Why you cannot think of a random number
Every wallet rests on one unguessable number, and the one tool that cannot produce it is the one you were born with. What people get wrong, how it has been measured, and what it cost the ones who tried.
Think of a number between one and ten. Hold it for a second. You almost certainly did not pick one or ten, and there is a fair chance you picked seven — and whatever you chose, you did not choose it randomly. You chose it the way people choose, which is a different thing, and it is the reason every serious way of making a wallet takes the decision away from you.
A bitcoin wallet is one enormous number kept secret. Not a password that a company checks, not an account someone can lock — a number so large that nobody can search for it. Your recovery words are that number written so a human can copy it down. Everything you will ever own in that wallet hangs on it having been unguessable at the moment it was made.
Which raises an awkward question, because the obvious way to make a number nobody can guess is to think one up. That instinct is exactly backwards, and this is a guide about why.
1Try it first
Rather than take any of this on trust, lose to a machine that has no idea who you are. It decides what you are going to press before you press it, and it is not clever: it remembers what you did the last few times you were in this position and bets you will do it again. That is the whole mechanism, and it is usually enough.
It cannot simply show you the guess — you would do the opposite and win every time, because in a game like this whoever moves second wins. So it seals the guess in a hash instead: you cannot unpick it, and it cannot wriggle out of it. Finish the round and it hands over the key, so you can recompute every commitment it made.
It has already guessed your next tap
Tap heads or tails as randomly as you can manage. Before each tap, the machine makes its guess and seals it as the code below. Once you choose, it reveals whether it read you correctly.
A coin would hold it to fifty percent, because a coin leaves nothing to remember. Most people cannot. Two numbers give them away, and both have exact answers for a real coin: how often you switch should be about half the time, because every gap between two flips is its own independent toss, and your longest streak of the same result should sit near six in sixty-four flips, because that is simply what happens.
It is worth sitting with why that guess has to be sealed rather than shown. The only reliable way to beat a predictor is to see its answer first — not to be random, just to be second. Take that away and there is nowhere to hide, because being contrary is a rule as much as being repetitive is, and either one is a pattern.
Most people switch closer to sixty percent of the time and stop their longest streak at three. Both errors come from the same place: a belief that randomness ought to look even.
Randomness is lumpy. Evenness is the fingerprint of a person trying.
2This has been measured for fifty years
The machine above is not a modern trick either. Claude Shannon built one at Bell Labs in 1953 — a box that played matching pennies against whoever walked past, remembering only a couple of moves of history — and it beat people reliably enough that he wrote it up as A Mind-Reading (?) Machine. The joke in the question mark is that there is no mind reading involved. There is just a person who cannot stop repeating themselves and a machine with a good enough memory to notice.
The finding is old and it is not subtle. Wilhelm Wagenaar surveyed the literature on human random generation in 1972 and found the same distortions turning up in study after study, whichever way the task was framed: people alternate too much, avoid repeating themselves, and produce sequences far more balanced than chance would ever deliver. Later work has poked at it from every angle — changing the instructions, the pace, the alphabet, paying people, telling them exactly what they are doing wrong — and the bias does not go away. Knowing about it does not fix it.
Some of the specific habits are worth naming, because you can catch yourself doing them:
- You avoid repeats. Having just written a 4, the next 4 feels illegitimate, so you write something else. A die has no such scruple.
- You spread things out. Asked for twenty numbers from one to six, people produce a suspiciously flat spread. Twenty real rolls are usually lopsided.
- You avoid the edges. One and ten feel like weak answers to "pick a number between one and ten", so they are picked less than their share.
- You reach for the same favourites. Seven does unreasonably well. So do odd numbers, and numbers that are not multiples of five.
- You think a streak owes you. After four heads, tails feels overdue. It is not. The coin has no memory, and neither does a die.
None of this is stupidity. It is a mind doing what it is built for — finding and producing pattern — applied to the one job where pattern is the enemy.
3What it cost people who tried anyway
For a while bitcoin let you do exactly the wrong thing. A brain wallet turned a passphrase you invented into a private key, with nothing else added. No file to lose, no metal plate to hide — the wallet lived in your head. It sounds elegant until you notice that anyone in the world can guess at it, forever, for free, without touching you or your computer.
Researchers went and counted the damage. A 2016 study checked around 300 billion candidate passphrases against the blockchain and found 884 brain wallets used between 2011 and 2015, holding about 1,806 BTC between them. All but 21 were emptied. Usually within a day of being funded, often within minutes — and by late 2013 the typical time to be drained was measured in minutes and seconds, because about a dozen automated bots were sitting there competing to be first.
The detail that should end the argument
The same study found no evidence that people storing more bitcoin chose stronger passphrases. Having more to lose did not make anyone better at this. The people with real money on the line were as guessable as everyone else, because the limitation is not effort or care — it is that a human mind has no source of randomness in it.
