping from physical randomness to BIP-39 word indexes easy to understand, audit, and verify. For a direct comparison with coins and dice, see §6.
3 · The mapping — coordinates, not multiplication
A common misunderstanding: SeedGrid does not multiply the two drawn numbers. The two numbers are coordinates.
Bag A selects one of 64 rows. Bag B selects one of 32 columns. Together they select one of 32 × 64 = 2,048 cells, and each cell is assigned exactly one BIP-39 index.
This is a bijection — a one-to-one pairing — between
{1, …, 64} × {1, …, 32} ↔ {1, …, 2,048}
The index of a cell is:
index = (A − 1) × 32 + B
Because the mapping is a bijection, every possible pair produces a distinct word, and every word is reachable. There are no collisions and no gaps.
Worked example
Suppose you draw A = 62 from Bag A and B = 21 from Bag B.
index = (62 − 1) × 32 + 21 = 1,952 + 21 = 1,973
Cell (62, 21) is row 62, column 21 of the grid below — index 1,973 — and maps to the 1,973rd word of the official BIP-39 English list.
Reference mappings
| A (row) | B (column) | Index | BIP-39 word |
|---|---|---|---|
| 1 | 1 | 1 | abandon |
| 1 | 32 | 32 | advance |
| 2 | 1 | 33 | advice |
| 2 | 32 | 64 | among |
| 62 | 21 | 1,973 | walk |
| 64 | 32 | 2,048 | zoo |
Index 1 is the first BIP-39 word (abandon); index 2,048 is the last (zoo). These mappings are asserted programmatically by the project's generator and are reproduced verbatim in the full grid below.
Reverse mapping
Given any index from 1–2,048, the coordinates are recovered by:
A = floor((index − 1) / 32) + 1
B = ((index − 1) mod 32) + 1
4 · Physical procedure
Preparation
- Print the large grid or compact grid (see printing instructions).
- Bag A: 64 identical tokens numbered 1–64.
- Bag B: 32 identical tokens numbered 1–32.
Materials — chits or housie coins
The tokens can be anything identical in size, weight, and feel except for the number printed on them. Two common options:
- Make-your-own chits. Cut equal rectangles of the same paper or plastic and number them 1–64 and 1–32. Keep every chit the same thickness; a chit that is creased, folded, or slightly larger can be detected by touch.
- Housie / Tambola coins. Commercial Housie (Tambola) games are sold with 90 numbered coins (1–90) of a uniform finish. Use the coins numbered 1–64 in Bag A and 1–32 in Bag B. One set supplies only 90 coins and the two bags need 96, so use two sets (or top up with home-made chits). Remove the unused coins — 65–90 and 33–90 — and store them separately so they can never be mixed into a bag by accident.
Token hygiene matters
Every token in a bag must be indistinguishable by touch, weight, or marking except for its number. A token you can feel or see through changes the probabilities.
- Use a single style, color, and batch. Never mix coins from different sets in one bag.
- Inspect housie coins for defects: worn or smudged numbers, scratches, or edge wear that reveals a number before the draw.
- Do not use translucent or see-through tokens.
- Do not reuse damaged or defaced tokens.
Each draw
- Thoroughly mix Bag A.
- Thoroughly mix Bag B.
- Draw one token from Bag A — record its number as A.
- Draw one token from Bag B — record its number as B.
- Locate the cell at row A, column B in the SeedGrid.
- Record the BIP-39 word shown in that cell, together with its index.
- Return both tokens to their respective bags.
- Mix both bags again.
- Repeat until you have the number of entropy words you need.
Returning each token before the next draw is mandatory. If a token is not replaced, the next draw is no longer independent and the resulting sequence is biased.
Record words and indexes on paper in the order drawn — the 12-word draw record sheet or the 24-word draw record sheet provides one blank row per draw and a numbered box for the final phrase. When you are finished, your written record is your seed material — handle it exactly as you would handle a seed phrase (see Security).
