Seed backup is the operational practice that determines whether a self-custody setup actually survives the events it was designed to survive. The principle: the seed must exist on durable physical media, in at least two geographically distinct locations, in a form that survives fire, flood, time, and the holder's eventual unavailability — and must be verified by actual restoration before being trusted with substantial funds. The dominant failure modes are well-catalogued: the untested metal backup that turns out incomplete or wrong; the paper backup that ink-fades or water-damages; the digital "temporary" backup that syncs to the cloud; the backup so secure the holder cannot find it years later. Backup discipline is a first-class practice distinct from device choice and configuration, and the patterns that actually work diverge sharply from the ones that produce most permanently-lost Bitcoin.


Why this note matters

Seed backup is the most-underweighted element of the operational discipline. Holders engage device choice and multisig configuration with substantial care; backup is often an afterthought (“I’ll just write it down”). The note matters because:

  • It establishes backup as a first-class operational practice rather than a setup-time afterthought. The discipline must hold for the entire holding horizon (often decades), not just the day of setup.
  • It surfaces the specific failure modes that account for most permanently-lost Bitcoin — the untested backup, the paper that degrades, the photo that syncs to the cloud, the location that gets renovated and discarded.
  • It anchors the verification requirement: a backup that has not been restored from is a hope, not a backup. The wipe-and-restore test is the discipline that converts a hope into a backup.

The defensible position: every meaningful Bitcoin holding should be backed up on durable physical media, in at least two geographically distinct locations, verified by restoration, documented for heirs, and rehearsed periodically. Anything less is structurally exposed to the failure modes that account for an estimated 11–18% of all Bitcoin (roughly 2.3–3.7 million BTC) now being permanently lost.


What this is

The seed-backup problem: how do you preserve a 12 or 24-word mnemonic (and possibly a passphrase, and possibly a multisig descriptor, and possibly multiple seeds) such that:

  • The backup survives environmental hazards — fire, flood, earthquake, paper degradation, ink fade
  • The backup survives time — decades, possibly across generations
  • The backup is not exposed to attackers — found-during-burglary, photographed-by-family-member, leaked-to-cloud
  • The backup is findable by the holder — locations that drift over time, mental models that fade
  • The backup is inheritable — heirs can locate, identify, and use it
  • The backup has been verified — actually tested by restoration

These are competing requirements. A backup so secure no one can find it is structurally lost. A backup so accessible everyone can find it is exposed. The trade-off is the central design problem.

The seed at any moment

The seed phrase exists in one of these states:

  • In the hardware wallet’s secure element — the “working copy.” Not a backup; lost if the device is destroyed.
  • In the holder’s head — memorization. Not a backup; lost if the holder dies, forgets, or experiences cognitive decline.
  • On physical media — paper, metal, etched substrate. This is the actual backup. Quality of the medium determines what events it survives.
  • In digital form — photo, password manager, cloud-synced file, encrypted file on a hard drive. Not a backup; an exposure event waiting to happen. Treat digital copies as catastrophic compromises.

The discipline: the seed should exist on durable physical media (multiple copies in distinct locations) and should never exist in digital form at any time, for any reason, even temporarily.


When this matters

Seed backup discipline applies from the moment the seed is generated. The relevant decisions:

  • At setup — what media to use; how many copies; which locations
  • At each ongoing review — annual verification that the backup is still intact and findable
  • At any change — moves, renovations, life events that affect location stability
  • At inheritance planning — documentation for heirs
  • At setup retirement — when the seed is no longer in use, what to do with the backup

The principle: backup is not a one-time event. It is an ongoing practice that must sustain for the holding horizon.


How seed backup actually works

The setup-time backup

  1. Hardware wallet generates the seed — displays the 12 or 24 words on the device screen
  2. Holder transcribes by hand onto paper — initial recording. Pencil or pen on paper.
  3. Holder verifies the transcription — read back to the device’s verification flow, or use the wallet’s check-backup feature
  4. Holder transfers to durable media — typically metal. See Steel seed storage for the specific products and patterns.
  5. Holder verifies the durable backup — re-reads the metal against the original paper, then performs a wipe-and-restore test if possible
  6. Holder destroys the paper — once the metal backup is verified, the paper is destroyed (paper is far less durable than metal and presents an additional exposure surface)

The paper-then-metal pattern is the synthesis’s recommendation. Paper-only is acceptable for Tier 0 hot wallets; for any hardware-wallet setup, metal is the standard.

