Safe and secure storage of a wallet seed phrase should be a primary concern for anyone using a self-custody cryptocurrency wallet. A seed phrase—also called a recovery phrase, secret recovery phrase, or wallet backup—can be used to restore the private keys associated with the wallet. If another person obtains it, they may be able to access and transfer the cryptocurrency from the associated accounts without possessing the original device. For most conventional seed-based wallets, safeguards such as a local password, PIN, biometric lock, or multi-factor authentication will not prevent someone from restoring the wallet elsewhere with its seed phrase.
1. Avoid Storing Your Seed Phrase Online
As a general rule, do not email the seed phrase to yourself or store it in an ordinary Google Drive, Dropbox, Evernote, iCloud Photos, Google Photos, or similar cloud account. Online accounts and automatically synchronized files can be exposed through phishing, malware, reused passwords, or an account takeover. Some wallet providers offer their own encrypted cloud-backup features, so the appropriate approach can vary by wallet. If you use an official backup feature, review the provider’s documentation and understand which credentials or devices could be used to restore it. A homemade digital copy should not be assumed secure merely because the file is hidden or password-protected.
2. Avoid Recording It on Internet-Connected Devices
Do not take a photograph or screenshot of the seed phrase or store it in a document, note, or ordinary USB drive connected to a computer or phone. Ledger’s seed phrase security guidance warns that spyware and automatic cloud synchronization can expose seed phrases recorded on internet-connected devices. A seed phrase should only be entered when the wallet owner deliberately intends to restore the wallet through verified, official software or hardware. It should never be entered into an unexpected website, online form, or application claiming that the wallet must be verified, synchronized, or unlocked.
3. Consider Using a Hardware Wallet
A hardware wallet can help keep private keys isolated from internet-connected devices and may be appropriate when the value of the cryptocurrency justifies the additional cost and responsibility. However, a hardware wallet does not protect the funds if its recovery phrase is disclosed. The phrase remains the backup for the wallet and must be protected independently. Follow the manufacturer’s recovery instructions carefully; hardware-wallet providers generally instruct users to enter the phrase through the hardware device itself rather than into a computer, website, or unrelated application.
4. Keep a Legible Physical Backup in a Secure Location
Consider recording the seed phrase by hand on paper or using a purpose-built metal backup that may offer greater resistance to fire or water damage. Verify that every word is spelled correctly, recorded in the correct order, and remains legible. Whether to maintain a second physical copy is a matter of individual risk and redundancy. A second copy stored in a separate secure location may protect against fire, flooding, accidental disposal, or loss, but each additional copy also creates another location where the phrase could potentially be found. Our seed phrase storage guide discusses these tradeoffs in more detail.
5. Protect the Backup From Discovery and Accidental Loss
Store the seed phrase somewhere it is unlikely to be accidentally found, photographed, discarded, or forgotten. The appropriate location depends on the owner’s living arrangements, physical security, and need for future access. Users should also consider how an authorized family member or representative could access the wallet in the event of death or incapacity without unnecessarily exposing the phrase during the owner’s lifetime. Optional wallet passphrases may provide another layer of separation, but they also create an additional critical credential; losing the passphrase can make the corresponding wallet inaccessible.
What to Do if Your Seed Phrase Is Compromised
If a seed phrase may have been exposed, the affected wallet should no longer be relied upon for storing cryptocurrency. Wallet providers including MetaMask and Coinbase recommend creating a new wallet with a new recovery phrase and transferring any remaining assets to it. The new wallet should be created through a verified application or device that is not suspected of compromise. After the transfer, do not reuse the old seed phrase or any wallet accounts derived from it to receive or store additional assets.