Your wallet hands you 12 to 24 plain words the first time you switch it on. That short list is the master backup behind every private key the wallet will ever hold.
Hold those words and you hold the coins. Anyone else who reads them holds the coins too, and that is the uncomfortable part.
We’ll cover what the words really are, how your device builds them, and where to put them so a house fire doesn’t wipe you out and a thief doesn’t get lucky. Everything here traces back to what Ledger, Trezor and MetaMask publish, or to the standards their wallets run on.

Table of contents
So What Is a Seed Phrase, Exactly?
Call it a human-readable backup of your wallet. One enormous random number goes in, a short list of words comes out, and those words can rebuild every account on any compatible device.
Naming is a mess across brands. Ledger says Secret Recovery Phrase and calls it the backup of all the private keys stored in a wallet. MetaMask borrowed the same term, while Trezor just says wallet backup.
A private key authorizes spending from one address, and nothing more. Sitting above all of them is the seed phrase, which regenerates the lot. That is the reason it brings back your whole wallet, every account included, on a different device.
Those Words Come Off a Fixed List
They aren’t random English. Nearly every wallet follows BIP-39, a Bitcoin standard whose wordlist runs to exactly 2048 entries. Each word stands in for a number between 0 and 2047.
Somebody thought hard about people copying these out with a pen. Four letters are enough to identify any word on the list, lookalike words were struck out, and everything sits in sorted order. Ten official language lists exist, though the specification itself notes that the vast majority of BIP-39 wallets handle English and nothing else.
What Your Wallet Does to Build a Seed Phrase
Picture the words as a legible printout of one gigantic random number. Five steps get you there.
- Your device produces entropy, which is just raw randomness, somewhere between 128 and 256 bits.
- A SHA-256 hash of that entropy gets taken, and its first ENT/32 bits become a checksum tacked on the end.
- Everything is chopped into 11-bit groups, and every group points at one word on the 2048-word list.
- Those words, together with a passphrase if you set one, go through PBKDF2 using HMAC-SHA512 across 2048 iterations.
- Out comes a 512-bit seed, and every key and address you’ll ever use in that wallet grows from it.
That checksum is doing quiet work for you. Swap one word and the arithmetic breaks, so the wallet throws the phrase out instead of opening some empty account you’d never think to question.
How many words you end up with isn’t a style choice. It falls straight out of the entropy, and BIP-39 nails down the pairings.
| Random bits | Checksum bits added | Words you write down |
|---|---|---|
| 128 bits | 4 | 12 |
| 160 bits | 5 | 15 |
| 192 bits | 6 | 18 |
| 224 bits | 7 | 21 |
| 256 bits | 8 | 24 |
The Passphrase You Can Add
There’s an optional extra in BIP-39, often nicknamed the 25th word. It gets stirred into the salt next to the fixed string “mnemonic” before your seed is worked out. Pick a different passphrase and you land in a completely different wallet.
Ledger caps it at 100 characters, case sensitive, with numbers and symbols welcome. Trezor stops at 50 ASCII characters. Neither device keeps a copy, and neither company can dig one up for you.
Why the Seed Phrase Is the Only Thing That Matters
Two things can go wrong here, and neither has an undo button. Either you lose the phrase, or somebody else gets to read it.
MetaMask puts it flatly: it cannot retrieve your Secret Recovery Phrase once it’s gone, and you cannot edit or change it. Not one wallet vendor keeps a copy on file. No reset link exists, and no support ticket ends with your balance handed back.
Transactions carry the same finality. Fire coins at the wrong address, or over the wrong network, and they’re gone. Nobody can reverse a confirmed blockchain transaction, not the vendor, not the exchange, not us.
No Honest Company Will Ever Ask for It
Ledger gives us the clearest case study on record. Someone unauthorized got into its e-commerce and marketing database on June 25, 2020. A researcher on Ledger’s bounty program flagged the hole on July 14, 2020.
About 1 million email addresses spilled out. A smaller group of 9,500 customers also lost their name, postal address, phone number and order history. Payment details and credentials weren’t touched, Ledger said, and the hardware wallets, Ledger Live security and customer crypto were all unaffected.
Phishing did the real harm, and it started almost immediately. Ledger’s line hasn’t shifted since: it will never ask you for the 24 words of your recovery phrase, and any email that does is a phishing attempt. MetaMask says it more bluntly, warning that the phrase can be used to steal all your accounts.
