Seed XOR
Split a seed into valid seeds
Splits one BIP39 seed into parts that are each an ordinary seed in their own right, and puts a set back together. Every part is required: N of N, with no threshold and no spare.
Last updated Sep 2026

Overview and the all-parts rule
Overview
An implementation of the Seed XOR scheme on Passport, an open standard that invites other implementations. Load a seed, choose two, three or four parts, and get that many seeds back, each a valid BIP39 seed that can be written down as words or transcribed as a SeedQR. Combining reverses it: say how many parts you have, load them in any order, and the original comes back. The same screens also make a new wallet, since XOR-ing seeds you already hold derives a fresh seed without changing anything about the originals.
This QnA-signed app is not Foundation-signed or independently security-audited. It cannot read the device master seed or Seed Vault: you must import a seed by scanning a SeedQR or typing its words. Seeds and parts live in memory for one session, and the app has no filesystem write permission. Keep another tested backup rather than relying on this app as your only backup for funds.
What it does
- Split a 12- or 24-word seed into two, three or four parts, each an ordinary BIP39 seed.
- Combine parts in any order to recover the original, or XOR seeds you already hold to derive a new wallet.
- N of N by design: every part is required, there is no threshold and no spare.
- A missing part does not fail loudly: it produces a different valid seed, which is why the app repeatedly explains the all-parts rule.
- Entering the same part twice is refused, because a value XOR-ed with itself cancels to the all-zero seed.
- An all-zero seed cannot become two distinct XOR parts, so the app asks you to choose three or four instead.
- The optional original checksum word gives you a manual comparison after recovery, but reveals information about the seed.
- Display parts as words or transcribe Standard or Compact SeedQR, then scan a copy back to check it.
- Random parts use the hardware TRNG. Deterministic generation is not implemented.
- Nothing is written to disk: no filesystem write permission, and mnemonics are zeroed on drop.
Technical breakdown
How the app is built, for developers evaluating the platform.
The algorithm
Combining XOR-es the entropy byte arrays and recomputes the checksum. The specification describes XOR-ing 11-bit word indices while excluding the checksum bits, which is the same operation said differently, since the entropy is exactly the non-checksum bits. Working in bytes means there is no bit shuffling to get wrong. Splitting generates N-1 random parts and sets the last to the original XOR-ed with all of them.
Designing around the quiet failure
The risk in an N of N scheme is not a loud error, it is a silent one. Combining a subset does not fail: it produces a different valid seed that opens a real but empty wallet, and nothing on screen distinguishes that from success. The app therefore repeats the all-parts requirement before it will generate anything, and a test asserts that every proper subset of a split lands somewhere other than the original.
What it is allowed to touch
The signed manifest grants read-only filesystem access, the GUI template, and read-only theme and touch-debug settings. It requests no os/security permissions, including GetSeed or GetRandom. Randomness comes through the SDK-patched getrandom crate and the hardware TRNG service. Scanning uses the system QR scanner modal rather than direct camera access. Word lengths are limited to 12 and 24 because the SDK seed type accepts only 16- or 32-byte entropy.
Dig into the source
README, architecture notes, and the wire protocol live in the repo.
