Skip to content
MyCryptoStart
Security Explainer beginner

What Is a Seed Phrase? How to Protect It

A seed phrase is a 12–24 word master key that controls your wallet. Learn what it is, how to store it safely, and how to spot the scams that steal it.

Lucas Almeida 5 min read

Key takeaways

  • A seed phrase is a list of 12–24 ordinary words generated when you create a self-custody wallet; it is the master key to every account in that wallet.
  • The words are drawn from a fixed list of 2,048 (BIP-39) and encode a random number so large that guessing is effectively impossible — every real theft starts with the phrase being seen, not guessed.
  • Whoever has the words has the money: there is no password reset, no support agent, and no way to make a leaked phrase secret again.
  • Store it offline on paper or stamped metal, in two physical locations, and never as a photo, screenshot, cloud note, or password-manager entry.
  • No legitimate service, app, or support agent will ever ask for your seed phrase — any request, in any form, is a scam.

A seed phrase is a list of 12 to 24 ordinary words that acts as the master key to your entire crypto wallet. Anyone who reads those words can spend everything in the wallet from anywhere, and there is no password reset and no support team that can get it back.

Protect it the way you would protect unsigned checks made out to whoever holds them: offline, in two physical places, never as a photo or file — and never shared with anyone, for any reason.

What is a seed phrase?

A seed phrase (also called a recovery phrase or mnemonic) is a list of 12, 18, or 24 ordinary words your wallet shows you once, when you first create it. It is a backup in human-readable form: the same words typed into any compatible wallet rebuild every account that wallet ever had.

Here is the shape of the thing, in plain English:

  • It is the master key. Every private key in your wallet is generated from these words, so the phrase controls everything at once.
  • It is a backup, not a password. You do not type it in every day. You write it down once, keep it safe, and use it only if you lose your device or move wallets.
  • It is a bearer instrument. Whoever can read it owns the funds — the wallet does not care who holds the words, only that someone does.

The words are not random poetry. They come from a fixed list of 2,048 common English words defined by a standard called BIP-39, which almost every wallet (MetaMask, Ledger, Trezor, Trust Wallet, and most others) shares. Because the list is standardized, a phrase created in one wallet can be restored in a different, compatible wallet — that cross-compatibility is the entire point.

The golden rule: your phrase is your money in readable form. Treat it like physical cash with a higher value and no way to cancel it.

How does a seed phrase relate to private keys?

A seed phrase sits at the top of a chain: it generates your private keys, which generate your public keys, which generate your addresses. One secret at the top, everything else flows down from it.

Modern wallets do not generate random keys one at a time. They generate one master secret — your seed phrase — and then derive every private key from it in a deterministic, reproducible order. The hierarchy looks like this:

  1. Seed phrase — the 12–24 words you back up.
  2. Private keys — derived from the phrase; one (or more) per address.
  3. Public keys — derived from each private key.
  4. Addresses — derived from public keys; the strings you actually share to receive funds.

The practical consequence is why the phrase is called a master key: restore the same 12 words into any compatible wallet and every account reappears, in order, without you doing anything else. Lose your phone, throw away your laptop, buy a new device a decade later — the phrase alone rebuilds the whole wallet.

A useful comparison:

What it isControlsCan it be reset?
AddressThe string you share to receive fundsNothing (it’s public)—
Private keySecret code for one addressOne addressNo
Seed phraseThe master backup of the walletThe entire walletNo

If you want the deeper picture of how the private-key layer works, read our guide on what a private key is. The seed phrase is what you actually write down; the private keys are what it generates.

How does a seed phrase work?

When your wallet generates a phrase, it is creating a random number so large that guessing it is beyond any realistic attack, then encoding that number as easy-to-type words.

A 12-word phrase encodes a 128-bit random number; a 24-word phrase encodes 256 bits. The math is worth sitting with for a second: 128 bits means 2¹²⁸ possible values — a number with roughly 39 digits. There are about 2¹²⁸ possible 12-word phrases. Even a supercomputer trying trillions of combinations per second would need more time than the age of the universe to find a specific one.

The last word of the phrase is a checksum, derived from the others, which lets a wallet detect a typo when you enter the phrase — but that is a convenience, not a security feature. The security comes entirely from the size of the number.

Here is the crucial, counterintuitive part: your crypto is not secured by being hidden — it is secured by being unguessable. The blockchain does not hide your funds somewhere; it holds them behind a key so large no one can break it. That is why every real-world loss happens not when someone guesses a phrase, but when someone sees it.

What does a seed phrase look like?

A seed phrase is 12 to 24 words, all lowercase, separated by single spaces, drawn from that fixed 2,048-word list. Here is what one looks like in shape (this is a deliberately fake example — never use a phrase you have seen published anywhere):

abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about

The famous “all abandon” phrase above is a real, valid example phrase used in the BIP-39 documentation and countless tutorials. People have lost money by using it, because a phrase you see in an article, video, or image is already public — and anyone who knows the words can empty the wallet.

That example teaches two lessons at once:

  • The format is ordinary. There is nothing special-looking about a seed phrase, which is exactly why people do not take it seriously enough.
  • A published phrase is a burned phrase. Never use, fund, or copy a seed phrase you have ever seen displayed anywhere, including screenshots, forum posts, or this article.

Your real phrase should be generated fresh by your own wallet, shown to you alone, and written down by hand — never photographed, never pasted, never shared.

How is a seed phrase created?

A seed phrase is created by your wallet, offline, at the moment you set up a new self-custody wallet. The flow is the same across MetaMask, Ledger, Trezor, and Trust Wallet:

  1. You choose “create a new wallet.”
  2. The wallet generates the phrase on your device and shows it to you — usually one screen of 12 or 24 words.
  3. The wallet asks you to confirm it (often by tapping the words in order) to prove you wrote it down.
  4. You write it down physically and store it securely — before you deposit anything.

The ordering matters: write the phrase down and verify it before you fund the wallet. The most expensive mistake beginners make is sending money to a wallet whose phrase they never backed up, then losing access to the device and learning — too late — that the backup was the only copy that existed.

A real detail that trips people up: some wallets let you skip the confirmation step or click “I’ll do it later.” Do not. The confirmation is not a test of your memory; it is your chance to verify that the words you wrote down actually restore the wallet. If you cannot read your own handwriting back, the backup is worthless.

Seed phrase vs. password vs. private key

Beginners routinely confuse three things that do different jobs. Here is the clean separation:

Seed phraseWallet passwordPrivate key
What it is12–24 words, master backupA login PIN/password for the app/deviceSecret code for one address
What it controlsThe entire walletAccess to the app or deviceOne address
What happens if lostFunds become permanently inaccessibleUsually resettable via the phraseThat one address is lost
Who might ask for itNobody legitimate, everYou (to unlock the app)Nobody legitimate, ever

The relationship that surprises most people: your wallet password is not your backup. If you forget a password, you can usually reset it using your seed phrase. If you lose the seed phrase, the password is irrelevant — there is nothing to reset to. The phrase is the thing that matters; the password is just a convenience for a specific device.

How to store a seed phrase safely

Store your phrase offline, on paper or stamped metal, in two separate physical locations — and verify you can read it back before you trust it with real money.

The core principle is one line: keep it out of anything that connects to the internet. Digitally stored phrases die in predictable ways — a photo syncs to a cloud account that gets breached, a note file gets indexed by malware, an email draft sits in an account you reused a password on.

The baseline that everyone should clear:

  1. Write it on paper, by hand, in your own handwriting. Do not type it, do not photograph it.
  2. Make two copies, stored in two separate physical locations — the same way you protect other important documents.
  3. Verify the backup works. Restore the phrase into a wallet once, before funding, to confirm you copied the words correctly and in order.
  4. Never store it digitally. No photos, no screenshots, no cloud notes, no password-manager “secure notes,” no email, no text message.
  5. Keep it private. No sharing with family, friends, or anyone who asks — even (especially) if they claim to be “helping.”

As balances grow, upgrade from paper to stamped metal. Metal plates survive fire and flood, where paper does not. It is the standard step-up for anyone holding a meaningful amount, and it costs a fraction of what a single mistake could lose.

Storage options compared

OptionSurvivesFails atVerdict
Paper (2 copies, 2 locations)Time, no power neededFire, water, fading inkThe baseline everyone should clear
Stamped metal platesFire, flood, decadesSomeone finding itThe standard upgrade for serious amounts
Password-manager “secure note”Convenient, encryptedA breached vault exposes everythingSome experts accept it; we say no
Photo / screenshotNothingEverything — sync, breach, malwareNever
Cloud note / email draftNothingAccount breach, indexing, syncNever
Bank safe deposit boxFire, theftAccess hours, bank failure, privacyFine as a second location

Two placements to avoid that do not appear on any official list: anything obvious to a burglar (the safe in the master bedroom is the first place they look), and anything trust-dependent (a copy left with someone who does not understand what it is). A seed phrase is a bearer instrument — whoever can read it owns you — so the location needs to be secret, disaster-proof, and recoverable by you, in that order.

Common seed-phrase mistakes

Most losses are not sophisticated attacks; they are ordinary people making one of a handful of predictable errors.

  • Storing it digitally. Photos, cloud notes, and email drafts are the single most common way phrases get exposed.
  • Funding before backing up. Sending money to a wallet whose phrase was never written down, then losing the device.
  • Using a published phrase. The “all abandon” example and similar tutorial phrases are public and already drained.
  • Sharing it to “prove” something. No contest, airdrop, or “verification” ever requires your phrase; anyone asking is stealing.
  • Relying on one copy. A single paper copy in one place is one fire, one flood, or one lost box away from total loss.
  • Trusting an untested backup. A phrase with a single miswritten or reordered word will not restore — and you will not know until it is too late.

Notice the pattern: every item on the list is a behavior, not a technical weakness. The security of a seed phrase is almost entirely about how you store it, not what wallet you chose.

How do seed phrases get stolen?

Seed phrases get stolen through deception, not codebreaking: phishing, fake support, fake apps, and “helpful” strangers all aim to get you to reveal the words yourself.

The scale is documented. Blockchain analytics firm Chainalysis reported US$2.2 billion stolen in crypto hacks in 2024, with private-key compromise the single largest cause at 43.8% of that total. Security firm CertiK put phishing as the top attack vector that year, at roughly US$1.05 billion across nearly 300 incidents. In almost every case, the victim handed over a key or phrase by entering it somewhere they should not have.

The classic traps, all of which arrive as sentences:

  • “Your wallet was compromised — enter your phrase to fix it.” Real wallets have no such feature. This is theft.
  • “Verify ownership by importing your phrase into this new app.” The “new app” is the scammer’s wallet.
  • “Support needs your phrase to complete your withdrawal.” Support never needs it, because it cannot do anything useful with it.
  • “Scan this QR code to sync your wallet.” The QR code is your phrase, pre-loaded into the attacker’s wallet.
  • A direct message from a “MyCryptoStart admin” or “exchange support.” Legitimate services do not initiate contact to ask for your phrase.

For the full pattern library, read our phishing field guide. The short version: the words are the money, and no real problem is ever solved by revealing them.

What to do if your seed phrase is exposed

If you believe your phrase has been seen — in a photo, a message, a device that was lost, or anywhere — move your funds to a brand-new wallet immediately. Do not wait to see what happens.

