⛧ dmnemonic Creator ⛧

A free, open-source Algorand seed phrase generator that runs offline in your browser. Every key is written in two tongues: the standard 25-word dmnemonic your wallet reads, and a demonic phrase from a grimoire of Gaelic roots and summoning names. Both name the same account. Split keys into k-of-n covens, or forge Falcon-1024 post-quantum master phrases.

self-test: running… network: … context: …
Press and hold for about one second to show the words for the chosen time. Press and hold a single word to peek at it.

An Algorand ed25519 account. The dmnemonic imports into Pera, Defly, goal and algosdk. The demonic phrase is the same 25 indices in the grimoire tongue.

The ritual

Summon forges 256 bits from your browser's cryptographic random generator. Words stay blurred. Press and hold Hold to reveal to show them for the time you choose, or press and hold one word to peek at just that word. Write them on paper, then prove it in the Seal step. Banish all wipes everything, and the page does it on its own after 5 idle minutes.

Nothing here touches the network or browser storage. For real funds, open the standalone file on an offline machine.

Reveal & Translate

Paste a phrase in either tongue: 25 words, or a 26-word coven shard. Unique prefixes work (4+ letters for dmnemonic, 6+ for demonic), and typos get a suggestion.

Split into a coven

Shamir secret sharing over GF(256). The key becomes n shards. Any k of them rebuild it, and fewer than k reveal nothing at all. Give each shard to a different keeper in a different place.

Bind the coven

One shard per line, in either tongue and any order. Extra shards are cross-checked, so shards from two different covens are caught.

How a mnemonic is made

A mnemonic is a key written as words. The words carry no meaning. Each one stands for an 11-bit number, because 211 = 2048 is the size of the wordlist.

BIP-39 (Bitcoin, Ethereum)

128–256 bits of entropy plus a few SHA-256 checksum bits are cut into 11-bit groups, giving 12–24 words. The phrase then runs through PBKDF2-HMAC-SHA512 (2048 rounds, salt "mnemonic" + passphrase) to make a 64-byte seed, and BIP-32/44 derive a tree of keys from it.

Algorand

Algorand uses the same English wordlist but skips the KDF and the tree. The phrase is the 32-byte ed25519 seed:

seed = 32 random bytes (256 bits) words = seed packed into 11-bit numbers, little-endian → 24 words (264 bits; last 8 are zero) check = SHA-512/256(seed)[0:2] → low 11 bits → word 25 pub = Ed25519(seed) addr = base32( pub ‖ SHA-512/256(pub)[-4:] ) → 58 characters

One phrase means one account. Change a word and the checksum word stops matching (except for a 1-in-2048 fluke), which is how typos get caught.

The two tongues

dmnemonic is the standard Algorand phrase. Its decentralized side is the coven: a k-of-n Shamir split of the seed, so custody is spread across keepers and no single one of them can move the funds.

demonic swaps the wordlist for the grimoire. Each 11-bit index splits into a 6-bit root (64 Old Irish, Welsh and Gaulish names of gods, feasts and ogham trees, plus Enochian, Goetic and alchemical names) and a 5-bit ending (32 Gaelic words such as mór “great”, dún “fortress” and lir “sea”, plus invocatory endings). draoi + mor = draoimor, “druid · great”. Indices, checksum and address are identical to the dmnemonic phrase, so translating back always recovers the real account.

Quantum mode

Since consensus v42, Algorand has native post-quantum accounts signed with Falcon-1024 (scheme tag f1), a NIST-selected lattice signature built to resist quantum attack. The backup is the same kind of 25-word phrase, holding 256 bits of master entropy. go-algorand turns it into keys like this:

falcon seed = SHA-512/256("PQK" ‖ "f1" ‖ entropy) pk, sk = Falcon-1024 deterministic keygen(falcon seed) salt = lowest 0…255 whose address is NOT an Ed25519 point address = SHA-512/256("PQA" ‖ "f1" ‖ salt ‖ pk)

This page makes, translates and shards the PQ master phrase and computes its Falcon seed. Falcon key generation is too large to write inline, so for the address use the tools/pqaddr helper from the repository, or algokey pq import -m "<dmnemonic phrase>". The helper reproduces go-algorand's own test vector.

Never import a PQ master phrase into an ed25519 wallet. The same 25 words are also a valid ed25519 seed. If that ed25519 key ever signs on-chain, its public key is exposed, and a quantum attacker could recover the entropy and with it the Falcon key.

What protects you here

  • Known-answer self-test at load (RFC 8032 Ed25519, SHA-512/256, Algorand mnemonic and address from algosdk, grimoire and coven vectors). If any check fails, every button that makes or reads keys stays disabled.
  • Randomness comes only from crypto.getRandomValues. An incantation is hashed into it and can never replace it.
  • Words are blurred by default. Revealing them takes a deliberate press and hold, and they blur again when the timer runs out. Holding one word peeks at that word alone. Inputs turn off autocomplete and spellcheck, since some browsers send spellcheck text to a server.
  • No network requests, no storage. Banish zeroes the key bytes and clears the page, and does so on its own after 5 idle minutes.
  • The address sigil is drawn from the public key, so showing it reveals nothing secret.
Wallets only understand the dmnemonic tongue. Keep a way to translate back: the standalone file, the Python tool, or a printed grimoire table. Anyone with either phrase, or with k shards, owns the account. This code has not had an external audit. Read it: github.com/cypherpunk4096/dmnemonic.

The grimoire · 2048 words

#wordmeaningdmnemonic