Super Smart Bitcoin
Bitcoin

Bitcoin Wallet Backup: What a Recovery Phrase Does and What Else to Record

Navy sealed recovery envelope beside a separate white inventory checklist and an unbranded hardware wallet, with yellow accents.

A bitcoin wallet backup is a way to regain access when a phone breaks, a computer fails or a signing device is lost. For many self-custody wallets, the recovery phrase is central to that plan. It may not be enough on its own. Before relying on any backup, identify who controls the keys, which wallet created them and what else its restore procedure requires.

Know what you are recovering

Bitcoin is not stored inside a device like a photograph on a phone. A self-custody wallet uses private keys to authorise spending, while its software identifies the relevant addresses and transactions. A replacement device can be useful only if you still have the material needed to recover the wallet. Keeping a working device does not protect you against losing the only usable backup.

A custodial account works differently. If a service controls the keys, you must use that service's account-recovery process. Words from an unrelated self-custody wallet cannot restore the account. If you control the keys and permanently lose access to them, there is no central authority that can reverse the loss. Bitcoin.org’s explanation of self-custody sets out that responsibility.

Find the instructions for your particular wallet before copying or testing a backup. Some wallets use a recovery phrase; others depend on a wallet file, individual keys or another documented method. A label saying “wallet” does not tell you which procedure applies. Bitcoin.org advises users to check how your wallet handles backups, including whether newly generated keys or addresses affect what must be saved.

What the phrase can and cannot do

A recovery phrase, also called a seed phrase, is a sequence of words that certain wallets use to recreate key material. A compatible deterministic wallet can regenerate keys after the original device is gone. Copy every word in the correct order and keep the phrase private. Someone with the required recovery material may be able to spend the bitcoin without your old device.

Wallets do not all use the same phrase format or address settings. Two wallets may accept the same words yet display different accounts or addresses. An apparently empty restore is a reason to check the original wallet's format, account selection and derivation settings. It does not, by itself, establish that the funds have disappeared. Record any setting your wallet says is needed; do not guess a derivation path from another wallet's guide.

Some wallets support an optional passphrase in addition to the recovery words. This is separate from a device PIN or an app password. Under BIP-39’s mnemonic specification, a different optional passphrase produces a different seed from the same words. If you used one, the words alone will not recreate that wallet. Your non-secret instructions can say that a passphrase exists, but the actual passphrase needs its own protected recovery plan.

A multisignature wallet can need more than one signer's recovery material and a record of how the wallet was assembled. Bitcoin Core’s multisignature tutorial uses a descriptor containing the signing arrangement and public-key information. One participant's words do not describe the complete wallet. Follow the backup instructions for the software and signing arrangement you actually use.

Record the wallet's recovery method

Keep a non-secret inventory alongside, but separate from, the protected backup. It should let you identify the right material and the right restore instructions without giving a reader the means to spend. The details depend on your setup:

  • Custodial account: Record the service name, your account identifier and where to find its official recovery instructions. Protect credentials through the service's recommended process.
  • Phone or desktop wallet: Record the wallet name, its documented backup format, whether a separate passphrase was used and any account settings required for restoration.
  • Hardware wallet: Record the device and companion software, the documented restore method and whether an optional passphrase or another signer is involved.
  • Wallet file or individual keys: Identify which protected file or keys are required, whether the file is encrypted and when the wallet says another backup is necessary.
  • Multisignature wallet: Identify the required signers, each signer's own recovery method and the wallet configuration or descriptor specified by its software.

These categories can overlap: a hardware device may be one signer in a multisignature wallet. Record the actual arrangement rather than choosing the first label that seems to fit. If the wallet displays a script type, account type or derivation path needed for recovery, copy it accurately from its settings or documentation. Include a neutral reference to each protected backup and the name of the official restore guide.

Do not place recovery words, private keys, an actual passphrase or an unencrypted wallet file in this general inventory. Avoid including balances, address lists or extended public keys in a document you may share; they can reveal financial activity even if they cannot authorise spending. The inventory helps you interpret a backup, but it cannot replace missing keys.

Protect against loss and disclosure

Create the backup using the wallet's own procedure, then check the copied material carefully in private. Consider damage, theft, accidental disposal and loss of access to a storage location. A single physical location can fail along with the original device. Several copies can reduce that risk, but each extra copy is another place where someone could find the secret. Choose locations you can maintain and revisit when your circumstances change.

If you use a passphrase, plan for both its loss and its disclosure. A record saying “passphrase used” will help you diagnose an incomplete restore, but cannot recreate a forgotten passphrase. Keep the phrase and passphrase protected according to the wallet's guidance, with a way to find each when genuinely needed. Do not rely on a memory-only secret unless you have accepted what forgetting it would mean.

Review the inventory after changing wallet software, adding an account, enabling a passphrase, replacing a signer or changing a multisignature setup. Check whether the wallet calls for a fresh backup or updated configuration record. Date the inventory when you verify it, so you can distinguish a checked procedure from an older note. An earlier restore test does not prove that a later change is covered.

Check that recovery works

  1. Read the wallet's restore procedure. Confirm which materials and settings it requires. If it offers a built-in backup check, use that procedure before considering a full restore.
  2. Check your copy in private. Compare the words and their order with the wallet's on-device check where available. Confirm that all required components exist. Do not photograph the phrase or paste it into an ordinary note for convenience.
  3. Choose a safe test. If you perform a full restore, use the genuine wallet flow on a trusted spare device or an environment its maker recommends. Preserve your working wallet and backup; do not wipe your only functioning device solely to test it.
  4. Compare an expected result. Check that the intended account and a known receiving address appear. A wallet that opens with different addresses has not proved recovery of the intended funds. Recheck the passphrase and account settings before drawing conclusions.
  5. Record the result without secrets. Note the date, method and what matched. If it did not match, investigate against official instructions while the original device is still available.

Never enter recovery words into a website to “verify” them. Do not send them to someone claiming to offer support or grant remote access for a stranger to inspect your wallet. Bitcoin.org’s scam guidance describes fake support requests for seed phrases and private keys. A polished page or convincing message does not make such a request safe.