Skip to content
Actuator

Seed Phrase

Your seed phrase is the master key to everything

Anyone who has your seed phrase can steal all your funds β€” across every account, every chain, forever. This page covers practical, physical storage methods that protect against fire, water, theft, and loss. Storing your seed phrase safely is the single most important security decision you will make in crypto.

1. Paper Backup

The minimum baseline, and why paper alone is not enough

Writing your seed phrase on paper is the minimum baseline.  It's better than a text file on your computer β€” but only barely.  Paper burns, tears, fades, and can be found by anyone who opens the drawer.

When paper is appropriate:

  • Temporary backup while setting up a wallet before engraving metal
  • Small holdings where the cost of metal isn't justified
  • As a secondary backup alongside a metal primary

How to implement:

  1. Use the seed phrase card that comes with your hardware wallet, or high-quality archival paper
  2. Write with a ballpoint pen or pencil β€” not gel pens (ink can smudge) or felt-tip (bleeds through)
  3. Write each word clearly and number it (1, 2, 3…). Word order matters β€” getting it wrong means losing everything
  4. Verify every word against the device display by re-reading it back
  5. Store in a sealed envelope inside a fireproof bag or document safe
  6. A photographed, typed-in, or cloud-stored phrase lives wherever that copy lives β€” every computer, phone, and cloud service it touches is a machine you do not control

Verdict: Paper is a starting point, not a destination.  If your holdings are meaningful, upgrade to metal.  Paper is the #1 reason people lose crypto to house fires and floods.

2. Metal Stamping

Stamped steel or titanium survives fire and water β€” products compared

Engraving or stamping your seed phrase into metal protects against fire, water, corrosion, and physical damage.  A house fire can reach 1,100Β°C (2,000Β°F) β€” paper is gone at 233Β°C (451Β°F).  Stainless steel melts at ~1,400Β°C (2,550Β°F).  Titanium is even higher.  Metal survives what paper cannot.

You don't need to write the full words β€” just the first four letters of each word.  The BIP-39 word list is designed so that the first four letters uniquely identify every word.  This makes metal stamping faster and reduces error risk.

Metal Backup Products

ProductMaterialFormatPriceNotes
Trezor Keep MetalAerospace-grade stainless steelSLIP-39 (20-word), 4-letter per word$99Designed for Trezor Shamir backup. Tamper-evident security seals included
Cryptosteel CapsuleStainless steel (titanium available)Slotted core, letter tiles$80–$120Fastens with a bolt. Fireproof to 1,400Β°C. Works with any BIP-39 seed
BillfodlStainless steelSliding metal tiles$99One-time assembly. Fireproof to 1,200Β°C. Carries 24 words (4 letters each)
Cryptotag ZeusTitaniumPunch directly into plate$120–$160Extremely durable. Fireproof to 1,668Β°C. Uses full BIP-39 wordlist input
ColdTiTitaniumEngravable plates$40–$60Two titanium plates. Requires engraving tool. Fireproof to 1,668Β°C
DIY Stainless PlateStainless steel sheetHand-stamped with letter punches$10–$25Buy letter stamp set + plate from any hardware store. Same protection at fraction of cost

How to implement (Trezor Keep Metal example):

  1. Set up your Trezor device. During setup, Trezor Suite generates your recovery seed or Shamir shares
  2. Take the Trezor Keep Metal capsule out of the box. It comes with a pre-marking pen, a holding box, and security seals
  3. Write each word's first four letters onto the metal plate using the pre-marking pen (erasable, for positioning)
  4. Verify every word against the Trezor device screen
  5. Once verified, use a steel punch tool to permanently stamp each letter into the marked positions
  6. The capsule sits in the holding box to keep it steady while punching
  7. Apply the tamper-evident security seals. If someone opens the capsule later, the seals break β€” you'll know it was accessed
  8. Store the completed capsule in a safe, hidden location (see sections below)

How to implement (DIY budget method):

  1. Purchase a 304 or 316 stainless steel plate (~$5) and a 3mm letter/number stamping set (~$15) from a hardware store or Amazon
  2. Write your words on paper first as a reference template
  3. Mark positions on the plate with a marker β€” number each row 1–24
  4. Stamp the first four letters of each word into the metal, one word per row
  5. Stamp the word number at the start of each row (critical β€” order matters)
  6. Verify against your paper reference, then destroy the paper
  7. Store the plate in a sealed container to prevent corrosion

Why first-four-letters works: The BIP-39 word list (2,048 words) is designed so that no two words share the same first four letters.  This means stamping just four letters per word is sufficient to uniquely identify every word β€” saving you time and metal space.

3. Shamir's Secret Sharing (SLIP-39)

Split your seed into shares so no single loss or theft is fatal

Shamir's Secret Sharing (SSS) is a cryptographic algorithm created by Adi Shamir.  It splits your seed phrase into multiple shares β€” where a minimum number of shares (the threshold) is needed to reconstruct the original.  No individual share reveals anything about the secret.