5 · The BIP-39 relationship
A BIP-39 mnemonic is a sequence of words drawn from the 2,048-word list. The number of words you need depends on the entropy (randomness) you want:
- 12-word mnemonic — 128 bits of entropy + a 4-bit checksum.
- 24-word mnemonic — 256 bits of entropy + an 8-bit checksum.
Each SeedGrid word carries 11 bits of entropy (log2(2,048) = 11). Eleven words therefore provide 121 bits — close to, but not quite, the 128 bits a 12-word phrase needs.
The final word is not random entropy
The last word of a BIP-39 mnemonic is constrained by a checksum: the first 4 bits (12-word) or 8 bits (24-word) of SHA-256 of the entropy. It must not be selected independently as random entropy, or your mnemonic will be invalid.
Precisely: for a 12-word phrase, generate 11 entropy words and derive the 12th from the checksum. For a 24-word phrase, generate 23 entropy words and derive the 24th. (Strictly, the final word also encodes the last 7 or 3 entropy bits respectively; the key point is that it is determined by a SHA-256 checksum and cannot be freely chosen.)
Deriving a checksum word requires computing SHA-256 over your entropy. Never type your words into an arbitrary website. If you use software for the checksum, use a well-known, verified BIP-39 tool on an air-gapped machine, and destroy or avoid any intermediate digital copies.
SeedGrid itself selects words. It does not create wallets, derive addresses, or manage keys.
6 · Comparison: coins, dice, and SeedGrid
SeedGrid is not more secure than fair dice or fair coin flips — all three can produce uniform, independent randomness. They differ in the work needed to turn raw outcomes into BIP-39 words.
| Method | Throws (12-word / 24-word phrase) | Mental math | Turning a throw into a word | Device needed to produce the words? |
|---|---|---|---|---|
| Coin flips | 128 / 256 flips | Count flips, group into 11-bit chunks, convert binary → decimal | Convert the index, then look up the word | No — possible by hand, but easy to get wrong |
| Dice (D6) | 50 / 100 rolls (base-6), or ~5–7 rolls per word with a rejection table | Convert base-6 to binary — impractical over many rolls | Needs base conversion or a printed dice table | Practically yes |
| SeedGrid | 22 / 46 draws (2 per word) | None | None — the cell already shows the word | No |
Coins
A coin flip is 1 bit. Eleven flips make 2¹¹ = 2,048 values — exactly one BIP-39 index, so nothing is wasted. But you must count 128 (or 256) flips without losing your place, group them into 11-bit chunks, and convert each chunk from binary to decimal before you can look up the word. Do it by hand and mistakes are easy; do it with a device and a device has entered the process.
Dice
A D6 gives log26 ≈ 2.585 bits per roll — not a power of two, so a single die cannot land on an exact 11-bit index. You must either accumulate 50 rolls (for a 12-word phrase) and convert the base-6 value to binary — base-6 arithmetic across 50 digits is not something to do in your head — or use a per-word rejection table and re-roll every out-of-range outcome, discarding a meaningful share of your throws. Either path leaves you dependent on a device or a specially printed dice table.
SeedGrid
Exactly two draws per word: Bag A (2⁶ = 64) picks a row, Bag B (2⁵ = 32) picks a column, and 2⁵ × 2⁶ = 2¹¹ = 2,048 cells means every pair is a distinct word. The cell shows the index and the word together. There is nothing to count, nothing to convert, and nothing to reject — you read the cell and write down the word.
Every method still needs one device: for the final word
The last word of a 12- or 24-word phrase is fixed by a SHA-256 checksum of the preceding entropy (see §5). That checksum cannot be computed by hand, and the word is not random. So all physical methods — coins, dice, and SeedGrid alike — need a device for that single final word.
