In brief
The 12 or 24 words your wallet gave you are the wallet itself, and the phone is only a window onto it. Whoever reads the words can take the coins, and if you lose both the phone and the words, the coins can no longer be recovered. Write them by hand, keep 2 copies in 2 places you control, never make a digital copy, and test the recovery once, without deleting anything, while the amount is still small.
No support desk, no reset button
With a bank, losing access is an inconvenience, because you prove who you are and someone resets it. Self-custody removes that someone. There is no support desk, no "forgot my words" button and no court that can order the network to give your coins back. It is what makes your bitcoin very hard to freeze or seize from a distance, and it also leaves you as the only person responsible.
2 things go wrong in real life, and they pull in opposite directions. The first is loss, when a phone falls into a lake, the paper is thrown out during a move, or a fire destroys the single copy. The second is theft, when the words were saved in a photo, an email draft, a cloud note or a password manager, and someone found them. In March 2025, US federal investigators linked a theft of about 150 million dollars, committed in January 2024, to secrets stored in the LastPass password manager, which had been breached in 2022. Coins stolen this way move within minutes and cannot be recalled, so a good backup has to protect against loss and theft at once.
A single random number, written as words
When you create a wallet, the app generates a single very large random number, and everything else comes from it, meaning every key and every address for every coin you will ever receive in that wallet. A standard called BIP39 writes this number as 12 or 24 words taken from a fixed list of 2,048 simple English words, because people copy words more reliably than long strings of digits. The last word includes a checksum, which detects most copying errors.
A single backup, made once, therefore restores everything, and you do not need to back up again after each payment. Enter the words into the same app on a new phone and your on-chain coins reappear, because they were never in the phone. In a wallet from a different team they usually reappear too, although you sometimes have to select the right address type or derivation path.
Lightning is the exception. Funds in channels depend on the wallet that opened them, and some Lightning wallets need an extra backup file in addition to the words. If so, the app says it clearly, and its instructions come first.
Nobody to trust, nobody to call
A seed phrase on paper is the rare case in this book where the trusted third party disappears completely. Recovery depends on no company, no server and no account, only on a public standard, which is exactly why nobody can help you once the words are lost. Availability and confidentiality both rest on you.
Every convenience that softens this brings a third party back. A steel plate ordered online puts your name and address in a maker's customer file, the kind that leaked at Ledger in 2020 (see "Mistakes to avoid"). Shamir shares and multi-signature spread the risk, but each person holding a share or a key can lose it or collude, and the software that splits and rebuilds the secret has to be trusted too. Any service that offers to recover your seed for you goes further. To return a backup after an identity check, a company has to hold it outside your home, where it can be breached, compelled or closed. It can suit someone who fears loss above all, knowing that trusted third parties are then back in the picture.
Verification takes a single form here, which is restoring the wallet from the words before you rely on them (step 6).
Choose how to store it
The right support depends on the amount and on what threatens your home, whether water, fire, burglars or curious visitors. All of the options below keep the words offline, and they can be combined.
| Method | Cost | Who you must trust | Strength | Weakness |
|---|---|---|---|---|
| Paper, pencil or permanent ink | Almost nothing | Nobody, apart from the people who can reach the place where it is kept | Immediate, no tool needed | Water, fire, fading, easily thrown away by mistake |
| Laminated paper | A few euros | Nobody, as long as the laminator is yours. A copy shop would be a third party. | Resists water and wear | Still burns. Use your own laminator, not a copy shop. |
| Steel product: Cryptosteel, Seedor and others | Tens of euros, up to about a hundred | The maker and the shop, which learn your name and address, but never the words | Resists fire, water and time | The price. A visible object that says "bitcoin" to whoever finds it. |
| DIY steel: letters stamped into steel washers held on a bolt | A few euros of hardware, plus a set of letter stamps | Nobody. A hardware shop has no idea what the washers are for. | Same resistance, discreet, no brand to trust | An hour of work, and care when stamping |
| Passphrase (the optional "25th word") | Free | Nobody else, provided it is written down and kept apart from the words | The words alone are no longer enough for a thief, if the passphrase is long and random | A short or guessable one adds almost nothing. An extra secret to back up and to pass on. Forgotten passphrase, lost coins. |
There are also 2 advanced options, for larger amounts:
- Splitting across locations. Standard schemes such as Shamir backup (SLIP39), supported by some hardware wallets, divide the secret into shares, for example any 2 of 3. SLIP39 uses its own word list and is not compatible with BIP39, so only wallets that support it can restore it. Do not invent your own scheme by cutting the word list in half (the next section explains why).
- Multi-signature. A wallet that requires several independent keys, for example 2 of 3, kept in different places, so that a single theft or loss is not fatal. Chapter 17 introduces the devices that make this practical.
A reasonable starting point for most people is paper on the first day, then a steel copy once the amount would hurt to lose, without a passphrase until you fully understand it. Beyond that, setups legitimately differ, as the next section shows.
No single right setup
There is no single right setup, because amounts, homes, families and threats differ, and 2 careful people can reasonably choose differently. The 3 main approaches can be combined.
| Approach | What you gain | The price |
|---|---|---|
| Several independent keys, or several hardware wallets, for different purposes such as spending and savings | A theft or a mistake touches 1 wallet, not everything | More backups to store, label and test |
| 1 key whose backup is split into fragments kept in different places, with a copy of each fragment in 2 places | Losing 1 place does not lose the money, and finding 1 fragment does not reveal it | More places and people involved, and a restore that needs compatible software |
| 1 key plus a passphrase (the optional extra word or sentence) | The words alone no longer open the wallet | 1 more secret to back up and to pass on |
Splitting only works with a proper scheme, Shamir backup or multi-signature, where a single fragment reveals nothing. Cutting the word list yourself gives each finder part of the secret, and in June 2020 John Cantrell found the 4 missing words of a 12-word phrase in about 30 hours with rented graphics cards.
An attacker who holds the words can also try passphrases very fast, so a short or guessable one adds almost no security, and it has to be long and random. Each different passphrase opens a different wallet, which allows separate or hidden sub-accounts. It must itself be backed up, separately from the words, where your heirs can find it.
The practical criterion is to choose the simplest setup you will still understand, and be able to restore, in 10 years.
Step by step
The example uses paper and a pen. The logic is the same on steel.
- Choose the moment. Alone, at a table, no camera behind you, not in a café or on a train.
- Write the words by hand, numbered, in order, in clear capital letters. Note the wallet's name and the date, not the amount.
- Check them twice. Read them back against the screen, word by word. Most wallets then ask you to confirm some of them.
- Never make a digital version. Do not type, photograph, print, dictate or email the words, and do not store them in the cloud or in a password manager. A seed phrase should not touch any device connected to the internet other than the wallet itself.
- Make 2 copies and store them in 2 places you control, for example your home and the home of a close relative, each in a sealed envelope. The second place is a trade-off, because without a passphrase whoever opens the envelope controls the coins. Choose someone you would trust with the same amount in cash, and consider one of the approaches above once the amount grows. If you use fragments or a passphrase, the rule of 2 copies applies to each of them, and a passphrase is never stored with the words.
- Test the recovery without deleting anything. Do it with an on-chain wallet that holds a tiny amount. Enter the words into the same app on a second device you own, or into a second compatible wallet, and check that the same balance appears. Then remove the restored copy. The original app stays in place during the whole test, so a wrong word costs you nothing. This is the step that replaces trust with verification, because it proves that the words on paper really open the wallet.
- Treat a Lightning wallet differently. Deleting an app that holds open channels can cost you the funds if the restore fails, and Phoenix, for example, warns against running 2 apps on the same seed. Read your wallet's restore instructions first. The real test usually comes when you change phones, with a small balance, the old phone switched off, and the old app kept until the balance shows on the new one.
- Plan the inheritance. Add a sealed letter explaining in plain words what this is, that it has value, that the words must never be typed into a website, who can be trusted to help, and how many pieces your setup has (words, fragments, passphrase) and where each is kept.
Mistakes to avoid
- Keeping a digital copy. Photos, notes, email drafts and cloud drives are the first places malware and intruders search.
- Keeping a single copy. A fire, a flood or a house move is enough to lose it, which is why you keep 2 copies in 2 places.
- Telling people how much you own. In December 2020, the names, postal addresses and phone numbers of about 272,000 Ledger customers were published on a hacking forum after a breach of the company's shop database, and these customers were then targeted by phishing campaigns. Talk about Bitcoin as much as you like, not about your balance.
- Entering your words into a website or giving them to "support". No wallet team, exchange or authority will ever ask for them, so whoever asks is attempting a theft.
- Building a scheme you will not remember in 5 years. Words hidden in a book, split in 4, with an improvised code, have locked many people out of their own coins. Keep the scheme simple, documented and tested.
- Never testing, or testing by deleting the app. An untested backup may contain a wrong word, and if you delete the app first you discover it after the only working copy is gone. Restore on a second device instead (step 6).
Go further
- At PROOF: "Why Your Internet Security Depends on Your Keys", by Satoshine. Your seed phrase is the most direct example of a key that is only yours.
- Steel backups tested against fire, acid and a press: Jameson Lopp's metal storage reviews (jlopp.github.io/metal-bitcoin-storage-reviews).
- Backup and recovery tutorials: Plan B Academy (planb.academy).
- The standard itself and its word list: BIP39, in the Bitcoin improvement proposals (github.com/bitcoin/bips).
- Which wallet can restore which seed: Wallets Recovery (walletsrecovery.org).
- Next chapter: Lightning and euros in everyday life.
Sources
- Feds Link $150M Cyberheist to 2022 LastPass Hacks, Krebs on Security, 6 March 2025.
- Message from Ledger's CEO on the data leak, Ledger, 21 December 2020.
- BIP39: Mnemonic code for generating deterministic keys, Bitcoin Improvement Proposals, 2013.
- SLIP39: Shamir's Secret-Sharing for Mnemonic Codes, SatoshiLabs, consulted in September 2026.
- How I checked over 1 trillion mnemonics in 30 hours to win a bitcoin, John Cantrell, republished by WORDS Bitcoin Journal, 18 June 2020.
- Phoenix FAQ: restoring a wallet, limitations, ACINQ, consulted in September 2026.