Geographic distribution

The principle: no single location should contain enough material to compromise the wallet.

  • Single-sig with one backup — two physical copies (in case one is destroyed) in two distinct locations
  • Single-sig + passphrase — seed in one location; passphrase backup in another location (so finding one doesn’t compromise the wallet)
  • 2-of-3 multisig — three keys + three seed backups; each seed backup co-located with its respective device, or stored separately if device and seed are in the same secure location

Common distribution patterns:

  • Home safe (primary)
  • Bank safe deposit box (secondary)
  • Family member in different city (tertiary)
  • Second property
  • Attorney’s office (for inheritance-integrated setups)

The principle: the backup must survive a catastrophic event at any single location.

Verification at setup

The wipe-and-restore test:

  1. Hardware wallet is initialized with the seed (already done at setup)
  2. Holder verifies the wallet is working — small test funds received and spent
  3. Holder wipes the hardware wallet completely
  4. Holder restores from the backed-up seed (and passphrase, if any)
  5. Holder confirms the same addresses appear and the test funds are still accessible
  6. The backup is now verified

For multisig: restore each key independently from its seed backup; confirm the coordinator can reconstruct the wallet from the restored keys; confirm the same addresses appear and the test funds are accessible.

This is the discipline that converts a hope into a backup. A backup that has not been restored from is not a backup. The wipe-and-restore test should be performed before substantial funds are placed in the wallet.

Ongoing verification

Setups drift. Locations get renovated. Family members move. The metal backup at the bank safe deposit box may have been replaced by the holder’s clean-up of “old documents.” The discipline: annual verification.

What to verify:

  • Can you locate each backup? Without prompting, go to each location and confirm the backup is where you expect.
  • Can you read each backup? Inspect for damage, fade, corrosion.
  • Can the hardware wallet still be restored from each backup? A signed-challenge-message rehearsal (see Recovery rehearsal practice) is the lightweight verification.

Annual verification catches drift before it becomes loss.


Tradeoffs and considerations

Paper vs metal

Paper:

  • Cheap; readily available
  • Easily destroyed by fire, water, ink fade, physical degradation
  • Appropriate for setup-time initial recording; not appropriate for long-term backup
  • Vulnerable to inadvertent discovery (looks like a document)

Metal (see Steel seed storage for the full treatment):

  • Substantially more durable against fire, water, time
  • Lopp’s stress tests show roughly half of products marketed as “indestructible” still fail one or more of heat, corrosion, or deformation tests — specific product choice matters
  • More expensive (200 per backup)
  • Less recognizable to attackers as a Bitcoin seed (some products are deliberately ambiguous)
  • The standard for Tier 1+ holdings

The synthesis recommendation: paper for setup-time transcription; metal for the actual backup; verify the metal against the paper; destroy the paper after verification.

One backup or multiple copies?

The synthesis’s read: at least two backups in geographically distinct locations for any substantial holding. The structural argument:

  • A single backup is one event away from being lost
  • Two backups in the same location is no better than one
  • Two backups in distinct locations survives a catastrophic event at any single location

For Tier 1, two metal backups (one at home, one at a bank safe deposit box or trusted family member) is the typical pattern. For Tier 2+, three or more locations spreading across jurisdictions.

The pitfall to avoid: too many copies. Each copy is an exposure surface. The right number is the minimum that provides the redundancy you need, not the maximum the holder feels comfortable with.

The passphrase backup problem

If the seed is protected by a BIP-39 passphrase (see Passphrases and the 25th word), the passphrase must also be backed up. The discipline:

  • Passphrase backup is its own artifact — backed up separately from the seed
  • Passphrase backup goes in a different location from the seed (so finding the seed doesn’t reveal the passphrase)
  • For inheritance: passphrase backup is part of the inheritance documentation
  • The “I’ll just remember the passphrase” pattern is the most-cited inheritance failure mode in the synthesis

Some holders SLIP-39-split the passphrase specifically, distributing shares among trusted parties so that a threshold can reconstruct the passphrase post-mortem. See SLIP-39 and Shamir Secret Sharing.

The descriptor backup (multisig)

For multisig setups, the wallet descriptor must be backed up alongside the seed backups. See PSBT and wallet descriptors:

  • The descriptor specifies the multisig configuration
  • Without the descriptor, holding all three seeds is not sufficient to reconstruct the wallet
  • The descriptor’s sensitivity is lower than the seed (an attacker with only the descriptor cannot spend) but its loss can turn recovery from difficult to impossible
  • Standard practice: descriptor backed up with each seed backup

The “where” question

Specific location considerations:

Home safe:

  • Fire-resistant rating matters (UL Class 350-1 for documents; higher ratings cost more)
  • Bolted to the structure (a portable safe is a portable target)
  • The holder’s home is not a perfect location — burglary, fire, family-member discovery
  • Acceptable for one backup of a multisig setup; rarely acceptable as the only backup

Bank safe deposit box:

  • Genuinely secure against home-based threats
  • Some institutional risk (rare cases of bank failures, regulatory issues affecting box access)
  • Geographic constraint — the holder must travel to access
  • The bank has no knowledge of the contents (legally), but the bank’s records show the box exists in your name
  • A solid second location; common in distributed backup patterns

Trusted family member or friend:

  • The person knows you have something with them; treat as security-sensitive
  • The location depends on their residential stability — moves can complicate retrieval
  • The relationship must be stable enough to last the holding horizon
  • Useful for one component of a multisig; less useful for the only backup of a single-sig

Second property:

  • For holders with multiple residences, distributing across them is straightforward
  • Same residential-stability considerations as family member locations
  • Useful if the secondary property is in a different jurisdiction

Attorney’s office or estate-planning vehicle:

  • Particularly relevant for inheritance-integrated setups
  • The attorney’s office is typically secure; the attorney’s professional obligation provides additional discipline
  • Some attorneys are uncomfortable holding crypto-related materials; engage explicitly
  • Common pattern for high-net-worth holders with established estate plans

Inheritance documentation

A seed backup that heirs cannot interpret is functionally lost. The inheritance documentation should include:

  • The existence of the Bitcoin holding (some heirs don’t know)
  • The location of each backup
  • The wallet software needed to use it (especially for multisig)
  • The descriptor (for multisig)
  • The passphrase (or a path to it, e.g., “in the sealed envelope at the attorney’s office”)
  • Basic operational instructions in language the heir can follow

The documentation lives in the holder’s estate plan, typically as part of a revocable living trust. See Inheritance planning for bitcoin for the full treatment; the broader estate-planning principles (findability as the primary failure mode, beneficiary mechanisms, and trust-design considerations) are well-established outside Bitcoin and operate as background.


Comparison with alternatives

ApproachSurvivalCostOperational complexityBest for
Memorization onlyLost on holder unavailabilityFreeVariableNever (alone); supplement only
Paper onlyDecades at best; very vulnerableFreeLowTier 0 hot wallet
Encrypted digital fileVulnerable to compromise of the hosting deviceFreeMediumNot recommended
Single metal backupDecades to centuries; survives single events200LowTier 1 if combined with verified setup
Two metal backups in distinct locationsSurvives catastrophic events at any single location400MediumTier 1+ standard
Three+ metal backups distributedSurvives multiple simultaneous events800HighTier 2+
SLIP-39 split across locationsSingle-share compromise reveals nothing; multiple locations1,000HighTier 2+ specific use cases
BIP-85 + master backupReduces backup count; concentrates risk200 for masterMediumMulti-wallet holders with strong master discipline

The synthesis-validated default: two metal backups in geographically distinct locations, verified by restoration, for any substantial holding.


Tiered application

Tier 0: Single paper backup is acceptable. The pattern that fails: no backup at all, or “the wallet remembers the seed” (the hardware wallet’s working copy is not a backup).

Tier 1 (50K): Two metal backups in geographically distinct locations. Verified by restoration before funding. Documented for the heir.

Tier 2 (1M+): Three or more metal backups distributed across at least three locations. Documented; rehearsed annually. Descriptor backed up alongside each seed.

Tier 3 (>$1M): Same as Tier 2 with explicit jurisdictional distribution; possibly SLIP-39-split for some keys; trust-vehicle integration for inheritance; documented procedures attorney-coordinated.

In all tiers: verification is non-negotiable. The wipe-and-restore test before funding is the discipline that distinguishes a backup from a hope.


Common pitfalls

The untested backup. A backup that has not been restored from is the dominant cause of “I thought I had this.” The wipe-and-restore test at setup is the canonical verification.

The digital “temporary” backup. “I’ll just take a photo of the seed for a minute while I find the metal backup.” The photo syncs to iCloud or Google Photos; the exposure window opens; the holder forgets. The pattern is structural — the temporary copy is the exposure.

The single paper backup in the home filing cabinet. Vulnerable to fire, water, family-member discovery, the inevitable filing-cabinet purge. Paper alone is not a backup for substantial holdings.

The “Indestructible” metal that isn’t. Lopp’s four rounds of metal-seed-storage stress tests show roughly half of products marketed as indestructible fail at least one common test (sustained fire, corrosion, deformation). Product choice matters. See Steel seed storage.

Co-located metal backups. Two metal backups in the same home is structurally one backup. Geographic distribution is required for the redundancy to matter.

Forgotten location. “I put it somewhere safe” — the holder cannot recall years later. The pattern is real and structurally common. Documentation is part of the backup discipline.

The “I’ll memorize it” attempt. Memorization fails over decades; the holder cannot reliably reproduce the mnemonic under stress; heirs cannot use a memorized seed. Memorization can supplement a physical backup, never replace it.

The complex obfuscation scheme. “I wrote every fourth word backward and XOR’d with my birthday.” The cryptography may work; the holder’s ability to reliably decode under stress does not. Novel schemes are the largest self-inflicted-loss category in the synthesis.

Inadequate inheritance documentation. Heirs find the metal backup; they don’t know what it is; they discard it as “an old document.” The backup must be findable, identifiable, and usable by the heir.

Skipping the annual verification. Setups drift. Locations get renovated. The metal at the bank safe deposit box may have been displaced. Annual verification catches drift before it becomes loss.

Treating BIP-39 passphrase as backed up by the seed. The seed is one artifact; the passphrase is another. Both must be backed up; both must be findable. The seed alone is not the wallet for passphrase-protected setups.


Tooling and resources

Metal backup products (representative; see Steel seed storage for the full treatment):

  • Cryptosteel Capsule
  • Blockplate (laser-etched stainless steel)
  • BillFodl
  • SafePal Cypher
  • COBO Tablet
  • Cryptotag

Specific product choice should be informed by Lopp’s stress-test reports.

Inheritance and documentation tooling:

  • Casa’s inheritance documentation templates
  • Unchained’s estate-planning resources
  • Custom estate-planning attorney engagement
  • Broader estate-planning documentation that integrates the seed-backup record — see Inheritance planning for bitcoin

The synthesis document: Bitcoin Self-Custody & Security (LegacyCipher, April 2026) — backup treated as the load-bearing discipline.

Primary practitioner sources:

  • Lopp — Metal Seed Storage Stress Tests (2018, 2020, 2022, 2024); the canonical empirical reference. See Jameson Lopp.
  • Blockchain Commons — Smart Custody Book; backup chapters
  • Casa, Unchained, Nunchuk — vendor-specific backup guidance

As of 2026-05-14: the backup landscape is mature. Steel-backup products are widely available; the discipline is well-codified. The remaining variables are operational — which location, what verification cadence, how integrated with inheritance.


Open questions for further development

  • The annual-verification cadence is the synthesis-validated default. Is this calibrated correctly? Some practitioners argue semi-annual; some argue triennial is sufficient. The right cadence depends on holding size and location stability.
  • The role of SLIP-39 in the backup taxonomy is unclear in the synthesis. Is SLIP-39 a backup scheme or a custody scheme? The two function differently and the framing should be sharper.
  • Memorization-as-supplement is sometimes advocated (Lopp has written about this). The pattern: memorize the seed plus maintain physical backups, so the holder has redundant access to the wallet during their lifetime. Is this a useful pattern or an over-claim?
  • The “find your backup blindfolded” stress test — can the holder go to each location and retrieve each backup without prompting? Some practitioners advocate this; it is operationally heavy but uniquely thorough.

The framing context:

Storage and key concepts:

Adjacent discipline notes:

Hardware wallets:

  • Hardware wallets overview — devices generate the seeds that are backed up
  • Coldcard — dice-entropy contribution affects what is backed up
  • BitBox — microSD backup as a controversial option
  • Trezor — native SLIP-39 backup support

Custody configurations:

Operational security:

Inheritance:

The principal practitioner:

The sub-MOC home: