Shamir Secret Sharing illustration

Shamir Secret Sharing

Splits a secret into n shares so that any k of them reconstruct it, while k−1 shares reveal absolutely nothing — Shamir’s threshold scheme, the standard way to back up master keys, wallet seeds and recovery codes without a single point of failure. Each byte is hidden as the constant term of a random degree-(k−1) polynomial over GF(256), evaluated at x = 1…n; combining runs Lagrange interpolation at x = 0. A 2-byte CRC-16 is prepended to the secret before splitting, so the combiner can tell you whether the reconstruction is plausible. Share format: "index-hexdata", one per line.

Runs 100% in your browser — keys and data never leave your device.

Notes

  • Information-theoretic security: with fewer than k shares every possible secret is exactly equally likely — there is nothing to brute-force, regardless of computing power.
  • The shares are points on a random polynomial. Any k points determine a degree-(k−1) polynomial uniquely; k−1 points leave the constant term (the secret) completely free.
  • The CRC-16 checksum only detects accidents (typos, wrong or mixed-up shares) — it is not a cryptographic proof of integrity, and a 1-in-65,536 false pass is possible. Use verifiable secret sharing when adversaries hold shares.
  • Store shares in separate places (safe, bank, lawyer, trusted friends). Anyone who collects k of them has the secret — distribution is the whole point.
  • Runs 100% in your browser — keys and data never leave your device.