103 · Private key creation · lesson 2 of 4
Backing up a seed phrase — so a fire, a flood, or a bad day can't erase your Bitcoin
Your seed phrase is the master key to your Bitcoin. If the only copy lives on one device, or on a scrap of paper in a drawer, you are one accident away from losing everything. Here is how to back it up so it survives.
When you set up a self-custody wallet, it shows you a list of 12 or 24 words. That list is your seed phrase — the one thing that can rebuild your wallet if your device is lost, stolen, or destroyed. Anyone who has those words can take your Bitcoin; anyone who loses them loses the coins for good. So the goal of a backup is simple: keep those words safe from fire, water, and time, keep them away from prying eyes, and make sure you (or your heirs) can still find and read them years from now. This page walks you through it, step by step.
Never keep it digital
The fastest way to lose your Bitcoin is to put your seed phrase into anything with a screen or a battery. A photo, a note in your phone, a password manager, a text file, an email to yourself — all of it eventually reaches the internet, and once it does, the words are exposed forever.
- No photos. A quick picture of the words silently syncs to iCloud or Google Photos, and now your seed lives on a server you don't control.
- No typing it in. Not into a computer, a phone, a cloud drive, or a password app — not even "just for a minute" while you find your metal backup. That minute is the exposure.
- No cloud, ever. Treat any digital copy as if the coins are already gone.
Your seed phrase should only ever exist in two places: written by hand on a physical object, and — for a moment during setup — on your hardware wallet's own screen.
Start on paper, then move to metal
The trusted pattern is paper first, then metal. Paper is for the moment of setup. Metal is for the long haul.
- Write it by hand on paper. As your wallet displays the words, copy them down with a pen or pencil. Then check your copy against the device to catch any spelling slips.
- Transfer the words to metal. Metal survives fire, flood, and decades of time; paper does not. Paper burns, soaks, fades, and gets thrown out in a cleanup. It is fine for a tiny pocket wallet, but for any real holding, metal is the standard.
- Check the metal against your paper, letter for letter.
- Destroy the paper once the metal is verified. It is both fragile and an extra copy someone could stumble on.
A note that saves you time: BIP-39 seed words are each identified by their first four letters, so many metal products only ask you to record those four letters. That is enough to recover the full word, with less chance of error.
Not all "indestructible" metal actually survives
Metal backups are the standard — but the label on the box is not a guarantee. Jameson Lopp, a well-known self-custody expert, has run several rounds of stress tests on these products, burning them, soaking them in acid, and crushing them. The finding is more reassuring than you might expect: most of them are fine. Of the 75 products he has tested, 45 came through everything with nothing lost and another 11 were marked down in one test only. Just 10 did badly — and those failures cluster in a few specific designs rather than being scattered at random, which means you can avoid them by knowing what to look for.
- Heat. A house fire can hold well over 1,000°F for hours. Good stamped stainless steel comes through readable; some cheaper plates warp or become illegible.
- Corrosion. Stainless steel shrugs off water and acid; weaker products don't.
- Deformation. Drops and crushing can knock loose the letter tiles that some designs rely on.
What actually holds up: high-quality stamped stainless steel plates (and titanium, which survives everything but costs several times more for little real-world gain). Marketing words are not a guide — pick a specific product that has been independently stress-tested and passed. We name five, with the criteria behind them, and the ones to avoid, on the metal-backups page. And do a practice run with a throwaway seed first: stamp a dummy set of words, see how the product behaves, then commit your real seed. One more trap to avoid: products that etch the words and fill them with ink can go blank in a fire when the ink burns away, so make sure the engraving is deep enough to read on its own.
Spread your backups across separate locations
One backup is one accident away from being gone. Two backups in the same house are really just one backup — the same fire or flood takes both. So the rule is at least two copies, each in a genuinely separate place.
- Home safe — fire-resistant and bolted down, as your primary copy. A safe you can carry is a safe a burglar can carry.
- A second, distant location — a bank safe deposit box, or a trusted family member in another city.
- For larger holdings, spread across three or more places, even different regions, so no single disaster reaches all of them.
The guiding idea: your backup should survive a catastrophe at any one location. And write down, in your estate documents, where each copy lives — "I put it somewhere safe" that you can't recall years later is a real and common way people lose coins.
The clever schemes people invent — and why we don’t
Backing up a seed looks like a puzzle, so almost everyone arrives with an idea for solving it more cleverly. They are worth naming, because the good ones and the bad ones look alike from the outside:
- Splitting the words across two places, so neither is enough. It sounds like it halves your risk and it does the opposite: now both halves have to survive, so you have doubled the ways to lose everything — and a finder holding half a phrase has a very large head start rather than nothing. There is a properly engineered version of this idea, and it is not this — it is Shamir backup, covered back in Beyond the ladder.
