What is a seed phrase and how to store 12 or 24 words

By Vault Capital Team·Published on ·Updated on ·6 min read·Also available in Português

A seed phrase is the list of 12 or 24 words that the BIP39 standard uses to generate every private key in a crypto wallet. The words come from a fixed list of 2,048 terms, and a 24-word seed encodes 256 bits of randomness, according to the specification kept in the Bitcoin repository on GitHub. Whoever holds the words holds the funds, and whoever loses them loses access, because neither Ledger nor Trezor keeps a copy.

In short

  • The seed is the wallet. The device, the app and the PIN are only ways to use it.
  • The best backup is physical, offline, tested and kept in two places.
  • Nobody legitimate asks for the seed by message, form or in a first conversation: not support, not an advisor, not a "wallet checker".

Where to keep it: five backup media compared

Medium Fire and water Theft Loss or forgetting Approximate cost
Paper High: burns and smudges Medium: readable by anyone who finds it Medium: disappears in a move Near zero
Metal plate Low: 304 stainless steel survives a house fire Medium: readable by anyone who finds it Low: lasts decades US$ 99 (Trezor Keep Metal, Trezor's site, September 2026)
Password manager Low High: online and dependent on one master password Low Free to US$ 5 a month
Photo or cloud Low Very high: one account leak exposes everything Low Zero
Memory only None Low Very high: illness, accident or death erase it Zero

Metal is the only medium that handles fire, water and time at once. Paper works as a temporary copy. Photos, cloud storage and password managers are out because a digital seed becomes a target for malware and data leaks, like the one at Ledger's own online store in 2020, which exposed 1 million email addresses and 9,500 postal addresses, according to the company's statement of July 29, 2020.

What BIP39 is

BIP39 is the 2013 proposal that standardized the words. The process starts with a random number of 128 to 256 bits, appends a few checksum bits and splits the result into 11-bit chunks. Each chunk points to a position in the 2,048-word list, so 128 bits become 12 words and 256 bits become 24. The BIP39 specification also defines that the words go through 2,048 rounds of PBKDF2 to produce the seed that derives the keys.

Two practical consequences follow. Order matters: the same 12 words in a different order produce a different wallet. And the list has only 2,048 entries, so you can check that every word you wrote down actually exists. The specification recommends the English list, since most wallets accept no other language.

Why the seed is the wallet

Ledger's documentation puts it plainly: never share the 24 words with anyone, not even with Ledger, because the company never asks for them. Trezor says the same: anyone with the backup can access the wallet without the device. The hardware wallet protects the key while it is in use; the seed is what rebuilds everything on any compatible device.

This means a broken Ledger, a Trezor wiped after wrong PINs or a lost phone cost nothing if the seed exists. It also means the reverse: an intact device does not help if a thief has the words. In 2025, personal wallet compromises accounted for 20% of all value stolen in crypto, across 158,000 incidents with at least 80,000 victims, according to Chainalysis in a report dated December 18, 2025.

How to store it

Write the words by hand, numbered, the moment the wallet is created. Check each one against the BIP39 list. Run a restore test: wipe the device and recover the wallet from the paper before depositing anything meaningful. Only then stamp it in metal.

Keep two copies in different places, for example home and a bank safe deposit box. Neither copy should sit next to the device. Tell one trusted person where the copies are, without revealing the contents, so heirs can find them. What to do when a backup fails is covered in lost access to your crypto wallet: what to do.

What never to do

Do not photograph it. Do not type it into a website, form or chat, even one that looks like Ledger's or MetaMask's. Do not keep it in email, phone notes or the cloud. Do not split the words among relatives as a form of protection: 12 known words out of 24 shrink the problem to a search an attacker can run.

Do not buy a used hardware wallet or one from an unofficial reseller. A device that arrives with a printed seed was set up by someone else. How to split funds between a daily wallet and a storage wallet is covered in hot wallet vs cold wallet.

The passphrase, or 25th word

A passphrase is extra text that, combined with the seed, opens a different wallet. Ledger accepts up to 100 characters and Trezor up to 50, both case-sensitive, according to the official documentation checked in September 2026. A single wrong character opens an empty wallet, and neither company stores the passphrase.

It protects against physical theft of the backup: whoever finds the paper sees only the wallet without the passphrase. The cost is one more secret to keep. Trezor's passphrase guide recommends writing it down, storing it apart from the seed and testing access regularly. It makes sense for large holdings; for someone starting out, a well-kept seed is enough.

Crypto assets carry high risk, including significant volatility and the possibility of losing the invested capital. This article is educational and is not a recommendation.

Frequently asked questions

Is a 12-word seed less secure than a 24-word one?

In practice, no. Twelve words carry 128 bits of randomness, already beyond the reach of any current computer. Twenty-four words add margin for the future and are Ledger's default.

Can I change my seed after creating it?

No. The seed is fixed. To change it, create a new wallet, move the funds and retire the old one. Do this whenever you suspect the words were exposed.

I am missing two words. Is everything lost?

Probably not. With 22 known words in order and a wallet address to check against, a recovery service can test the remaining combinations. Above four missing words the odds drop sharply.

Does the seed work in any wallet?

It works in any BIP39-compatible wallet, which includes Ledger, Trezor, MetaMask and Electrum. Some coins use different derivation paths, so you may need to select the right path when restoring.

Let's talk

Storing the seed correctly is the half of self-custody nobody teaches at the exchange. At Vault's Self-Custody Immersion the backup is made and tested live, with a succession plan, and nobody ever needs to see your words. Vault Capital is a securities advisory firm authorized by Brazil's CVM under Resolução CVM nº 19/2021, never takes custody of client assets, and the most common questions are answered in our FAQ.

Want to hold your crypto safely, on your own?

Vault's Self-Custody Immersion teaches wallets, seed backups and succession planning, hands on.

Learn about the Immersion