Where to store a seed phrase: metal, locations, handoff
Where to store a seed phrase: stamped metal in two separated places, never digital — and hand over the map, not the words. Comparison table and checklist.
Store a seed phrase offline on stamped metal, in at least two locations far enough apart that one fire or flood cannot reach both — never in any digital form. Keep one copy concealed at home and a second off-site, and arrange things so no single location holds enough to spend on its own. Hand the people who depend on you the location and the instructions in advance; never hand them the words.
What are you actually storing when you store a seed phrase?#
You are storing the wallet, not a hint about the wallet. BIP-39 describes the mnemonic sentence as a human-readable transcription of computer-generated randomness that backs up a wallet seed, and notes "the sentence could be written on paper or spoken over the telephone" — which is exactly why anyone who reads the words has the coins. The same spec sets the allowed entropy size at 128 to 256 bits, producing mnemonics of 12, 15, 18, 21, or 24 words.
That property sets both tests below: the medium has to survive fire and water, and the location has to survive people. Jameson Lopp maintains a public database of physical attacks against bitcoin owners — home invasions, kidnappings and extortion to extract access — running from December 2014 through December 2025, while noting "this list is not comprehensive; many attacks are not publicly reported". Concealment is a security control, not paranoia.
Where should you store a seed phrase? The options compared#
| Location or method | Theft resistance | Disaster resistance | What your people face later |
|---|---|---|---|
| Paper in a drawer or file | Low — readable by anyone who opens it | Low — "ink can wear off, water could leave it illegible, and fire could destroy it" | Easy to find, easy for a stranger to find first |
| Laminated paper in a home safe | Moderate — a burglar "could more easily break into your home and open the safe than get inside your safe deposit box at your bank" | Moderate — lamination makes paper waterproof "at a minimum"; fire rating still governs | Accessible with the combination and a pointer |
| Stamped metal, concealed home safe | Moderate, higher if concealed | High — survives ~2000°F for 10 minutes followed by water submersion in Lopp's fire test | Same as above, and legible after a structure fire |
| Metal in a bank safe deposit box | High against burglary | High | Slow and rule-bound — see the box section below |
| Split shares across locations (SLIP-39) | High — "knowledge of fewer than the required number of parts does not leak information about the master secret" | High, if shares are separated | Recoverable only if the threshold is reachable and understood |
| Multisig quorum | High — eliminates single points of failure, at the cost of convenience | High | Needs the wallet configuration, not just keys |
| Custodial exchange | Delegated to the platform | Delegated to the platform | Coinbase supports no beneficiary designation, so heirs go through probate |
Two rows in that table need their caveat stated rather than implied. Unchained states that "it's not a good idea to use a safe deposit box for singlesig or singlesig + passphrase" — boxes earn their place when one item is not enough to spend. And custody is a trade, not a fix: the Ontario Securities Commission found QuadrigaCX's Gerald Cotten became the sole individual in control of customer funds in 2016, running the business "as he saw fit, with no proper system of internal oversight or controls", with roughly 76,000 clients losing at least 169 million dollars. Creditors were ultimately offered about 13 cents on the dollar.
Why should a seed phrase never touch a phone, cloud, or camera roll?#
Because a photograph of the words is the words. Ledger states a seed phrase "must never be entered into any smartphone, computer, or other device that can connect to the internet," and that taking pictures of it or uploading it to cloud storage compromises security. Trezor's own Shamir documentation repeats it for shares: "Never make digital copies of your recovery seed or recovery shares. Never upload them online!"
The scale of the surrounding fraud economy explains the strictness. The FBI's Internet Crime Complaint Center recorded more than 11 billion dollars in reported cryptocurrency-related fraud losses in 2025 — a 22 percent rise on the prior year — with crypto investment fraud alone accounting for about 7.2 billion. Cloud notes and password-manager text fields are searchable targets in that environment.
