What You’re Actually Protecting Against

Most people think “seed phrase storage” means hiding it from hackers. Hackers are the least of its problems — a phrase that exists only on paper can’t be phished. The real threat list is physical and mundane:

  1. Fire and flood. Your backup dies with the building.
  2. Theft and burglary. Someone takes the backup, or takes the safe it’s in.
  3. Casual discovery. A visitor, a cleaner, a relative, a mover finds a card with 12 words on it. They may not know what it is — or they may.
  4. Coercion. Someone with leverage wants you to open the wallet. This is the wrench attack scenario, and storage choices affect how much protection a wallet passphrase layer can give you.
  5. Yourself. You forget the location, misread your own handwriting, die without instructions, or “improve” the backup into oblivion.

Every design decision below is a trade among these five. There is no perfect solution — there are only deliberate ones.

The Baseline: Paper Done Properly

The seed phrase is written down once, at creation, from the screen of the device that generated it — never from a photo, never from memory, never re-typed through an intermediate copy. Write the words in order, number them, and include the checksum word if your wallet shows 13. Handwriting matters more than people admit: ambiguous letters have turned “restore” into hours of despair. Write clearly, in pen, on the card that ships with the wallet or on plain paper.

Then — and almost nobody does this — verify by test-restore: wipe the device (or use a spare), restore from your written phrase, confirm the addresses match what you recorded at creation. A backup you have never restored from is a hypothesis, not a backup.

What paper protects against: remote everything. No malware, no phishing page, no cloud breach touches a card in a drawer. What it doesn’t protect against: physics. Paper ignites at around 230°C (the famous “Fahrenheit 451”); a fully involved house fire runs far hotter than that, and water — from firefighters or a burst pipe — destroys it without any flame at all.

If paper is your medium, it lives in a fire-rated bag or small safe at minimum, in a location that survives the scenarios you actually face.

Why Metal Backups Exist

A steel backup is the same words, stamped or engraved into a stainless plate — the standard answer to the fire-and-flood line of the threat list. Stainless steel doesn’t ignite, doesn’t care about water, and survives corrosion for decades. Kits that let you punch characters with a hammer, or engrave them, cost a few tens of dollars and require no trust in any vendor — you can make one from a hardware-store blank.

Two honest caveats:

  • Steel protects the words, not you. A plate is smaller and more durable than a notebook, which makes it easier to hide and easier to steal. The discovery and coercion threats are untouched.
  • Human error moves to a new medium. Punched plates are mis-punched. Verify a steel backup the same way as paper — test-restore — and store a numbered word order so a jumbled set of letter tiles doesn’t become a puzzle your heirs can’t solve.

For most self-custody users, the progression is: paper at creation → verified steel backup within the week → paper becomes the travel/emergency copy or gets destroyed.

The Digital Sins

Everything below has one thing in common: the phrase leaves the physical world and becomes findable by software.

  • A photo on your phone. Gallery apps sync to clouds by default; infostealer malware catalogs photos; a phone repair tech scrolls. This is among the most commonly documented drain vectors.
  • Cloud drives and notes apps. “I’ll delete it later” — you won’t. The cloud is someone else’s computer with an unguessable retention policy.
  • Password manager “secure notes.” A password manager is a magnificent single point of failure for things that can be rotated. A seed phrase can’t be rotated — if the vault leaks once, the wallet is compromised forever.
  • Email drafts, messages to yourself, chat apps. Every chat platform is a log on someone else’s server. “Just between my own accounts” is not a property that exists.
  • An encrypted file on your everyday computer. The encryption is probably fine. The computer that also runs your browser, extensions, and downloads is the weak link — and it’s the machine malware targets first.

The seed phrase generator risks article covers why third parties must never create your phrase. The storage rule is the mirror image: no third-party system may ever hold it. If it has ever existed digitally, treat it as burned — create a fresh wallet on-device, move funds, and start the storage process over.

Copies: How Many, and Where

The tension: one copy is fragile, many copies are discoverable. The standard resolution:

  • Two or three copies, geographically separated. Home + a trusted second location (family member’s safe, a bank safe deposit box). If one location burns, floods, or gets burgled, you are not done.
  • Tamper-evident, not just hidden. Numbered tamper-evident bags or seals tell you whether a copy has been touched while you were away — which converts “probably fine” into “verifiably fine.”
  • No copies in places with shared access. Office desks, storage units with staff access, anyone else’s home you wouldn’t audit.
  • Document the scheme, not the secret. A note (separate from any backup) recording that copies exist, how many, and their general custodians — without the phrase itself — is what makes recovery possible when you’re hit by the fifth threat: yourself, injured, or gone.

For meaningful holdings, the better answer than more copies is fewer single points of control: a multi-sig wallet with keys in different locations, or social recovery designs. Then stealing one backup — or one person — is not enough.

Layers on Top

  • A wallet passphrase (what it is) turns one backup into two logical wallets: a decoy that satisfies a finder or a coercer, and the real one that needs a second secret you never wrote next to the seed. It is powerful and unforgiving — a forgotten passphrase is permanent loss, so it belongs in your inheritance documentation.
  • Shamir backup (SLIP-39), supported natively by Trezor, splits the secret into shares where any k of n recover the wallet — 2-of-3 beats both “one plate” and “three identical plates” for most threat models. The cost is procedural discipline: shares must stay separated and findable.
  • Geographic separation applies to shares as much as copies: a 2-of-3 scheme with all three shares in one safe is theater.

The Inheritance Problem

Estimates of how much crypto is permanently lost with its owners run into the millions of wallets — not stolen, not hacked: unwritten instructions. Storage that only you can unwind is a coin flip on your family’s inheritance.

The minimum viable inheritance kit:

  1. The instruction letter — stored with (or referenced by) your regular documents: what you hold, that a hardware wallet and backups exist, that a passphrase exists (say so — do not write it), and who to contact. Point at this site’s recovery guides rather than improvising technical instructions under stress.
  2. A rehearsed recovery path — at minimum, a trusted person who knows where the instruction letter is. Better: they’ve watched (or done) a test restore.
  3. Legal context — in many jurisdictions, a safe deposit box is sealed during probate. If your only backup is in one, your heirs may hold a legally untouchable wallet for months.

Test It, on a Schedule

Backups decay silently: handwriting fades, plates corrode in coastal air, hiding spots get renovated over, memory of “where exactly” erodes in about a year. Put two recurring events on the calendar:

  • Annual check — open, verify presence and legibility, reseal with fresh tamper evidence.
  • Restore drill — every year or two, on a spare device: wipe, restore, confirm addresses. This is the only test that proves the whole chain — medium, transcription, derivation path — still works.

The unifying principle is the same one behind everything else on this site: your security is a process, not a purchase. A $6 steel blank with an annual restore drill beats a $600 safe nobody has opened since 2023.

Related reading: why seed phrases must never be generated online, the first 24 hours after a theft, and how to audit your wallet activity.

Frequently Asked Questions

Is writing my seed phrase on paper really safe enough?

Paper is the acceptable baseline — most lost crypto involves no paper backup at all, or a digital one that got found. The risks paper doesn't cover are physical: house fires routinely exceed 600°C while paper ignites around 230°C, and floods and humidity destroy it outright. If your holdings justify a hardware wallet, they justify a metal backup — a punched or engraved stainless plate costs a few tens of dollars and survives what paper cannot. Whatever the medium, verify the backup by test-restoring a wallet from it before you rely on it.

How many copies of a seed phrase should I keep?

Two or three, in geographically separate locations, is the standard answer. One copy is a single point of failure — one fire, one burglary, one forgetful move and the funds are gone forever. But every additional copy multiplies discovery risk, so past three the trade turns negative. Use tamper-evident measures (numbered pouches, seals, a photo of the plate's arrangement stored nowhere near the plate) so you can tell if a copy was accessed, and rehearse the recovery path at least once a year.

Where should I NOT store a seed phrase?

Anywhere digital: no photos on your phone (gallery sync and infostealer malware both harvest them), no cloud drives, no password manager secure notes, no email drafts, no messages to yourself in chat apps, no encrypted file on the same computer you browse with. Also avoid the classic hiding spots that burglars check first — the desk drawer, the safe in the bedroom closet, and taped under the keyboard. A bank safe deposit box is a defensible option if you accept that access depends on the bank and legal process.