BIP-39 seed phrases feel magical: 12 ordinary words recreate an entire wallet. The machinery behind it is deterministic and worth five minutes of your understanding.
From entropy to words
A wallet starts with 128 bits of random entropy, checksummed and mapped through the BIP-39 English wordlist (2048 words) into 12 words. Those words are not encrypted — they are the secret itself, which is why they must never be photographed or typed into websites.
From words to keys
The phrase is stretched through PBKDF2 (2048 rounds, with the "mnemonic" salt) into a 512-bit seed. That seed feeds BIP-32, which builds a tree: a master key, then child keys derived by a path of indexes. Because derivation is one-way, a child key cannot reveal its parent — but the seed regenerates the whole tree, forever, identically.
Reading m/44'/60'/0'/0/0
44' — BIP-44 purpose (hardened, marked by the apostrophe)
60' — coin type: 60 is Ethereum-family, so every EVM chain shares it (Tron uses 195', Bitcoin 0')
0' — account index
0 — change branch (0 = external, receiving addresses)
0 — address index
Change the last number to get a fresh address from the same seed; change the account index to separate funds.
Why you see the same address on many chains
EVM chains (Ethereum, BSC, Polygon, Arbitrum, Optimism, Avalanche) all recognize the same private key format and address format. One key — one address — valid on every EVM network simultaneously, each holding its own separate balances.
Verifying an import
When you import a phrase into a different wallet app, the first question is "same address?". If an app derives m/44'/60'/0'/0/0 and your original used the same path, the addresses match exactly. Our import screen shows the derived address and path before you commit, so mismatches are caught immediately — not after funds arrive.