I’ve heard all of the following as this topic has come up previously. Unsure if all are accurate:
  • If the 12 and 24 worlds are both truly random, then it is easier to crack the private key itself than to brute force either the 12 or 24 words. [I believe there are also some caveats here as to if the particular address has been spent from before or not, and what bitcoin address type it is. Someone could clarify that aspect]
  • If your source of randomness for the 12 or 24 words had some slight bias (but was still fairly random) then the extra 12 words could help a lot. [Also tin foil hat things like the dice that were used were assessed for their deviation from random, sound was analyzed from writing down the 12 words, etc etc.]
  • The increased risk of loss or a transcription error of 24 words vs 12 words might negate any benefits. Assess which risk is larger for you.
  • If future changes to bitcoin make it so cracking the private key is harder than brute forcing 12 words, having 24 would have you covered. Or, when that happens, just move your funds to the new address type in the future with a new 24 word seed.