Does metal really beat paper, and does any metal do?#
Metal wins the fire and water argument, but the product matters. Lopp's stress tests apply "~2000°F heat for 10 minutes," after which "the device was submerged in a bucket of water to simulate a firefighter putting out a structure fire", and go further with 12-plus hours in muriatic acid and a "20 ton hydraulic press to deform the devices and simulate something like a large building collapsing on top of the device".
Not everything survives. The Copper Seed Safe, a thin copper sheet, failed catastrophically under crush pressure and suffered partial data loss in acid; the 1.8mm CipherTag failed catastrophically under crush force. Buy thickness and a hard alloy, not marketing copy. Vendor guidance points the same way: Ledger recommends a steel backup that makes the phrase "resistant to fire, water damage, and other physical threats", and Unchained recommends "using metal backups wherever possible," with lamination as the paper minimum.
What does a safe's fire rating actually promise?#
Less than people assume. UL 72, "Tests for Fire Resistance of Record Protection Equipment," classifies safes by what they protect: Class 350 for paper records, Class 150 for paper plus non-paper media such as magnetic tape, Class 125 also for flexible computer disks. A Class 350 1-Hour rating means the interior stays under 350°F for an hour under test conditions reaching 1,700–1,850°F — a threshold chosen because paper chars around 387°F and burns at 451°F. A paper-rated safe is being asked to do less than a metal plate does unaided — which is the argument for putting metal inside the safe rather than trusting the safe alone.
How many copies, and how many locations?#
Borrow the framework that already exists for data. The 3-2-1 rule CISA recommends calls for three copies of critical data, on at least two different types of media, with at least one stored offline and off-site. Applied to a seed, the off-site clause is the load-bearing part.
Unchained sets the distance at two scales. Within a property, two storage areas should be "hidden and separate enough so that multiple seed phrases won't be simultaneously destroyed or compromised in an unexpected event like a burglary or fire". Across properties, their collaborative 2-of-3 multisig example counts four items to protect — two hardware wallets and two seed phrases — stored "geographically separated, in some combination of" a primary home safe, a secondary home safe, safe deposit boxes at two different banks, or a safe held by trusted family. Copies in the same building are one copy with extra steps.
How do you check the backup works without exposing it?#
Rehearse it on the device, not on the internet. Trezor's check-backup flow has the device compare the backup held in its own memory against the words you enter, with no balance or fund access involved. Trezor recommends running it before you wipe the device and before every firmware update, and the dry-run has been part of Trezor firmware since version 1.5.1.
CISA's ransomware guidance tells organizations to maintain offline, encrypted backups and to test restoration regularly; an untested seed backup is an assumption with a balance attached to it.
Why is a safe deposit box a poor place for the only copy?#
Because the box is governed by rules you do not control, and its contents are not covered by the protection people assume banks provide. The FDIC is explicit that "the contents, including cash, checks or other valuables, are not insured by FDIC deposit insurance if damaged or stolen," and that "financial institutions generally do not insure the contents of safe deposit boxes" — a separate rider on homeowner's or renter's insurance is the only route.
Access is the harder problem. The FDIC notes the rules for entering a box after the owner's death "depends on state law," and those rules "restrict entry into the safe deposit box to certain individuals and permit entry only under controlled situations". In practice:
- A sole-name box generally waits for the court. It stays sealed until an executor or administrator presents court-issued letters, though some states allow a supervised opening to search for a will.
- Opening a box and emptying it are different rights. Florida law lets a spouse, parent, adult descendant or named personal representative "open and examine the contents" on proof of death — but removing them falls to an appointed personal representative, who must conduct the initial opening before two qualifying witnesses and file an inventory with the court within 10 days. Examining your metal plate is not the same as taking it home.
- Early access is narrow by design. Clark County, Nevada's self-help guidance describes a judge-signed order to open the box solely to remove the will: "Nothing else will be permitted to be removed from the safe-deposit box if this petition is granted--only the will" — with a seven-step priority hierarchy of relatives, roughly three to four weeks for a signed order on an unopposed petition, and a possible bank drill fee if the key is missing. New York is comparable: SCPA § 2003 lets a court order the box examined and inventoried, but directs delivery only of a will, a deed to the burial plot, or a policy of insurance to its named beneficiary. A metal seed plate is none of those.
- A forgotten box can drift out of reach entirely. The OCC states that if a box is classified as abandoned, "the bank may be required to transfer the contents of the safe deposit box to the state treasurer or unclaimed-property office in a process called escheat," with the dormancy period "defined by state statute", and NAUPA's tables show safe deposit box dormancy ranging from 1 year in Alaska to 7 in Massachusetts.
- Nobody finds a box they were never told about. Ledger notes "safe deposit boxes become inaccessible if executors don't know which institution holds them".
A box is a good place for one component of a split setup. It is a poor place for the one object that spends everything.
Why does writing a seed phrase into your will backfire?#
Because a will is a broadcast channel with a delay. FindLaw states plainly that "when you die, and your estate goes through the probate process, your will becomes part of the public record," and instructs: "Do not include your private keys in your will," because that "information allows hackers to access your private keys and potentially steal your cryptocurrencies".
The timing is the part people get wrong. A will is not public before it is filed; it becomes public when filed with the probate court, after which anyone can view the case file at the clerk's office or, in some counties, online. Once a case is open, anyone — heir or not — can read documents in the file or obtain copies. New York's Surrogate's Court is a court of record whose files are public with very limited exceptions.
The correct structure is a pointer, not a payload. FindLaw's recommended alternative is to "make a written list of any digital wallets and private keys and store the information in a safe-deposit box or fire-proof safe," which the personal representative accesses when administering the estate, and estate-planning practitioners describe a letter of instruction or separate memo held by the executor or attorney. Note also what the statutes can and cannot reach: RUFADAA, maintained by the Uniform Law Commission and enacted in most US states, gives fiduciaries a path to a decedent's digital assets, but it operates on custodians and provider disclosure — a self-custodied private key has no custodian to compel.
Why not simply tell one trusted person now?#
Because the moment they know the words, they can spend the coins, and so can anyone who reaches them. Ledger's guidance is that "a seed phrase must never be shared with anyone and must be kept out of anyone else's reach", with no exception carved out for family. Ledger frames inheritance planning as "the art of sharing secrets, but every heir, guardian, or service you add becomes a potential point of failure (or a target)", and Unchained warns that "sharing information about a singlesig self-custody setup is risky" while you are alive, since "ensuring your hardware devices, seed phrases, and PINs are secure while you're still alive should be your top priority".
The other half is competence, not honesty. Ledger describes the failure directly: an heir "eager to access funds—connects their wallet to a 'support agent' who asks them to 'verify ownership' by signing a transaction, which drains the account". Whoever receives your instructions needs a rehearsal, not just an envelope.
How do you split the secret so no one holder can spend?#
Two standards do this, and they fail in different ways.
Shamir shares (SLIP-39). SLIP-0039, "Shamir's Secret-Sharing for Mnemonic Codes," splits a master secret into parts distributed among participants, and is "mainly intended as a replacement for BIP-0039", with the core property that knowledge of fewer than the required number of parts does not leak information about the master secret. A Trezor share is 20 or 33 English words, to be shared "among trusted friends and/or secure locations". The honest downsides: if you lose more shares than the threshold allows, recovery is impossible, auto-correction of transcription errors can produce a mnemonic that is "valid but different from the original," and "use of such a mnemonic may cause funds to be lost irrecoverably", and the two-level group scheme "should only be used if you fully understand how to manage complex wallet backup structures" — a complexity warning from the vendor that invented it.
