On Jan. 10, 2026, a bitcoin and litecoin holder handed over their 12-word recovery phrase to someone posing as Trezor support and watched $282 million vanish in minutes, not because any encryption was broken, but because those 12 words are the entire wallet, and whoever holds them holds the funds.
Key Takeaways
A Trezor-impersonation scam drained $282 million after a victim shared their seed phrase earlier this year.A full 12-word BIP39 phrase carries about 128 bits of entropy, effectively impossible to brute force.Chainalysis estimates up to 23% of all mined bitcoin, several million BTC, is permanently lost via lost keys.There’s no company database holding a copy, no customer service line that can look up a forgotten one, and no “forgot password” flow. Whoever can produce the words controls every coin those words can derive (instantly, and irreversibly).
The attacker didn’t need to break anything. They just needed the victim to type 12 words into the wrong place, then moved fast: the roughly $139 million in bitcoin and $153 million in litecoin was split across THORChain bridges, run through instant-exchange services into monero, and layered through peel-chain transfers within minutes.
Why 12 Words Is Actually an Enormous NumberEach BIP39 word carries 11 bits of entropy, because the wordlist has exactly 2,048 (2^11) entries. A 12-word phrase carries roughly 128 bits of total entropy once you account for a built-in checksum, and a 24-word phrase carries 256 bits.
Those aren’t just “bigger” numbers than a typical password, they’re astronomically bigger. Brute-forcing every possible combination of a full 12-word phrase, even at an extremely generous 1 billion guesses per second, would take on the order of 10^22 years. The universe is about 13.8 billion years old.
There is no realistic amount of future computing power that closes that gap; guessing a complete, unknown seed phrase isn’t a risk anyone needs to plan around.
The danger is never the math but exposure. If even a handful of the words leak, or an attacker learns some of them from a photo, a cloud backup, or a support-impersonation scam, the remaining search space collapses catastrophically rather than gracefully. The chart above shows why: with 6 of 12 words already known, cracking the rest would still take an estimated 1,169 years at that same guess rate (still safe).
But at 7 words known, that number drops under a year. At 8 words known, it’s a few hours. By 10 or 11 words known, it’s milliseconds. Security doesn’t degrade in a straight line as words leak; it falls off a cliff, which is exactly why “just the first six words” or “half my phrase” is not a meaningfully safer thing to expose than the whole thing.
BIP39’s checksum exists for a much more mundane reason than security against guessing: it catches typos. The last word of a seed phrase isn’t purely random; a few of its bits are a checksum calculated from the other words, so a wallet can verify the phrase was transcribed correctly.
Millions of Coins Prove the Bigger Risk Isn’t Theft

















