Wild.io
Crypto Basics

Seed Phrases and Private Keys: How to Secure Your Crypto

A seed phrase is the human-readable backup of your crypto keys. Learn how private keys work, the never-share rules, and how to store a phrase safely.

PNPriya Nair7 min readUpdated
Cover image for “Seed Phrases and Private Keys: How to Secure Your Crypto”
On this page

The short answer

A seed phrase is a list of 12 or 24 everyday English words that backs up every private key in your crypto wallet. Whoever holds those words controls the funds, no exceptions. Write the phrase on paper or steel, keep it offline in two locations, and never type it into any website or app that asks.

Your wallet app is just a viewer

The first idea to get right: your crypto isn't inside the wallet app. Coins never leave the blockchain, the shared ledger that records who owns what. What the app holds is your keys, the secret credentials that let you move those coins.

That makes the app closer to a window than a vault. Delete it, drop your phone in a lake, buy a new laptop, and your funds are untouched. They're still sitting on the chain, waiting for anyone with the right keys to spend them.

The flip side is less comfortable. If someone else gets your keys, they can spend your coins from their own device, and no app setting of yours can stop them. Keys control funds. Apps just display them. If the ledger part is new to you, our cryptocurrency basics guide covers how ownership on a blockchain actually works.

What is a private key?

A private key is an enormous secret number, so large that guessing one is practically impossible. Your wallet uses it to sign transactions, which is how the network knows a payment really came from you. Think of it as the master signature for one blockchain account.

Each private key mathematically produces a public address, the string you share when someone wants to pay you. The math only runs one way. Anyone can see your address, but nobody can work backwards from the address to the key.

A useful comparison:

  • Your address is like an account number. Share it freely; people need it to send you funds.
  • Your private key is like the sole signature that authorizes withdrawals. Anyone who has it can drain the account.
  • There's no override. No bank manager, no fraud department, no password reset can undo a signed transaction.

Raw private keys look like 64 characters of hex gibberish, which is miserable to write down accurately. That's the problem seed phrases were invented to solve.

What is a seed phrase?

A seed phrase, also called a recovery phrase, is a human-readable backup of your wallet. It's usually 12 or 24 words drawn from a fixed list of 2,048 English words, defined by a standard called BIP-39. From that one phrase, your wallet derives every private key and address it will ever use.

That last part surprises people. You don't back up keys one by one. The phrase is the seed, and all your keys grow from it in a repeatable way. Restore the same words in any BIP-39 compatible wallet and the same accounts reappear, with balances intact.

The word order matters as much as the words themselves. "River" in position three is a different wallet than "river" in position nine. The list was also chosen so the first four letters identify each word uniquely, which keeps handwriting mistakes survivable.

The math is the whole defense. Twelve words drawn from 2,048 options give 2,048 to the twelfth power possible sequences, a number with 40 digits, and the BIP-39 spec pins the underlying entropy at 128 to 256 bits. Nobody brute-forces that. Every real-world seed theft works by getting you to hand the words over.

So the whole security model reduces to one question: who can read those words? Not which app you used, not how strong your phone PIN is. The words are the wallet.

The iron rules of seed phrase safety

Because the phrase equals the funds, a few rules aren't negotiable. Scammers know that stealing 12 words is far easier than breaking the math, so almost every wallet theft starts with tricking someone into revealing their phrase. The numbers bear this out. Chainalysis counted $2.2 billion stolen from crypto platforms in 2024, and compromised private keys were the leading vector at 43.8% of the stolen funds. In 2023, the FBI's Internet Crime Complaint Center logged more than 69,000 crypto-fraud complaints with over $5.6 billion in reported losses. We cover the usual playbook in common crypto scams, but the defense fits in one list.

  • Anyone who has the phrase owns the funds. There's no "they'd still need my password." They wouldn't.
  • No photos. A screenshot or camera-roll picture syncs to the cloud and sits in every backup forever.
  • No cloud notes, email drafts, or messaging apps. Anything typed on a connected device can leak.
  • Never type it into a website. Not to "validate" your wallet, "sync" it, or "claim" a reward.
  • No legitimate service will ever ask for it. Not support staff, not the wallet's own developers, not an airdrop, nobody.

How should you store a seed phrase?

Physically, offline, and in more than one place. Write the words by hand on paper, in order and legibly, or stamp them into a steel backup plate if you're protecting a serious balance. The hardware-wallet makers give the same advice: Trezor's backup guidance says never store the words digitally, and Ledger's seed-security guide flags paper's weakness to water and fire.

Then store a second copy in a different location: a relative's safe, a bank deposit box, anywhere a single disaster can't reach both copies. One copy protects you from theft of the wallet; two protect you from losing the backup itself.

How the common options compare:

Storage method

Fire and flood

Online-theft exposure

Verdict

Paper

Poor: burns, soaks, fades

None while offline

Fine for small balances

Steel plate

Excellent: survives both

None while offline

Best once a loss would hurt

Password manager

Not an issue

High: one breach or infected device exposes it

Avoid

Photo on your phone

Not an issue

Very high: syncs to cloud backups forever

Never

One tempting middle path deserves a warning. Split copies, half the words here, half there, sound clever but double your failure points. Lose either half and you've lost everything, which is why most people are better served by two complete copies in separate places.

A few practical habits help:

  • Don't label it "crypto seed phrase." A plain numbered word list attracts less attention.
  • Check on your copies occasionally. Ink fades, papers migrate, and safes get cleaned out.

What happens if you lose it?

That depends entirely on who holds the keys. With a custodial service, like an exchange account, the company controls the keys and you log in with a normal password. Lose access and you recover it the familiar way: support tickets, ID checks, email resets. Convenient, but you're trusting the custodian.

Self-custody has no such safety net. If your device dies and you can't produce the seed phrase, the funds are stranded on the blockchain forever. They don't disappear; they become unspendable, visible to everyone and reachable by no one. No developer or government can regenerate your words.

That's the honest trade. Custodial means someone can rescue you, and also that someone else controls your coins. Self-custody means total control, and total responsibility for one small set of words. Both are legitimate answers. What's wrong is holding self-custody funds while treating backups like an afterthought.

Run a recovery drill before you fund the wallet

Don't discover a backup mistake with real money on the line. Before your wallet holds anything meaningful, prove the recovery actually works. The drill takes fifteen minutes.

  • Set up the wallet and write down the seed phrase as usual.
  • Note your first receiving address, then send nothing yet.
  • Wipe the wallet: delete the app or use its reset option.
  • Reinstall and restore using only your written phrase.
  • Confirm the restored wallet shows the same receiving address.
  • Now send a small test amount first, then the rest.

If the addresses match, your backup is real and you've rehearsed the exact steps you'd use in an emergency. If they don't, you've found a transcription error while it costs nothing. Our walkthrough on how to set up a crypto wallet builds this drill into the setup process from the start.

One drill, done once, turns "I think I backed it up" into "I've restored from it." That difference is worth more than any gadget or app feature in crypto security. In our experience, the backup that fails is rarely the stolen one. It's the one that was written down wrong and never tested.

Sources

Frequently asked questions

Can someone steal my crypto if they know my wallet address?

No. Your public address is like an account number and is safe to share freely — people need it to send you funds. The math linking a private key to its address only runs one way, so nobody can work backwards from the address to the key. Theft requires your private key or seed phrase, which is why those must never be shared.

Is it safe to store a seed phrase in a photo or cloud note?

No. A screenshot or camera-roll photo syncs to the cloud and sits in every backup forever, and anything typed on a connected device — cloud notes, email drafts, messaging apps — can leak. A seed phrase should exist only in physical form: handwritten on paper or stamped into a steel plate, stored offline in two separate locations.

What happens to my crypto if I delete my wallet app or lose my phone?

Nothing happens to the funds. Coins never leave the blockchain; the app only holds your keys and displays balances. Delete the app, drop your phone in a lake, or buy a new laptop, and your crypto stays on the chain untouched. Restore your seed phrase in any BIP-39 compatible wallet and the same accounts reappear with balances intact.

Should I split my seed phrase across two locations for extra security?

Usually not. Storing half the words in one place and half in another doubles your failure points — lose either half and you have lost everything. Most people are better served by keeping two complete copies in separate locations, such as home plus a relative's safe or a bank deposit box, so no single disaster can destroy both backups.

Will wallet support staff ever ask for my seed phrase?

No legitimate service will ever ask for your seed phrase — not support staff, not the wallet's own developers, not an airdrop or reward claim. The phrase should travel in exactly one direction: from the wallet's setup screen to something physical you control. Any person, website, form, or 'support agent' asking you to enter it is attempting theft.

How do I know my seed phrase backup actually works?

Run a recovery drill before funding the wallet. Write down the phrase, note your first receiving address, then wipe the wallet and restore it using only your written words. If the restored wallet shows the same receiving address, the backup is real; if not, you have caught a transcription error while it costs nothing. The drill takes about fifteen minutes.

Go deeper with a course

About the author

Priya Nair

Table Games & Wallets Writer

Priya covers the classic tables — blackjack, roulette, baccarat, craps, and poker hand rankings — plus the wallet and self-custody basics every crypto player needs.

One clear lesson, every week

Join thousands learning crypto the right way. New guides and plain-English breakdowns — never spam, unsubscribe anytime.