For millions of cryptocurrency users, the single most anxiety-inducing artifact in their digital lives is not a password but a string of twelve seemingly random words. These mnemonic recovery phrases, standardized under the Bitcoin Improvement Proposal 39 protocol known as BIP 39, are the master key to deterministic digital wallets. Write them down and store them carelessly, and a thief can drain your funds in seconds. Lose them in a house fire or simply forget one word, and your digital assets may be gone forever, with no customer service department to call and no way to reset the lock. A new study published in Multimedia Tools and Applications by Fatemeh Hora Haghighatkhah and Maedeh Mosharraf of Shahid Beheshti University in Tehran proposes a way out of this dilemma: a biometric authentication system that could allow users to recover and access their wallets using their own bodies, supplemented by only a single mnemonic word and a personal passphrase.
The scale of the problem the researchers set out to address is growing rapidly. Digital wallets have matured from a niche curiosity into a mainstream payment technology, with industry analyses such as the Worldpay Global Payments Report 2024 describing a golden age of digital wallet adoption. At the same time, surveys conducted for the payments industry suggest that European consumers are increasingly willing to use biometrics to secure payments, and market researchers project substantial growth in the biometric payment sector through 2034. Yet the recovery mechanisms underpinning self-custodied cryptocurrency wallets have remained largely unchanged since BIP 39 was introduced in 2013. Users are expected to transcribe a sequence of twelve or more words drawn from a fixed vocabulary of 2048 English terms, hide that transcription securely, and remember where they put it, sometimes for decades.
The consequences of this design are well documented in the security literature. Recovery phrases can be photographed by malware, discovered by anyone with physical access to the hiding place, or irretrievably forgotten. Previous attempts to soften the burden have taken several forms, including user-defined seed phrases that substitute memorable personal phrases for random word lists, secure testament methodologies that entrust recovery material to third parties, and decentralized backup schemes that split the mnemonic across multiple locations using techniques such as elliptic curve cryptography and secret sharing. Others have explored binding cryptographic keys to biometric templates through fuzzy vault schemes and fuzzy extractors, or deriving authentication material from behavioral biometrics such as typing patterns. Each approach trades some combination of security, convenience, and trust in external parties. The Iranian team’s proposal aims to minimize reliance on the mnemonic phrase itself while keeping the entire authentication process local to the user.
At the heart of the new system is a multi-factor construction that combines three distinct elements: fingerprint recognition, facial feature extraction, and a minimal remnant of the traditional mnemonic scheme. The facial component is deliberately unusual. Rather than relying solely on a face match, the system extracts attributes including the user’s gender and dominant emotional expression from facial images, treating these inferred characteristics as additional authentication factors. According to the paper’s experimental results, the gender classification component achieved an accuracy of 97.44 percent, while emotion recognition reached 91.5 percent. The fingerprint module, evaluated on the publicly available Sokoto Coventry Fingerprint Dataset, produced a False Non-Match Rate of 0.0598, meaning roughly six legitimate users in a hundred would fail a verification attempt, and a False Match Rate of zero, meaning no impostor in the tested population was wrongly accepted.
The choice of those two error metrics matters enormously in a wallet recovery context. A False Match Rate of zero indicates that the system did not grant access to any unauthorized fingerprint in the evaluation, which is the more dangerous failure mode when cryptographic keys controlling real money are at stake. The nonzero False Non-Match Rate, by contrast, represents a usability cost: some legitimate users would need to retry or fall back on their remaining factors. This tension between false accepts and false rejects is the fundamental trade-off of all biometric systems, and the researchers tuned their thresholds toward the conservative end, accepting occasional inconvenience in exchange for tighter security. Feature extraction for the fingerprint stage drew on established computer vision techniques, including Harris corner detection and the ORB algorithm, an efficient alternative to older methods such as SIFT and SURF that is well suited to resource-constrained devices.
Biometric matching alone, however, does not produce cryptographic keys. Fingerprints and faces are noisy, variable, and impossible to reproduce exactly, whereas wallet keys demand bit-perfect determinism. The system bridges this gap using modern, standards-based key derivation functions. The first is Argon2id, the winner of the Password Hashing Competition, which is specifically designed to be memory-hard, meaning it forces any attacker attempting a brute-force search to consume large amounts of memory as well as computation. This makes large-scale guessing attacks dramatically more expensive, particularly for adversaries running parallel attempts on graphics processors. The second is the HMAC-based Extract-and-Expand Key Derivation Function, standardized as RFC 5869, which takes unevenly distributed input material and distills it into cryptographically strong, uniformly random key material through an extract phase followed by an expand phase.
