Temple of FortuneDE
Menu

Security

Securing your seed phrase: the one step almost everyone puts off

Twelve or 24 words decide who controls your entire crypto holdings. How to store them without losing them — and without ever handing them to someone else.

By Petra Stahl · Temple of Fortune · Updated:

Quick answer

Your seed phrase belongs offline and physically backed up: handwritten on paper to start, stamped on metal for meaningful amounts, in at least two separate secure locations. Never as a photo, in the cloud, in a password manager or in a chat — and no one, no "support" included, ever has a legitimate reason to ask for it.

Why these twelve or 24 words are everything

When you set up your own wallet, it generates a seed phrase — usually twelve or 24 random words. Every private key in your wallet is derived mathematically from that sequence. That is convenient: lose your device, type the words into a new one, and the wallet is back. It is also the most dangerous property it has. Because the same sequence that lets you recover also lets anyone who reads it recover.

One sentence captures the whole thing: whoever holds the seed phrase holds the funds. An attacker needs neither your device nor your password nor physical access to your hardware wallet — the words are enough, from anywhere on earth. Germany’s Federal Office for Information Security (BSI) states the underlying principle plainly: wallet access credentials must be protected, and larger holdings do not belong unsecured on a PC or smartphone but should be treated like cash.

This article is deliberately not a product recommendation. It is about the method — and the method is the same across every reputable wallet.

The one non-negotiable rule: offline

The most important decision is made before you write down the first word: the seed phrase must never exist in digital form. No screenshot, no photo, no notes app, no cloud storage, no email to yourself, no password manager.

The reason is simple: anything digital is potentially connected to the internet — and anything connected is attackable. Manufacturers are unusually blunt here. Ledger explicitly says to never photograph your recovery phrase and never store it on a computer or phone. Trezor states it as a fixed rule: keep the words offline, make no digital copy — no screenshot, no photo, no email, no cloud.

The flip side of the “I’ll just save it in my password manager” convenience: a single successful breach — of your account, your device or the provider — then exposes your entire crypto holdings. A handwritten note in a safe does not carry that attack surface.

Step by step: how to back it up properly

1. On setup: transcribe by hand, do not type. Write the words down by hand while the wallet displays them. Check order and spelling — every word counts, and many come from a fixed list of similar-sounding terms.

2. The start: paper, but done right. For the beginning and for small amounts, clean paper is acceptable — in a place only you know, shielded from prying eyes. Treat the note like cash of that value.

3. For meaningful amounts: metal. Paper loses against fire, water and time. A metal backup (a stamped or engraved steel plate) survives these. Ledger and others sell such products, but the principle works regardless of brand. Key point: this is protection from destruction, not from theft.

4. Redundancy: at least two locations. A single copy is a total-loss risk. Keep at least two complete backups in separate, secure locations — for example a home safe and a bank deposit box. Separate means: a fire, a burglary or a flood must not be able to hit both at once.

5. The rehearsal: recover once. This is almost always skipped — and it is the most common silent failure. A backup whose recovery you have never tested is a hope, not a backup. Set up the wallet with a small test amount, wipe it from the device, and restore it from your backup. Only when that works do you know your words are correct and complete.

The advanced tier: passphrase and multisig

If you want more than the standard setup, two proven tools exist:

The passphrase (often called the “25th word” or “hidden wallet”) is a self-chosen extra word. Combined with your 24 words, it generates a separate wallet. The effect: even someone who finds your seed phrase sees only an empty or harmless wallet without the passphrase. The price is added complexity — forget the passphrase and the funds are gone. It is a strong tool for advanced users, not a requirement for starting out.

Multisig (multi-signature) splits control across several keys: a transaction then needs, say, two of three signatures. If an attacker compromises one key, that is not enough. It is the standard for large holdings and shared funds — but with noticeable overhead in setup and management.

The attack that needs no technology: “give me your words”

The costliest losses often come not from hacking but from social engineering. A supposed support agent reaches out, a “wallet check” demands your words, a convincingly fake website asks you to enter your seed phrase “to sync”.

Here one rule holds without exception: no reputable manufacturer, no genuine support agent, no legitimate app ever asks for your seed phrase. Trezor states plainly that its own support never asks for it — not even during a conversation. You enter your words only into your own device, never on a website and never in a message.

CISA (the US cybersecurity agency) describes the general warning signs of phishing: slightly altered sender addresses, time pressure, unexpected links, requests for unusual actions. Translated to crypto: any unsolicited message pushing you to enter your seed phrase is the attack — no matter how professional it looks.

What gets forgotten: inheritance

Self-custody has an uncomfortable consequence: if no one knows about your backups, the funds are lost after your death. A well-thought-out setup therefore includes a plan for how trusted people gain access in an emergency — without those people having access in everyday life. Multisig or a securely stored set of instructions are common routes here. This is not a morbid detail but part of a complete backup.

The short checklist

  • Seed phrase offline only — never photo, cloud, chat, password manager
  • Start on paper, move to metal for serious amounts
  • Two separate secure locations, no shared risk of loss
  • Recovery rehearsed once before you rely on it
  • Give the words to no one — no support asks for them
  • Inheritance considered — access arranged for the worst case

None of this promises returns or protects against market swings. It only protects against the one mistake that is final: losing access to your own funds. And that protection costs no money — only an hour of care.

FAQ

Is a photo of my seed phrase in encrypted cloud storage enough?
No. The moment the words exist digitally, a single successful breach of your account, device or provider exposes them. Manufacturers like Ledger and Trezor explicitly warn against photographing the words or storing them on a connected device. Offline backups are the standard.
Paper or metal — do I really need a steel plate?
Paper is a fine start and acceptable for small amounts. For sums whose loss would hurt, a metal backup makes sense: it survives fire, water and time, which paper does not. This is about protection from destruction, not from theft.
What is a passphrase (25th word) and do I need one?
A passphrase is a self-chosen extra word that, combined with your seed phrase, creates a separate "hidden" wallet. It protects you even if someone finds your 24 words — but it adds complexity and the risk of locking yourself out. Optional for beginners, a strong tool for advanced users.
What happens if I lose one location holding a backup?
That is exactly why the second backup sits in a separate place. As long as one complete copy survives, you restore the wallet on a new device. After a loss, move the funds promptly to a new wallet with a fresh seed phrase.

Sources

This article is for general information only.

Comments

Argue hard on substance, fair in tone. No financial "tips" with profit promises, no ads, no links to scams — that gets removed, and repeat offenders lose their account. Otherwise: welcome to the temple.