00 Which tier are you?
Tiers are set by consequence, not by a bitcoin amount. The same 1 BTC is "Everyday" for one person and "Whale" for another. When in doubt, pick the higher tier: the extra setup costs a weekend and a few hundred dollars.
Everyday Tier 1
Losing it would hurt but would not change your life. Nobody outside your household knows you hold bitcoin.
Core setup
One hardware wallet, single-sig, two metal backups in two places, a letter for your heirs.
Serious Tier 2
A meaningful share of your net worth, or an amount a burglar or a relative would find tempting.
Core setup
Tier 1 plus either a BIP39 passphrase held apart from the seed, or a 2-of-3 multisig across two vendors, with a recovery drill every year.
Whale Tier 3
Life-changing money, or you are publicly known to hold bitcoin (employer, podcast, conference talks, company treasury).
Core setup
Geographically distributed multisig (self-run or collaborative), no single person or place that can move funds, duress plan, estate attorney, quarterly signing drills.
01 Quick reference: the rules that prevent most losses
- Your seed is the wallet. The device is a replaceable signing tool. Anyone who reads the 12 or 24 words owns the coins; anyone who loses every copy loses the coins.
- Never digitize the seed. No photo, cloud note, password manager, email draft, or "validation" website. Words go on paper, then metal, and nowhere else.
- Test recovery before you fund. Wipe the device (or use a second one), restore from your backup, confirm the same first receive address appears. Then deposit.
- Two backups, two buildings. One fire, flood, or burglary should never touch every copy.
- Verify every address on the device screen. Your computer and phone can be lying to you. The hardware wallet's screen is the only display you trust.
- No one legitimate ever asks for your seed. Not support, not an exchange, not a "recovery service", not a wallet update prompt. Any request is an attack.
- Buy hardware from the manufacturer. Never use a device that arrives with words already printed or a PIN already set.
- Exchanges are for trading, not storage. Withdraw anything you do not plan to sell soon.
- Silence is a security control. What you do not disclose cannot be used to target you.
- Write down how an heir gets in. A perfectly secured wallet no one can inherit is a loss that has not happened yet.
Setup by tier at a glance
| Control | Everyday | Serious | Whale |
|---|---|---|---|
| Signing | 1 hardware wallet, single-sig | Single-sig + passphrase, or 2-of-3 multisig | 2-of-3 or 3-of-5 multisig, 2+ vendors, or collaborative custody |
| Seed backups | 2 copies (metal preferred), 2 buildings | 2+ metal copies, passphrase stored apart | One metal seed per key, each in a different location or region |
| Wallet config | Note the wallet type and script (e.g. "native SegWit, bc1q") | If multisig: output descriptor with every backup | Descriptor with every key site, plus a coordinator copy |
| Account security | Password manager, authenticator app, no SMS 2FA | FIDO2 security keys on email and exchanges, carrier port-out PIN | Separate crypto identity, dedicated signing laptop, PII removal |
| Physical | Backups out of sight, fire-resistant storage | Bolted safe, tamper-evident bags | Distributed sites, decoy/duress wallet, alarm, professional advice |
| Inheritance | Letter of instruction, executor knows where it is | Letter + walkthrough, named technical helper | Estate attorney, trust or LLC where fitting, timelock or collaborative recovery path |
| Drills | Full restore at setup; review yearly | Full restore yearly | Signing drill quarterly, full restore yearly, rotate after staff or life changes |
| Setup cost | One device + metal plate | 2 to 3 devices, 2 to 3 plates, safe | 3 to 5 devices, sites, legal fees, optional service subscription |
02 Threat model
Risk ratings escalate with the amount held and, above all, with how many people know you hold it. Loss by your own hand is the top risk at every tier.
| Threat | How it happens | Everyday | Whale | Primary defense |
|---|---|---|---|---|
| Self-inflicted loss | Lost or illegible seed, words out of order, forgotten passphrase, lost multisig config, backup burned or flooded | Critical | Critical | Metal backups in 2+ places, recovery drill, descriptor backup |
| Phishing & fake support | Lookalike wallet apps and sites, "support" DMs, fake firmware update pages that ask for the seed | High | High | Seed never typed into a computer or phone; bookmarks for official sites only |
| Malware & clipboard hijack | Clipper malware swaps a copied address for the attacker's; keyloggers take exchange logins | High | High | Confirm the full address on the hardware screen before signing |
| Address poisoning | Attacker sends dust from an address matching the first and last characters of one you used, hoping you copy it from history | Medium | High | Never copy addresses from transaction history; use saved, verified contacts |
| Custodian failure | Mt. Gox (2014, about 850,000 BTC), FTX (bankrupt Nov 2022), frozen withdrawals, hacks | High if on exchange | High if on exchange | Withdraw to self-custody; keep only a trading float on platforms |
| SIM swap & account takeover | Carrier moves your number to the attacker, who resets email and exchange passwords | Medium | High | FIDO2 keys, no SMS recovery, carrier port-out PIN or number lock |
| Supply chain | Tampered or counterfeit devices; the 2020 Ledger customer database leak (about 272,000 home addresses) was followed by fake replacement devices mailed to customers | Medium | High | Buy direct, check tamper evidence, generate the seed on the device yourself |
| Blind signing | Signers approve what a compromised interface shows them. Bybit lost about $1.5B in ETH (Feb 2025) when multisig signers approved a transaction the web UI misrepresented | Low | Critical | Read amount, address, and change on each device screen; second coordinator on a separate machine |
| Burglary & device theft | Thief takes the safe; seed card stored in the device box | Medium | High | PIN on device, seed stored away from device, no single site holds a quorum |
| Wrench attack & kidnapping | Coercion in person. Jameson Lopp's public list of physical bitcoin attacks grows every year; Ledger co-founder David Balland was kidnapped in France in January 2025 | Low | Critical | Silence, geographic multisig, duress wallet, timelocks you cannot bypass |
| Insider & family | Someone who knows where the backups are, or holds enough keys | Medium | High | No one person holds a signing quorum; tamper-evident seals |
| Heirs locked out | Death or incapacity with no instructions, or instructions no one can follow | Critical | Critical | Letter of instruction, tested by a non-technical reader |
| Seizure & regulation | Account freezes, capital controls, forced disclosure in some jurisdictions | Low | Medium | Self-custody, legal counsel, keys in more than one jurisdiction |
| Quantum (future) | A large quantum computer could derive keys from exposed public keys (reused addresses, old P2PK outputs) | Low | Low today | Avoid address reuse; follow the post-quantum custody migration work |
What protocol-level attacks mean for you
A 51% attack can reorder recent transactions; it cannot spend coins from your keys. Treat deep confirmations (6+ blocks) as settlement for large incoming payments. Breaking secp256k1 or SHA-256 with classical computers is not a practical threat.
Custodian and counterparty risk
Every custodian adds its insolvency, hack, and policy risk to yours. If you use one, prefer segregated, audited custody, read the withdrawal terms, and keep it below the amount you can afford to have frozen for years. The custody responsibility matrix shows what stays your job in each model, and institutional custody covers the qualified-custodian side.
03 Wallet setups compared
Every setup trades theft resistance against loss resistance. Adding keys removes single points of theft but adds things you must back up. Choose the simplest setup that removes the threats in your tier.
| Setup | Single point of failure | To recover you need | Complexity | Fits |
|---|---|---|---|---|
| Exchange account | The company, your login, its jurisdiction | The company's cooperation | None | Trading float only |
| Phone or desktop hot wallet | The device's malware exposure; the one seed | 12 or 24 words | Low | Spending money |
| Hardware wallet, single-sig | The one seed backup | 12 or 24 words (plus script type) | Low | Tier 1 |
| Single-sig + BIP39 passphrase | Forgetting the passphrase; no error on a typo | Words + exact passphrase | Medium | Tier 2 |
| SLIP-39 Shamir backup (Trezor) | One signing device at spend time | M of N shares (e.g. 2 of 3) | Medium | Tier 2 backup distribution |
| 2-of-3 self-run multisig | The wallet config, if not backed up | 2 seeds + output descriptor (or all 3 xpubs) | High | Tier 2 Tier 3 |
| Collaborative multisig | Provider cannot spend alone; you still hold a quorum | Your keys + config (provider keeps a copy) | Medium | Tier 3 |
| Timelocked recovery path (miniscript) | Coins must be refreshed before the timelock matures | Primary key now, or recovery key after the delay | High | Tier 3 inheritance |
Everyday: single-sig hardware wallet Tier 1
- Buy direct from the maker (see tools). Generate the seed on the device, never import one.
- Choose native SegWit (
bc1q…) or Taproot (bc1p…) addresses; write the choice on the backup. - Set a PIN of 6+ digits. Most devices wipe after a set number of wrong entries, which is why the seed backup matters more than the device.
- Use a Bitcoin-only companion app (Sparrow, the vendor's app) on a clean machine; connect through your own node when you can.
Serious: passphrase or first multisig Tier 2
- Passphrase route: seed words in one place, passphrase in another. A thief with only the words sees an empty or decoy wallet.
- Multisig route: 2-of-3 with devices from 2 or 3 vendors, coordinated in Sparrow, Nunchuk, or Specter.
- Losing any one key is survivable; losing the descriptor with one key missing is not.
Whale: distributed multisig Tier 3
- Single-sig is a single point of coercion and loss at this size. Use 2-of-3 or 3-of-5 across vendors and sites.
- No location, and no person, should hold enough keys to sign. That also makes "I cannot move it today" true under duress.
- Collaborative custody (Unchained, Casa, Swan Vault) adds a professional co-signer, key-replacement support, and inheritance help without handing over control.
- Airgapped signing (PSBT by QR or microSD) on a laptop used for nothing else.
04 Seed, passphrase & backup management
Your 12 or 24 words are your bitcoin. The facts below explain why backups fail and which failures are silent. For what each word turns into, see how 12 words become an address.
Writing the backup
- Number every word (1 to 24). Order errors are the most common unrecoverable mistake.
- Record the metadata that recovery needs: wallet type, script (
bc1q/bc1p), and for multisig the descriptor. The seed alone does not say where the coins are. - Paper first, then transfer to metal. Check each word against the device's display twice.
- Stamp or etch rather than rely on loose letter tiles, which can scatter if the holder is crushed or opened.
BIP39 passphrase ("25th word")
- Case, spaces, and punctuation all matter.
Correct horseandcorrect horseare different wallets. - Everyday: usually skip it. Forgetting it is permanent, and a solid PIN plus separated backups covers your risk.
- Serious: worthwhile if the passphrase is on metal, stored in a different place from the words, and in your inheritance letter's instructions.
- Whale: one layer among several; a small-balance wallet with no passphrase doubles as a duress decoy.
Multisig backup: the descriptor Tier 2+
A multisig address is built from all cosigners' public keys. With 2 of 3 seeds but no record of the third public key, you cannot rebuild the address and the coins are stuck.
- Export the output descriptor (or wallet config file) from your coordinator.
- Store a copy with every seed backup. It reveals balances but cannot spend, so it can live alongside a seed.
- Standard multisig path:
m/48'/0'/0'/2'(P2WSH).
Derivation paths to note on the backup
| Script | Path | Address |
|---|---|---|
| Legacy | m/44'/0'/0' | 1… |
| Nested SegWit | m/49'/0'/0' | 3… |
| Native SegWit | m/84'/0'/0' | bc1q… |
| Taproot | m/86'/0'/0' | bc1p… |
Wallets scan 20 unused addresses by default (the gap limit). A restored wallet that shows zero is often on the wrong path, not empty.