- Encrypting the words and keeping the file in the cloud. You have swapped a secret you must protect for a password you must never forget, never leak, and never lose — and the encrypted file is now permanently in somebody else's backup history, where it will sit patiently for as long as it takes. It is the digital rule with one extra step in front of it.
- Hiding the real words among decoys, or inside a book. Any scheme you have to remember is a scheme your family has to be told, and the day it matters most is the day you are not there to explain it. It reliably makes the backup harder for you under stress, and barely harder for someone who is already holding it.
- A photo, but only on a phone with no internet. Phones get backed up, updated, handed in for repair, upgraded and sold. The photo outlives the intention every time.
- Memorising the words and writing nothing down. This is the single most thoroughly documented way Bitcoin is lost for good, and it fails in the one direction you cannot correct later.
- Leaving a sealed copy with a lawyer or a relative. This one is genuinely reasonable, and plenty of careful people do it — just be clear about what the seal is. It is a social control, not a cryptographic one, and it turns your backup into part of your inheritance plan, which the course comes back to later.
The reason the boring answer keeps winning is that a backup has to work decades from now, for a tired version of you or for somebody who has never heard of any of this. Complexity you added on purpose is still complexity.
If you use a passphrase, back it up too
Some wallets let you add a second secret of your own on top of the seed, often called a passphrase or "25th word" — though it is not a word, and it is rolled rather than invented. It is powerful protection, but it comes with its own rule: the passphrase is a separate secret, and it needs its own backup. Your seed words alone will not open the wallet without it.
- Back up the passphrase on its own, and keep it in a different location from the seed — so someone who finds one still can't reach your coins.
- Include it in your inheritance notes (for example, "in the sealed envelope at the attorney's office"). "I'll just remember it" is the single most common way passphrase-protected coins are lost forever.
Then prove it works — before you fund it
Everything above is preparation. None of it is worth anything until you have watched your words rebuild the wallet, and that is the step people skip.
The short reason: a backup fails silently. The metal in your safe looks exactly as reassuring whether it is correct or not, and the day you find out is the one day you have no second option.
So: put a trivial amount in, erase the device back to factory settings, and rebuild the wallet from your written words alone.
The next lesson walks it step by step — why the test proves what it proves, what to do when it fails, and the lighter check worth repeating each year. Don't move anything meaningful into this wallet until you have done it.
Never let your seed phrase touch anything digital — no photo, no cloud, no typing it into a phone or computer, not even for a second. And never trust a backup you haven't tested. Before you put real money in, erase your device and rebuild your wallet from your backup. If it comes back with your funds, your backup is real. If you skip this step, you won't find out it failed until the day you need it — and by then it's too late.
- Write the seed by hand and double-check every word against your device — never photograph it, type it, or store it in the cloud.
- Transfer the words to a stamped stainless steel backup that stress tests show actually survives fire, water, and crushing.
- Practice on a throwaway seed first, then destroy the paper once the metal copy is verified.
- Keep at least two copies, each in a genuinely separate location, so no single fire, flood, or theft reaches both.
- If you use a passphrase, back it up separately, in a different place from the seed.
- Do a wipe-and-restore test before funding the wallet — prove you can rebuild it from the backup alone.
- Write down where each backup lives for your heirs, and re-check everything about once a year.
Check yourself
2 questions on what this lesson just covered. Nothing is scored, recorded or saved — it isn’t sent anywhere and it’s gone when you close the tab.
1Which of these counts as keeping your seed phrase off anything digital?
Your seed should only ever exist in two places: written by hand on a physical object, and — for a moment during setup — on the wallet’s own screen. A password manager swaps a secret you must protect for a password you must never forget or leak, and leaves an encrypted copy sitting permanently in somebody else’s backup history. A phone with the internet switched off is still a phone: they get backed up, updated, handed in for repair, upgraded and sold, and the photo outlives the intention every time. Paper for the moment of setup, then metal for the long haul.
2You split your 24 words so that 12 live at home and 12 at your sister’s house — neither place holds the whole phrase. Is that a good backup?
It sounds like it halves your risk and it does the opposite: now both halves have to survive, so you have doubled the ways to lose the lot — and someone who finds one half holds a very large head start rather than nothing. There is a properly engineered version of this idea, Shamir backup, and a hand-split list is not it. The boring answer keeps winning because a backup has to work decades from now, for a tired version of you or for somebody who has never heard of any of this: at least two complete copies, each in a genuinely separate place.
That's the concept: why paper fails, what metal survives, and how to store copies so no single event takes them all. This is the course, and the course teaches — it doesn't set anything up for you. When you are ready to buy a plate, we name five that have been independently stress-tested, with the criteria behind the picks and the ones to avoid. It's in the Hardware & services menu, under Metal backups, whenever you want it.
✓ Last verified: August 4, 2026