Guide — the part that actually loses money

Seed phrase backup, properly

More crypto is lost to bad backups than to every hack combined. This is how to do it so that a house fire, a burglary, a bad memory or your own death does not end your access — and how to prove it works before you need it.

  • 2 copies Minimum, in two different buildings
  • 0 digital Photos, notes and password managers all excluded
  • Test it Wipe and restore before funding
  • NZ$200 Westpac safe deposit box, incl GST

What the phrase actually is

Twelve or twenty-four ordinary English words, in a specific order, generated by your wallet. They are not a password and they are not a backup of your wallet — they are the seed from which every private key in the wallet is derived. Whoever holds them holds the funds, completely and immediately. Whoever loses them, and loses the device, has lost the funds permanently.

Two implications follow and both are unintuitive if you are used to normal accounts.

First, the phrase is more valuable than the device. Your hardware wallet is a commodity — break it, lose it, drop it in Lake Taupō, and you buy another one and restore. The words are irreplaceable. People instinctively protect the expensive object and treat the card of words as documentation, which is exactly the wrong way round.

Second, the phrase is portable. Because nearly all non-custodial wallets implement the same BIP39 standard, a Trezor phrase restores in a Ledger, a Ledger phrase restores in free software, and a phone wallet's phrase restores on a hardware device. Your access does not depend on any single company continuing to exist. That is a genuine and underappreciated safety property, and it is why we are wary of proprietary backup schemes that trade it away for convenience.

The two rules that cover most of it

Almost every backup failure we have read about violates one of these.

Rule one: it never gets typed into anything except the wallet itself, during setup or recovery. Not a website. Not a support chat. Not a form that says it will validate, migrate, sync or verify your wallet. Not a "claim your airdrop" page. No legitimate service has ever needed your recovery phrase, and none ever will. If something is asking, it is stealing — and once you have typed it, no hardware, no certification and no secure element makes the slightest difference.

Rule two: it never exists in digital form. No photographs, because photos sync to iCloud or Google Photos, and those accounts get compromised through passwords that leaked from some unrelated site years earlier. No note app entries, for the same reason. No password manager records — we will come back to that. No text to yourself, no email draft, no encrypted zip on your desktop.

A pen and the card in the box outperforms every digital option here. That is an odd thing to be true and it is true because the threat is network-reachable compromise, and paper is the only medium with no network.

On password managers specifically

We know this is contentious, because password managers are genuinely excellent tools and we recommend them for passwords. The problem is concentration: your vault is a single point of failure, and if the master password leaks or an unlocked vault sits on a compromised machine, everything inside goes at once. For a password that can be reset, that is a recoverable event. For a seed phrase, it is terminal. Keep the two categories separate.

Paper, steel, and what fails how

Every wallet ships with a card to write the words on, and for a modest holding in a dry, low-risk house, that card in a sensible place is a defensible backup. Do not let anyone make you feel that paper is negligent — it is the correct answer for a great many people.

What paper fails at is specific: fire, water, and casual discovery. It burns at a low temperature, it disintegrates in a flood, cheap ink fades over a decade, and a curious flatmate can read it in three seconds. For New Zealand specifically, water is more relevant than most people assume — Hawke's Bay, parts of Auckland and much of the West Coast have flood exposure that a card in a drawer will not survive.

The upgrade is a steel backup plate: words stamped or punched into metal, which survives fire, water and time. The Bitcoin Shop in Tauranga stocks TinySeed plates alongside its hardware, which saves the import wait. Expect to pay somewhere in the NZ$60 to NZ$150 range depending on the design.

Our threshold: paper below about NZ$10,000, steel above it, and steel immediately if you live somewhere with meaningful fire or flood exposure. And regardless of medium, handwriting matters — print in capitals, and be careful with letters that look alike. A backup that cannot be read is not a backup.

Two copies, two buildings — and where in New Zealand

One copy means a single event — a fire, a flood, a burglary, a well-meaning relative clearing out a drawer — ends your access. Two copies in the same house is still one location. The standard we would hold ourselves to is two copies in two different buildings.