Seed Phrases on Real Wallets
Everyone shares the standard. Nobody shares the details, and those details change where you should keep the words.

Ledger
Ledger sticks to 24 words on every device, which the company says works out to 256 bits of entropy. In the box you get a paper Recovery Sheet with 24 numbered slots, and the Ledger Flex adds a Ledger Recovery Key on top. Our Ledger Nano X review shows how the setup screens hand the words over.
Two of Ledger’s own rules are worth memorizing. Cloud-based services are off limits for the phrase, and you should never restore a hardware wallet’s seed phrase into a software wallet.
There’s also Ledger Recover, a subscription you can ignore entirely. It encrypts the entropy sitting behind your phrase, splits it into three fragments, and parks them with three companies in three countries, and any two of the three can bring your wallet back. You’ll need a passport or national identity card to sign up, although a driver’s license works for US and Canadian users.
Trezor
Trezor gives you 12, 20 or 24 words, depending on which box you opened. Model One still defaults to a 24-word BIP-39 backup, and the Model T and Safe 3 units built before June 2024 came with 12 BIP-39 words. Anything from June 2024 onward, meaning the Safe 3, Safe 5 and Safe 7, defaults to a 20-word SLIP-39 backup.
SLIP-39 is its own standard, with a 1024-word list, and nothing about it is compatible with BIP-39. Splitting is the point: a single backup can be cut into as many as 16 shares. Set it up 3-of-5 and you can lose two shares in a fire and still walk away with your coins.
Our Trezor Safe 5 review covers the device that ships with this turned on by default. Every Trezor box also holds a pair of paper backup cards, and Trezor is blunt about not filling them out digitally.
MetaMask, Electrum and Other Software Wallets
MetaMask’s Secret Recovery Phrase creates and restores the whole wallet, every account inside it included. What changes against a hardware wallet is where the phrase lives, and a machine with an internet connection is a worse home for it. That difference is exactly what the custodial versus non-custodial argument turns on.
BIP-39 isn’t universal, either. Electrum rolls its own 12-word seed worth 132 bits of entropy, reusing the same 2048-word list with different derivation, so what Electrum gives you is not a BIP-39 seed. Our Electrum wallet review digs into that.
Compatibility does flow the other way. SLIP-39 backups can be pulled into Electrum, Rabby, Sparrow and Blue Wallet, and Keystone’s hardware wallet reads the standard as well.
Where to Store a Seed Phrase Without Losing Sleep
Storage trips up more people than anything else on this page. You’re aiming for a backup that shrugs off fire, flood and a decade in a drawer, and that never once touches something with an internet connection.

- Write the words out by hand, in order, on the card that shipped with your device. Trezor’s instruction is to use a pen and never to complete those sheets digitally on a computer.
- Compare each word against the device screen while you write it down, then read the finished list back before a single coin goes in.
- Screens are the enemy here. Trezor’s rule bans storing a wallet backup digitally at all, and that ban covers screenshots, photographs, emails and Dropbox.
- The words never go into a website, a chat window or a support form. Your own device asking for them is the only moment you should be typing them anywhere.
- Once the balance starts to matter, get the phrase onto metal. Trezor recommends a steel backup against fire or flood, and paper loses that contest every single time.
- Pick a spot you actually control, like a hidden home safe, and keep it away from the eyes of guests, housemates and cleaners.
- SLIP-39 splitting buys you redundancy without one fragile hiding place. With a 2-of-3 or 3-of-5 threshold, one share can vanish and your wallet still comes back.
- Reading the words aloud sits on Trezor’s do-not list alongside digital copies, which sounds paranoid until you remember the smart speaker in the corner.
Comparing the Storage Options
| Where you keep it | Handles fire and water? | What can go wrong | What we think |
|---|---|---|---|
| The paper card in the box | No | Fire, damp, and ink that fades | Fine on day one, thin as a ten-year plan |
| A stainless steel or titanium plate | Yes | Someone finding it and walking off with it | The one upgrade we’d push almost anyone to make |
| SLIP-39 shares kept apart | Down to the material you use | Fiddly, and shares spread so wide you lose track | Earns its keep once the balance gets serious |
| A bank safe deposit box | Usually | Opening hours, plus a third party in the chain | Fine for one copy, and we wouldn’t keep them all there |
| Cloud storage, photos, a password manager | Yes | Whoever gets into the account gets the money | Ruled out by Ledger and Trezor alike |
Metal Plates Worth Buying
The Trezor Keep Metal 24-word runs $99 at the time of writing (September 2026). Its AISI 304 aerospace grade stainless steel comes with a black finish, measures 115×30 mm, and lands at 475 g. Only the first four letters of each word get punched in, and a rubber O-ring keeps water out of the capsule.
Titanium is the other family. The Cryptotag Loki sells for $89, takes up to 24 words on a single 3 mm plate, handles BIP-39 and SLIP-39 both, and carries a 1665 degrees C rating.
Zeus is the heavier sibling, spreading 24 words over two 6 mm plates with a 1667 degrees C rating. Rather than letters, it has you punch BIP-39 word numbers, which is quicker and, we’d argue, easier to botch. Our Cryptotag Zeus review runs that method through its paces.
Mistakes We See Over and Over
- Snapping a photo of the recovery sheet. That photo lands in a cloud account with none of your wallet’s defenses, so whoever gets into the account gets the coins. Paper or metal, nothing else.
- Pasting the phrase into a support chat. Since Ledger states it will never ask for the 24 words, whoever is asking is robbing you. Shut the window and report them.
- Loading a hardware wallet phrase into a software wallet just to confirm it works. Ledger warns you off this, because the phrase then sits on an internet-connected machine. A second hardware device is the safe way to test it.
- Adding a passphrase and never writing it down. Each passphrase opens its own wallet, a typo opens an empty one, and forgetting it costs you everything behind it. Keep it offline and apart from the words.
- Leaving the only copy in the drawer next to the device. A single burglary or fire takes the pair. One copy belongs somewhere else entirely.
- Burying the backup out in the garden somewhere. Damp eats the material and people forget the spot, as Trezor points out. We’d rather trust a safe you can open on a bad day.
FAQ
Is a 12-word seed phrase weaker than a 24-word one?
Barely. Trezor rates 12-word and 20-word backups at 128-bit security and 24-word ones at 256-bit, then calls all the formats extremely secure. Both numbers sit so far past brute force that the gap is academic.
Someone may have seen my seed phrase. Can I change it?
No. MetaMask is clear that you cannot edit or change your Secret Recovery Phrase. Generate a fresh wallet, move every coin over, and retire the old one.
Does my seed phrase work in another brand of wallet?
A BIP-39 phrase does. According to Trezor, you can type a BIP-39 backup into a new Trezor or any wallet that supports the standard. SLIP-39 keeps a shorter guest list: Trezor Safe 7, Safe 5, Safe 3 and Model T, plus imports into Electrum, Rabby, Sparrow and Blue Wallet.
Can I cut my seed phrase in half and hide the pieces separately?
Please don’t try that with a BIP-39 phrase. Handing someone half the words shrinks the guessing job enormously, and neither half opens the wallet by itself. SLIP-39 multi-share exists for exactly this, with thresholds like 2-of-3 that split a backup properly.
What’s a passphrase, and should I use one?
It’s an extra secret blended with the words that opens a separate wallet. Ledger permits up to 100 characters; Trezor stops at 50 ASCII characters. Strong stuff, and unforgiving, since neither vendor keeps a copy and forgetting it seals off whatever you put behind it. We’d only bother once you’re comfortable juggling two secrets rather than one.
Is a metal backup actually worth it?
Depends what you’re holding. Trezor recommends steel against fire and flood, and you’re looking at $99 for the Trezor Keep Metal 24-word or $89 for the Cryptotag Loki. Once your coins are worth more than a few plates, the plate wins easily.
The Short Version
12 to 24 words rebuild your entire wallet, and nobody at any vendor holds a spare. Write them by hand, check them against the device screen, then keep them off every screen and cloud account you own.
Once you’ve got a balance worth defending, move the words onto metal and stash a second copy somewhere a house fire can’t reach. And if you want redundancy without betting everything on one hiding place, a SLIP-39 split at 2-of-3 is the tidiest option on the table right now.
Treat everything above as general information, not financial, legal, or investment advice. Features and prices move around, so check the vendor’s own page before you buy.



