Skip to content
MyCryptoStart

Wallets & security

What Is a Seed Phrase and How Do You Store It Safely?

Short answer

A seed phrase (recovery phrase) is a list of 12–24 ordinary words generated when you create a self-custody wallet. It is the master key to every account in that wallet: anyone who reads it can spend your crypto from anywhere, and no password reset exists. Store it offline, on paper or metal, never as a photo, file, or cloud note — and never share it with anyone, ever.

Key takeaways

  • 12–24 words from a fixed list (BIP-39) that mathematically generate all your wallet's private keys.
  • Whoever has the words has the money — possession is ownership, and there is no reset.
  • Restore the phrase into any compatible wallet to recover every account, even on a new device.
  • Never store it digitally: no photos, no password managers' notes, no cloud backup, no email.
  • No legitimate service, support agent, or app will ever ask for it. Any request is a scam.

What does a seed phrase actually do?

When your wallet generates the phrase, it’s creating a random number so large that guessing it is beyond any realistic attack, then encoding that number in a fixed list of 2,048 easy-to-type words — the BIP-39 standard almost every wallet shares. Twelve words encode a 128-bit number: 2 to the power of 128, roughly 340 undecillion possibilities. There is no path to guessing one; every real-world loss starts with the phrase being seen.

Every private key your wallet uses is derived from it deterministically — restore the same 12 words into any compatible wallet and every account reappears in order. That’s why it’s called the master key: lose your phone, throw away your laptop, the phrase alone rebuilds everything. It’s also why the key hierarchy matters: the addresses you share are derived from private keys, which are derived from the phrase. One secret at the top, everything else flows from it.

How should you store it?

Offline and duplicated. Write it on paper — or better, stamp it into metal, which survives fire and water — and keep copies in two separate physical locations, the same way important documents are protected. Digitally is where phrases die: photos sync to cloud accounts that get breached, files get indexed by malware, and “helpful” password-manager notes leak. The 2020s are littered with seven-figure losses from a single screenshot.

Two refinements worth adopting as balances grow. Check yourself: a backup that can’t be read back correctly is worth nothing — verify you can restore the phrase into a wallet before you trust it with real money. Split wisely: some people split the phrase across two locations (words 1–7 and 8–12), which protects against a single location being found — but introduces the new risk of losing one half forever. A simple two-location copy of the whole phrase is the right trade-off for almost everyone.

Custodial or self-custody — where does the phrase even apply?

If you keep crypto on a regulated exchange, you don’t manage a seed phrase at all — the exchange does, and you carry account risk (password, 2FA, the company’s solvency) rather than custody risk. Both models are legitimate for beginners; mixing them badly — custody amounts you can’t afford to lose with sloppy phrase hygiene — is the actual mistake. The honest comparison: exchanges get hacked and freeze, self-custody gets lost and phished, and the right choice is whichever risk you’re better equipped to manage at your current size.

What are the classic seed-phrase traps?

All of them arrive as sentences. “Your wallet was compromised, enter your phrase to fix it.” “Verify ownership by importing your phrase into this new app.” “Support needs it to complete your withdrawal.” “Scan this QR code to sync your wallet” — where the QR is the phrase pre-loaded into the scammer’s wallet. Every one is theft; real support never needs your phrase, and no real problem is solved by revealing it. The words are the money — treat them like unsigned checks made out to whoever holds them, and read our phishing field guide for the full pattern library.

Paper, metal, or something better? Storage options compared

OptionSurvivesFails atVerdict
Paper (2 copies, 2 locations)Time, no power neededFire, water, fading inkThe baseline everyone should clear
Stamped metal platesFire, flood, decadesNobody finding itThe standard upgrade for serious amounts
Password manager noteConvenient, encryptedA breached vault exposes the crown jewelsAcceptable to some experts; we say no
Photo / cloud noteNothingEverything — sync, breach, malwareNever
Bank safe deposit boxFire, theftAccess hours, bank failure, privacyFine as a second location

Two placements to avoid that don’t appear on any official list: anything obvious to a burglar (the safe in the master bedroom) and anything trust-dependent (a copy left with someone who doesn’t understand what it is). A seed phrase is a bearer instrument — whoever can read it, owns you — so the storage location needs to be secret, disaster-proof, and recoverable-by-you, in that order of difficulty.

Frequently asked questions

Can I change my seed phrase?
Not the phrase itself — it mathematically generates your keys, so 'changing' it means creating a brand-new wallet with a new phrase and moving all funds to the new addresses. People do this after suspected exposure, and it's the correct move: if the words may have been seen, treat them as burned and migrate, because there is no way to make leaked words secret again.
Is a 12-word phrase less safe than 24 words?
For practical purposes, no. Both are drawn from the same 2,048-word list; 12 words encode 128 bits of entropy and 24 encode 256 bits — and brute-forcing even 128 bits is beyond any realistic attacker. The documented seed-phrase thefts all happened through phishing, malware, screenshots, and sloppy storage, never through anyone guessing words. Storage discipline matters infinitely more than word count.
What should I do if my seed phrase is exposed?
Move immediately: create a fresh wallet, generate its new phrase offline, transfer every asset to the new addresses, and only then consider the old wallet empty. Also revoke token approvals from the old wallet where possible, because approvals can persist even after funds move. Speed matters — automated bots sweep publicly exposed phrases within minutes.
Can my exchange account be recovered from a seed phrase?
No — exchange accounts don't have seed phrases; they have logins, passwords, and 2FA, all recoverable through the exchange's support process. A seed phrase only exists for self-custody wallets. Confusing the two is a common scam vector: fraudsters ask exchange customers for a 'recovery phrase' the account doesn't even have.

Editor-in-Chief & Lead Researcher

Lucas Almeida

Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.

View author page →

Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.

Learn more about seed phrase

Our full guides that cover this term in depth.