The obvious answer used to be a bank safe deposit box, and that has quietly disappeared in New Zealand. Over the past decade most major banks exited the business: ANZ, BNZ and the old National Bank handed their box operations to New Zealand Vault. Westpac still offers boxes — around NZ$200 including GST for a standard size and NZ$600 for a large one at our last check — but the branch network for them is thin.

The remaining formal options are private vaults. New Zealand Vault has operated since 1931 with facilities in Auckland and Wellington. Imperial Vaults and Commonwealth Vault operate in Auckland. Vault NZ offers boxes in Dunedin. Annual fees and restricted access hours apply, and for something you hope never to retrieve, restricted access is barely a downside.

The informal options are perfectly good and free. A locked fireproof document safe at a parent's or sibling's house in a different suburb. A workplace safe, if you have that kind of workplace. What matters is that it is a different building, that you can reach it within a day, and that the person whose house it is does not know what the sealed envelope contains.

Bitcoin token in low light, representing long-term protected storage of a recovery phrase
The device is a commodity. The words are the asset. Protect them accordingly, in two places.

A good-enough arrangement

Handwritten card in a locked drawer at home. Steel plate in a sealed envelope inside a fireproof document safe at a family member's house in another suburb. Neither location holds both the phrase and the device. A note with your will explaining that both exist. That beats the vast majority of holders and costs under NZ$200.

Passphrases: the double-edged upgrade

Most hardware wallets support an optional passphrase, sometimes marketed as a "hidden wallet" or a "25th word". It is genuinely powerful and genuinely dangerous, and the danger is not obvious.

Mechanically, the passphrase is combined with your recovery phrase to derive a completely different set of keys. The same twenty-four words with no passphrase open one wallet. With the passphrase "kereru" they open a different wallet. With "Kereru" — capital K — a third. None of these wallets knows about the others, and the passphrase is not stored anywhere: not on the device, not in the seed, nowhere.

The benefit is real. Someone who finds your written words gets an empty or decoy wallet. That is meaningful protection against a burglary, a nosy relative, or the specific scenario where a hardware wallet vendor leaks its customer list — as Ledger did in July 2020, exposing roughly 270,000 customers' names, phone numbers and home addresses, and again through its payment processor in January 2026. Some Ledger owners subsequently received extortion letters. A passphrase is the answer to someone standing in your house having read your seed card.

The cost is absolute. Forget the passphrase and the funds are gone permanently. There is no support line, no recovery process, no brute-force option for anything you chose sensibly. And people are extremely confident about remembering strings they will not type for three years, at a rate that should worry you.

Our position: use one above roughly NZ$20,000, and treat the passphrase as a second backup problem rather than something you will obviously remember. Write it down too — separately from the seed words, in a different location, so that finding one does not give someone both.

Splitting a phrase, and why not to improvise

A tempting idea: put the first twelve words in one place and the last twelve in another, so that no single location holds the whole thing. Do not do this.

The reason is that BIP39 phrases are not random independent words — they encode a seed plus a checksum, and knowing half of them reduces the remaining search space by far more than intuition suggests. An attacker who finds one half is meaningfully closer to the funds than one who finds nothing, and you have simultaneously doubled the number of places where losing one destroys your access. It is worse on both axes.

If you want genuine splitting, use a scheme designed for it. Shamir backup, supported on the Trezor Safe 5 and on Keystone, splits a seed into shares such that a defined threshold — say three of five — reconstructs it while any smaller number reveals absolutely nothing. That is the mathematically correct version of the idea, and it is genuinely useful for larger holdings distributed across locations or people.

The alternative, and often the better one, is multisig: instead of splitting one key, use several independent keys and require a subset to spend. It solves the same distribution problem, survives losing a key, and gives your estate a workable path.

Testing the backup

This is the most important paragraph on the page. Wipe your wallet and restore it from your written phrase, before you fund it.

On a hardware wallet: reset the device to factory settings, then run the recovery flow and enter your words. On a software wallet: uninstall or create a new wallet, choose restore, enter your words. If the same addresses and the same balance appear, your backup is real. If they do not, you have discovered a fatal problem at zero cost.

