Skip to content
BIP-39 Passphrase and 25th Word Recovery - Crypto Wallet Recovery New Zealand

Passphrase recovery

BIP-39 Passphrase and 25th Word Recovery

BIP-39 passphrase reconstruction and hidden-wallet derivation

A BIP-39 passphrase, often called the 25th word, combines with your recovery phrase to derive an entirely separate hidden wallet. It is not checked against a stored value, it is mixed directly into the key derivation as salt, which means every possible passphrase produces a valid wallet. There is no wrong-passphrase error, only a different, usually empty, wallet. That is why a correct phrase with the wrong passphrase looks like lost funds when it is not. Recovery is a constrained search over the variations of what you remember, each candidate tested against a known address or balance from the hidden wallet, entirely offline.

10%recovery fee
Only charged on successful recovery

Meet the team

Meet our recovery experts

A team built on years of experience across New Zealand's most complex crypto matters.

Our methods

How we recover a passphrase-protected wallet

Every recovery is methodical and fully offline. Your key material never leaves our air-gapped equipment, and the work happens in an environment of your choosing.

Hidden wallet derivation analysis

Understanding why a wrong passphrase shows an empty wallet rather than an error.

  • The passphrase is mixed into BIP-39's key derivation as part of the salt, not checked against a stored hash
  • Every possible passphrase, including a typo, derives a technically valid wallet
  • There is no error state by design, so a wrong entry simply shows a different, empty wallet
  • The visible wallet (phrase alone) and the hidden wallet (phrase plus passphrase) are separate derivation results
  • An empty balance is routinely misread as lost funds rather than the wrong passphrase
  • Confirming a passphrase-protected wallet is involved is often the first diagnostic step

Systematic variation testing

Enumerating the realistic variations around a remembered or partially recorded passphrase.

  • Capitalisation and case variations tested systematically across the whole string
  • Leading, trailing, and internal spacing differences checked, since these change the result entirely
  • Character substitutions and the punctuation conventions you tend to use
  • Invisible characters, autocorrect artefacts, and encoding differences ruled out
  • Unicode normalisation differences, a common cause of a "correct" passphrase being rejected
  • Near-miss variations of what you believe it was prioritised before any broader search

Habit-based passphrase reconstruction

Building candidates from how you construct secrets when the passphrase is genuinely forgotten.

  • The same interview-led process used for wallet password recovery, applied to the passphrase
  • Patterns drawn from passwords and passphrases you set in the same period
  • Common passphrase structures, such as a favourite line, phrase, or word, checked first
  • Partial notes and fragments expanded into a structured set of plausible variations
  • Candidate quality prioritised over raw search volume, since the space is otherwise unbounded
  • An honest read on feasibility, since a long random passphrase with nothing remembered is not recoverable

Cross-wallet and entry-handling checks

Accounting for how different software accepts and processes passphrase entry.

  • Different wallets handle passphrase entry, trimming, and normalisation differently
  • The same passphrase can succeed in one wallet and appear to fail in another
  • Hardware wallet on-device entry checked against host-side entry
  • Testing across the major wallet implementations the phrase may have been used with
  • Identifying which application originally created the hidden wallet

Balance-verified confirmation

Testing candidates against known data from the hidden wallet before anything moves.

  • Each candidate derived and checked against a known address or on-chain balance
  • The match confirmed conclusively before any funds are touched
  • Derivation path scanned once the correct passphrase is found, since the hidden wallet has its own tree
  • No blockchain interaction until a candidate produces the expected wallet
  • Verification independent of any single wallet application

Controlled migration and handover

Securing the recovered wallet once the passphrase is found.

  • All work performed offline on air-gapped equipment throughout
  • Funds migrated to a new wallet you control once access is confirmed
  • The recovered passphrase and phrase destroyed or returned at handover, nothing retained
  • The correct passphrase and its exact form documented for you at handover
  • Guidance on recording it so the hidden wallet is never lost again

Failure modes

Failure modes we handle

  • Recovery phrase accepted but wallet shows zero balance

    A hallmark of a passphrase-protected wallet. The phrase alone opens the visible wallet; your funds are in the hidden wallet behind the passphrase.

  • Passphrase remembered but not accepted by the wallet

    Almost always capitalisation, spacing, an invisible character, or a normalisation difference. These are exactly the variations we enumerate.

  • Passphrase set years ago with no record of what was used

    Reconstruction from your habits, the same method used for wallet passwords, applied to a passphrase.

  • A written note exists but the wording is ambiguous

    Partial notes are genuinely valuable. A remembered stem plus plausible variations is a small, fast search space.

  • The same passphrase works on one device but not another

    A difference in how two wallets handle entry or normalisation, not a wrong passphrase. We reconcile the two.

  • A passphrase you may have set without realising

    Some setups apply a passphrase by default or through a checkbox that is easily forgotten. We confirm whether a hidden wallet exists at all.

Scam Warning

Most “crypto recovery” services are scams

If someone contacts you first about recovering your crypto, it's a scam - we only ever work with people who come to us. The rest ask for payment upfront, promise results nobody can promise, and want your recovery phrase typed into a website. Scammers also trade lists of people who've responded before, which is often how they found you.

You'll hear back from Nic or Harry directly - not a call centre. Beware of scammers.

Contact us

Describe your situation in general terms - no recovery phrases or private keys through this form. We will call you back within 24 hours with an honest read on whether passphrase recovery is possible in your case.

  • No fee unless we succeed

    10% of what's recovered, agreed in writing beforehand. Nothing if we fail.

  • We can come to you

    Anywhere in New Zealand, at our cost, for cases of significant value.

  • Nothing is retained

    Keys and phrases are destroyed or returned at the end of the engagement. NDA signed before we start.

Never send a recovery phrase or private key through this form, or through any website. Describe the situation in general terms and we will handle the sensitive detail securely on the call.

No fee unless we succeed. We respond within 24 hours.

FAQ

Passphrase recovery - common questions

What is the 25th word?

It is an optional extra secret, the BIP-39 passphrase, that you add on top of your 12 or 24-word recovery phrase. It is not one of the standard wordlist words, it can be anything, and it combines with your phrase to unlock a completely separate hidden wallet.

Why doesn't my wallet just tell me the passphrase is wrong?

Because it cannot. The passphrase is mixed directly into the key derivation, so every possible passphrase produces a valid wallet. A wrong one does not fail, it simply opens a different, empty wallet. This is by design, and it is exactly why a wrong passphrase looks like lost funds.

Could I have set a passphrase without realising?

Yes, it happens. Some wallets present it as an easily overlooked option, and people sometimes enable it once and forget. If your phrase restores but the balance is empty and you know funds were there, an unremembered passphrase is one of the first things we check.

Is a passphrase the same as a wallet password?

No, and the difference matters. A wallet password locks a file or app locally and can be reset if you have your phrase. A BIP-39 passphrase is part of the cryptography itself, it derives a different wallet, and there is no reset. Losing it means the hidden wallet is inaccessible until the passphrase is recovered.

I remember roughly what it was. Is that enough?

Often, yes. A remembered stem, a theme, or a partial note turns an unbounded problem into a small, targeted search over variations, and those cases resolve well. The more you can tell us about how you chose it, the better.

Can any passphrase be recovered?

No, and we are honest about the limit. A passphrase built from something you remember is often recoverable. A long, genuinely random passphrase with nothing recorded and nothing recalled generally is not, and we will tell you that on the first call rather than take a fee.

My passphrase is definitely correct but the wallet rejects it. What now?

This is usually a formatting difference, capitalisation, a stray space, an invisible character, or how two wallets normalise the text, rather than a wrong passphrase. These near-variants are precisely what we test, and they resolve a large share of these cases.