Private Key Tools

Passphrase → private key (brainwallet)

SHA-256 one sentence and you get a whole wallet: WIF, public key, hash160 and addresses. This page shows exactly how thin that is — and why every funded brainwallet gets swept within seconds.

Educational demonstration only. A brainwallet address is derivable by anyone who guesses or knows the phrase, and sweepers watch the chain and the mempool around the clock. Never send funds to an address produced by this page.
The classic XKCD example is shown as a sample. The passphrase is hashed exactly as typed — the server sends nothing anywhere, but a real money-bearing phrase must never be entered into a web page at all. Watch the derived address change completely when you add a single space.
No input yet

Enter a value above and press Convert. Not sure what to type? Press “Use example” to load the sample from the placeholder.

How it works

What this page computes

It takes a passphrase and derives a complete Bitcoin wallet from it with a single SHA-256 call. That is the whole algorithm — there is no salt, no iteration count, and no memory-hardness parameter:

k = SHA-256( UTF-8 bytes of the passphrase )   →   WIF, public key, hash160, addresses
passphrase→ UTF-8 bytes→ SHA-256 (one pass)→ private key k→ k · G→ hash160→ address

The page is deliberately complete: it shows the input bytes, the digest, and every derived value, so that you can see exactly how little stands between a sentence you can remember and a private key. It is also deliberately one-sided about the consequences — see below.

Educational only — do not send money to anything this page produces

Any address derived here is derived from a phrase that is either famous enough to be in every attacker's wordlist or weak enough to be found by a targeted search. Automated bots monitor the blockchain and the mempool continuously and sweep brainwallet deposits within seconds, usually paying a higher fee than you did so that their spend confirms instead of yours. Funds sent to a brainwallet address, including the one this page shows for the sample phrase, will be taken. There is no way to make this page safe; use a BIP39 mnemonic generated by a hardware wallet.

1. The brainwallet idea, and why it feels so appealing

Bitcoin private keys are just 256-bit numbers, and any deterministic function of a memorable string can produce one. That gives an irresistible pitch: no paper backup, no metal plate, no seed phrase to lose — the wallet lives in your head and can be re-created anywhere on earth, from any computer, forever. Whole blog posts of 2011–2013 recommended it.

The flaw is not in the hashing. The flaw is in the word memorable. A private key has to be unpredictable to an attacker; a phrase you can recall without notes is, by construction, a phrase that comes from the tiny and heavily documented region of language space that humans find memorable. You have not created 256 bits of secret — you have created a lookup entry.

Two failure modes cover essentially every real brainwallet loss:

2. Why a single unsalted SHA-256 is a catastrophic key-derivation function

SHA-256 is a fast, general-purpose hash. Its designers optimised it for exactly the property that makes a key-derivation function fail: maximum throughput per second per dollar. When you hash a phrase once and spend the result, the attacker's cost to test one guess is one SHA-256 evaluation — measured in nanoseconds, and on dedicated silicon in picoseconds.

Property a password KDF needsBrainwallet (one SHA-256)Why it matters
A random salt, stored with the recordnone — the phrase alone determines the keyWithout a salt, one precomputation serves every target and every address forever. Salts also stop rainbow tables and make identical phrases produce different keys.
A tunable work factor (iterations)1 iteration, unchangeableThe cost per guess cannot be raised as hardware gets faster. What was expensive in 2011 is free today.
Memory hardnessnone — a few hundred bytes of stateASICs and GPUs love low-memory algorithms. Memory-hard functions force the attacker to buy RAM and memory bandwidth, which does not scale like hashing does.
Collision/collapse resistance to weak inputsnone — the input space is the attacker's wordlistThe security of the key is the entropy of the phrase, not the strength of the hash. A hash cannot add entropy that was never there.

That last row is the whole story. Hash functions do not create unpredictability; they preserve the unpredictability of their input, and they preserve the predictability of it just as faithfully.

