Seed backup is the operational practice that determines whether a self-custody setup actually survives the events it was designed to survive. The principle: the seed must exist on durable physical media, in at least two geographically distinct locations, in a form that survives fire, flood, time, and the holder's eventual unavailability — and must be verified by actual restoration before being trusted with substantial funds. The dominant failure modes are well-catalogued: the untested metal backup that turns out incomplete or wrong; the paper backup that ink-fades or water-damages; the digital "temporary" backup that syncs to the cloud; the backup so secure the holder cannot find it years later. Backup discipline is a first-class practice distinct from device choice and configuration, and the patterns that actually work diverge sharply from the ones that produce most permanently-lost Bitcoin.
Why this note matters
Seed backup is the most-underweighted element of the operational discipline. Holders engage device choice and multisig configuration with substantial care; backup is often an afterthought (“I’ll just write it down”). The note matters because:
- It establishes backup as a first-class operational practice rather than a setup-time afterthought. The discipline must hold for the entire holding horizon (often decades), not just the day of setup.
- It surfaces the specific failure modes that account for most permanently-lost Bitcoin — the untested backup, the paper that degrades, the photo that syncs to the cloud, the location that gets renovated and discarded.
- It anchors the verification requirement: a backup that has not been restored from is a hope, not a backup. The wipe-and-restore test is the discipline that converts a hope into a backup.
The defensible position: every meaningful Bitcoin holding should be backed up on durable physical media, in at least two geographically distinct locations, verified by restoration, documented for heirs, and rehearsed periodically. Anything less is structurally exposed to the failure modes that account for an estimated 11–18% of all Bitcoin (roughly 2.3–3.7 million BTC) now being permanently lost.
What this is
The seed-backup problem: how do you preserve a 12 or 24-word mnemonic (and possibly a passphrase, and possibly a multisig descriptor, and possibly multiple seeds) such that:
- The backup survives environmental hazards — fire, flood, earthquake, paper degradation, ink fade
- The backup survives time — decades, possibly across generations
- The backup is not exposed to attackers — found-during-burglary, photographed-by-family-member, leaked-to-cloud
- The backup is findable by the holder — locations that drift over time, mental models that fade
- The backup is inheritable — heirs can locate, identify, and use it
- The backup has been verified — actually tested by restoration
These are competing requirements. A backup so secure no one can find it is structurally lost. A backup so accessible everyone can find it is exposed. The trade-off is the central design problem.
The seed at any moment
The seed phrase exists in one of these states:
- In the hardware wallet’s secure element — the “working copy.” Not a backup; lost if the device is destroyed.
- In the holder’s head — memorization. Not a backup; lost if the holder dies, forgets, or experiences cognitive decline.
- On physical media — paper, metal, etched substrate. This is the actual backup. Quality of the medium determines what events it survives.
- In digital form — photo, password manager, cloud-synced file, encrypted file on a hard drive. Not a backup; an exposure event waiting to happen. Treat digital copies as catastrophic compromises.
The discipline: the seed should exist on durable physical media (multiple copies in distinct locations) and should never exist in digital form at any time, for any reason, even temporarily.
When this matters
Seed backup discipline applies from the moment the seed is generated. The relevant decisions:
- At setup — what media to use; how many copies; which locations
- At each ongoing review — annual verification that the backup is still intact and findable
- At any change — moves, renovations, life events that affect location stability
- At inheritance planning — documentation for heirs
- At setup retirement — when the seed is no longer in use, what to do with the backup
The principle: backup is not a one-time event. It is an ongoing practice that must sustain for the holding horizon.
How seed backup actually works
The setup-time backup
- Hardware wallet generates the seed — displays the 12 or 24 words on the device screen
- Holder transcribes by hand onto paper — initial recording. Pencil or pen on paper.
- Holder verifies the transcription — read back to the device’s verification flow, or use the wallet’s check-backup feature
- Holder transfers to durable media — typically metal. See Steel seed storage for the specific products and patterns.
- Holder verifies the durable backup — re-reads the metal against the original paper, then performs a wipe-and-restore test if possible
- Holder destroys the paper — once the metal backup is verified, the paper is destroyed (paper is far less durable than metal and presents an additional exposure surface)
The paper-then-metal pattern is the synthesis’s recommendation. Paper-only is acceptable for Tier 0 hot wallets; for any hardware-wallet setup, metal is the standard.
Geographic distribution
The principle: no single location should contain enough material to compromise the wallet.
