From Mastering Bitcoin:
“From a safety perspective, the quantity of entropy truly used for the manufacturing of HD wallets is roughly 128 bits, which equals 12 phrases. Offering greater than 12 phrases produces further entropy which is pointless, and this unused entropy will not be used for the derivation of the seed in the way in which that one may intially suspect.”
Why roughly 128 bits, and never precisely?
Why the extra entropy offered by utilizing greater than 12 phrases will not be used?