Prices: CoinGecko

Seed phrase guide: how to back up and protect your recovery words

What a seed phrase is, how it links to your private keys, and how to write, store, test and pass it on safely, plus passphrase and Shamir backup risks.

Beginner8 min readUpdated October 4, 20265 sourcesCrypto Foundations · Lesson 6 of 20
On this page
  1. What a seed phrase is
  2. How it relates to your private keys
  3. How to write it down and store it
  4. The golden rules
  5. Common mistakes to avoid
  6. Passphrases: the optional “25th word”
  7. Shamir and multi-share backups
  8. How to test a backup safely
  9. Inheritance basics
  10. Where to go next

Key takeaways

  • A seed phrase is a human-readable master backup: anyone who has the words can recreate your wallet and move your funds, from anywhere.
  • Write it on paper or metal, keep it offline and away from cameras and cloud services, and never type it into a website or share it with anyone.
  • Test your backup with a small amount before you rely on it, and plan how a trusted person could find it if something happens to you.

A seed phrase, also called a recovery phrase, is a list of 12 to 24 ordinary words that can rebuild your entire self-custody wallet. Whoever holds those words controls the funds, so learning to record, store and test them properly is the most important safety habit in crypto.

What a seed phrase is

When you create a self-custody wallet, the app generates a large random number. Remembering or copying a number that long would be miserable, so the wallet translates it into a short list of words instead. That list is your seed phrase.

Most wallets follow a standard called BIP-39. It uses a fixed list of 2,048 words and creates phrases of 12, 15, 18, 21 or 24 words, with 12 and 24 being the most common. The final word includes a small checksum, a built-in check that helps a wallet notice many typos.

Because the standard is shared, you can usually restore the same phrase in a different wallet app if the original one disappears.

How it relates to your private keys

In the wallets lesson you learned that a private key is what signs transactions. Your seed phrase sits one level above that.

Think of it like a master recipe. From one recipe, a wallet can bake as many private keys and addresses as you need, across many networks, always in the same order. Lose a single key and you can bake it again. Lose the recipe and every key goes with it.

That is also why the phrase is so dangerous in the wrong hands. A thief does not need your phone or your PIN. With just the words, they can rebuild your wallet on their own device and move everything.

How to write it down and store it

  1. Set up in private. No cameras, screen sharing or people looking over your shoulder.
  2. Write by hand. Use the card that came with your hardware wallet or plain paper and a pen. Print clearly and number each word.
  3. Double-check every word. Compare spelling with what the device shows. Under BIP-39, the first four letters of each word are enough to identify it, which helps when handwriting is messy.
  4. Confirm the backup. Most wallets ask you to re-enter some words. Do not skip this.
  5. Consider a metal copy. Paper burns and gets wet. Stamped or engraved steel backups survive fire and flood far better. See our seed storage comparisons.
  6. Choose locations carefully. A home safe, a safe deposit box, or a second secure location you trust. Avoid obvious spots like a desk drawer next to the hardware wallet.

The golden rules

  • Never type it into a website. The only place your words should ever be entered is the wallet app or hardware device during a genuine restore.
  • Never photograph or screenshot it. Photos sync to cloud accounts automatically, and cloud accounts get hacked.
  • Never store it in email, notes apps or chat. Digital copies can leak without you ever noticing.
  • Nobody legitimate will ask for it. Not your wallet maker, not an exchange, not support staff, not the government, not a “recovery expert.” A request for your seed phrase is a scam, full stop.
  • Never use a phrase someone else gave you. Pre-filled recovery cards in a hardware wallet box are a known trick. A genuine device always creates its own words.

Common mistakes to avoid

  • Keeping the only copy in the same box as the hardware wallet, where one fire or burglary takes both.
  • Writing words out of order, or leaving them unnumbered.
  • Mixing up similar-looking letters in rushed handwriting.
  • Telling several people where the backup is “just in case,” which widens the circle of risk.

Passphrases: the optional “25th word”

BIP-39 allows an optional extra secret called a passphrase, often nicknamed the 25th word even though it can be any phrase you choose. The seed words plus the passphrase together produce the wallet.

The benefit is protection if someone finds your written words. Without the passphrase, they only reach an empty or decoy wallet.

The risks are real, though:

  • Every different passphrase opens a different valid wallet. There is no “wrong passphrase” error, so a single typo or capital letter silently leads to an empty wallet.
  • If you forget it, nobody can recover it for you, and your funds are gone.
  • Your heirs need to know it exists and where to find it.

If you use one, back it up separately from the seed words. Many beginners are better off skipping it until they are comfortable with basic backups.

Shamir and multi-share backups

A single seed phrase is a single point of failure: one copy can be lost, and one copy can be stolen. Shamir backup, defined in a standard called SLIP-39, splits your backup into several separate shares.

You choose how many shares exist and how many are needed to recover, such as any 2 of 3. In Trezor's implementation, each share is 20 or 33 words, and you can create up to 16 shares. A thief who finds one share learns nothing useful, and losing one share does not lock you out.

Trade-offs to know: shares only work with wallets that support SLIP-39, they use a different word list from BIP-39, and if you lose enough shares to fall below the threshold, the wallet cannot be recovered. Multisig wallets and some newer smart-contract wallets offer other ways to avoid one fragile backup.

How to test a backup safely

A backup you have never tested is a hope, not a plan. Here is a cautious way to check it:

  1. Start with only a small amount in the wallet.
  2. Write down one receiving address the wallet shows you.
  3. Reset the hardware wallet, or use the official recovery check feature many devices offer, which confirms the words without exposing them to a computer.
  4. Restore from your written words only, plus the passphrase if you set one.
  5. Confirm the same address and balance appear. Then add larger amounts.

Never test by typing your words into a website or a phone you also use for everyday browsing. If a restore does not match, our wallet recovery guide explains common causes such as passphrase mistakes and derivation paths.

Inheritance basics

If something happened to you tomorrow, could someone you trust reach your crypto? With self-custody, the answer depends entirely on your preparations.

  • Leave a letter of instructions explaining which wallets you use, where backups are stored, and whether a passphrase or Shamir shares are involved.
  • Do not put the seed words in a will. Wills can become public during probate.
  • Consider splitting knowledge so no single person can act alone, for example a Shamir scheme or keeping the passphrase separate from the words.
  • Talk with an estate attorney about how digital assets fit into your plan.

Where to go next

You now know how wallets work and how to protect the backup that controls them. The final step in this part of the course puts it into practice: how to buy crypto safely, including how to move your first purchase into a wallet you control.

Frequently asked questions

Is a 24-word seed phrase safer than a 12-word one?

A 24-word phrase carries more randomness, but a properly generated 12-word phrase is already far beyond what anyone can guess by brute force. In practice, how you store the words matters much more than how many there are.

Can I store my seed phrase in a password manager?

Security professionals disagree, but most hardware wallet makers advise against any digital copy, because a hacked account or device could expose it. If you hold meaningful amounts, an offline paper or metal backup is the safer default.

What if someone sees my seed phrase?

Treat the wallet as compromised. Create a brand-new wallet with a new seed phrase on a trusted device and move your funds to it as soon as possible.

Does my seed phrase work in other wallet apps?

Usually, if both wallets use the BIP-39 standard, though you may need to select the right network or account type. Shamir (SLIP-39) shares only work with wallets that support that standard.

Sources

  1. BIP-39: Mnemonic code for generating deterministic keys — Bitcoin Improvement Proposals
  2. SLIP-0039: Shamir's Secret-Sharing for Mnemonic Codes — SatoshiLabs
  3. What is Shamir backup? — Trezor
  4. Crypto Asset Custody Basics for Retail Investors – Investor Bulletin — U.S. Securities and Exchange Commission (Investor.gov)
  5. Account abstraction: beyond seed phrases — ethereum.org

Updated October 4, 2026 by The Crypto Guide editorial team. Educational content, not financial, legal or tax advice. Spot an error? Request a correction.