- Single-sig with one backup — two physical copies (in case one is destroyed) in two distinct locations
- Single-sig + passphrase — seed in one location; passphrase backup in another location (so finding one doesn’t compromise the wallet)
- 2-of-3 multisig — three keys + three seed backups; each seed backup co-located with its respective device, or stored separately if device and seed are in the same secure location
Common distribution patterns:
- Home safe (primary)
- Bank safe deposit box (secondary)
- Family member in different city (tertiary)
- Second property
- Attorney’s office (for inheritance-integrated setups)
The principle: the backup must survive a catastrophic event at any single location.
Verification at setup
The wipe-and-restore test:
- Hardware wallet is initialized with the seed (already done at setup)
- Holder verifies the wallet is working — small test funds received and spent
- Holder wipes the hardware wallet completely
- Holder restores from the backed-up seed (and passphrase, if any)
- Holder confirms the same addresses appear and the test funds are still accessible
- The backup is now verified
For multisig: restore each key independently from its seed backup; confirm the coordinator can reconstruct the wallet from the restored keys; confirm the same addresses appear and the test funds are accessible.
This is the discipline that converts a hope into a backup. A backup that has not been restored from is not a backup. The wipe-and-restore test should be performed before substantial funds are placed in the wallet.
Ongoing verification
Setups drift. Locations get renovated. Family members move. The metal backup at the bank safe deposit box may have been replaced by the holder’s clean-up of “old documents.” The discipline: annual verification.
What to verify:
- Can you locate each backup? Without prompting, go to each location and confirm the backup is where you expect.
- Can you read each backup? Inspect for damage, fade, corrosion.
- Can the hardware wallet still be restored from each backup? A signed-challenge-message rehearsal (see Recovery rehearsal practice) is the lightweight verification.
Annual verification catches drift before it becomes loss.
Tradeoffs and considerations
Paper vs metal
Paper:
- Cheap; readily available
- Easily destroyed by fire, water, ink fade, physical degradation
- Appropriate for setup-time initial recording; not appropriate for long-term backup
- Vulnerable to inadvertent discovery (looks like a document)
Metal (see Steel seed storage for the full treatment):
- Substantially more durable against fire, water, time
- Lopp’s stress tests show roughly half of products marketed as “indestructible” still fail one or more of heat, corrosion, or deformation tests — specific product choice matters
- More expensive (200 per backup)
- Less recognizable to attackers as a Bitcoin seed (some products are deliberately ambiguous)
- The standard for Tier 1+ holdings
The synthesis recommendation: paper for setup-time transcription; metal for the actual backup; verify the metal against the paper; destroy the paper after verification.
One backup or multiple copies?
The synthesis’s read: at least two backups in geographically distinct locations for any substantial holding. The structural argument:
- A single backup is one event away from being lost
- Two backups in the same location is no better than one
- Two backups in distinct locations survives a catastrophic event at any single location
For Tier 1, two metal backups (one at home, one at a bank safe deposit box or trusted family member) is the typical pattern. For Tier 2+, three or more locations spreading across jurisdictions.
The pitfall to avoid: too many copies. Each copy is an exposure surface. The right number is the minimum that provides the redundancy you need, not the maximum the holder feels comfortable with.
The passphrase backup problem
If the seed is protected by a BIP-39 passphrase (see Passphrases and the 25th word), the passphrase must also be backed up. The discipline:
- Passphrase backup is its own artifact — backed up separately from the seed
- Passphrase backup goes in a different location from the seed (so finding the seed doesn’t reveal the passphrase)
- For inheritance: passphrase backup is part of the inheritance documentation
- The “I’ll just remember the passphrase” pattern is the most-cited inheritance failure mode in the synthesis
Some holders SLIP-39-split the passphrase specifically, distributing shares among trusted parties so that a threshold can reconstruct the passphrase post-mortem. See SLIP-39 and Shamir Secret Sharing.