The arithmetic of a dictionary attack

Suppose an attacker has a corpus of 10,000,000 candidate phrases (a downloaded password list, famous quotes, song lyrics, Wikipedia sentences, plus every phrase ever posted about brainwallets). The time to exhaust it is simply corpus ÷ throughput, and raw SHA-256 throughput is enormous:

Attacker throughput10⁷-phrase corpus exhausted inEquipment, for scale
10⁴ guesses/s1,000 s ≈ 17 minutesone CPU core running a naive script
10⁵ guesses/s100 sone CPU core, optimised
10⁶ guesses/s10 sa laptop GPU with a tuned tool
10⁹ guesses/s0.01 sa single modern graphics card on raw SHA-256
10¹¹ guesses/s0.0001 s = 100 µsa small cluster or FPGA farm

Read the top row again: a corpus of ten million phrases is exhausted in minutes on one CPU core. The bottom row is why sweepers are described as instantaneous. And notice what the same corpus costs against real key-derivation functions — the only thing that changes is the price of one guess:

KDF applied to each candidate phraseHash operations per guessGuesses/s at 10⁹ hash-ops/s10⁷-phrase corpus
one SHA-256 (this page)11,000,000,0000.01 s
double SHA-2562500,000,0000.02 s
PBKDF2-HMAC-SHA512, 2048 iterations (BIP39)~4,096~244,000~41 s
PBKDF2-HMAC-SHA512, 2,097,152 iterations~4,194,304~238~11.7 hours
scrypt N=2¹⁵, r=8, p=1 (≈32 MiB per guess)memory-boundhundreds to thousands per machinehours to days, and RAM-bound
Argon2id, 64 MiB, t=3memory-boundhundreds to thousands per machinehours to days, and RAM-bound

The last two rows are qualitative on purpose: their cost is set by how much memory the attacker can afford to fill, not by how many hashes they can compute, so a single number would be misleading. That is exactly the point of a memory-hard KDF.

3. Human-chosen phrases have tens of bits of entropy, no matter how long they look

Entropy is not a property of a string; it is a property of the process that chose it. If you had generated the sample phrase by rolling dice over 95 printable characters, its 28 characters would carry 28 × log₂(95) ≈ 184 bits and it would be unbreakable. But you did not: you, or the author of the blog post, chose a sentence that other humans find memorable, and the set of such sentences is small and extensively catalogued. The string is long; the choice was short.

Kind of passphraseApparent lengthIllustrative attacker search spaceTime at 10⁹ guesses/s
one dictionary word~8 characters~10⁵100 µs
two dictionary words plus digits~12 characters~10¹⁰10 s
four common words (XKCD style)~28 characters~2⁴⁴ ≈ 1.76 × 10¹³17,592 s ≈ 4.9 hours
a line from a famous book or song40+ charactersevery line of every digitised book, song and quote — order 2³⁵~34 s
12-word BIP39 mnemonic (measured honestly)~93 characters2¹²⁸~10²² years
random 256-bit key64 hex characters2²⁵⁶~10⁶¹ years

The search-space column is order-of-magnitude illustration, not measurement — but the arithmetic that converts it into time is exact, and that is the argument. Moving from "four common words" to "twelve words drawn from a 2048-word list" changes the attacker's job from hours to more than the age of the universe, because the entropy went from 44 bits to 128 bits. Memorability and entropy pull in opposite directions: every trick that makes a phrase easier for you to recall makes it easier for a wordlist to contain.

4. The historical record: the sweepers

Between roughly 2013 and 2015 brainwallets were not merely risky — they were actively farmed. Automated sweeper bots worked the problem at both ends:

The practice was studied academically. In The Bitcoin Brain Drain (Vasek, Bonneau, Castellucci, Keith and Moore, Financial Cryptography 2016) the authors scanned the blockchain for passphrase-derived addresses, found several hundred that had ever been funded, and reported that the great majority had been drained by attackers — press coverage of the paper put the stolen total at roughly $103,000. The specific figure matters far less than the pattern: funded brainwallets were emptied, nearly universally, and usually within minutes or seconds.

Meanwhile, the phrases that were famous enough to appear in tutorials — the XKCD sentence used as the sample on this page, the first lines of well-known books and songs, anything repeated in a forum thread — were derived by thousands of people and swept years ago. Publishing a brainwallet is the same as donating it. The address shown in the results panel for the sample phrase has been republished countless times; treat it as burned, because it is.

