NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3599 most downloaded on npm
Secure, audited & minimal implementation of BIP39 mnemonic phrases
Last release 1 months ago
28 Aug 2026
Release timing varies
gaps range from 8 days to 7 months
Nearly every release is documented
notes for 18 of 19 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
21 releases · first in 2022
One column per quarter.
Hardening: Unpaired UTF-16 surrogates are now rejected in mnemonics & passphrases. Normal input is unaffected
Full Changelog: 2.3.0...2.4.0
Rewrite package: the logic is now declared in scure-bip39 instead of @scure/base dependency, which was removed.
@scure/base dependency, which was removed.Full Changelog: 2.2.0...2.3.0
April 2026 self-audit (all files): no major issues found
Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>TS2345wordlists/traditional-chinese.js: it was exported incorrectly(We're skipping v2.1, to align with other noble / scure packages)
Full Changelog: 2.0.1...2.2.0
.js extension must be used for all modules
.js extension must be used for all modules
@scure/bip39/wordlists/english@scure/bip39/wordlists/english.jsFull Changelog: 2.0.0...2.0.1
The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
mnemonicToSeedWebcrypto, which uses built-in / native / WebCrypto method - useful for React Native and similar slow environmentsFull Changelog: 1.6.0...2.0.0
Nothing published for this version
Bump hashes to v1.8.0 , base to v1.2.5
Full Changelog: 1.5.4...1.6.0
Small update of scure-base to 1.2.4, to explicitly ensure broken 1.2.2 (and 1.2.3) is not used
Small update of scure-base to 1.2.4, to explicitly ensure broken 1.2.2 (and 1.2.3) is not used
Full Changelog: 1.5.3...1.5.4
Small update of scure-base to 1.2.3, to explicitly ensure broken 1.2.2 is not used
Full Changelog: 1.5.2...1.5.3
Use typescript verbatimModuleSyntax to support future node.js type stripping
Full Changelog: 1.5.1...1.5.2
Bump noble-curves to 1.8.0 and noble-hashes to 1.7.0
Full Changelog: 1.5.0...1.5.1
Refactor: remove backticks to be parser-friendly
add "sideEffects": false to package.json by @tmm in https://github.com/paulmillr/scure-bip39/pull/22
"sideEffects": false to package.json by @tmm in https://github.com/paulmillr/scure-bip39/pull/22Full Changelog: https://github.com/paulmillr/scure-bip39/compare/1.3.0...1.4.0
Update noble-hashes to v1.4, adding support for Big-Endian platforms.
Update noble-hashes to v1.4, adding support for Big-Endian platforms.
Full Changelog: https://github.com/paulmillr/scure-bip39/compare/1.2.2...1.3.0
Add Portuguese wordlist by @mikeobank in https://github.com/paulmillr/scure-bip39/pull/19
Full Changelog: https://github.com/paulmillr/scure-bip39/compare/1.2.1...1.2.2
The package is now hybrid common.js + ESM.
The package is now hybrid common.js + ESM.
Full Changelog: https://github.com/paulmillr/scure-bip39/compare/1.2.0...1.2.1
- Update noble-hashes to 1.3 Full Changelog: https://github.com/paulmillr/scure-bip39/compare/1.1.1...1.2.0
Full Changelog: https://github.com/paulmillr/scure-bip39/compare/1.1.1...1.2.0
Nothing published for this version
Remove viral esModuleInterop option from typescript compiling
esModuleInterop option from typescript compilingFull Changelog: https://github.com/paulmillr/scure-bip39/compare/1.0.0...1.1.0
First stable post-audit release
First stable post-audit release
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →