Seed Phrase Backup Beyond Paper: Steel, Shamir and Multisig
More crypto has been lost to bad backups than to attackers. The backup, not the wallet, is where self-custody usually fails.
More crypto has been lost to bad backups than to attackers. The backup, not the wallet, is where self-custody usually fails.
A seed phrase backup has to survive fire, water, time and the people who find it. Steel plates solve physical destruction. A BIP39 passphrase splits the secret into two things that must be combined. Shamir backup splits the seed into shares with a threshold. Multisig avoids a single secret entirely. Choose by amount and by who else needs access, and test the restore before relying on it.
Hardware wallets solved key extraction. What they did not solve is the piece of paper in the drawer, which is still how most self-custodial crypto is actually protected — and how most of it is actually lost.
A backup has to survive four separate threats, and they pull in opposite directions. Physical destruction. Gradual loss — moves, clear-outs, a relative tidying up. Discovery by someone who should not have it. And your own unavailability, when someone else needs to recover the funds and cannot.
Metal backup plates store the words by stamping, engraving, or arranging letter tiles. They survive house fires and flooding, which paper does not, and they cost less than a hardware wallet.
Three practical notes. Most designs only need the first four letters of each word, because BIP39 words are unique to four characters — this halves the work and reduces mistakes. Stamped or engraved plates are more durable than tile-based ones, which can scatter if the case fails. And a metal plate is still a plaintext secret: it defeats fire, not a burglar.
For most people holding a meaningful amount on one device, steel plus good hiding is the whole answer, and everything below is optional complexity.
A passphrase — often called the 25th word — is combined with the seed to derive a completely different set of wallets. Without it, the seed opens an entirely valid but different (and empty, or deliberately decoy-funded) wallet.
This means the metal plate alone is not enough to steal from. It also means the passphrase alone is not enough, and if you lose it the funds are unrecoverable with no support path — there is no way to detect a wrong passphrase, only an empty wallet. That property is exactly why it works and exactly why it kills funds.
The rule that makes it survivable: the passphrase must be backed up too, in a different place from the seed, and it must be memorable enough that a heir with instructions could obtain it. A passphrase existing only in your memory is a plan to lose the money. The full mechanics are in passphrases and hidden wallets.
Shamir backup splits the seed into shares such that any threshold — say three of five — reconstructs it, and fewer reveal nothing. Shares can be stored in different places, so no single location is either a total loss or a total exposure.
It is elegant and it is implemented natively on Trezor's devices. Its weaknesses are practical rather than mathematical: fewer wallets support the standard, so recovery is tied more tightly to a vendor's ecosystem; managing five locations is a real ongoing chore; and reconstruction brings the whole seed back together on one device, which is the moment of exposure Shamir does not remove.
The strongest structure for large amounts, because there is no seed to protect. Two of three keys are required to spend; each key has its own backup; losing one is a rotation rather than a disaster; and finding one gives an attacker nothing.
The cost is complexity — the wallet configuration itself must be backed up alongside the keys, and a multisig whose descriptor is lost can be as unrecoverable as a lost seed. The trade-offs against MPC and single-key setups are covered in choosing a custody model, and the practical picks sit in the hardware wallet ratings.
Geography matters more than cleverness. Two copies in the same house are one copy against a fire. Copies in two places you can reach reduce the destruction risk without much added exposure — a home safe and a trusted second location is the standard answer, and a bank box is fine as one of two but poor as the only one, because access can be interrupted.
Avoid the classic mistakes: anything photographed, anything typed, anything in a password manager or cloud note, anything labelled with the amount or the exchange, and anything stored where a curious visitor will read it. And never enter a seed into a website, ever, for any reason — every seed-phrase form is a theft.
Test the restore. Wipe the device, or use a spare, and recover from the backup alone with no help from the original. Do it before you fund the wallet, and repeat it if you change anything.
Untested backups fail in exactly the ways you would expect: a mis-stamped word, a passphrase with a trailing space, a share stored in a place you can no longer access, a derivation path the new wallet does not default to. All of these are trivial to fix in advance and terminal to discover afterwards.
Small spending balance: single seed on steel, one location, no passphrase. Meaningful holdings: steel, two locations, a passphrase backed up separately, restore tested. Large holdings or anything with dependants: 2-of-3 multisig with keys from different vendors in different places, the configuration backed up with each key, and written instructions someone else could follow — which is the subject of inheritance planning and the part of self-custody most people never finish.

A practical, low-tech guide to backing up a crypto recovery phrase so it survives theft, fire, and your own future forgetfulness.
One key is a single point of failure. Multisig and MPC remove it in different ways, and the differences matter more than the marketing suggests.

A plain-language breakdown of how crypto wallets actually work, and why the choice between hot and cold storage is the first real security decision every holder makes.