Tools/Explorers

Which Bitcoin Backup Strategy Should I Use?

Find the right Bitcoin backup strategy for your security needs: single seed, metal plates, Shamir splits, or multisig elimination.

Spark Team

Choosing a Bitcoin Backup Strategy

Every self-custody Bitcoin wallet generates a seed phrase: a sequence of 12 or 24 words that can reconstruct your private keys. How you back up that seed phrase determines whether you can recover your bitcoin after a fire, theft, hardware failure, or your own death. An estimated 3 to 4 million BTC (roughly 16-20% of the mined supply) is permanently lost, much of it due to poor backup practices.

The right strategy depends on your holdings, technical comfort, geographic distribution needs, and whether you need an inheritance plan. This guide compares five approaches: paper seed in a safe, metal seed plates, Shamir secret sharing splits, multisig (which eliminates single-seed risk entirely), and seedless recovery.

StrategyCostTechnical SkillSingle Point of FailureInheritance ReadyBest For
Paper seed in safe$0-$50LowYesDifficultSmall holdings, beginners
Metal seed plate$50-$150LowYesDifficultLong-term single-sig storage
Shamir 2-of-3 split$80-$250MediumNoModerateGeographic distribution
Multisig 2-of-3$200-$2,100/yrMedium-HighNoYes (with provider)Significant holdings
Seedless recovery$99-$250LowNoModerateNon-technical users

Paper Seed in a Safe

The simplest approach: write your seed phrase on paper and store it in a fireproof safe or bank safe deposit box. This costs nothing beyond the safe itself and requires no technical knowledge. For holdings under a few thousand dollars, paper backup is often sufficient.

The limitations are physical. Paper ignites at approximately 233°C, well below residential fire temperatures. Ink fades. Water destroys it. A fireproof safe rated UL 72 will protect documents at standard house fire temperatures for 1-2 hours, but many "fireproof" safes are only rated for 30 minutes. Bank safe deposit boxes avoid fire risk but introduce access constraints: limited hours, government seizure risk, and complications during estate settlement.

Paper backup is a single point of failure. If the paper is destroyed, stolen, or lost, your bitcoin is gone. Storing copies at multiple locations helps with loss but doubles your theft exposure. For anything beyond small amounts, consider upgrading to metal or eliminating the single-seed model entirely.

Metal Seed Plates

Metal seed storage replaces paper with stainless steel or titanium plates that survive fire, flooding, and structural collapse. Jameson Lopp has stress-tested over 75 metal backup devices across six rounds, subjecting each to a 1,093°C propane torch for 10 minutes, a 12-hour muriatic acid bath, and a 20-ton hydraulic press. The results vary significantly by design.

Punch-style plates (where you stamp dots into solid metal) consistently outperform tile-slot designs (where loose letter tiles sit in rails). Under crushing force, tiles dislodge and scatter, causing catastrophic data loss. The Billfodl ($99, 316 marine-grade stainless) received a C grade from Lopp because its tiles fell out under both heat and crush tests. By contrast, the Blockplate ($79, 304 stainless, 3mm thick) scored straight A's across all three tests.

Top-performing products by Lopp's testing:

  • Blockplate 24: $79, 304 stainless steel, triple-A rating
  • Seedplate by Coinkite: $50, stainless steel, triple-A rating
  • Steelwallet by BitBox: $65, 304 stainless, triple-A rating
  • CryptoTag Zeus: $129, 6mm titanium, melting point 1,667°C
  • Cryptosteel Capsule Solo: $99, A- rating (crush can jam the cap)

Metal plates solve durability but not the fundamental problem: they are still a single point of failure. One stolen plate means total loss. For a detailed product comparison, see the Bitcoin seed storage comparison.

Shamir Secret Sharing (SLIP-39)

Shamir's Secret Sharing splits a seed into multiple shares where only a threshold number are needed to reconstruct the original. A 2-of-3 split produces three 20-word shares: any two recover the wallet, but any single share reveals nothing about the seed. This eliminates the single point of failure while keeping you in a single-signature model.

The SLIP-39 standard is supported by Trezor hardware wallets (Model T, Safe 3, Safe 5, and Safe 7 with firmware 2.7.2+). SLIP-39 is now the default backup type on Trezor Safe family devices. The standard supports configurable M-of-N thresholds and even two-level "Super Shamir" backup for complex setups. Each share is 20 words with its own checksum.

The tradeoff: Shamir is hardware-wallet-specific. SLIP-39 shares are not compatible with BIP-39 wallets. If Trezor discontinues support, you need another SLIP-39-compatible tool to recover. You also need to store each share on its own metal plate at a separate location, multiplying your physical storage costs and complexity.

Shamir works well for users who want geographic distribution (shares in different cities, with different trusted people) without the complexity of multisig. For deeper technical analysis, see our research on Shamir secret sharing for Bitcoin backup.

Multisig: Eliminating Single-Seed Risk

A 2-of-3 multisig wallet requires two out of three separate private keys to authorize any transaction. Each key is generated independently on a different hardware wallet, ideally from different manufacturers. This eliminates single-seed risk in both directions: an attacker who steals one key cannot spend, and a user who loses one key can still recover with the remaining two.

The multi-vendor approach proved its value during the Coldcard entropy bug disclosure in mid-2026. A critical randomness flaw in Coldcard devices led to over $100 million stolen from single-signature wallets. Mixed-vendor 2-of-3 multisig setups reported zero losses because even a compromised key from one vendor was insufficient without a second key from a different device.

You can set up multisig yourself using free tools like Sparrow Wallet or Caravan, or use a collaborative custody provider:

  • Nunchuk: free DIY multisig, or $120/yr for assisted 2-of-3
  • Casa: $250/yr for 2-of-3 with built-in inheritance
  • Unchained: $250/yr per vault, 2-of-3 collaborative custody
  • DIY with Sparrow: free software, ~$200-500 total for three hardware wallets

Multisig does add complexity. You must back up each seed phrase separately plus the wallet's output descriptor: a string encoding the script type, threshold, all extended public keys, and derivation paths. Without the descriptor, individual seed phrases cannot reconstruct the wallet. Collaborative custody providers simplify this by storing the descriptor and assisting with recovery.

For holdings above $50,000, multisig is widely considered the standard. For a comparison of custody approaches, see our collaborative custody comparison.

Seedless Recovery

Seedless wallets eliminate the seed phrase from the user experience entirely. Instead of writing down words, they distribute key material across multiple parties or devices so that recovery works through authentication rather than memorization.

Bitkey by Block ($150 for the original model, ~$250 for the 2026 touchscreen version) uses a 2-of-3 multisig under the hood: one key on your phone, one on the hardware device, and one on Block's servers. Any two keys can sign a transaction. Recovery after losing one device uses the remaining two. No seed phrase is ever shown to the user.

Ledger Recover ($9.99/month) takes a different approach: it encrypts your existing seed, splits it into three shards, and distributes them to Ledger, Coincover, and EscrowTech. Recovery requires identity verification through Onfido. This model is controversial because it transmits seed material to third parties, creating new trust assumptions.

Seedless designs trade self-sovereignty for usability. They work well for non-technical users who would otherwise store seeds insecurely. The risk is counterparty dependence: if Block shuts down or Ledger Recover's custodians are compromised, recovery may fail. For more on this tradeoff, see our research on seedless wallet recovery design.

Risk Matrix: Threats by Strategy

Each backup strategy protects against different threats. The following matrix shows how each approach performs against the five most common risks to cold storage bitcoin.

ThreatPaper SeedMetal PlateShamir 2-of-3Multisig 2-of-3Seedless
Fire / floodVulnerableProtectedProtected (distributed)Protected (distributed)Protected
Theft of one backupTotal lossTotal lossSafe (need 2 shares)Safe (need 2 keys)Safe (need 2 factors)
Loss of one backupTotal lossTotal lossRecoverable (need 2 of 3)Recoverable (need 2 of 3)Recoverable
Coercion ($5 wrench attack)VulnerableVulnerablePartial (shares distributed)Strong (keys distributed)Moderate
Death / incapacitationLikely lostLikely lostPossible with planningSupported (with provider)Provider-dependent

Physical attacks against cryptocurrency holders increased 33% year-over-year in the first half of 2026, with 52 attacks reported worldwide through June. Geographic distribution of keys (whether through Shamir or multisig) provides the strongest defense: the holder can truthfully say they cannot move funds alone, even under threat. For coercion defense, some hardware wallets also support duress PINs and passphrase-protected decoy wallets.

Common Backup Mistakes

These errors cause more losses than sophisticated attacks:

  • Taking photos or screenshots of seed phrases: cloud sync (iCloud, Google Photos) uploads them automatically, and a single account breach exposes everything. After the 2022 LastPass breach, researchers linked over $35 million in thefts to seed phrases stored in the password manager.
  • Storing the seed phrase with the hardware wallet: a single theft or fire destroys both the device and its only recovery path.
  • Splitting a 24-word seed into 12+12 halves: this is not cryptographic splitting. Each half retains partial entropy, and you now have two single points of failure instead of one. Use Shamir's Secret Sharing or multisig instead.
  • Using a brain wallet (memorization only): memory degrades after illness, trauma, or simply time. If you die or become incapacitated, the bitcoin is gone.
  • Never testing recovery: transcription errors (wrong word order, smudged letters) stay hidden until you actually need the backup. Always perform a full recovery test before depositing significant funds.
  • Storing in cloud services (Google Docs, iCloud Notes, Dropbox): these are server-accessible records. A single breach exposes the seed.

Cost-Benefit by Portfolio Size

Security spending should scale with your holdings. Over-engineering a $500 stack wastes time and money. Under-protecting $100,000 is reckless.

  • Under $1,000: paper seed in a secure location is sufficient. Focus on learning the basics of self-custody before adding complexity.
  • $1,000 to $10,000: upgrade to a metal seed plate ($50-$80) and a dedicated hardware wallet. Store the plate separately from the device.
  • $10,000 to $50,000: consider Shamir 2-of-3 backup (requires a Trezor Safe family device plus three metal plates) or a basic collaborative custody plan like Nunchuk Iron Hand ($120/yr).
  • $50,000 to $500,000: multisig 2-of-3 is the standard. Either DIY with Sparrow (three hardware wallets from different vendors, ~$300 total) or use Casa ($250/yr) or Unchained ($250/yr) for guided setup and inheritance support.
  • Over $500,000: 3-of-5 multisig with a premium custody provider. Casa Premium ($2,100/yr), Unchained Signature ($6,000 first year), or Nunchuk Honey Badger Premier ($2,100/yr) provide dedicated support, inheritance protocols, and multiple vaults.

For inheritance planning at any level, collaborative custody providers simplify the process significantly. Casa uses inactivity detection with a six-month waiting period. Unchained allows your executor to co-sign with their key. Nunchuk's Honey Badger tier uses time-locked vault policies built with Miniscript. DIY inheritance requires heirs to understand wallet descriptors, locate multiple seed phrases, and use coordinator software: a plan that often fails in practice. For a deeper dive, see our research on Bitcoin inheritance planning.

Frequently Asked Questions

What is the best way to back up a Bitcoin seed phrase?

For most users, a punch-style metal seed plate stored in a separate location from your hardware wallet is the minimum. Products like the Blockplate ($79) and Seedplate ($50) scored straight A's in Jameson Lopp's stress tests, surviving fire, corrosion, and crushing. For holdings above $50,000, multisig eliminates the single-seed risk entirely and is the recommended standard.

Is Shamir backup better than multisig?

They solve different problems. Shamir backup splits one seed into shares, removing the single point of failure for that seed. Multisig uses multiple independent keys, removing the single-seed model entirely. Multisig provides stronger security because each key is generated on separate hardware: a flaw in one device (like the 2026 Coldcard entropy bug) does not compromise the wallet. Shamir shares all derive from the same entropy source. Multisig also enables collaborative custody and simpler inheritance protocols.

How much bitcoin should I have before using multisig?

There is no hard threshold, but most security professionals recommend multisig once holdings exceed $10,000-$50,000. The cost of a basic collaborative custody plan (Nunchuk at $120/yr, Casa or Unchained at $250/yr) is small relative to the risk at these amounts. DIY multisig with Sparrow Wallet is free (software) and costs only the price of three hardware wallets (~$200-$500 total).

Can I recover bitcoin if I lose my seed phrase?

With a standard single-signature wallet: no. If the seed phrase is lost and the hardware wallet is also lost or broken, the bitcoin is permanently inaccessible. This is why backup strategy matters. With Shamir 2-of-3, you can lose one share and recover with the remaining two. With multisig 2-of-3, you can lose one key and still spend with the other two. With seedless wallets like Bitkey, recovery uses the remaining two of three factors (phone, device, server).

What is the $5 wrench attack and how do I protect against it?

The "$5 wrench attack" refers to physical coercion: someone threatens violence to force you to hand over your keys. Physical attacks against crypto holders reached 52 incidents in the first half of 2026, up 33% from the prior year. The strongest defense is geographic distribution of keys through multisig: you can truthfully say you cannot move funds alone. Hardware wallets with duress PINs (Coldcard, Nunchuk) and passphrase-protected decoy wallets add an additional layer.

Should I store my seed phrase in a bank safe deposit box?

A safe deposit box protects against fire and home theft, but introduces other risks: limited access hours, potential government seizure, employee access, and inheritance complications. Contents are not FDIC-insured. A safe deposit box works best as one location in a multi-location backup strategy (one Shamir share or one multisig seed phrase), never as the sole backup for a single-signature wallet.

How do I set up Bitcoin inheritance with multisig?

Collaborative custody providers offer the simplest path. Casa's inheritance protocol uses inactivity detection: if you stop responding for six months, your designated beneficiary can initiate a transfer with Casa's co-signing. Unchained gives your executor one key from the 2-of-3 setup and works with them to co-sign. Nunchuk uses time-locked vault policies with dedicated inheritance keys. DIY inheritance (distributing seed phrases and wallet descriptors to heirs) is possible but requires technically capable beneficiaries and detailed written instructions. For comprehensive guidance, see our inheritance planning guide.

This tool is for informational purposes only and does not constitute financial advice. Product pricing, features, and availability change frequently. Stress test results are based on Jameson Lopp's published methodology. Always verify current data with product manufacturers and service providers before making security decisions.

Build with Spark

Integrate bitcoin, Lightning, and stablecoins into your app with a few lines of code.

Read the docs →