SeedGrid needs no device for anything else. For the checksum word, use an air-gapped, open-source device such as a SeedSigner, which includes an offline "Calculate word 12/24 of a BIP39 seed phrase" feature, or another well-known BIP-39 tool on a computer that has never touched the network. Never use an online website for this step.
The final word also carries the last entropy bits
When a tool is given 11 (or 23) words and asked to compute the last word, that word encodes the remaining 7 (or 3) bits of entropy together with the checksum bits. Some tools silently zero-fill those bits, which reduces a 12-word phrase to 121 bits of entropy instead of 128. SeedSigner (version 0.5.1 and later) instead lets you supply them — for example with a few coin flips — so that the full 128 (or 256) bits come from physical randomness. Prefer that option when it is offered.
Honest caveats
- Preparation. SeedGrid requires assembling the two bags and printing the grid before you begin. Coins and dice need no setup — but they also need a separate printed word list, which SeedGrid's grid replaces.
- No superiority claim. This is a usability comparison. The security analysis in §8 is unchanged: a fair coin, a fair die, and a well-mixed bag are all valid sources of entropy.
7 · The complete 2,048-cell grid
The grid maps every (A, B) pair to exactly one of the 2,048 BIP-39 words: 64 rows (A = 1–64) by 32 columns (B = 1–32), each cell showing the index, the word, and its A, B coordinates.
Open the large grid PDF (8 readable A4 sheets) or the compact grid PDF (2 pages, best on A3) to view or print — colour, A4-landscape documents holding nothing but the grid. For the draws themselves, print a 12-word draw record sheet or a 24-word draw record sheet (single A4 portrait page) to write down your A, B, index, and word values.
8 · Security analysis
Why the mapping is unbiased
There are exactly 32 × 64 = 2,048 possible coordinate pairs. Each pair maps to exactly one BIP-39 index, and every index is mapped to exactly once. Therefore, assuming the two physical draws are uniform and independent:
P(each BIP-39 index) = 1 / 2,048
Each generated word therefore represents
log2(2,048) = 11 bits of entropy
This arithmetic is necessary for a secure method — but it is not sufficient. Correct mathematics cannot compensate for weak physics.
What practical security actually depends on
- Quality of physical randomization. Thorough, honest mixing of both bags on every draw.
- Indistinguishable tokens. No visual, tactile, or weight differences between tokens in a bag.
- No ability to predict or influence draws. Including the order you draw and the way you reach in.
- Replacement of every token after every draw. Withdrawal without replacement breaks independence.
- Protection against observation. Cameras, sight lines, and eavesdroppers can record your draws.
- A correct BIP-39 implementation. Including the checksum word and a genuine, unmodified word list.
- Secure handling of the resulting mnemonic. The words are your private keys in a human-readable form.
Not a complete hardware wallet
SeedGrid is an entropy-generation and word-selection method. It is not a complete hardware wallet. It does not store, sign, transmit, or otherwise protect your keys. Once a mnemonic exists, its security is governed entirely by how you generate, store, and use it.
Never enter an existing seed phrase here
This site operates only on three values: an A coordinate, a B coordinate, and a BIP-39 word index. It never asks for — and you should never enter — an existing seed phrase, a private key, an extended private key, or a wallet password. If a page ever asks for those, you are not on a SeedGrid page.
Privacy and offline operation
- This page is a single static HTML file. There is no server, no database, and no user accounts.
- There are no analytics, no trackers, and no third-party scripts.
- The lookup happens entirely locally — on paper, or in your browser against the word list bundled in the page. No seed material ever leaves your device.
- The page makes no external network requests. After the page is loaded, it works offline.
9 · Threat model and limitations
An honest threat model lists what a method defends against and what it cannot. SeedGrid addresses the risks of computational word generation; it cannot address the physical and human risks around you.
Threats SeedGrid helps address
- Biased word selection in software. The website is never the source of randomness.
- Malicious website modification. The mapping is a simple bijection you can verify by hand against the official list.
