← All articles

Seed Phrase: What It Is and How to Protect It

Crypto Industry

Crypto Go Team · Published · 10 min read

A seed phrase is a list of 12 or 24 ordinary words that your wallet generates when you create it, and that can restore every key in the wallet on a new device. Whoever holds those words controls the crypto, which is why they are also called a recovery phrase or backup phrase. Nobody can reset them for you, so protecting them well is one of the most important habits in crypto.

In brief

  • A seed phrase is a human-readable backup of your wallet's master key, usually 12 or 24 words, and the order of the words matters.
  • Anyone who has the words can move your funds, and if you lose them together with the device, nobody can restore your access.
  • Write the words on paper or metal, keep them offline in a safe place, and never type them into a website, chat or app.
  • No legitimate support team, exchange or trading bot has a reason to ask for your seed phrase.
Seed Phrase: What It Is and How to Protect It
In this article · 10 min read
  1. What a seed phrase is
  2. How a seed phrase works, step by step
  3. Seed phrase, private key, password and PIN: what is the difference?
  4. What can go wrong
  5. How scammers go after seed phrases
  6. How to store a seed phrase safely
  7. What not to do with your seed phrase
  8. Where this fits: wallets, exchanges and automation
  9. How to start, step by step
  10. Checklist before you add funds
  11. Frequently asked questions
  12. Sources

What a seed phrase is

A crypto wallet does not store coins. Your coins are recorded on the blockchain, and the wallet stores the keys that let you spend them. Writing down a long random key by hand would be error-prone, so modern wallets turn it into words. Wikipedia's article on the cryptocurrency wallet describes a seed phrase as a random list of 12 to 24 dictionary words, an unencrypted form of the private key, which can be used to regain access to the wallet and its coins if the wallet is misplaced, damaged or compromised.

The most widely used standard is BIP-39, a Bitcoin improvement proposal that describes a mnemonic sentence, a group of easy-to-remember words, for generating deterministic wallets. In BIP-39 each word is picked from a list of 2,048 words, and the sentence includes a checksum so that a mistyped word can usually be detected. The proposal also notes that the sentence can be written on paper.

How a seed phrase works, step by step

Seed phrase: the wallet generates words, you write them down, and the words later restore the same wallet on a new device
Seed phrase: how the words create and restore a wallet

  1. The wallet generates the words. When you create a new wallet, it produces random data and converts it into 12 or 24 words.
  2. The words stand for a master key. From that one starting point the wallet derives all your private keys and addresses, a design called a deterministic wallet.
  3. You write the words down. The wallet shows them once, usually with a request to confirm a few of them.
  4. You keep the backup offline. The paper or metal copy is stored somewhere safe, away from your phone and computer.
  5. You restore if needed. On a new phone or device you enter the words in the same order, and the same keys and addresses reappear.

Bitcoin.org explains the practical side in Securing your wallet: most modern wallets are deterministic, so a single backup of the recovery phrase is enough to restore all past and future addresses, and a backup kept in a safe place can protect you against computer failures and many human mistakes.

Seed phrase, private key, password and PIN: what is the difference?

These four are often confused, and the confusion costs people money.

What it is What it does If someone else has it
Seed phrase 12 or 24 words Restores the whole wallet They can take everything in it
Private key A long secret number Signs transactions for one address They can take what that address holds
Password Text you choose Unlocks the app on your device It is not enough without the device, in many wallets
PIN A short code Unlocks a hardware wallet Usually limited by attempt counters

The key point is that the seed phrase sits above the others. A strong password or PIN protects the device in your hand, but the words can rebuild the wallet somewhere else with no password at all.

What can go wrong

There are two opposite risks, and a good backup has to handle both.

  • Someone else sees it. A photo in your gallery, a note in a cloud drive, a screenshot or an email can all be read by malware or by anyone who gets into that account. Bitcoin.org warns that any backup stored online is highly vulnerable to theft.
  • You cannot find it. If the phone is lost, the device breaks and the paper has burned or been thrown away, the funds cannot be recovered by anyone.

The same recovery-phrase risk appears in the EBA factsheet on crypto fraud and scams, published on 15 December 2025: it says never to share passwords, private keys or seed phrases, because anyone with access can take control of your assets, and that losing private keys means a permanent and irreversible loss of access to them. It adds that, unlike bank transfers, a crypto transfer is usually impossible to recover once made.

How scammers go after seed phrases

Because the words are the whole prize, many scams are built to extract them. Bitcoin.org's scams page lists several patterns:

  • Fake support. Scammers pose as support staff for wallets or exchanges, often after you post a question publicly, and ask for the seed phrase under the pretext of verifying your account. The page states that no legitimate support representative will ask for it or for your private key.
  • Fake recovery services. A second variant targets people who were scammed before, promising to recover lost funds for an upfront fee.
  • Fake hardware wallets. Counterfeit devices are sold on third-party marketplaces, sometimes with a pre-generated phrase known to the attacker. The advice is to buy only from the manufacturer or an authorised reseller and always generate the words yourself on first use.
  • Fake websites and QR codes. Never enter the words into a site you reached through a link or QR code.

The scale of the problem is large. Chainalysis reported in its analysis of crypto theft in 2025, published on 18 December 2025, about 158,000 incidents of individual wallet compromises affecting around 80,000 victims in 2025, worth roughly 713 million US dollars in total. Not every one of these involved a recovery phrase, but they show how often personal wallets are the target.

How to store a seed phrase safely

There is no single perfect method, and what works depends on the amount and on how you live. These practices are widely recommended:

  • Write it by hand, in order, on paper at first. Number the words, and check the spelling against the wallet's word list. Metal backup plates exist for people who worry about fire or water, and many people consider them worth the cost for larger amounts.
  • Keep it offline. No photo, no screenshot, no notes app, no email to yourself, no password manager entry you cannot fully trust.
  • Use more than one location. Bitcoin.org points out that single points of failure are bad for security, and suggests keeping copies in more than one physical place.
  • Let the device create it. With a hardware wallet the words are generated on the device. Never use a phrase that came already written on a card in the box.
  • Test the backup. Before you put a large amount in a wallet, restore it once with a small amount to be sure the words work.
  • Plan for the unexpected. Bitcoin.org also reminds readers that funds can be lost forever if nobody knows where your wallets or backups are. Think about who could find them if you could not.

A common extra protection is the optional passphrase mentioned in BIP-39, sometimes called the 25th word. It creates a different wallet from the same words, so a stolen paper alone is not enough. It also adds a second secret to lose: without the exact passphrase, the funds in that wallet cannot be reached, so use it only if you are sure you can manage it.

What not to do with your seed phrase

  • Do not type it into a website, app, chat window or form, even one that looks like your wallet's.
  • Do not read it to a support agent, however professional they sound.
  • Do not store it in photos, screenshots, cloud drives or email.
  • Do not use a seed phrase that someone else generated for you.
  • Do not share it with a friend, a "broker" or a "recovery expert".
  • Do not enter it into a trading bot or any service that claims it needs it to trade: trading tools that work with an exchange do not need your wallet's words.

Where this fits: wallets, exchanges and automation

A seed phrase belongs to a wallet where you hold the keys yourself. If you keep your crypto on an exchange, the platform holds the keys and your protection is your account security, with a strong password and two-factor authentication. If you are still choosing where to buy, our guide to buying cryptocurrency safely covers the first steps.

Crypto Go Bot, which we built, trades your own Kraken account through an API key that can trade but cannot withdraw, so connecting it does not involve any recovery phrase at all. Trading is risky and the bot also closes trades at a loss, whatever the setting. The point here is simpler: keep custody and trading separate, and never hand your words to any tool.

John Bax's book Cryptocurrency Investing explains wallets, private and public keys and how to hold crypto step by step, before moving on to investing.

How to start, step by step

  1. Choose a reputable wallet, preferably from the manufacturer or a well-known developer, downloaded from its official site.
  2. Create the wallet yourself and choose 12 or 24 words if the wallet offers a choice.
  3. Write the words down by hand, in order, with no one watching and no camera nearby.
  4. Check the backup by reading it back against the wallet's confirmation screen.
  5. Store it offline, ideally in two places, and out of sight.
  6. Send a small test amount and practise a restore before you add more.
  7. Think about the future: decide who could find your backup if you could not.

Checklist before you add funds

  • The words were generated by my wallet, not given to me.
  • They are written on paper or metal, in order and legible.
  • No photo, screenshot or cloud copy exists.
  • I stored the backup in a safe place that only I can reach.
  • I tested a restore with a small amount.
  • I know that no support team will ever need the words.

Frequently asked questions

What is a seed phrase?

It is a list of usually 12 or 24 words that your wallet generates and that can restore all of the wallet's keys and addresses. Anyone who knows the words in the right order can control the funds.

Is a seed phrase the same as a private key?

Not exactly. A private key signs transactions for one address, while the phrase is a readable form of the master key from which many private keys are derived. Protect both, and treat the words as the more powerful secret.

What happens if I lose my seed phrase?

If the wallet still works on your device, create a new wallet with a new phrase and move the funds there while you can. If you lose both the phrase and the device, the funds cannot be recovered by anyone.

Can I store my seed phrase on my phone or in the cloud?

Most guidance says no. Any backup stored online is exposed to malware and account takeover. A paper or metal copy kept offline avoids that, at the cost of having to look after a physical object.

Does a hardware wallet remove the need for a seed phrase?

No. A hardware wallet generates the words and keeps the keys safe in the device, but the written backup is still what lets you recover if the device is lost or broken.

Will a company ever ask for my seed phrase?

No legitimate support team, exchange or wallet maker has a reason to ask for it. Anyone who does, by chat, email or phone, should be treated as a scammer.

Is a 24-word phrase safer than a 12-word one?

A 24-word phrase encodes more randomness, but a 12-word phrase is already very hard to guess. In practice, how you store the words matters far more than their number.

Sources