The descriptor backup (multisig)
For multisig setups, the wallet descriptor must be backed up alongside the seed backups. See PSBT and wallet descriptors:
- The descriptor specifies the multisig configuration
- Without the descriptor, holding all three seeds is not sufficient to reconstruct the wallet
- The descriptor’s sensitivity is lower than the seed (an attacker with only the descriptor cannot spend) but its loss can turn recovery from difficult to impossible
- Standard practice: descriptor backed up with each seed backup
The “where” question
Specific location considerations:
Home safe:
- Fire-resistant rating matters (UL Class 350-1 for documents; higher ratings cost more)
- Bolted to the structure (a portable safe is a portable target)
- The holder’s home is not a perfect location — burglary, fire, family-member discovery
- Acceptable for one backup of a multisig setup; rarely acceptable as the only backup
Bank safe deposit box:
- Genuinely secure against home-based threats
- Some institutional risk (rare cases of bank failures, regulatory issues affecting box access)
- Geographic constraint — the holder must travel to access
- The bank has no knowledge of the contents (legally), but the bank’s records show the box exists in your name
- A solid second location; common in distributed backup patterns
Trusted family member or friend:
- The person knows you have something with them; treat as security-sensitive
- The location depends on their residential stability — moves can complicate retrieval
- The relationship must be stable enough to last the holding horizon
- Useful for one component of a multisig; less useful for the only backup of a single-sig
Second property:
- For holders with multiple residences, distributing across them is straightforward
- Same residential-stability considerations as family member locations
- Useful if the secondary property is in a different jurisdiction
Attorney’s office or estate-planning vehicle:
- Particularly relevant for inheritance-integrated setups
- The attorney’s office is typically secure; the attorney’s professional obligation provides additional discipline
- Some attorneys are uncomfortable holding crypto-related materials; engage explicitly
- Common pattern for high-net-worth holders with established estate plans
Inheritance documentation
A seed backup that heirs cannot interpret is functionally lost. The inheritance documentation should include:
- The existence of the Bitcoin holding (some heirs don’t know)
- The location of each backup
- The wallet software needed to use it (especially for multisig)
- The descriptor (for multisig)
- The passphrase (or a path to it, e.g., “in the sealed envelope at the attorney’s office”)
- Basic operational instructions in language the heir can follow
The documentation lives in the holder’s estate plan, typically as part of a revocable living trust. See Inheritance planning for bitcoin for the full treatment; the broader estate-planning principles (findability as the primary failure mode, beneficiary mechanisms, and trust-design considerations) are well-established outside Bitcoin and operate as background.
Comparison with alternatives
| Approach | Survival | Cost | Operational complexity | Best for |
|---|---|---|---|---|
| Memorization only | Lost on holder unavailability | Free | Variable | Never (alone); supplement only |
| Paper only | Decades at best; very vulnerable | Free | Low | Tier 0 hot wallet |
| Encrypted digital file | Vulnerable to compromise of the hosting device | Free | Medium | Not recommended |
| Single metal backup | Decades to centuries; survives single events | 200 | Low | Tier 1 if combined with verified setup |
| Two metal backups in distinct locations | Survives catastrophic events at any single location | 400 | Medium | Tier 1+ standard |
| Three+ metal backups distributed | Survives multiple simultaneous events | 800 | High | Tier 2+ |
| SLIP-39 split across locations | Single-share compromise reveals nothing; multiple locations | 1,000 | High | Tier 2+ specific use cases |
| BIP-85 + master backup | Reduces backup count; concentrates risk | 200 for master | Medium | Multi-wallet holders with strong master discipline |
The synthesis-validated default: two metal backups in geographically distinct locations, verified by restoration, for any substantial holding.
Tiered application
Tier 0: Single paper backup is acceptable. The pattern that fails: no backup at all, or “the wallet remembers the seed” (the hardware wallet’s working copy is not a backup).
Tier 1 (50K): Two metal backups in geographically distinct locations. Verified by restoration before funding. Documented for the heir.
Tier 2 (1M+): Three or more metal backups distributed across at least three locations. Documented; rehearsed annually. Descriptor backed up alongside each seed.
Tier 3 (>$1M): Same as Tier 2 with explicit jurisdictional distribution; possibly SLIP-39-split for some keys; trust-vehicle integration for inheritance; documented procedures attorney-coordinated.
In all tiers: verification is non-negotiable. The wipe-and-restore test before funding is the discipline that distinguishes a backup from a hope.
Common pitfalls
The untested backup. A backup that has not been restored from is the dominant cause of “I thought I had this.” The wipe-and-restore test at setup is the canonical verification.
The digital “temporary” backup. “I’ll just take a photo of the seed for a minute while I find the metal backup.” The photo syncs to iCloud or Google Photos; the exposure window opens; the holder forgets. The pattern is structural — the temporary copy is the exposure.
The single paper backup in the home filing cabinet. Vulnerable to fire, water, family-member discovery, the inevitable filing-cabinet purge. Paper alone is not a backup for substantial holdings.
The “Indestructible” metal that isn’t. Lopp’s four rounds of metal-seed-storage stress tests show roughly half of products marketed as indestructible fail at least one common test (sustained fire, corrosion, deformation). Product choice matters. See Steel seed storage.
Co-located metal backups. Two metal backups in the same home is structurally one backup. Geographic distribution is required for the redundancy to matter.