Speed is the whole game, because automated bots sweep publicly exposed phrases within minutes. The steps:

  1. Create a fresh wallet on a clean, trusted device.
  2. Generate a new phrase and write it down offline, then verify it.
  3. Move every asset from the compromised wallet to the new addresses as fast as you can.
  4. Abandon the old wallet. Treat the old phrase as permanently burned and never use it again.
  5. Revoke token approvals from the old wallet where possible — approvals can persist even after the funds move.

There is no “undo,” no fraud department, and no way to make a leaked phrase secret again. A phrase that may have been seen should be treated as if it was seen — the cost of migrating is small compared to the cost of being wrong.

Custodial vs. self-custody: where does the phrase apply?

A seed phrase only exists for self-custody wallets. If you keep crypto on an exchange like Binance or OKX, the exchange holds the keys, and you carry account risk instead of custody risk.

The two models, clearly:

  • Custodial (exchange). You log in with an email, password, and 2FA. If you forget the password, the exchange’s support process resets it. The risk you carry is the platform’s security and solvency, not your own key management.
  • Self-custody (wallet). You hold the seed phrase, so you hold the funds directly. The risk you carry is your own storage discipline — lose the phrase and no one can help you.

Both are legitimate for beginners, and most people use both at different times: small trading amounts on an exchange for convenience, larger savings in self-custody. The actual mistake is not choosing one or the other — it is mixing them badly, by holding amounts you cannot afford to lose under sloppy phrase hygiene.

A common scam exploits the confusion between the two models: a fraudster asks an exchange customer for a “recovery phrase” that the account does not even have. If you only use exchanges, you have no seed phrase — anyone who tells you otherwise is lying. Learn how to set up an exchange account properly in our Binance registration guide.

The bottom line

A seed phrase is the master key to your wallet: 12–24 words that rebuild every account you own, and that anyone else can use to empty it. Store it offline, in two physical places, on paper or metal. Never photograph it, never type it into a website, and never share it — no legitimate person or service will ever ask.

If you are new to self-custody, the order of what to learn matters: understand what a private key is, then the most common crypto scams, and only then choose between hot and cold wallets. Getting the storage basics right before you put real money in is worth more than any trading tip you will ever read.

Don't have a Binance account yet?Sign up nowenter the referral codeBN2688

Frequently asked questions

Can someone guess my seed phrase?
No. A 12-word phrase encodes 128 bits of randomness and a 24-word phrase 256 bits, both drawn from a fixed 2,048-word list. Brute-forcing even 128 bits is beyond any realistic attacker. Every documented seed-phrase theft happened through phishing, malware, screenshots, or sloppy storage — never through anyone guessing the words.
Is a 12-word phrase less safe than 24 words?
For practical purposes, no. 12 words encode 128 bits of entropy and 24 encode 256 bits; both are effectively unguessable. Storage discipline matters infinitely more than word count, because real-world losses come from the phrase being exposed, not broken.
Can I change my seed phrase?
Not the phrase itself — it mathematically generates your keys. 'Changing' it means creating a brand-new wallet with a new phrase and moving all funds to the new addresses. If your phrase may have been exposed, this migration is the correct and only move.
What happens if I lose my seed phrase?
Your funds become permanently inaccessible the moment you lose access to the wallet that holds them. No exchange, wallet provider, or support team can recover a lost phrase. This is why you verify a backup works before trusting it with real money.
Is a seed phrase the same as my wallet password or a private key?
No. A password protects a device or app and can usually be reset. A private key controls one address. A seed phrase is the master key that generates and restores every private key in the wallet — and it cannot be reset.
Do exchange accounts like Binance or OKX have a seed phrase?
No. Exchange accounts use a login, password, and 2FA, all recoverable through the exchange's support process. Seed phrases only exist for self-custody wallets. Scammers exploit this confusion by asking exchange customers for a 'recovery phrase' the account does not even have.

Editor-in-Chief & Lead Researcher

Lucas Almeida

Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.

View author page →

Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.