Home › Knowledge Hub › Protecting your seed phrase
How to protect your seed phrase and private keys
A recovery phrase is not a password that protects your wallet. It is the wallet. Anyone holding those words can recreate every account derived from them, on any device, without your permission and without needing anything else from you. That single fact decides every other decision on this page.
Who this is for
You have written down a set of words during a wallet setup and you want to know where to keep them. Or you have a nagging feeling you stored them somewhere you should not have.
No technical background needed. Every term is explained where it first appears.
What a recovery phrase is
When you set up a self-custody wallet, it generates a sequence of words, usually 12 or 24, drawn from a standard list. This is called a recovery phrase, seed phrase, or mnemonic.
Those words are a human-readable encoding of a large random number. From that number, your wallet mathematically derives every private key it will ever use, across every account and often across multiple blockchains. The derivation is deterministic: the same phrase always produces the same keys, on any wallet software that follows the same standard.
Two consequences follow, and both matter.
Your funds are not in the wallet app or on the device. They exist on the blockchain. The phrase is what proves you may move them.
There is no issuer. No company holds a copy, no support team can reset it, and no authority can restore it. That is the design, not a gap in it. A system where someone could restore your access would be a system where someone could take it.
A phrase cannot be derived from an address
This is worth stating plainly, because it disarms one of the most common frauds aimed at people who have lost access.
Your public address is derived from your private key. The mathematics runs in one direction. Working backwards, from a public address to the private key or the phrase, is not feasible with any existing technology. It is the property the entire system depends on.
Any service claiming it can recover your wallet from your address alone is lying. Not mistaken. There is no version of that claim that is true, and it appears constantly in adverts aimed at people searching for help.
Our guide to spotting recovery scams covers the rest of that pattern.
Where a phrase must never go
Every item here has produced documented losses. The phrase is the wallet, so anywhere it exists, the wallet exists.
- A photograph. Phone galleries sync to cloud services by default. A photo taken as a temporary measure outlives the intention.
- Cloud storage. Google Drive, iCloud, Dropbox, OneDrive.
- Email, including an email to yourself.
- A notes app, including one described as secure.
- A password manager. Reasonable people disagree here. A password manager is a single point of failure protected by one password, and it syncs. If you use one for this, understand you have chosen convenience over separation.
- A text message or chat, to anyone, including yourself.
- A spreadsheet or document, local or otherwise.
- Any website, extension, support chat, or verification tool. There is no legitimate reason for any of these to ask, in any circumstance.
Never type it into a computer at all, other than during a deliberate wallet restoration you initiated on a device you trust.
Backing it up without creating a new risk
Backup has two failure modes that pull against each other. Too few copies and you lose access to a fire, a flood or a misplacement. Too many, or badly placed, and someone finds one.
Write it by hand. Paper is fine to start. Check it twice against the device before funding the wallet, because a transcription error found now costs minutes and found later costs everything.
Move to metal for anything you intend to keep. Steel backup plates survive fire and water in ways paper does not. They cost considerably less than most people's holdings.
Make two copies, in separate places. Two copies in one drawer is one copy. Separate buildings if you can.
Think about who else can reach each location. A home safe stops a burglar and not a household member or a contractor. A bank deposit box stops both and introduces a third party. Neither is wrong; choose deliberately.
Record which wallet each backup belongs to, without recording anything that helps an attacker. A label saying "hardware wallet, set up March 2026" is useful to you and useless to a stranger.
Passphrases
Many wallets support an optional extra word, sometimes called a 25th word, a passphrase, or a hidden wallet. Combined with the recovery phrase, it produces a different wallet entirely.
What it gives you. Someone who finds your written backup gets an empty or decoy wallet rather than your funds. That is a meaningful improvement against the most common physical risk.
What it costs you. Forgetting it loses those funds permanently. There is no recovery path, no hint system, and no support to appeal to. It is not a password you can reset.
Use one if you have a dependable way to remember it and a separate, safe way to back it up. Skip it if you are uncertain, because the failure mode is total.
Splitting a phrase
People sometimes divide a phrase into parts stored separately. Done naively this is worse than not splitting at all.
Splitting 24 words into two sets of 12 does not halve the difficulty for an attacker. It reduces the remaining search space enormously. Meanwhile it doubles the number of things that must survive for you to recover.
Shamir Secret Sharing is the properly designed version, supported by some hardware wallets. It splits a secret into shares where a defined number are needed to reconstruct it, and fewer than that reveal nothing. Use the implementation your device provides rather than inventing a scheme.
Inheritance and emergency access
If something happens to you, your funds are unreachable unless someone can find and use the backup. Most people never address this, and the outcome is permanent.
Approaches that work without writing the phrase anywhere new: a sealed letter with a solicitor describing the location rather than the contents; a trusted person who knows a safe exists and how to access it, without holding the phrase; formal inheritance arrangements through a professional.
What does not work: telling nobody, or leaving instructions that themselves contain the phrase.
This is a good use of an hour with someone qualified where you live. It is also, unavoidably, legal and financial territory rather than security territory.