The architecture can be understood as a layered funnel. Biometric measurements and the user’s chosen passphrase feed into the derivation pipeline, where Argon2id first imposes its memory-hard cost on any computation, whether legitimate or adversarial. HKDF then normalizes the resulting material and expands it into the key components the wallet requires. The single retained mnemonic word acts as an additional secret that the user must supply, preserving a small foothold of the traditional scheme while eliminating the need to safeguard eleven or more words. Because the derivation is deterministic, the same combination of biometric presentation, passphrase, and mnemonic word reliably regenerates the same wallet keys, which is precisely the property that deterministic wallets demand. An attacker who lacks any one of the factors cannot reconstruct the key, and the memory-hardness of Argon2id ensures that even partial knowledge does not translate into a tractable offline guessing campaign.
The datasets underpinning the evaluation are themselves a notable aspect of the work. The researchers trained and tested their facial attribute models on two publicly available facial emotion recognition datasets from Kaggle, contributed by Roman K in 2023 and Kapadnis in 2024, while fingerprint experiments used the Sokoto Coventry Fingerprint Dataset, a widely cited benchmark assembled by Shehu and colleagues in 2018. Relying on public benchmarks allows independent researchers to reproduce and stress-test the reported figures, an important consideration for any security proposal that aspires to real-world deployment. The authors have also made their data available through a public repository link, further supporting reproducibility. The work was conducted without external funding, and the authors report no competing interests.
Still, the path from a promising prototype to a wallet that safeguards life savings is long, and the paper’s approach raises questions that future research must confront. Biometric characteristics are not secrets in the cryptographic sense: faces are visible in public, and fingerprints are left on surfaces everywhere. The security of the scheme therefore rests not on the secrecy of the biometric itself but on the difficulty of converting a stolen image or latent print into the exact digital template the system expects, combined with the passphrase and mnemonic word that the user keeps secret. The broader biometric cryptosystem literature has developed countermeasures such as cancellable templates, which allow a compromised biometric reference to be replaced the way a password would be, and recent work on privacy-preserving template generation suggests these defenses are maturing. How well such protections integrate with the new wallet architecture remains to be demonstrated.
There is also the question of what happens when biology misbehaves. Cuts, scars, aging, and injuries can change fingerprints; illness, fatigue, and lighting conditions can alter facial appearance and even emotional expression. With a False Non-Match Rate approaching six percent, a meaningful fraction of legitimate recovery attempts would initially fail, and the consequences of a failed recovery in a self-custody context are far more severe than a failed login to a social media account. The single mnemonic word and passphrase provide a fallback factor, but they also mean the system does not entirely eliminate the cognitive burden it set out to remove. What the study does demonstrate is that the burden can be reduced from memorizing and safeguarding a dozen high-entropy words to remembering one word and a personal passphrase, with biometrics carrying most of the load. If the reported accuracy figures hold up under adversarial scrutiny and real-world variability, the framework could mark a meaningful step toward wallets that are both safer and more humane, turning the body itself into a recovery phrase that can never be left on a train.
Subject of Research: Biometric authentication for deterministic cryptocurrency wallets to reduce reliance on mnemonic recovery phrases
Article Title: Biometric authentication system for deterministic digital wallets: aiming to reduce the reliance on mnemonic phrases
Article References: Haghighatkhah, F. H., & Mosharraf, M. (2026). Biometric authentication system for deterministic digital wallets: aiming to reduce the reliance on mnemonic phrases. Multimedia Tools and Applications, 85(10), Article 800. https://doi.org/10.1007/s11042-026-21960-w
Image Credits: AI Generated
DOI: 10.1007/s11042-026-21960-w
Keywords: biometric authentication, digital wallets, cryptocurrency, mnemonic phrases, BIP 39, fingerprint recognition, facial recognition, emotion recognition, Argon2id, HKDF, key derivation, biometric cryptosystem
Cite Scienmag News
Denise Maddox. (October 8, 2026). Fingerprints and Faces Could Replace the 12-Word Phrases That Guard Crypto Wallets. Scienmag. https://scienmag.com/fingerprints-and-faces-could-replace-the-12-word-phrases-that-guard-crypto-wallets/
Denise Maddox. "Fingerprints and Faces Could Replace the 12-Word Phrases That Guard Crypto Wallets." Scienmag, 8 October 2026, https://scienmag.com/fingerprints-and-faces-could-replace-the-12-word-phrases-that-guard-crypto-wallets/. Accessed 8 October 2026.
Denise Maddox. "Fingerprints and Faces Could Replace the 12-Word Phrases That Guard Crypto Wallets." Scienmag. October 8, 2026. https://scienmag.com/fingerprints-and-faces-could-replace-the-12-word-phrases-that-guard-crypto-wallets/

