Passphrase → private key (brainwallet)
SHA-256 one sentence and you get a whole wallet: WIF, public key, hash160 and addresses. This page shows exactly how thin that is — and why every funded brainwallet gets swept within seconds.
Enter a value above and press Convert. Not sure what to type? Press “Use example” to load the sample from the placeholder.
What this page computes
It takes a passphrase and derives a complete Bitcoin wallet from it with a single SHA-256 call. That is the whole algorithm — there is no salt, no iteration count, and no memory-hardness parameter:
The page is deliberately complete: it shows the input bytes, the digest, and every derived value, so that you can see exactly how little stands between a sentence you can remember and a private key. It is also deliberately one-sided about the consequences — see below.
Any address derived here is derived from a phrase that is either famous enough to be in every attacker's wordlist or weak enough to be found by a targeted search. Automated bots monitor the blockchain and the mempool continuously and sweep brainwallet deposits within seconds, usually paying a higher fee than you did so that their spend confirms instead of yours. Funds sent to a brainwallet address, including the one this page shows for the sample phrase, will be taken. There is no way to make this page safe; use a BIP39 mnemonic generated by a hardware wallet.
1. The brainwallet idea, and why it feels so appealing
Bitcoin private keys are just 256-bit numbers, and any deterministic function of a memorable string can produce one. That gives an irresistible pitch: no paper backup, no metal plate, no seed phrase to lose — the wallet lives in your head and can be re-created anywhere on earth, from any computer, forever. Whole blog posts of 2011–2013 recommended it.
The flaw is not in the hashing. The flaw is in the word memorable. A private key has to be unpredictable to an attacker; a phrase you can recall without notes is, by construction, a phrase that comes from the tiny and heavily documented region of language space that humans find memorable. You have not created 256 bits of secret — you have created a lookup entry.
Two failure modes cover essentially every real brainwallet loss:
- Precomputation. An attacker hashes millions of candidate phrases once, derives the addresses, and stores them. From then on, any deposit to any of those addresses is detected instantly — it does not matter that the phrase was "secret", because the attacker never needed to guess it again.
- Targeted search. If your phrase is personal, an attacker who knows something about you ("a fan of Tolkien, likes horses") searches a far smaller space than 2²⁵⁶. Because one SHA-256 is all it costs per guess, that space is cheap to enumerate.
2. Why a single unsalted SHA-256 is a catastrophic key-derivation function
SHA-256 is a fast, general-purpose hash. Its designers optimised it for exactly the property that makes a key-derivation function fail: maximum throughput per second per dollar. When you hash a phrase once and spend the result, the attacker's cost to test one guess is one SHA-256 evaluation — measured in nanoseconds, and on dedicated silicon in picoseconds.
| Property a password KDF needs | Brainwallet (one SHA-256) | Why it matters |
|---|---|---|
| A random salt, stored with the record | none — the phrase alone determines the key | Without a salt, one precomputation serves every target and every address forever. Salts also stop rainbow tables and make identical phrases produce different keys. |
| A tunable work factor (iterations) | 1 iteration, unchangeable | The cost per guess cannot be raised as hardware gets faster. What was expensive in 2011 is free today. |
| Memory hardness | none — a few hundred bytes of state | ASICs and GPUs love low-memory algorithms. Memory-hard functions force the attacker to buy RAM and memory bandwidth, which does not scale like hashing does. |
| Collision/collapse resistance to weak inputs | none — the input space is the attacker's wordlist | The security of the key is the entropy of the phrase, not the strength of the hash. A hash cannot add entropy that was never there. |
That last row is the whole story. Hash functions do not create unpredictability; they preserve the unpredictability of their input, and they preserve the predictability of it just as faithfully.
The arithmetic of a dictionary attack
Suppose an attacker has a corpus of 10,000,000 candidate phrases (a downloaded password list, famous quotes, song lyrics, Wikipedia sentences, plus every phrase ever posted about brainwallets). The time to exhaust it is simply corpus ÷ throughput, and raw SHA-256 throughput is enormous:
| Attacker throughput | 10⁷-phrase corpus exhausted in | Equipment, for scale |
|---|---|---|
| 10⁴ guesses/s | 1,000 s ≈ 17 minutes | one CPU core running a naive script |
| 10⁵ guesses/s | 100 s | one CPU core, optimised |
| 10⁶ guesses/s | 10 s | a laptop GPU with a tuned tool |
| 10⁹ guesses/s | 0.01 s | a single modern graphics card on raw SHA-256 |
| 10¹¹ guesses/s | 0.0001 s = 100 µs | a small cluster or FPGA farm |
Read the top row again: a corpus of ten million phrases is exhausted in minutes on one CPU core. The bottom row is why sweepers are described as instantaneous. And notice what the same corpus costs against real key-derivation functions — the only thing that changes is the price of one guess:
| KDF applied to each candidate phrase | Hash operations per guess | Guesses/s at 10⁹ hash-ops/s | 10⁷-phrase corpus |
|---|---|---|---|
| one SHA-256 (this page) | 1 | 1,000,000,000 | 0.01 s |
| double SHA-256 | 2 | 500,000,000 | 0.02 s |
| PBKDF2-HMAC-SHA512, 2048 iterations (BIP39) | ~4,096 | ~244,000 | ~41 s |
| PBKDF2-HMAC-SHA512, 2,097,152 iterations | ~4,194,304 | ~238 | ~11.7 hours |
| scrypt N=2¹⁵, r=8, p=1 (≈32 MiB per guess) | memory-bound | hundreds to thousands per machine | hours to days, and RAM-bound |
| Argon2id, 64 MiB, t=3 | memory-bound | hundreds to thousands per machine | hours to days, and RAM-bound |
The last two rows are qualitative on purpose: their cost is set by how much memory the attacker can afford to fill, not by how many hashes they can compute, so a single number would be misleading. That is exactly the point of a memory-hard KDF.
3. Human-chosen phrases have tens of bits of entropy, no matter how long they look
Entropy is not a property of a string; it is a property of the process that chose it. If
you had generated the sample phrase by rolling dice over 95 printable characters, its 28 characters would
carry 28 × log₂(95) ≈ 184 bits and it would be unbreakable. But you did not: you, or the author of
the blog post, chose a sentence that other humans find memorable, and the set of such sentences is small and
extensively catalogued. The string is long; the choice was short.
| Kind of passphrase | Apparent length | Illustrative attacker search space | Time at 10⁹ guesses/s |
|---|---|---|---|
| one dictionary word | ~8 characters | ~10⁵ | 100 µs |
| two dictionary words plus digits | ~12 characters | ~10¹⁰ | 10 s |
| four common words (XKCD style) | ~28 characters | ~2⁴⁴ ≈ 1.76 × 10¹³ | 17,592 s ≈ 4.9 hours |
| a line from a famous book or song | 40+ characters | every line of every digitised book, song and quote — order 2³⁵ | ~34 s |
| 12-word BIP39 mnemonic (measured honestly) | ~93 characters | 2¹²⁸ | ~10²² years |
| random 256-bit key | 64 hex characters | 2²⁵⁶ | ~10⁶¹ years |
The search-space column is order-of-magnitude illustration, not measurement — but the arithmetic that converts it into time is exact, and that is the argument. Moving from "four common words" to "twelve words drawn from a 2048-word list" changes the attacker's job from hours to more than the age of the universe, because the entropy went from 44 bits to 128 bits. Memorability and entropy pull in opposite directions: every trick that makes a phrase easier for you to recall makes it easier for a wordlist to contain.
4. The historical record: the sweepers
Between roughly 2013 and 2015 brainwallets were not merely risky — they were actively farmed. Automated sweeper bots worked the problem at both ends:
- Offline: hash enormous candidate lists, derive the addresses once, and keep the resulting set. This is a one-time cost that then answers every future deposit instantly.
- Online: watch every new block — and often the mempool, before a block is even mined — for an output paying one of those addresses. The moment one appears, broadcast a spend of it with a higher fee so that the sweeper's transaction confirms first. Deposits were emptied in seconds, and in many documented cases the money never even reached a confirmed balance in the victim's own wallet.
The practice was studied academically. In The Bitcoin Brain Drain (Vasek, Bonneau, Castellucci, Keith and Moore, Financial Cryptography 2016) the authors scanned the blockchain for passphrase-derived addresses, found several hundred that had ever been funded, and reported that the great majority had been drained by attackers — press coverage of the paper put the stolen total at roughly $103,000. The specific figure matters far less than the pattern: funded brainwallets were emptied, nearly universally, and usually within minutes or seconds.
Meanwhile, the phrases that were famous enough to appear in tutorials — the XKCD sentence used as the sample on this page, the first lines of well-known books and songs, anything repeated in a forum thread — were derived by thousands of people and swept years ago. Publishing a brainwallet is the same as donating it. The address shown in the results panel for the sample phrase has been republished countless times; treat it as burned, because it is.
Possibly true today. This is not the defence it feels like. The attacker's list is not fixed: it grows with every leaked password dump, every published brainwallet article and every social-media post, and your address is watchable forever at zero cost. A brainwallet is not a secret with a long shelf life; it is a public challenge with a prize attached, and it stays open for as long as the coins are there.
5. What a properly designed KDF does instead
Password-based key derivation functions are engineered to be expensive for the attacker while staying tolerable for the legitimate user:
- A salt — random per user, stored next to the ciphertext — makes precomputation useless
and ensures that two people with the same passphrase get different keys. BIP39 uses a deterministic salt
(
"mnemonic" ‖ passphrase) precisely because the wallet must be re-derivable; the entropy of the words has to carry the security instead. - An iteration count multiplies the cost of a single guess. Raising it from 1 to 2048 makes each guess 2048 times more expensive; raising it to two million makes brute force 2,000,000 times slower. This is the parameter that fights GPUs and ASICs, and it is why a brainwallet with one hash is indefensible: the attacker is running the cheapest possible inner loop.
- Memory hardness attacks the economics of parallel hardware. A GPU can run thousands of SHA-256 cores because SHA-256 needs a few dozen bytes of state; scrypt and Argon2id require megabytes per guess, so throughput becomes a memory-bandwidth and RAM-capacity problem instead of a raw-hash-rate problem. Argon2id (the 2015 Password Hashing Competition winner, standardised in RFC 9106) adds tunable memory and parallelism on top of the iteration count.
Note carefully, though: BIP39 uses only 2048 PBKDF2 iterations. That is not a strong KDF setting, and it is not meant to be. BIP39 does not depend on the KDF for security — it depends on 128–256 bits of entropy that the words encode, plus an optional passphrase that acts as a salt. The lesson generalises: choose an input with real entropy and a KDF that is expensive; neither alone is enough.
6. Brainwallet vs BIP39 mnemonic vs random key
| Brainwallet | BIP39 mnemonic | Random 256-bit key | |
|---|---|---|---|
| Entropy source | A phrase recalled by a human being | A CSPRNG, then encoded as words | A CSPRNG or a secure element |
| Real entropy | Tens of bits at best; effectively 0 for a published phrase | 128 bits (12 words) … 256 bits (24 words) | Up to 256 bits |
| Key derivation | One unsalted SHA-256 — no work factor at all | PBKDF2-HMAC-SHA512, 2048 iterations, salted with the passphrase | None needed |
| Recoverable from memory? | Yes — which is the whole problem | Yes, if the written backup is lost | No — without the backup the coins are gone |
| Safe to use? | No | Yes, if generated by trustworthy software and the backup is protected | Yes, with a backup |
| Brute-force cost per guess | ~1 hash | ~4,096 hash operations | Irrelevant — 2²⁵⁶ guesses |
| What an attacker needs | A wordlist and a browser tab | Your backup, or a flaw in your software | Your backup, or a flaw in your hardware |
7. Worked example: the XKCD phrase
The sample in the input box is the famous four-word sentence from XKCD #936, and this is exactly what the form above computes for it — the real values, reproducible right here:
| Step | Value |
|---|---|
| Passphrase | correct horse battery staple (28 characters, 28 UTF-8 bytes) |
| Input bytes as hex | 636f727265637420686f727365206261747465727920737461706c65 |
| Private key = SHA-256 of those bytes | c4bbcb1fbec99d65bf59d85c8cb62ee2db963f0fe106f483d9afa73bd4e39a8a |
| WIF (compressed) | L3p8oAcQTtuokSCRHQ7i4MhjWc9zornvpJLfmg62sYpLRJF9woSu |
| Public key (compressed) | 0378d430274f8c5ec1321338151e9f27f4c676a008bdf8638d07c0b6be9ab35c71 |
| hash160 | 79fbfc3f34e7745860d76137da68f362380c606c |
| P2PKH address | 1C7zdTfnkzmr13HfA2vNm5SJYRK6nEKyq8 |
| P2SH-P2WPKH / P2WPKH / P2TR | 3KToBU4ykTWfjnu4kAUV1q8QosnxT61sbf / bc1q08alc0e5ua69scxhvyma568nvguqccrv4cc9n4 / bc1p3833qjvky7c2w3r7earqqwc377qeztadmfwjpwyy5srsch868lgs2v8tnw |
| Apparent entropy if the 28 characters had been random | 28 × log₂(95) ≈ 184 bits |
| Actual security of this phrase | None — it is in every brainwallet tool, tutorial and wordlist in existence |
Notice how complete the wallet looks. That is the trap: the output is indistinguishable from a properly generated wallet. Nothing in the address, the WIF or the checksum reveals that the key behind it came from a sentence that half the internet has already hashed. The only thing that distinguishes a safe wallet from this one is where the key came from.
8. Common mistakes
- "It is long, therefore it is strong." Length is not entropy. A 60-character quote has less real entropy than three dice-chosen words.
- "I added a symbol and a number." Every cracker applies those rules automatically; a mangling rule list is a standard feature, not a defence.
- "Nobody knows my sentence." If it is from a book, a film, a song, a forum post or your own social media, somebody — or somebody's corpus — knows it. If you invented it, it followed a human-generated pattern, and those are modelled too.
- "The blockchain is anonymous, so nobody will find it." The opposite is true: the blockchain is a permanently public, machine-readable list of exactly which addresses received money, and sweepers read all of it.
- "I will remember it forever." Memory is the least reliable storage medium humans have. People forget phrases, lose interest in the project, or die; the coins stay forever.
- Confusing this with a memory-hard KDF. Iterating a hash 200,000 times in your head is not the same as a KDF designed against GPUs — and if the input has 30 bits of entropy, no KDF saves it.
9. Quick reference
| Item | Value |
|---|---|
| Derivation | k = SHA-256(UTF-8 bytes of the passphrase), one pass |
| Salt | none |
| Iterations | 1 |
| Memory hardness | none |
| Attacker cost per guess | one SHA-256 evaluation (~nanoseconds) |
| Entropy of a human-memorable phrase | tens of bits, and effectively zero if it was ever published |
| Typical sweep latency after a deposit | seconds |
| Recommended alternative | A BIP39 mnemonic from a hardware wallet — see BIP39 mnemonic → BIP32 child key |
| Should you use this? | No. Read it, understand it, and use it as a demonstration of what not to do. |