- Opaque "randomness." Physical draws are visible and auditable by anyone present.
- Modified word list. This project publishes its word list and its source (see Project); a printed grid is a fixed artifact you can spot-check.
- Transmission of the mnemonic. Nothing is ever sent anywhere.
Threats SeedGrid does NOT address
- Biased or insufficient physical draws. Bad mixing, distinguishable tokens, or non-replacement produce biased entropy no matter how correct the grid is.
- Damaged or missing tokens. A torn or worn coin, or a missing token, skews the distribution.
- Observation. Cameras, mirrors, or someone watching your draws and your records.
- Compromised lookup table. If you use a printed grid from an untrusted source, verify it against the official list before relying on it.
- A compromised computer. Keyloggers and screen capture during any digital step, including checksum derivation.
- Malware. The browser you view this page in could, in principle, be hostile; physical paper avoids this entirely.
- Photographing or filming your mnemonic.
- Storing the mnemonic digitally. Screenshots, password managers, cloud notes, or email.
- Human transcription errors. Reading the wrong row or column, or writing a wrong word.
- Loss, theft, or destruction of your paper records.
If you act on a mnemonic generated this way, your overall security is the weakest link in this list — not the arithmetic.
10 · Printing instructions
Three ready-made PDFs ship with this guide — the two grids in colour, A4 landscape, containing nothing but the grid, plus a draw record sheet (A4 portrait) for writing down each draw. Pick what suits your printer, then choose File → Print (or Ctrl/Cmd + P):
Option 1 — the large grid (recommended): seedgrid.pdf
Eight A4 sheets, one 16-row × 16-column tile each, in the order: rows 1–16 (cols 1–16, 17–32), rows 17–32, rows 33–48, rows 49–64 (cols 1–16, 17–32). Arrange the sheets 2 wide × 4 tall, in sheet-number order — each sheet repeats its row and column headers and shows its own ranges in the title bar and footer. The large cells keep the type comfortably readable without any aid. It is more pages to navigate and tape together, but it prints easily at home on plain A4.
Option 2 — the compact grid: seedgrid-compact.pdf
The whole 64 × 32 grid on two A4 pages (four 8-row bands per page). Recommended paper: A3 — print the two pages on A3 landscape for a single large grid. On A4 the type is small: it will print, but you will likely need a magnifier.
Option 3 — the draw record: seedgrid-record-12.pdf and seedgrid-record-24.pdf
A single A4 portrait page you fill in by hand as you draw. Use the 12-word sheet for a 12-word seed (11 rows — one per draw — with blank boxes for the A and B values, the cell index, and the word you find at cell (A, B)) and the 24-word sheet for a 24-word seed (23 rows). At the bottom, a numbered box with 12 or 24 slots lets you write the final seed phrase in order before you destroy or file the log. The last slot is highlighted as the checksum — compute word 12/24 with an air-gapped device such as SeedSigner ("Calculate word 12/24"); never draw it from the bags. Print one sheet per phrase you generate.
- Select a printer or "Save as PDF".
- Paper size: A4 for Options 1 and 3, A3 (or A4) for Option 2.
- Orientation: landscape for Options 1–2 (the documents already default to it); portrait for Option 3 (also the default).
- Scale: 100% — avoid "Fit to page", which shrinks the type.
- Keep colour on; the tints help your eye track rows across the wide page.
Each cell shows its index, its word, and its A, B coordinates, stacked. Words are set at a readable size that is still sized to the column width, so words never bleed into an adjacent cell. The shading is decoration only: indexes and words are always legible in black-and-white.
The printed A, B coordinates double as a verification aid: after writing your seed words, re-read each cell's pair against the row and column headers to catch a one-cell misread.
Before you trust a printed grid for real funds, verify a handful of cells by hand against the official BIP-39 English word list linked in the Project section.