This eliminates the single point of failure.  If one share is lost, stolen, or destroyed, your wallet is still recoverable β€” as long as you can gather enough shares to meet the threshold.

How it works:

  • 2-of-3 β€” split into 3 shares, any 2 needed. Simple, good for smaller holdings. Lose 1 share? Still recoverable. Thief finds 1 share? Useless.
  • 3-of-5 β€” split into 5 shares, any 3 needed. Good for medium holdings distributed across multiple locations
  • 5-of-7 β€” high security for large holdings. Distributed across multiple people and locations
  • You can choose 1 to 16 shares. The threshold cannot be 1 β€” you always need at least 2

Trezor Shamir Backup (SLIP-39):

Trezor Safe 3, Safe 5, and Safe 7 support Shamir Backup natively.  The default backup on the Safe 3 (since June 2024), Safe 5 and Safe 7 is a 20-word SLIP-39 Single-share Backup; Multi-share (Shamir shares) is one drop-down choice away, and a Single-share Backup can later be upgraded to Multi-share.  The Trezor Model T also supports Shamir Backup.

During device setup, Trezor Suite guides you through creating Shamir shares.  Each share is a sequence of 20 English words (128-bit strength) or 33 words (256-bit strength).  The first two words of each share are the same across all shares β€” they serve as identifiers so you can recognize shares that belong together.  The third word encodes the group index.

How to implement with a Trezor:

  1. Get a Trezor Safe 3, Safe 5, Safe 7, or Model T. Buy only from trezor.io β€” never from resellers
  2. Open Trezor Suite and begin device setup
  3. When prompted for backup type, select Multi-share Backup (Shamir) from the Wallet backup type drop-down.  Current devices preselect the 20-word Single-share Backup, so Multi-share has to be chosen
  4. Choose your scheme: number of shares (e.g., 3) and threshold (e.g., 2)
  5. The device displays each share one at a time β€” write each one down. The device generates the shares internally; your seed never touches a computer
  6. Verify by re-entering each share when prompted
  7. Store each share in a different physical location.  Shares kept together are one find away from being the whole seed
  8. Optionally stamp each share into metal (Trezor Keep Metal is designed for SLIP-39 20-word shares)
  9. The passphrase (Trezor Suite β†’ Settings β†’ Device β†’ Passphrase) works with both backup standards: it opens a hidden wallet the shares alone cannot reach

Full walkthroughs of both standards β€” SLIP-39 multi-share and 24-word BIP-39 β€” plus the passphrase setup, the practice restore, and the 33-word command-line expert path live in the backup guide.  Note: Trezor Suite creates 20-word shares; 33-word shares require the command line.

Tools that support Shamir's Secret Sharing:

  • Trezor hardware wallets β€” native SLIP-39 Shamir Backup during device setup. The gold standard
  • SeedTool β€” open-source tool for creating Shamir shares from any seed phrase. Run offline
  • Ian Coleman's BIP39 tool β€” can be downloaded and run offline for advanced seed management

Critical: a digitally stored Shamir share (cloud drives, password managers, photos, text files) is a share on someone else’s machine β€” enough of them leak, the phrase reassembles without you.  Each share should be stamped into metal and stored in a separate physical location.  If you lose too many shares to meet the threshold, your wallet is permanently unrecoverable.  There is no recovery path.

Single Backup vs. Shamir Backup:

FeatureSingle Seed (BIP-39)Shamir Backup (SLIP-39)
Word length12, 18, or 24 words20 or 33 words per share
Number of shares1 (single seed)1 to 16 shares
Threshold for recoveryAll words required (1/1)User-specified (e.g., 2-of-3, 3-of-5)
Loss toleranceNone β€” one loss = total lossCan lose shares up to threshold
Theft toleranceOne theft = total compromiseShares below threshold are useless to attacker

4. Bank Safe Deposit Box

Off-site vault storage at a bank, with its pros and cons

A bank safe deposit box provides off-site physical security in a vault.  It protects against fire, flood, and theft at your home.  Most banks and credit unions offer boxes in various sizes at annual rates of $50–$200.

Pros:

  • Banks have professional vaults β€” fire suppression, climate control, physical security
  • Dual-key system: the bank keeps one key, you keep the other β€” both needed to open
  • Off-site β€” a home break-in doesn't compromise this backup
  • Contents are private β€” bank employees cannot legally open your box

Cons:

  • Bank hours only β€” you can't access it at 2am on a Sunday
  • If the bank fails, box access may be temporarily frozen during resolution
  • Not ideal as your only backup β€” combine with a home backup
  • Some jurisdictions require next-of-kin to access boxes after death β€” plan your estate

How to implement:

  1. Open a safe deposit box at your bank or credit union (small size is fine for a metal plate)
  2. Place your stamped metal seed backup (or one Shamir share) in a sealed, tamper-evident envelope
  3. Store the envelope in the box
  4. Keep the box key separate from your house keys β€” don't label what it's for
  5. Visit once or twice a year to verify it's still there and intact
  6. Include instructions for your next of kin β€” they need to know what it is and how to use it

Best practice: Use the safe deposit box for one Shamir share, not your only backup.  If the bank is inaccessible for any reason, you still have shares elsewhere.