Forgotten location. “I put it somewhere safe” — the holder cannot recall years later. The pattern is real and structurally common. Documentation is part of the backup discipline.
The “I’ll memorize it” attempt. Memorization fails over decades; the holder cannot reliably reproduce the mnemonic under stress; heirs cannot use a memorized seed. Memorization can supplement a physical backup, never replace it.
The complex obfuscation scheme. “I wrote every fourth word backward and XOR’d with my birthday.” The cryptography may work; the holder’s ability to reliably decode under stress does not. Novel schemes are the largest self-inflicted-loss category in the synthesis.
Inadequate inheritance documentation. Heirs find the metal backup; they don’t know what it is; they discard it as “an old document.” The backup must be findable, identifiable, and usable by the heir.
Skipping the annual verification. Setups drift. Locations get renovated. The metal at the bank safe deposit box may have been displaced. Annual verification catches drift before it becomes loss.
Treating BIP-39 passphrase as backed up by the seed. The seed is one artifact; the passphrase is another. Both must be backed up; both must be findable. The seed alone is not the wallet for passphrase-protected setups.
Tooling and resources
Metal backup products (representative; see Steel seed storage for the full treatment):
- Cryptosteel Capsule
- Blockplate (laser-etched stainless steel)
- BillFodl
- SafePal Cypher
- COBO Tablet
- Cryptotag
Specific product choice should be informed by Lopp’s stress-test reports.
Inheritance and documentation tooling:
- Casa’s inheritance documentation templates
- Unchained’s estate-planning resources
- Custom estate-planning attorney engagement
- Broader estate-planning documentation that integrates the seed-backup record — see Inheritance planning for bitcoin
The synthesis document: Bitcoin Self-Custody & Security (LegacyCipher, April 2026) — backup treated as the load-bearing discipline.
Primary practitioner sources:
- Lopp — Metal Seed Storage Stress Tests (2018, 2020, 2022, 2024); the canonical empirical reference. See Jameson Lopp.
- Blockchain Commons — Smart Custody Book; backup chapters
- Casa, Unchained, Nunchuk — vendor-specific backup guidance
As of 2026-05-14: the backup landscape is mature. Steel-backup products are widely available; the discipline is well-codified. The remaining variables are operational — which location, what verification cadence, how integrated with inheritance.
Open questions for further development
- The annual-verification cadence is the synthesis-validated default. Is this calibrated correctly? Some practitioners argue semi-annual; some argue triennial is sufficient. The right cadence depends on holding size and location stability.
- The role of SLIP-39 in the backup taxonomy is unclear in the synthesis. Is SLIP-39 a backup scheme or a custody scheme? The two function differently and the framing should be sharper.
- Memorization-as-supplement is sometimes advocated (Lopp has written about this). The pattern: memorize the seed plus maintain physical backups, so the holder has redundant access to the wallet during their lifetime. Is this a useful pattern or an over-claim?
- The “find your backup blindfolded” stress test — can the holder go to each location and retrieve each backup without prompting? Some practitioners advocate this; it is operationally heavy but uniquely thorough.
Related notes
The framing context:
- Loss vs exposure failure modes — backup is the principal defence against loss
- Threat modeling for self-custody — backup decisions depend on threat profile (environmental, socially close)
- Self-custody configuration ladder — backup discipline scales with configuration complexity
Storage and key concepts:
- Seed phrases and BIP-39 — the artifact being backed up
- Passphrases and the 25th word — the second artifact for passphrase-protected wallets
- BIP-85 child seeds — backup discipline for BIP-85 masters
- SLIP-39 and Shamir Secret Sharing — alternative backup distribution scheme
- PSBT and wallet descriptors — the third artifact for multisig setups
Adjacent discipline notes:
- Steel seed storage — specific metal backup products and patterns
- Recovery rehearsal practice — the verification practice that converts backup-as-hope into backup-as-fact
Hardware wallets:
- Hardware wallets overview — devices generate the seeds that are backed up
- Coldcard — dice-entropy contribution affects what is backed up
- BitBox — microSD backup as a controversial option
- Trezor — native SLIP-39 backup support
Custody configurations:
- Multisig setups — backup discipline multiplies in multisig
- Collaborative custody services — partner provides additional backup support
Operational security:
- Common attack vectors — seed-targeting attacks
- Operational security practices
- Common failure modes in self-custody — backup-specific failure modes
Inheritance:
The principal practitioner:
- Jameson Lopp — Metal Seed Storage Stress Tests
The sub-MOC home: