How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Seed phrase storage: the weak point that decides who keeps your coins
The attack on Coldcard devices, running since the end of July, has steered the debate towards manufacturers, firmware and supply chains. Where a wallet backup actually sits, and in what condition, has barely come up. For most retail investors, that is the more practical question.
Coinkite, the manufacturer, set out the issue itself in its security advisory of July 30, 2026: funds from affected seeds are at risk unless the seed rests on at least fifty independent dice rolls thrown in private. That is a statement about how a seed comes into being, not about how it is stored. It leads to the same place all the same. A seed is a piece of information whose value depends entirely on who knows it. The scale of the damage remains open; estimates in the first days of August ranged between $86 million and more than $130 million, depending on the survey and the cut-off date. We described the case and the manufacturer question in our assessment of the Coldcard attack.
This article deals with the other half of the problem: how to store those twelve or twenty-four words so that they survive a house fire, a burglary, a house move and fifteen years of time. Which devices even qualify for the job is set out in our hardware wallet comparison.
What the 12 or 24 words of a seed phrase actually contain
The words are not passwords, and they are no shorthand for account access either. They are a readable encoding of a random number. Grasp that, and better storage decisions follow almost automatically.
Why the word list holds exactly 2,048 entries
The standard behind it is called BIP-39. It defines a list of 2,048 words, which means every word carries exactly eleven bits. The length of a phrase therefore reveals the underlying entropy directly: 128 bits give twelve words, 160 bits fifteen, 192 bits eighteen, 224 bits twenty-one and 256 bits twenty-four words.
Some of those bits carry no random information at all. They form a checksum, which BIP-39 builds from the first ENT/32 bits of the SHA256 hash of the entropy. In practice that means a phrase with one word copied down wrongly is rejected as invalid by any correctly implemented wallet, instead of quietly opening an empty wallet. A transcription error therefore shows up at the first recovery attempt, and not years later.
How the words become the seed
The derivation is laid down as well: PBKDF2 with HMAC-SHA512, 2,048 iterations, the string "mnemonic" followed by an optional passphrase as the salt, and 512 bits as the result. Two consequences follow from this that matter considerably for storage.
First, recovery needs no device from any particular manufacturer. Anyone holding the words reconstructs the seed with any software that implements the standard. That is the real insurance against a manufacturer disappearing from the market. Second, there is no confirmation prompt and no undo button. Whoever knows the words is the owner.
Three ways to lose a seed phrase backup
Before turning to materials and methods, a sober list of the ways a backup gets lost is worth having. Measures against one of them routinely raise the risk of another.
- Someone finds it. The slip of paper in the drawer, the photo in the phone gallery, the note in the password manager. The typical case is rarely a targeted attack. It is an ordinary burglary in which the paper happens to catch someone's eye.
- It gets destroyed. Fire, water, mould, fading ink. House moves belong here too, when a box never turns up again.
- Your own memory. Anyone who wants to keep a passphrase in their head alone, or invents a personal encryption scheme whose rule they can no longer reconstruct eight years later, loses access without any external event at all. Inheritance comes on top of that.
A seed phrase on paper: how long a sheet really lasts
Almost every hardware wallet ships with a cardboard card on which the words are meant to be noted down. For the first day that is fine. As a permanent solution, paper has a second weakness alongside the familiar physical one, and it is considered far less often: the writing itself. Ballpoint ink fades depending on how much light reaches it, and handwriting turns ambiguous after years, particularly with words that resemble one another. The BIP-39 list is built so that the first four letters are unique, but that only helps as long as they stay legible.
Anyone staying with paper should write in block capitals with an archival pen and number the sequence. The real safeguard, however, is a second copy in a different place, not the material.
A steel plate for your seed phrase: what the construction has to get right
Metal backups have been the standard advice for years, and the advice is sound. Yet "steel" says nothing about quality. The differences between designs are considerable, and some products fail at precisely the scenario they are sold against.
What the stress tests measure
The most usable public data on this is the open-source project metal-bitcoin-storage-reviews by Jameson Lopp, which has assessed backup devices to a consistent method for years. The results are condensed into three grades: one for heat, one for corrosion and one for crushing. That split makes sense, because a device can be excellent in one category and useless in another.
Two patterns run through the evaluation. Plate designs that hold the information through holes or punched patterns in solid material score well throughout. Designs that rely on sealing, coating or inserted carriers fail heat and corrosion tests unusually often. What is missing from the metal itself can burn off or come away.
Stamping, punching, engraving
A ranking follows from that for practical purposes. Ahead are the methods that remove or deform material, meaning punching, stamping with letter punches and deep engraving. Behind them come systems with individual letter tiles, which are heat-resistant but can shift when dropped or crushed. At the end sit all the variants where the writing merely rests on the surface.
After this week, that strikes us as the more important criterion: what decides the matter is not whether a backup is made of metal, but whether the information sits in the metal or only on it. Anyone who already owns a plate can check that in two minutes by running a fingernail across the characters.
One note on practice: never stamp your only copy. Letter punches slip, and a character set wrongly cannot be corrected. Transfer the sequence from paper first, and destroy that paper once the plate has been checked.
The passphrase: the 25th word as an additional layer of protection
The optional passphrase from BIP-39 is the most powerful and at the same time the most dangerous tool in this field. It enters the derivation as part of the salt, and so turns the same twelve words into an entirely different wallet.
A backup found on its own is therefore of no use to a thief any more. The standard describes the property explicitly: every passphrase produces a valid seed and with it a working wallet, but only the right one opens the intended wallet. That creates the option of running a second, lightly funded wallet alongside the actual holdings, which can be shown under duress.
The price for this often goes unmentioned. If the passphrase is lost, the seed is gone beyond recovery, and the standard puts it in exactly those terms. There is no checksum that flags a misremembered passphrase. The wallet simply opens empty, which regularly leads those affected to assume their device is broken.
Our own view on this is cautious. A passphrase is worth having if it is written down and kept separately from the word backup. Anyone who insists on holding it in their head alone trades a theft risk for a markedly higher risk of forgetting. For sums that matter in everyday life, we rarely consider that a sensible trade.
Multisig and SLIP-0039: splitting the seed phrase instead of hiding it
Anyone holding more than a small amount eventually runs into the limits of a single backup. One location is always either too accessible or too inaccessible. Two established methods resolve this in very different ways.
Multisig
In a multisignature wallet the authority to sign is divided up, rather than the backup. Spending then requires two of three keys, for example, and those keys can sit on devices from different manufacturers. A single compromised device no longer suffices, and that was precisely the lesson of the Coldcard case. The drawback is the effort involved: alongside the keys you have to back up the wallet descriptor, otherwise the construction cannot be reconstructed later on.
SLIP-0039
The Shamir standard from SatoshiLabs splits the secret itself into several shares; reconstruction happens only once enough shares are brought together. SLIP-0039 works on two levels: a group threshold across up to sixteen groups, and a member threshold of up to sixteen shares per group. Rules such as two of your own four shares, or three of five friends together with two of six family members, can be modelled that way. Technically the standard uses a word list of its own with 1,024 words. One share runs to twenty words for a 128-bit secret and thirty-three words at 256 bits; tampered shares are detected through a digest check.
The drawback is obvious. The method is far from supported by every device, and at the moment of reconstruction the complete seed sits on a single device once again. Anyone whose main concern is redundancy against destruction is still better served by it than by three identical copies. Where the goal is protection against one faulty device, multisig is the more suitable tool. Which software handles both methods is set out in our overview of software wallets.
Where a seed phrase backup should be kept
In practice the question of location decides more than the material does. A brief orientation:
- At least two locations that cannot be hit by the same event. A flat and the cellar of the same building do not qualify.
- No location where strangers work regularly, so neither the office nor a holiday home.
- A safe deposit box suits the second copy, not the only one. Access is tied to opening hours, and in the event of inheritance the release takes time.
- One location should be reachable without travelling, otherwise the annual test never happens.
- The passphrase and the words never belong in the same place.
- Record in writing where the copies are, and leave that description with a person you trust or in your will, without naming the words themselves.
The recovery test for your hardware wallet
A backup that has never been checked is an assumption. The test takes little effort and should be carried out once a year, ideally on a fixed date.
Reset a second, inexpensive device or a wallet application on a clean computer, and restore exclusively from the backup, never from memory. Then compare the first receiving address with the one from your production wallet. If the two match, the backup is complete, passphrase included. Afterwards you wipe the test device again.
Anyone working with a passphrase checks the exact spelling in the same pass. An extra space or a capital first letter leads to a different wallet, and deviations of that kind otherwise surface only when it counts.
Common mistakes in storing a seed phrase
The following list comes from reader correspondence and forum cases of recent months. It is not representative, though the patterns repeat strikingly often.
- The photo of the words on a smartphone that syncs automatically to the cloud. This is by far the most common mistake.
- Entering the phrase on a website that offers to check whether it is valid. Such forms are a known attack pattern.
- The printout from the office printer, which keeps the file in the device memory.
- Splitting the phrase into two halves in two places.
- A home-made encryption, such as shifting every word by three positions. After years, nobody recalls the rule.
- The backup that a partner holds but cannot operate.
Point four deserves a note, because it resembles a Shamir split without being one. Halving twelve words substantially lowers the effort for an attacker who finds one half. At the same time the risk of loss rises, because two locations now have to work where one did before.
What you should take away from this
- Check today what your words are written on. If the phrase sits on the cardboard card from the packaging, plan the move to a metal backup in which the characters sit inside the material. Which devices suit that and what they cost is in the hardware wallet comparison.
- Fix a second location and put the test date in your calendar. Two copies in places independent of each other, plus one recovery on a test device each year. If you want to move to multisig or SLIP-0039 in the process, the software wallet overview helps with picking the right application.
- Document your holdings separately from the words. Record which wallets exist and where the backups are kept, without noting the phrase itself. For a running overview and the tax export, the tools from our comparison of portfolio trackers and tax software are the ones to use.
Transparency: the linked comparison pages contain partner links. If you sign up through such a link, we may receive a commission. This has no influence on our assessment of the methods described here; the technical details come from the linked standards.
The technical parameters in this article come from the original specifications: BIP-39 and SLIP-0039.
(As of August 7, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
- D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
- Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
- Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 23, 2026 10:15 AM

Coldcard 5.6.1 Is Here: Why the Update Will Not Rescue Your Old Seed
Coinkite shipped Coldcard firmware 5.6.1 and 1.5.1Q on August 20, 2026. The update closes the gap for new seeds but does not repair a seed already affected.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
September 26, 2026 7:34 AM

Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 19, 2026 1:23 AM

Hardware wallet lost: how to rescue your coins and what the tax office accepts
Your hardware wallet is gone, your coins are still on the blockchain: all that matters is whether you still have your recovery phrase. What goes wrong during a restore, and why the tax office as a rule does not recognise permanently lost access as a loss under Section 23 of the Income Tax Act.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 25, 2026 7:11 AM

EU Supervisors Rate Quantum Risk as High: What to Check on Crypto Custody and Exchange Choice
EBA, EIOPA and ESMA name quantum computers explicitly as a threat to blockchain cryptography in their autumn risk picture of September 23. What the paper says, which migration deadlines run to 2030, and three things you can check about your custody.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
More from CryptoTicker