The reason this matters so much is that handwriting is ambiguous and people make predictable errors: transposed word pairs, an "l" that reads as a "1", a word written from a different device entirely, a twenty-third word that got skipped. Every one of those is invisible until the moment you need the backup, at which point it is catastrophic. Ten minutes now, or everything later.

Devices with an encrypted microSD backup — the BitBox02 is the notable one — make this dramatically easier, because restoring takes thirty seconds and involves no transcription. That is a genuine reason to prefer it if you suspect you will not do a paper restore test.

Inheritance: what to leave behind

A recovery phrase that only you know is a guaranteed permanent loss. This is the least discussed failure in self-custody and it destroys more crypto than any hack.

What works: a sealed written instruction held with your will by your solicitor, and crucially written for someone who does not know what a seed phrase is. Not just twenty-four words — a page explaining that a cryptocurrency holding exists, roughly what it is worth, where the device and backups are, what the words do, and the practical steps to access or liquidate it. Name a person who could help if the beneficiary cannot.

What does not work: putting the phrase in the will itself, because wills can become public documents through the probate process. Relying on a "dead man's switch" service you have never tested. Assuming a family member will work it out from your browser history. Or splitting the phrase between two relatives without understanding the weakness described above.

For substantial amounts, multisig is the better answer: a two-of-three arrangement where you hold two keys and an executor holds the third means nobody can spend unilaterally, you can lose a key without consequence, and your estate has a defined path.

From our testing notes

We asked people who already owned hardware wallets a single question: have you ever restored from your written phrase? Most had not. Several were confident the backup was fine. Two, when they tried, found errors — one transposed pair and one card that turned out to be from an earlier device they had since reset. Both would have lost everything, and both found out for free. If this page persuades you to do one thing, make it that.

Frequently asked

Questions on this topic

How do I back up a crypto wallet properly?

Write the recovery phrase by hand on paper or stamp it into steel, make two copies, keep them in two different buildings, and prove the backup works by wiping the wallet and restoring from your written copy before you fund it. Never photograph it, never type it into a password manager or note app, and never store it in the same place as the device. That is the entire method, and the test restore is the part almost everyone skips.

Is it safe to store a seed phrase in a password manager?

We would not, and this is one of the few places we are unequivocal. A password manager is an excellent tool protecting a single point of failure: if the master password leaks, or the vault provider is breached, or the device holding an unlocked vault is compromised, everything inside is exposed at once. Your crypto then depends on that one credential rather than on physical possession of something. Paper is unglamorous, offline, and cannot be exfiltrated over a network.

What is a BIP39 passphrase and should I use one?

A passphrase is an extra secret combined with your recovery phrase to derive a completely different wallet. The same words with no passphrase open one wallet; with "kereru" they open another; with "Kereru" a third. It means anyone who finds your written words gets an empty or decoy wallet. It also means forgetting the passphrase destroys your funds permanently, with no recovery path anywhere. We would use one above roughly NZ$20,000 — and write it down separately, in a different place from the seed words.

Should I split my seed phrase in half and store the parts separately?

Not by hand, no. Naive splitting — first twelve words here, last twelve there — actually weakens security rather than improving it, because each half dramatically reduces the search space for an attacker who finds one. If you want real splitting, use a scheme designed for it: Shamir backup, supported on the Trezor Safe 5 and Keystone, splits a seed into shares where a defined number reconstructs it and fewer reveal nothing. Or use multisig, which solves the same problem more robustly.

Where can I store a seed phrase backup in New Zealand?

Most New Zealand banks have exited the safe deposit business — New Zealand Vault acquired the ANZ, BNZ and National Bank box operations, and Westpac still offers boxes at around NZ$200 including GST for a standard size. Private options include New Zealand Vault in Auckland and Wellington, Imperial Vaults and Commonwealth Vault in Auckland, and Vault NZ in Dunedin. A locked fireproof document safe at a trusted family member's house in another suburb is also a perfectly reasonable answer, and free. Our city pages list what exists regionally.

Next in this cluster

Keep reading