Naar hoofdinhoud
Live markt
Block #9

Dossiers

Dossier seed phrase: backup and security

The recovery phrase, or seed phrase, is the only thing that truly matters when holding your own crypto. Devices break, brands disappear and apps go stale, but those twelve or twenty-four words restore everything. This dossier covers how to have a seed generated correctly, how to store it on paper or in metal, when an extra passphrase makes sense, and how to test that your backup actually works.

Dani OosterhuisWritten by Redacteur payments, GroningenUpdated Checked by the editorial desk

Timeline

  1. BIP39 sets the standard for recovery phrases of twelve or twenty-four words.
  2. The first metal seed backups appear as an answer to fire and water damage.
  3. Shamir backup (SLIP39) makes it possible to split a seed into shares.
  4. Phishing with fake wallet apps grows: 'enter your recovery phrase' remains the most used trick.

What a recovery phrase is and why it must never be digital

A recovery phrase is a sequence of words from a fixed word list from which your wallet derives every private key. Order matters: the same words in a different order produce a different set of funds. Because the phrase follows an open standard, you can restore it in almost any wallet, including another brand.

That universality is exactly what makes it dangerous to store digitally. A photo in your camera roll, a note in a cloud app, a screenshot or a text file on your desktop will sooner or later sync to a server or end up in a backup. Malware that specifically hunts for word sequences has been common for years; only one infected device is needed.

Always let the device generate the phrase, and never type it into a website or app that asks for it. No legitimate wallet, exchange or support desk ever asks for your recovery phrase; anyone who does is trying to rob you.

  • Never photograph, email, upload or paste it into a password manager
  • Never type it into a website, not even for a 'validation' or 'migration'
  • Always have the device generate it; never invent words yourself
  • Number the words, because their order is part of the backup

Paper: cheap, a fine start, but fragile

Paper is free and immediately available, and for small amounts it is a defensible solution. Write the words down numbered and legibly with a pen that does not fade, note the wallet type and whether there are twelve or twenty-four words, and keep it in a sealed envelope somewhere visitors never go.

The weaknesses are well known: fire, damp, mould, fading, rodents and house moves. A card in a kitchen drawer does not survive a house fire, and printed ink in a damp basement can become half unreadable within a few years. Paper is fine as a first copy but rarely wise as the only copy.

Make at least two paper copies and do not keep them in the same building. A fire, burglary or flood then costs you at most one of the two. Never note on either copy how much crypto is involved or which platform you use.

Metal: resistant to fire, water and time

A metal backup stores the words in stainless steel or titanium by stamping letters, engraving plates or sliding punched tiles into a holder. Products such as Cryptosteel, Billfodl, Blockplate, Keystone Tablet and the NGRAVE plate all work on the same principle: no ink, no paper, no electronics.

The gain is that the backup survives fire, firefighting water, flooding and decades of time. Stainless steel holds well above the temperature of an average house fire, and there is no battery or chip to degrade. The first four letters of each word are usually enough, because the standard word list is already unambiguous at that point.

When stamping, watch two things: verify every word twice before moving on, because a wrong letter in steel cannot be corrected, and do not store the plate in the same cupboard as your hardware wallet. Metal protects against natural disaster, not against a thief who takes everything at once.

  • Stainless steel or titanium; no aluminium and no laminated paper
  • Stamping or engraving lasts longer than loose letter tiles
  • Check word by word and never photograph the result
  • Keep the plate and the device at different addresses

Passphrase, splitting and geographic spread

An extra passphrase, often called the twenty-fifth word, is added to the seed and produces a completely different set of addresses. Anyone who finds your metal plate but does not know the passphrase gets nowhere. The downside is equally hard: forget it and the funds are gone. Store it separately and make sure one trusted person knows it exists.

To spread risk without a passphrase, a Shamir backup is an alternative. The seed is split into, say, three shares of which two are needed to restore. One lost share is then no problem, and one found share gives a thief nothing. Distribute shares across locations with different risks: home, family in another city, and possibly a bank vault.

Finally, remember that most losses are caused by carelessness rather than hackers: a moving box thrown away, a vault key nobody could find, an heir who did not know what the metal plate was. Record in plain language what is kept where and who may know what, without putting the words themselves in that document.

  • Store the passphrase separately from the seed, never on the same plate or sheet
  • Shamir backup: for example two of three shares needed to restore
  • Spread across locations with different fire, burglary and water risks
  • Document the emergency plan, but never the words themselves

Testing: a backup you never tried does not count

You verify a recovery phrase by actually restoring it. Reset the hardware device to factory settings and restore from your backup, or use a second empty device and check that the first address matches exactly. Do this once at setup and then annually, together with a quick check that the plate is still readable and present.

With a new setup, send a small amount first, restore the wallet from the backup and move that amount again before transferring a large balance. Those ten minutes prevent the most common self-custody disaster: a correctly written phrase that still returns nothing because of a typo or a missing twenty-fifth word.

Frequently asked questions

Can I store my recovery phrase in a password manager?

Better not. A password manager is a digital target that syncs over the internet. Keep the phrase physically on paper or in metal and use the manager at most for a hint about where it is stored.

Is metal really necessary, or is paper enough?

Paper is enough for small amounts, provided you keep two copies in different places. From a few thousand euros upwards, the price of a metal backup is trivial against the risk of fire or water damage.

What do I do if someone has seen my recovery phrase?

Treat the wallet as compromised. Create a new wallet with a new seed on a clean device and move all funds there immediately; changing passwords does not help.

Can I keep parts of the phrase in different places?

Splitting loose words weakens security less than people assume and makes recovery error-prone. Use a Shamir backup instead, which is mathematically designed for this.

What happens to my crypto when I die?

Without an emergency plan it is unreachable. Record where the backup is and how a relative can gain access with help, for example via a notary or a sealed envelope, without combining the words in one document.

Read next

Newsletter

Bitcoin for breakfast, Brussels for lunch

One short email with what actually matters: prices, regulation and the banks that move. No hype, no noise.

  • Daily at 07:00
  • 2 minute read
  • No spam

Free. Unsubscribe in one click.