Multisig. Bitcoin Optech defines multisignature as signatures created using two or more private keys, with threshold signatures allowing k-of-m signers. Unchained says multisig "offers much better security than singlesig by eliminating single points of failure," since "each key can sign independently, at a different time and place," but "comes with the trade-off of lesser convenience", and names the lack of reliable technical support for DIY multisig as a real cost. The subtle failure mode is not key loss but descriptor loss: the wallet configuration holds the master fingerprints, the quorum size, all of the xpubs, all of the derivation paths and the script type — and "all of the xpubs are required". In a 2-of-3 setup, holding two master private keys is not sufficient — you "would also need the xpub from the third master private key" — and recovery "can be challenging—if not impossible—without the wallet configuration". Back up the configuration file everywhere you back up metal.
For handoff specifically, Unchained's approach is to "share a key (or backup of the said key) with an executor, trustee, or other trusted third party," alongside "simple documentation detailing your security model and how your loved ones can orchestrate the moving of funds", and Ledger recommends multisig on the grounds that "no single mistake should cost you everything". Casa illustrates the principle in a shipped product: a three-key vault where the recipient uses a shared mobile key plus a signature from the Casa Recovery Key to reach the 2-of-3 threshold, and where neither Casa nor the recipient can spend alone. The recipient holds a key ahead of time but "can't initially use it or see the vault balance", and the trigger is time-locked: requesting access "starts a six month timer, and sends a ton of notifications every month to the owner" — no death certificate is required, and if the owner does not reject the request within six months, access is granted.
What does a passphrase change about where you store things?#
It separates the findable object from the spendable one. BIP-39 specifies an optional passphrase, and because "every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available," the scheme provides plausible deniability. In practice, a passphrase "opens a separate set of accounts with brand-new addresses, and those accounts start empty"; Ledger "does not store it anywhere," and "if you lose or forget it, your hidden accounts become inaccessible". Someone needs "both your 24 words and your Ledger Passphrase, the 25th word" to reach those accounts — "if they only have your 24 words, they can only access your regular accounts".
That lets the metal plate live somewhere reachable while the passphrase lives on a different path entirely. It also creates a second secret no vendor can reset for you, so the passphrase needs its own backup and its own line in your instructions.
What should you hand over in advance? A working checklist#
Share the map and the method. Never share the words.
- Stamp the phrase into thick metal, not paper, and not into any device. Ink wears, water blurs, fire destroys.
- Make a second copy and separate the copies geographically, hidden and separate enough that one event cannot destroy both, following the three-copies, two-media, one-off-site pattern.
- Decide whether any single location can spend. If yes, split it — a single Shamir share reveals nothing below the threshold — or move to a quorum. Only then does a safe deposit box stop being a bad fit, as it is for singlesig.
- Back up the wallet configuration alongside the keys; without the descriptor and all xpubs, a quorum of keys may still not recover the funds.
- Verify the backup on the device, comparing your written words against the device's own memory, with no funds involved — at minimum before every firmware update or wipe.
- Write the instructions, not the secret. Name the institution and branch for any box, since executors cannot reach a box they don't know exists, and keep it out of the will itself — the will points, the separate document holds the detail.
- Rehearse with the person who will act. The documented failure is an untrained heir signing a transaction for a fake support agent. This is the same discipline as leaving passwords for family if you go unreachable: the recipient needs to know the process before they need it.
- Review it once a year, alongside the backup check, and confirm any box fees are current — dormancy periods are set by state statute and start the clock toward escheat.
Nobody publishes a reliable count of coins lost because a backup existed but no one could follow it — by definition those losses are silent, and the widely circulated estimates of "lost bitcoin" measure dormant coins, not failed handoffs. What is documented is the mechanism: a box no executor knew about, a court order that releases only a will, a share threshold nobody understood. Steps 6 and 7 are what close each of them.
Proceedly covers that last layer: a check-in you answer on a schedule, where missing it past a grace window means a person you name confirms — or, on a paid plan, it releases automatically — before your encrypted handoff plan reaches the people who depend on you. It holds your instructions and where the keys live, never the seed phrase, private keys or passwords themselves.
FAQ: what else do people ask?#
Is a bank safe deposit box the safest place for my seed phrase? Only as one part of a split setup. Unchained advises against using a box for singlesig or singlesig plus passphrase, and the FDIC confirms box contents are not covered by deposit insurance and are generally not insured by the institution.
Can I store the phrase in my password manager or an encrypted cloud file? No. Ledger's rule is that it must never be entered into any internet-connected device, and photographing or uploading it compromises security.
Is metal always safe, or can a metal backup fail too? It can fail. In Lopp's testing, a thin copper product failed catastrophically under crush and lost data in acid, and a 1.8mm device failed catastrophically under crush force. Thickness and alloy decide the outcome.
Should the phrase go in my will so my family can find it? No. A will becomes part of the public record in probate, and FindLaw explicitly says not to include private keys. Keep the detail in a separate secured document the representative can reach.
How many words should my phrase be, and does it change storage? BIP-39 allows 12, 15, 18, 21, or 24 words depending on entropy from 128 to 256 bits. Longer means more characters to stamp; the location rules are identical.
How often should I test the backup? Before wiping the device and before every firmware update, in line with CISA's guidance to keep offline backups and test restoration regularly. Once a year is a reasonable floor if your firmware rarely changes.
What if I use an exchange instead of self-custody? Recovery becomes a paperwork process. Coinbase offers no beneficiary designation, and an executor must supply a death certificate, probate documents such as Letters Testamentary, Letters of Administration or a small-estate affidavit, government photo ID, and a signed letter instructing Coinbase what to do with the balance.
Sources#
- BIP-39 — Mnemonic code for generating deterministic keys
- SLIP-0039 — Shamir's Secret-Sharing for Mnemonic Codes
- Bitcoin Optech — Multisignature
- Jameson Lopp — Metal bitcoin seed storage stress tests, round VI
- Jameson Lopp — Known physical bitcoin attacks
- Ledger Academy — Best ways to protect your recovery phrase
- Ledger Academy — Passphrase, an advanced security feature
- Ledger Academy — What happens to your crypto when you die
- Trezor — What is Shamir backup
- Trezor — SLIP39 FAQs
- Trezor — Check backup on Trezor Safe 5
- Trezor blog — Test your seed backup with dry-run recovery
- Unchained — How to store bitcoin seed phrase backups
- Unchained — Singlesig vs multisig
- Unchained — Bitcoin wallet configurations
- Unchained — How to make a bitcoin inheritance plan
- Casa — Inheritance FAQs for recipients
- Cointelegraph — Casa's multi-key solution for bitcoin inheritance
- CISA — Back up your business data
- CISA — #StopRansomware Guide
- UL Standards Catalog — UL 72, Tests for Fire Resistance of Record Protection Equipment
- Safe and Vault Store — Fire ratings explained
- FDIC — Five things to know about safe deposit boxes, home safes and your valuables
- OCC HelpWithMyBank — Old safe deposit boxes and escheat
- NAUPA — Safe deposit box property type and dormancy periods
- Civil Law Self-Help Center (Clark County, NV) — Safe deposit boxes
- New York SCPA § 2003 — Examination of safe deposit box
- Florida Statutes § 733.6065 — Opening safe-deposit boxes
- Atticus — Safe deposit box regulations
- FindLaw — Can you inherit crypto?
- FreeWill — Are wills public record?
- Trust & Will — Are probate records public?
- Sciacca Law — Public access to New York Surrogate's Court records
- NY Estate Plan — Cryptocurrency estate planning
- Uniform Law Commission — Fiduciary Access to Digital Assets Act committee
- FBI IC3 — 2025 Internet Crime Report
- Ontario Securities Commission — QuadrigaCX review
- CoinDesk — QuadrigaCX bankruptcy claimants to get 13% on the dollar
- Coinbase Help — Claim a decedent's Coinbase account