You supply dice, cards, hex, a seed, or a key. EntropyLab derives the BIP-39 seed, master fingerprint, xpubs, and receive addresses. It does not generate entropy for you. Nothing leaves this page.
Derivation method
24 words use 256 bits of BIP39 entropy.
Dice roll options
Dice rolls (D6)
Derived seed phrase
Master fingerprint
Measuring this device…
Walks either the passphrase or the account number until the address matches your prefix. Same key and same counter always give the same address. Key Station matches can be written back; BIP-85 children stay unchanged. Generates no new entropy.
Found passphrases remain in this page only and are never intentionally stored or sent. Memory clearing is best-effort because browsers may retain internal copies; close the page before reconnecting the computer.
Mode
Each candidate is the starting passphrase followed by the counter characters, stretched into a seed (2,048 PBKDF2 rounds) and derived at the key's path. A match is a new passphrase for the same seed words.
Use an existing key
Derive a key on the Keys tab first — the grinder searches that key's passphrase or account index. A key with seed words supports both methods; a root-xprv key supports the derivation grind only.
Selected key
Vanity Formula
Live-filtered to lowercase bech32 characters; each free character multiplies the work by ~32.Matching passphrases
Idle. No range has been ground this session.
Same parent, same settings, same child every time. English BIP-39 children match COLDCARD. No new entropy is generated.
Any derived child key that isn't cleared will be available elsewhere in the app wherever choosing an existing key is an option. Anyone with the parent seed, passphrase, application, and index can reproduce them.
Choose a compatible HD-root key from this session, or paste a root extended private key below.
Use an existing key
Path m/83696968'/39'/0'/24'/0'
You supply individual co-signer xpubs, choose from keys entered in the Key Station, or paste in an existing multisig wallet descriptor. Verify the derived addresses, or any other info needed to setup a watch-only multisig wallet.
Only accepts watch-only public keys; a descriptor carrying private keys will be refused.
Quorum
This will be updated for you if you import an existing multisig above, or you can configure a new multisig directly below.
Multisig requires a quorum of m signatures of n total signing keys to spend.
Uses m/87'/coin'/account' with this Legacy P2SH descriptor. BIP87 account keys are script-agnostic. Leave unchecked for default BIP45 without accounts.
Keep selected keys available for more than one co-signer input. Reused keys need different derivation paths.
Advanced multisig entry
Measuring this device…
Get an sp1q… address to reuse. Print the URI and DNS text if you want to publish it. Make a sender output or check pasted outputs against your scan key. No chain. No network.
Session keys remain in this page only and are never intentionally stored or sent. Memory clearing is best-effort because browsers may retain internal copies; close the page before reconnecting the computer.
Mode
Use a key from Key Station
Results
Fill in the fields above and run the calculation to see the results here.
No session key. Receive and verify need a seed or root xprv.
Paste a PSBT or a raw transaction. You’ll see where the coins go, the fee, and the signatures.
A “PSBT” is a Partially Signed Bitcoin Transaction.
Add a key to enhance the PSBT inspection features. When a key is entered the inspection results will highlight which transaction outputs belong to that key.
Use a key from Key Station
Session keys remain in this page only and are never intentionally stored or sent. Memory clearing is best-effort because browsers may retain internal copies; close the page before reconnecting the computer.
No session key. Inspect-only mode.
PSBT inspect result
Provide a PSBT and click Inspect to view the details here.
Disable the consensus layer: edits are no longer checked against Bitcoin's rules (transaction sanity, UTXO claims, signatures, witness data) and a violating result builds and exports anyway. The problem list still reports what it finds.
“Insane editing” is for deliberately broken files only.
Editor
Paste a second PSBT to see what changed relative to the one in the editor. The comparison reads the decoded contents, so reordered maps are not a difference; transaction, signing-state, and metadata changes are reported separately. It describes differences only — it does not judge whether a change is safe.
PSBT comparison result
Paste a second PSBT and click Compare to view the differences here.
Inspect with key
Add a key to check each signature against RFC 6979 and low-r grinding, so an unexpected nonce can be told apart from a deterministic one.
Use a key from Key Station
Session keys remain in this page only and are never intentionally stored or sent. Memory clearing is best-effort because browsers may retain internal copies; close the page before reconnecting the computer.
USB Jade only (Green host nonce + opening). QR / sign_psbt does not run anti-exfil yet. BitBox anti-klepto is a different mix — do not paste it here.
Compare this inspection with earlier ECDSA signatures without keeping a PSBT or signature. The versioned file records when each r value was checked, its master fingerprint when available, the raw r value, hashed signing-key and message/source identifiers, and a verification flag. A master fingerprint groups a wallet; the hashed signing-key identifier keeps different child keys distinct. This is correlation-sensitive metadata, so keep it offline.
No nonce history in memory. Inspect a PSBT or upload a history file.
No session key. Inspect-only mode.
ECDSA nonce check result
Provide a PSBT or signed transaction and click Inspect Nonces to view the details here.
LND seed → LND node key. BIP-39 seed → LDK node key. Decode only. Does not create a seed. Nothing leaves this page.
No node key derived. Enter a seed phrase and derive.
Seeds and derived keys remain in this page only and are never stored or sent. Memory clearing is best-effort because browsers may retain internal copies; close the page before reconnecting the computer.
A local notebook of entropy you already produced. Password is optional. No password means anyone with the file can open it. Not a password manager. Does not generate entropy.
Journal open
No entries yet. Download the journal file after you add one.
The journal lives in this page until you download its file. Password-protected files require the exact password; files created without one can be opened by anyone. Memory clearing is best-effort; close the page before reconnecting the computer.
Notes for this sitting. Closing the page throws them away unless you download them.
Save key inputs in one .elkeys file. Imports are unchecked until you load and derive again. Uses the Journal password. Nothing leaves the machine.
What’s on this page right now. Private material stays hidden unless you tick the box.
This snapshot follows the current stations automatically.
Last 400 actions, with a time and a fingerprint. No seeds, no keys, no secrets.
Download this with a bug report. It names tools and fingerprints, not seeds.
No events yet.
Ian Coleman BIP39: github.com/iancoleman/bip39 — pull bip39-standalone.html from Releases, or src/js/index.js, entropy.js, jsbip39.js, wordlist_english.js.
bitaddress.org: github.com/pointbiz/bitaddress.org — pull bitaddress.org.html, or src/ninja.key.js, ninja.detailwallet.js, ninja.paperwallet.js, bitcoinjs-lib.eckey.js.
BitBox02 diceware: roll-the-dice-generate-your-own-seed — lookup table is the BIP39 English list in order.
D++ D8 & D16 method: Roll Your Own Bitcoin Seed Phrase — the published 24-word workflow uses one D8 labeled 1–8 and two hexadecimal D16 dice labeled 0–F per word, then a final D8.
Die Distribution / Fairness Analysis (Pearson’s χ²): How can I test whether a die is fair? — live check while entering rolls, following the Dice Fairness Tester thresholds.
Jade anti-exfil (sign-to-contract): Anti-Exfil: Stopping Key Exfiltration — secp256k1-zkp ecdsa_s2c / anti_exfil_host_verify.
BIP-85 deterministic entropy: bip-0085.mediawiki — HMAC-SHA512 of a fully hardened child; English BIP-39 / WIF / XPRV / HEX / password applications match COLDCARD.
BIP-352 Silent Payments: bips/bip-0352 — reusable sp1q… addresses and unique taproot outputs. Descriptors: BIP-392. Publish URI: BIP-321. DNS name: BIP-353 — this page prints the TXT, it does not resolve names.
Inscription envelopes: docs.ordinals.com/inscriptions — OP_FALSE OP_IF "ord" parser only. This tool does not create inscriptions or number sats.
Connection and browser warnings for this session. No secrets recorded.