How phrases get exposed
Not usually through dramatic attacks. The common paths:
- Typed into a fake wallet interface during what looked like a restoration or verification
- Photographed and synced to a cloud service
- Given to fake support during a moment of panic about a real problem
- Supplied with a tampered hardware wallet that generated it before you opened the box
- Found in a shared home by someone who was not looking for it
- Entered into a "wallet checker" or "revocation tool" reached through an advertisement
- Read aloud near a device with a voice assistant
- Stored in a password manager that was later compromised
Notice how few of these involve technical skill on the attacker's part. Most involve a person being persuaded, or being ordinarily careless in a way that had no consequences until it did.
If your phrase may be exposed
Our step-by-step guide to an exposed seed phrase covers the order to act in.
Act on suspicion. Certainty arrives too late to be useful.
1. Create a new wallet. A fresh one, on a device you trust, with a phrase that has never existed anywhere else.
2. Move everything to it, now. Attackers frequently monitor a compromised address and sweep anything that arrives. This includes funds you send back to the old address by habit.
3. Treat the old phrase as burned. Do not reuse it, do not keep the wallet "just in case", and do not fund it again.
4. Check every account derived from it. One phrase can generate accounts across several blockchains. Check each one you have used.
5. Do not pay anyone to help. There is nothing a third party can do here that you cannot do faster yourself, and this is the exact moment recovery scammers look for.
If funds have already gone, our evidence checklist covers what to preserve and the country guides cover where to report it.
Red flags
- Any request for your recovery phrase, from anyone, for any reason
- A "verification", "migration", "synchronisation" or "validation" process asking you to enter it
- Support contacting you first about a wallet problem
- A service claiming it can recover a wallet from the address alone
- A hardware wallet arriving with a phrase already supplied
- A prompt to enter the phrase after an urgent security notice
- Anyone offering to hold or store the phrase for you
What not to do
- Do not store it in any digital form
- Do not photograph it, even temporarily
- Do not type it into any website, extension or chat
- Do not split it naively across locations
- Do not use a passphrase you might forget
- Do not keep only one backup
- Do not fund a wallet whose phrase you have not verified
Checklist
When you first write it down
- [ ] Written by hand from the device screen
- [ ] Verified against the device when prompted
- [ ] Nothing typed, photographed or spoken aloud
- [ ] Small test transaction sent and received before funding properly
Backup
- [ ] At least two copies
- [ ] Separate physical locations
- [ ] At least one on a durable medium
- [ ] Nothing digital anywhere
- [ ] Passphrase decision made deliberately and backed up separately
- [ ] Someone can find it if you cannot
Ongoing
- [ ] No copy has been created since, including temporary ones
- [ ] Locations still accessible and still private
- [ ] Nobody has asked you for it and received an answer
What this guide cannot do
Good storage reduces risk. It does not eliminate it, and nothing here guarantees that funds cannot be lost or stolen. Fires happen, people forget, and someone under enough pressure will do what they are told.
This is general information, not legal, tax or financial advice. Inheritance arrangements in particular need someone qualified where you live.
If you have been targeted
Anyone who has lost access to a wallet becomes a target for services claiming they can restore it. Read how to spot a crypto recovery scam first.
Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.
Sources
FBI, Cryptocurrency and AI Scams Bilk Americans of Billions, April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
FBI Internet Crime Complaint Center, 2025 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
Frequently asked questions
Can anyone recover my wallet if I lose my recovery phrase?
No, if you hold no other valid recovery method such as a private key, keystore file or hardware backup. There is no issuer, no reset, and no authority that can restore access. Services claiming otherwise are fraudulent.
Is it safe to store my recovery phrase in a password manager?
It concentrates your most valuable secret behind a single password, in software that syncs. Some experienced users accept that trade. If you do, understand you have chosen convenience over separation, and that a compromise of the manager is a compromise of the wallet.
What is the difference between a private key and a recovery phrase?
A private key controls one account. A recovery phrase is the seed from which many private keys are derived, across accounts and often across blockchains. Losing one key loses one account. Losing the phrase loses all of them.
Can someone steal my crypto with just my public address?
No. A public address is meant to be shared; it is how people send you funds. Deriving a private key from it is not feasible. Anyone claiming to recover a wallet from an address alone is running a scam.
Should I use a passphrase in addition to my recovery phrase?
It improves resistance to someone finding your written backup, which is the most common physical risk. It also means forgetting it loses those funds permanently, with no recovery path. Use one only with a dependable way to remember and back it up separately.
Is it safe to split my phrase in half and store the parts separately?
Naive splitting is worse than not splitting. It reduces an attacker's search space enormously while doubling what must survive for you to recover. Use Shamir Secret Sharing through your device if you want this property.
I typed my phrase into a website. What should I do?
Assume the wallet is compromised permanently. Create a new wallet and move everything to it immediately, before anything else. Attackers commonly automate sweeping a known-compromised address. Changing a password does not help, because the phrase is the wallet.
What happens to my crypto if I die?
It becomes unreachable unless someone can find and use your backup. Address this deliberately: a sealed letter with a solicitor describing the location rather than the contents, or a formal inheritance arrangement. Never leave instructions that themselves contain the phrase.
If your phrase may already be exposed
Ten questions showing what can realistically be done in your case.
Recovery pathway assessment