"But mine is not in any wordlist"

Possibly true today. This is not the defence it feels like. The attacker's list is not fixed: it grows with every leaked password dump, every published brainwallet article and every social-media post, and your address is watchable forever at zero cost. A brainwallet is not a secret with a long shelf life; it is a public challenge with a prize attached, and it stays open for as long as the coins are there.

5. What a properly designed KDF does instead

Password-based key derivation functions are engineered to be expensive for the attacker while staying tolerable for the legitimate user:

Note carefully, though: BIP39 uses only 2048 PBKDF2 iterations. That is not a strong KDF setting, and it is not meant to be. BIP39 does not depend on the KDF for security — it depends on 128–256 bits of entropy that the words encode, plus an optional passphrase that acts as a salt. The lesson generalises: choose an input with real entropy and a KDF that is expensive; neither alone is enough.

6. Brainwallet vs BIP39 mnemonic vs random key

BrainwalletBIP39 mnemonicRandom 256-bit key
Entropy sourceA phrase recalled by a human beingA CSPRNG, then encoded as wordsA CSPRNG or a secure element
Real entropyTens of bits at best; effectively 0 for a published phrase128 bits (12 words) … 256 bits (24 words)Up to 256 bits
Key derivationOne unsalted SHA-256 — no work factor at allPBKDF2-HMAC-SHA512, 2048 iterations, salted with the passphraseNone needed
Recoverable from memory?Yes — which is the whole problemYes, if the written backup is lostNo — without the backup the coins are gone
Safe to use?NoYes, if generated by trustworthy software and the backup is protectedYes, with a backup
Brute-force cost per guess~1 hash~4,096 hash operationsIrrelevant — 2²⁵⁶ guesses
What an attacker needsA wordlist and a browser tabYour backup, or a flaw in your softwareYour backup, or a flaw in your hardware

7. Worked example: the XKCD phrase

The sample in the input box is the famous four-word sentence from XKCD #936, and this is exactly what the form above computes for it — the real values, reproducible right here:

StepValue
Passphrasecorrect horse battery staple (28 characters, 28 UTF-8 bytes)
Input bytes as hex636f727265637420686f727365206261747465727920737461706c65
Private key = SHA-256 of those bytesc4bbcb1fbec99d65bf59d85c8cb62ee2db963f0fe106f483d9afa73bd4e39a8a
WIF (compressed)L3p8oAcQTtuokSCRHQ7i4MhjWc9zornvpJLfmg62sYpLRJF9woSu
Public key (compressed)0378d430274f8c5ec1321338151e9f27f4c676a008bdf8638d07c0b6be9ab35c71
hash16079fbfc3f34e7745860d76137da68f362380c606c
P2PKH address1C7zdTfnkzmr13HfA2vNm5SJYRK6nEKyq8
P2SH-P2WPKH / P2WPKH / P2TR3KToBU4ykTWfjnu4kAUV1q8QosnxT61sbf / bc1q08alc0e5ua69scxhvyma568nvguqccrv4cc9n4 / bc1p3833qjvky7c2w3r7earqqwc377qeztadmfwjpwyy5srsch868lgs2v8tnw
Apparent entropy if the 28 characters had been random28 × log₂(95) ≈ 184 bits
Actual security of this phraseNone — it is in every brainwallet tool, tutorial and wordlist in existence

Notice how complete the wallet looks. That is the trap: the output is indistinguishable from a properly generated wallet. Nothing in the address, the WIF or the checksum reveals that the key behind it came from a sentence that half the internet has already hashed. The only thing that distinguishes a safe wallet from this one is where the key came from.

8. Common mistakes

9. Quick reference

ItemValue
Derivationk = SHA-256(UTF-8 bytes of the passphrase), one pass
Saltnone
Iterations1
Memory hardnessnone
Attacker cost per guessone SHA-256 evaluation (~nanoseconds)
Entropy of a human-memorable phrasetens of bits, and effectively zero if it was ever published
Typical sweep latency after a depositseconds
Recommended alternativeA BIP39 mnemonic from a hardware wallet — see BIP39 mnemonic → BIP32 child key
Should you use this?No. Read it, understand it, and use it as a demonstration of what not to do.