5. Split-Location Strategy

Never keep every copy in one place

The core principle: never store all your backup copies in one place.  A single location β€” your home, a single safe, one bank β€” is a single point of failure.  Fire, flood, burglary, or a natural disaster at one location should not mean total loss.

This strategy pairs naturally with Shamir's Secret Sharing (each share goes to a different location) but also works with duplicate metal backups.

Example: 3-location setup with Shamir 2-of-3

  • Share 1 β€” Home safe (fireproof, bolted to floor)
  • Share 2 β€” Bank safe deposit box
  • Share 3 β€” Trusted family member or attorney's office

Any 2 of these 3 shares reconstruct your wallet.  If your house burns down (lose Share 1), you still have Shares 2 and 3.  If a thief finds Share 3, it's useless without at least one more.

Example: Duplicate metal backups (no Shamir)

  • Copy A β€” Home safe
  • Copy B β€” Bank safe deposit box or trusted family member

Each copy is a full seed, so one found copy opens the wallet on its own unless a passphrase is set; with a passphrase set, the passphrase is what still guards the funds.  The trade: simpler than shares, and a BIP-39 seed restores on nearly any wallet.

How to implement:

  1. Identify 2–3 geographically separate locations. "Separate" means a fire at one can't reach the other
  2. Choose trusted people if using family/friends β€” give them only a share, never the full seed
  3. Stamp each share into metal. Paper in multiple locations is still paper β€” it burns everywhere
  4. Document what each share is, without revealing its contents. A label like "Recovery Share 2 of 3" is fine
  5. Create a recovery instruction sheet β€” stored separately β€” so your heirs know what to do
  6. Review annually: verify each location is still accessible and shares are intact

Important: If you give a share to a person, make sure they understand: (a) what it is, (b) that it's useless without the other shares, (c) that they should never try to "help" by combining shares.  Clear communication prevents well-meaning mistakes.

6. Hidden Storage & Decoys

Concealment and decoys β€” they can't steal what they can't find

Even with metal backups and Shamir shares, where you hide the backup matters.  A burglar who finds your safe will take what's inside.  Concealment adds another layer β€” they can't steal what they can't find.

Concealment methods:

  • Wall safe β€” installed behind a picture or mirror. Invisible to casual inspection. Cost: $50–$300
  • Floor safe β€” embedded in concrete floor under a rug or furniture. Very hard to find or remove. Cost: $100–$500
  • Hollow book β€” a real book with a cutout. Hide on a shelf among hundreds of books. Cost: $5–$15
  • False container β€” fake food cans, cleaning product bottles, or electrical outlets with hidden compartments. Cost: $10–$30
  • Inside furniture β€” taped under drawers, inside hollow chair legs, behind baseboards
  • Buried β€” in a waterproof container in your yard. Use a PVC pipe with end caps. Cost: $5–$10

Decoy strategy:

A decoy is a fake or low-value backup placed where an attacker would look first β€” a visible safe, a drawer, a USB drive.  The idea: if someone breaks in and finds something that looks like your seed phrase, they take it and leave.  Your real backup stays hidden elsewhere.

  • Put a paper with random 24 words (not your real seed) in a visible safe
  • Label it "Bitcoin Recovery Seed" β€” make it obvious so the thief takes the bait and runs
  • Store your real metal backup in a concealed location the burglar won't find

How to implement:

  1. Choose a concealment method that fits your home and lifestyle
  2. Store your real metal backup or Shamir share in the concealed location
  3. Create a decoy: generate random BIP-39 words (use an offline tool), write on paper, place in a visible safe or drawer
  4. Tell only trusted family members where the real backup is β€” not where the decoy is
  5. Document the real location in your estate planning documents (stored with your attorney)

Key principle: Security through obscurity is a layer, not a complete solution.  Concealment works as one layer alongside metal backups and Shamir shares β€” alone, it cannot carry the whole load.  A well-hidden paper backup is still paper β€” it still burns.

7. Memorization (Brain Wallet)

A supplement only, never your sole backup

Memorizing your seed phrase means it exists only in your head β€” no physical object to steal, burn, or lose.  This sounds appealing, but it is extremely risky as a sole strategy and should only be used as a supplement to physical backups.

