Proof of Work · Chapter 14

Backing up your seed phrase

In brief

The 12 or 24 words your wallet gave you are the wallet itself, and the phone is only a window onto it. Whoever reads the words can take the coins, and if you lose both the phone and the words, the coins can no longer be recovered. Write them by hand, keep 2 copies in 2 places you control, never make a digital copy, and test the recovery once, without deleting anything, while the amount is still small.

No support desk, no reset button

With a bank, losing access is an inconvenience, because you prove who you are and someone resets it. Self-custody removes that someone. There is no support desk, no "forgot my words" button and no court that can order the network to give your coins back. It is what makes your bitcoin very hard to freeze or seize from a distance, and it also leaves you as the only person responsible.

2 things go wrong in real life, and they pull in opposite directions. The first is loss, when a phone falls into a lake, the paper is thrown out during a move, or a fire destroys the single copy. The second is theft, when the words were saved in a photo, an email draft, a cloud note or a password manager, and someone found them. In March 2025, US federal investigators linked a theft of about 150 million dollars, committed in January 2024, to secrets stored in the LastPass password manager, which had been breached in 2022. Coins stolen this way move within minutes and cannot be recalled, so a good backup has to protect against loss and theft at once.

A single random number, written as words

When you create a wallet, the app generates a single very large random number, and everything else comes from it, meaning every key and every address for every coin you will ever receive in that wallet. A standard called BIP39 writes this number as 12 or 24 words taken from a fixed list of 2,048 simple English words, because people copy words more reliably than long strings of digits. The last word includes a checksum, which detects most copying errors.

A single backup, made once, therefore restores everything, and you do not need to back up again after each payment. Enter the words into the same app on a new phone and your on-chain coins reappear, because they were never in the phone. In a wallet from a different team they usually reappear too, although you sometimes have to select the right address type or derivation path.

Lightning is the exception. Funds in channels depend on the wallet that opened them, and some Lightning wallets need an extra backup file in addition to the words. If so, the app says it clearly, and its instructions come first.

Nobody to trust, nobody to call

A seed phrase on paper is the rare case in this book where the trusted third party disappears completely. Recovery depends on no company, no server and no account, only on a public standard, which is exactly why nobody can help you once the words are lost. Availability and confidentiality both rest on you.

Every convenience that softens this brings a third party back. A steel plate ordered online puts your name and address in a maker's customer file, the kind that leaked at Ledger in 2020 (see "Mistakes to avoid"). Shamir shares and multi-signature spread the risk, but each person holding a share or a key can lose it or collude, and the software that splits and rebuilds the secret has to be trusted too. Any service that offers to recover your seed for you goes further. To return a backup after an identity check, a company has to hold it outside your home, where it can be breached, compelled or closed. It can suit someone who fears loss above all, knowing that trusted third parties are then back in the picture.

Verification takes a single form here, which is restoring the wallet from the words before you rely on them (step 6).

Choose how to store it

The right support depends on the amount and on what threatens your home, whether water, fire, burglars or curious visitors. All of the options below keep the words offline, and they can be combined.

Method Cost Who you must trust Strength Weakness
Paper, pencil or permanent ink Almost nothing Nobody, apart from the people who can reach the place where it is kept Immediate, no tool needed Water, fire, fading, easily thrown away by mistake
Laminated paper A few euros Nobody, as long as the laminator is yours. A copy shop would be a third party. Resists water and wear Still burns. Use your own laminator, not a copy shop.
Steel product: Cryptosteel, Seedor and others Tens of euros, up to about a hundred The maker and the shop, which learn your name and address, but never the words Resists fire, water and time The price. A visible object that says "bitcoin" to whoever finds it.
DIY steel: letters stamped into steel washers held on a bolt A few euros of hardware, plus a set of letter stamps Nobody. A hardware shop has no idea what the washers are for. Same resistance, discreet, no brand to trust An hour of work, and care when stamping
Passphrase (the optional "25th word") Free Nobody else, provided it is written down and kept apart from the words The words alone are no longer enough for a thief, if the passphrase is long and random A short or guessable one adds almost nothing. An extra secret to back up and to pass on. Forgotten passphrase, lost coins.

There are also 2 advanced options, for larger amounts:

A reasonable starting point for most people is paper on the first day, then a steel copy once the amount would hurt to lose, without a passphrase until you fully understand it. Beyond that, setups legitimately differ, as the next section shows.

No single right setup

There is no single right setup, because amounts, homes, families and threats differ, and 2 careful people can reasonably choose differently. The 3 main approaches can be combined.

Approach What you gain The price
Several independent keys, or several hardware wallets, for different purposes such as spending and savings A theft or a mistake touches 1 wallet, not everything More backups to store, label and test
1 key whose backup is split into fragments kept in different places, with a copy of each fragment in 2 places Losing 1 place does not lose the money, and finding 1 fragment does not reveal it More places and people involved, and a restore that needs compatible software
1 key plus a passphrase (the optional extra word or sentence) The words alone no longer open the wallet 1 more secret to back up and to pass on

Splitting only works with a proper scheme, Shamir backup or multi-signature, where a single fragment reveals nothing. Cutting the word list yourself gives each finder part of the secret, and in June 2020 John Cantrell found the 4 missing words of a 12-word phrase in about 30 hours with rented graphics cards.

An attacker who holds the words can also try passphrases very fast, so a short or guessable one adds almost no security, and it has to be long and random. Each different passphrase opens a different wallet, which allows separate or hidden sub-accounts. It must itself be backed up, separately from the words, where your heirs can find it.

The practical criterion is to choose the simplest setup you will still understand, and be able to restore, in 10 years.

Step by step

The example uses paper and a pen. The logic is the same on steel.

  1. Choose the moment. Alone, at a table, no camera behind you, not in a café or on a train.
  2. Write the words by hand, numbered, in order, in clear capital letters. Note the wallet's name and the date, not the amount.
  3. Check them twice. Read them back against the screen, word by word. Most wallets then ask you to confirm some of them.
  4. Never make a digital version. Do not type, photograph, print, dictate or email the words, and do not store them in the cloud or in a password manager. A seed phrase should not touch any device connected to the internet other than the wallet itself.
  5. Make 2 copies and store them in 2 places you control, for example your home and the home of a close relative, each in a sealed envelope. The second place is a trade-off, because without a passphrase whoever opens the envelope controls the coins. Choose someone you would trust with the same amount in cash, and consider one of the approaches above once the amount grows. If you use fragments or a passphrase, the rule of 2 copies applies to each of them, and a passphrase is never stored with the words.
  6. Test the recovery without deleting anything. Do it with an on-chain wallet that holds a tiny amount. Enter the words into the same app on a second device you own, or into a second compatible wallet, and check that the same balance appears. Then remove the restored copy. The original app stays in place during the whole test, so a wrong word costs you nothing. This is the step that replaces trust with verification, because it proves that the words on paper really open the wallet.
  7. Treat a Lightning wallet differently. Deleting an app that holds open channels can cost you the funds if the restore fails, and Phoenix, for example, warns against running 2 apps on the same seed. Read your wallet's restore instructions first. The real test usually comes when you change phones, with a small balance, the old phone switched off, and the old app kept until the balance shows on the new one.
  8. Plan the inheritance. Add a sealed letter explaining in plain words what this is, that it has value, that the words must never be typed into a website, who can be trusted to help, and how many pieces your setup has (words, fragments, passphrase) and where each is kept.

Mistakes to avoid

Go further

Sources

Your checklist

Your checklist: all →

PreviousYour first wallet and your first sats NextLightning and euros in everyday life

Back to contents