11 · Project, source, and license
SeedGrid 32×64 is an open-source project. Its goal is a method and an artifact that a security researcher — or a careful user — can fully inspect.
- The word list is the official BIP-39 English word list from the Bitcoin BIPs repository, reproduced verbatim. See docs/WORDLIST.md for the exact source, its SHA-256 digest, and how the 2,048 words were validated.
-
The mapping is
index = (A − 1) × 32 + B. It is a bijection and contains no hidden logic. -
The generator (
scripts/generate_guide.py) is plain Python that expands this page from the word list and asserts the word count, uniqueness, endpoints, and sample mappings on every run. - No JavaScript, no frameworks, no dependencies. This page is HTML + CSS.
SeedGrid makes no claim of superiority over dice, coin flips, or other physical entropy methods. It claims only that its mapping is exact, auditable, and unbiased given unbiased physical draws.
License: MIT. Contributions are welcome.
Follow @seedGrid on X (Twitter) and email seedgrid@outlook.com for feedback, questions, or reports.
Support the project
SeedGrid is free and open source. Donations are optional and help with continued development.
Bitcoin — Silent Payments (BIP-352):
sp1qq27nm90szvswd0lsgj8g8d6k6u5rk74p6ndm6d5234vdadnhspvuvqmj2gpg4cagz5ukk62c2ewh7hukmxdaeluc2c5je7e5jm37fcujgyn7tet4
Lightning: seedgrid@coinos.io
Both addresses are case-sensitive — copy exactly.
Upcoming
- 1-on-1 consulting. Coming soon. Guided setup and support for building your SeedGrid tokens, running the method, and verifying seeds. Email or DM to register interest.
- Online support AI agent. In development — not yet available. An always-on assistant for questions, troubleshooting, and on-demand explanations of the lookup method.
- Multi-language support. Planned. The guide and grid will be localised in Español, 中文, Français, and 日本語 so the method is accessible to non-English speakers.
12 · FAQ — generating seed words offline
What is the easiest way to generate Bitcoin seed words?
SeedGrid generates BIP-39 seed words with two physical draws and a printed 2,048-cell grid. Shake one bag of 64 numbered tokens and one bag of 32, draw one token from each, then read the word at that grid cell. No counting, no binary or base-6 conversion, and no device is needed for the entropy words.
Can I generate a seed phrase offline, without a computer or internet?
Yes. The randomness comes from two bags of physical tokens, and the grid is a printed lookup table, so no computer or internet connection is involved. The only exception is the final checksum word (the 12th or 24th), which you compute with an air-gapped tool such as SeedSigner.
Should I use an online seed-phrase generator?
No. Online generators put your entropy in software, which can be compromised, logged, or replaced. SeedGrid keeps entropy entirely offline and physical: the grid performs a deterministic lookup only, and nothing about your seed ever touches the internet.
How do I make a 12- or 24-word seed phrase?
Make one draw for each word. Each draw selects one of the 2,048 BIP-39 words. Do 12 draws for a standard 12-word seed or 24 draws for a 24-word seed, writing each word down in order on the supplied 12-word or 24-word draw-record sheet. The last word is a checksum, not random entropy.
Is SeedGrid easier than dice or coin flips?
Dice and coin flips need counting and binary or base-6 conversion to become word indices. SeedGrid skips the conversion: the grid maps every (A, B) draw directly to a word, so it is easier to do correctly and easier to audit.
Do I need a hardware wallet to generate seed words?
No. The entropy words are produced by physical draws, so no hardware wallet is required to generate them. You only need an air-gapped device (such as a SeedSigner) to calculate the final checksum word, and later a wallet to turn the phrase into addresses.
How is the last (checksum) word computed?
The 12th or 24th BIP-39 word is a checksum derived from the entropy of the words before it, so it must be computed rather than drawn. An air-gapped tool like SeedSigner has a "Calculate word 12/24" feature for exactly this. Never type your full phrase into a website.