The risks:

  • Head injury or illness β€” amnesia, stroke, or cognitive decline can erase the memory permanently
  • Death β€” if you die, the seed phrase dies with you. Your heirs lose everything
  • Stress and time β€” under duress, people forget things they "knew." Months later, doubt creeps in: "Was it 'actual' or 'actuar'?"
  • No redundancy β€” if you forget one word, the entire seed is unrecoverable

If you choose to memorize:

  1. Memorize in chunks: 4 words at a time, creating a rhythm or story. 6 chunks of 4 = 24 words
  2. Recite it weekly at first, then monthly, to maintain retention
  3. Test yourself by writing it down and verifying against your metal backup
  4. A memory with no physical backup is a single point of failure β€” memorization is a supplement, not a replacement
  5. A passphrase (the "25th word") is shorter than a seed phrase; forgotten, it takes its hidden wallet with it — the seed phrase alone opens only the standard wallet

Warning: A "brain wallet" β€” a seed derived from a passphrase you chose (e.g., "correct horse battery staple") β€” is trivially crackable by brute force.  A randomly generated seed phrase from a hardware wallet has no such weakness.

Quick Comparison

All seven methods side by side: fire, water, theft, cost

MethodFireWaterTheft ResistantCostDifficulty
PaperNoNoNo$0Trivial
Metal StampingYesYesModerate$45–$180Easy
Shamir (SLIP-39)Per sharePer shareExcellentHardware + metalModerate
Safe Deposit BoxYesYesExcellent$50–$200/yrEasy
Split-LocationPer locationPer locationExcellentVariesModerate
Hidden / DecoyDependsDependsGood$5–$50Easy
MemorizationYesYesNo$0Hard

Quantum Security Note

Pick your backup for theft and fire β€” quantum is a different problem

Quantum computers powerful enough to break current elliptic curve cryptography are not available today; experts generally estimate they could appear sometime between the late 2020s and mid-2030s.  The realistic quantum risk is Shor's algorithm deriving private keys from public keys revealed when you spend β€” a risk no backup format changes.

What this means for you today:

  • Pick your backup for theft and fire, not quantum β€” twelve words, 24 words, Shamir shares, metal plates: those are theft-and-fire decisions, not quantum ones.
  • Hold long-term on receive-only addresses β€” an address that has never signed has never shown its public key, and there is nothing on-chain for Shor to attack.
  • When a vault must spend, sweep it whole β€” move the entire balance to a fresh address in one transaction.

The full reasoning is in Security, section 8; the deep dive on quantum threats to seed phrases and ECDSA has the realistic Shor's-algorithm timelines.

Frequently Asked Questions

Short answers on word counts, SLIP-39 and backups

What is the difference between a 12-word and 24-word seed phrase?

A 12-word seed phrase (BIP-39) provides 128 bits of entropy, while a 24-word seed phrase provides 256 bits.Β  Both are considered cryptographically secure today.Β  The realistic quantum risk is Shor's algorithm deriving private keys from public keys revealed when you spend β€” a risk seed length does not change β€” but if you want maximum headroom, prefer 256-bit backups: a 24-word seed, or β€” the expert tier β€” 33-word SLIP-39 shares (command-line only): same strength plus no single point of failure.

What is SLIP-39 and how many words does it use?

SLIP-39 is Trezor's implementation of Shamir's Secret Sharing.Β  It splits your wallet backup into multiple 20-word shares (33-word for 256-bit seeds).Β  You choose how many total shares to create and how many are needed (threshold) to recover the wallet β€” for example, 3 total shares with 2 required to recover.

Should I store my seed phrase digitally?

A digital copy lives wherever that file lives: cloud drives, password managers, photos and text files all put the phrase on machines you do not control, and a phrase typed into any computer or phone has touched the internet.Β  A hardware wallet with a secure screen is the one device built to hold it.Β  Paper burns; metal survives.Β  Metal stamping gives the best physical protection.

What is the best way to back up a seed phrase?

The strongest backup combines: (1) metal stamping (engrave on stainless steel or titanium), (2) SLIP-39 multi-share backups split across geographic locations (20-word shares in Trezor Suite; 33-word shares via the command line are the expert tier), and (3) a strong passphrase on your hardware wallet.Β  Products like Trezor Keep Metal, Cryptosteel, or Billfodl survive fire, water, and corrosion.

Can I recover my wallet if I lose my hardware wallet?

Yes.Β  As long as you have your seed phrase (or SLIP-39 shares meeting the threshold), you can recover your wallet on any compatible hardware wallet.Β  This is why secure backup storage is critical β€” your seed phrase IS your wallet.

Facts last reviewed: September 23, 2026

Suggest or Correct

Spotted an error?  Have an idea?  Found something missing?
Let us know.  This site is community-built and your input is welcome.

Anything sent here arrives as an email that a person reads.  A Seed Phrase sent here gives its wallet to whoever reads it.