What is a seed phrase used for?
Our guide to how a crypto wallet works already distinguishes the wallet from the blockchain. Funds are not stored on a phone or hardware device: the wallet stores or derives the keys that authorize transactions. The recovery phrase is used to reconstruct that set of keys.
Most wallets use a standardized list of 12 or 24 words. The BIP-39 standard describes how entropy is converted into words and then into a cryptographic seed. However, not all wallets use exactly the same method, and a phrase that is valid in one application may require the correct derivation path or network to recover the expected accounts.
A seed phrase is neither a login password nor a support code. It should never be entered on a website received by message, sent by email or shared with someone claiming to verify the wallet.
Create an offline backup
The simplest backup method is to write the words down in the exact order on a medium kept offline. A photo, screenshot, cloud note or email draft could be copied by malware or synchronized to a compromised account.
Each word should be checked when the backup is created. Some wallets offer a confirmation test; it should be completed before depositing a significant amount. An apparent typo may be a word that is absent from the BIP-39 list or a different but valid word, which would lead to another wallet.
Paper is suitable to start with, but it is vulnerable to water, fire and deterioration. A metal plate offers greater resistance to physical disasters. The storage medium should match the actual risk: a shared home, frequent moves, humidity, fire or access by relatives.
One copy or several?
A single copy creates a single point of failure. Two copies kept in the same place do not protect against fire or theft. Separating them reduces that risk, but increases the number of locations that must be monitored.
A phrase should not be split randomly into two halves. Each half becomes unusable on its own, and losing one destroys the backup. For a multi-fragment setup, it is better to use a designed and documented scheme with a recovery threshold than a personal method that cannot be passed on.
Bitcoin.org’s page on wallet security highlights the importance of backups and encryption. These recommendations should be adapted to the amount involved, the user’s skills and the risk of coercion.
Test recovery without exposing the funds
An untested backup remains an assumption. The test should be prepared in a way that avoids exposing the seed to a connected device or unverified application. Some hardware wallets offer a recovery check directly on the device, without transmitting the words to a computer.
Another method is to run a test before using the wallet permanently: create the phrase, receive a small amount, reset the device according to the official procedure, restore it and then verify the address. This should only be done when the user understands every step and still has a second legible copy.
After restoration, several accounts and networks should be checked. Seeing a zero balance does not necessarily mean the phrase is wrong: the wallet may be using a different derivation path, another address type or an additional passphrase.
Seed phrase and additional passphrase
Some wallets allow users to add a passphrase, sometimes called a “25th word.” Every different passphrase produces a different set of accounts. A typo can therefore open a valid but empty wallet without generating an error message.
This feature improves access separation, but creates a second secret that must be backed up. If the seed is preserved without the passphrase and the latter is forgotten, the funds cannot be recovered. The setup should be documented without storing all the elements in the same place.
Hardware wallets reduce the exposure of keys to connected devices, but they do not fix poor backup practices. The device can be replaced; the seed and, where applicable, the passphrase remain at the heart of recovery.
What to do if the phrase has been exposed
A seed displayed on a fake website, photographed by an unauthorized person or stored on a compromised device should be considered lost from a security standpoint. Changing the wallet password does not revoke the keys derived from that phrase.
The response is to create a new wallet with a new seed in a secure environment, verify the address and then transfer the assets. The phrase should not be shared with a purported recovery service. DeFi permissions and tokens held on multiple networks must also be inventoried.
Our guide to securing cryptocurrency expands on this procedure with authentication, device security and address verification.
Plan for succession
A backup should be retrievable by the right person without becoming accessible to everyone. A separate inventory can indicate that the wallet exists, identify the devices used and provide general instructions without directly containing the seed.
For significant assets, the solution must account for inheritance law, physical access and the heirs’ technical ability. An overly complex arrangement can be more dangerous than a simple, tested setup.
Key takeaways
- Never digitize or share a seed phrase.
- Keep durable copies in separate, documented locations.
- Test recovery before depositing significant value.
A good backup is not merely secret. It is legible, complete, tested, resistant to disasters and transferable under a plan established in advance.