These were not careless people picking "password". They were choosing phrases they believed were obscure: song lyrics, private jokes, lines of scripture, sentences in other languages. Every one of them was reachable by a word list, because the space of things a person thinks of is unimaginably smaller than the space of things a coin can produce.
4The size of the gap
It helps to see the numbers, because "not random enough" hides how enormous the shortfall is.
A 24-word recovery phrase carries 256 bits. That is not a big number written down, but it is roughly the count of atoms in the observable universe — a search nobody finishes, ever, with any machine that could be built. A 12-word phrase carries 128 bits, which is also never getting searched.
Now price the alternatives. Ninety-nine rolls of a six-sided die give 255.9 bits — just short of the 256 a 24-word seed holds, which is why some wallets ask for a hundredth roll and others hash the ninety-nine and call it done. Two hundred and fifty-six coin flips give 256 bits, one per flip. A thoroughly shuffled deck of cards is worth 225.6 bits all by itself, because the order it ended up in is one of 52 factorial possibilities, and dealing it out records that order. A memorable passphrase a person invents, by the estimates used in password research, tends to land somewhere in the twenties of bits — and the sequence you just tapped out above, however it scored, is worth less than the sixty-four bits it looks like, because your switching habit is itself information an attacker already has.
The gap between twenty-odd bits and 256 is not a matter of degree. One is a search that finishes while you make coffee. The other does not finish.
A wallet is only as unguessable as the moment it was created. Nothing you do afterwards can add randomness that was never there.
5So where does real randomness come from
From physics, not from thought. Something has to actually happen in the world, with an outcome nothing recorded in advance.
It is worth being precise about what that means, because there are two different grades of it. A die is not actually random: it is a lump of plastic obeying ordinary mechanics, and a good enough measurement of the throw would tell you the face. It works because that measurement is impossible in practice — the outcome depends so violently on the starting conditions that nobody can know them well enough. That is chaos, not randomness, and for our purposes it is enough.
Then there is the other kind. A single atom of a radioactive isotope will decay at some point, and as far as physics can tell nothing whatsoever determines when. Not a hidden mechanism, not a variable nobody has measured yet — the timing appears to be indeterminate at the bottom. The half-life only describes what a vast number of them do on average; no fact about the individual atom is waiting to be discovered. That is randomness in the strongest sense available, and it is why serious hardware generators sample physical noise of this sort rather than anything a program computes.
Both beat you comfortably. The gap between a person and a die is far wider than the gap between a die and an atom.
Dice are the honest version of this and the reason people bother with them: you can watch the whole process, and there is no step where you are asked to decide anything. Rolling your own entropy covers doing it properly — and covers the trap this guide should make obvious, which is that the moment you re-roll a result for looking wrong, you have put your judgement back in charge and undone the point of the exercise. Six sixes is exactly as likely as any other six rolls. Write it down.
If you would rather see every step of the conversion too, three dice, one word uses one octal and two hex dice to name each word directly, with nothing hashed.
Your hardware wallet's built-in generator is the other real option, and it is genuinely good — a dedicated circuit sampling physical noise, which is a far better randomness source than you are. The only thing it cannot do is let you watch. That is the whole trade: trust the sealed chip, or supply the randomness yourself from something you can see. Both are defensible. Inventing the number yourself is not.
6What to take away
Not that you are bad at this. Everyone is, measurably, including the people who study it, and no amount of trying harder moves the needle.
What is worth carrying is the instinct to notice when a system is quietly asking you to be a random number generator — a passphrase you invent, a "memorable" seed, a set of rolls you tidied up because they looked wrong. In each case the fix is the same: hand the job to something physical, record whatever it says without editing, and check the result rather than trusting it.
The dice do not care what looks random. That is exactly why they are better at this than you are.
Sources
- Wagenaar, W. A. (1972), "Generation of random sequences by human subjects: A critical survey of literature", Psychological Bulletin 77(2) — the survey that established the over-alternation and repeat-avoidance findings.
- Instruction effects on randomness in sequence generation (Frontiers in Psychology, 2023) — recent work on how far changing the task moves the bias, which is: not far.
- Vasek, Bonneau, Castellucci, Keith and Moore (2016), "The Bitcoin Brain Drain", Financial Cryptography 2016 — the source of every brain wallet figure quoted above, including the drain times and the finding about larger balances.
- Claude Shannon, "A Mind-Reading (?) Machine" (Bell Laboratories memorandum, 18 March 1953) — the original of the guessing machine above, and still the clearest description of why it works.
- The Aaronson Oracle — a modern version of the same demonstration, if you want to lose to a different implementation.
- John Towse's random generation resources — methods and measures used in this area, for anyone who wants the underlying statistics.
The panel above is a demonstration, not a test. A short round cannot establish anything about you in particular, and a fair coin beats it often enough that one good result proves nothing either. What it can do is let you watch a very small amount of memory anticipate you, using nothing but what you already typed — and the longer you play, the harder that is to dismiss.