Backup media
| Medium | Survives | Fails to | Verdict |
|---|---|---|---|
| Paper | Short-term, dry storage | Fire (ignites around 230°C), water, fading ink | Setup and transfer only |
| Aluminum tiles | Water, corrosion in dry storage | House fires (aluminum melts at 660°C; fires can exceed that) | Avoid for primary backups |
| Brass | Water, moderate heat | Hot, long fires (melts near 900°C) | Acceptable |
| Stainless steel (304/316), stamped or etched | Fire (melts around 1,400°C), water, corrosion, crushing | Deliberate destruction, theft | Recommended |
| Titanium, stamped | Fire (melts around 1,670°C), corrosion | Theft | Recommended; costs more |
Where to keep copies
| Location | Strength | Weakness | Use for |
|---|---|---|---|
| Home safe (bolted) | Instant access, you control it | Burglary, fire, coercion at home | Primary copy, or one multisig key |
| Bank safe deposit box | Physical security, fire protection | Bank hours, no FDIC insurance on contents, can be sealed at death or frozen | One copy or one key, never a quorum |
| Trusted family or friend | Geographic separation, helps heirs | Their home security, their discretion, relationship changes | Sealed, tamper-evident copy, or one key |
| Estate attorney | Continuity at death | Staff turnover; you must trust the firm | Instructions or a sealed key, not a full single-sig seed |
| Second property or other region | Survives a local disaster | Harder to check | Tier 3 key sites |
05 Sending and receiving safely
Before every send
- Compare the full address on the device screen with the recipient's, from a second channel (call, in person) for large amounts.
- Check amount, fee, and change address on the device; change should return to your own wallet.
- Send a small test first when the address is new; bitcoin transactions cannot be reversed.
Receiving
- Generate the receive address on the hardware wallet and confirm it on its screen before sharing.
- Use a fresh address each time. Reuse links your payments and exposes the public key.
- Label incoming coins by source (exchange, salary, private sale) in your wallet software.
Privacy & coin control Tier 2+
- Use coin control (Sparrow, Electrum) to choose which coins you spend so you do not merge identified and unlinked coins.
- Consolidate small coins when fees are low; each input raises future fees.
- Run your own node or connect through a trusted Electrum server so a third party does not learn your addresses.
06 Operational security & privacy
Every link between your identity, your address, and your holdings is a way for someone to find and target you. Remove them in order of cost.
The shield of silence All tiers
- No posts about buys, sells, balances, or wallet screenshots.
- Do not discuss holdings with strangers or casual acquaintances.
- Unbox hardware wallets off camera; the box and device are signals.
Accounts & devices All tiers
- Unique passwords in a manager (Bitwarden, 1Password).
- Authenticator app or security key instead of SMS 2FA on exchanges and email.
- On public Wi-Fi, use a VPN (Mullvad, ProtonVPN) or wait.
- Think about where hardware wallets are shipped; an office or P.O. box avoids tying "bitcoin buyer" to your home.
Harden identity Tier 2+
- FIDO2 security keys (two, one as spare) on email, password manager, and exchanges.
- Ask your carrier for a port-out PIN or number lock; remove the phone number as a recovery method where you can.
- Separate email for crypto accounts (Proton Mail, Tuta).
- End-to-end encrypted messaging (Signal) for anything about your setup.
Whale footprint reduction Tier 3
- Pseudonyms for all crypto activity; separate "crypto" and everyday identities.
- Remove PII from data brokers (DeleteMe, Optery).
- Mail forwarding for crypto deliveries (Traveling Mailbox, PhysicalAddress.com).
- A dedicated, minimal laptop used only for signing and coordination.
- Legal structures (LLC, trust) that keep your name off asset records where lawful.
- A policy for family and staff on what is never discussed, including with people outside the security plan.
07 Physical security & duress
Keys and devices All tiers
- Store the device and the seed in different places. A device alone is protected by its PIN; a seed alone is the whole wallet.
- Keep the home copy in a fire-resistant box or safe, out of sight.
- Keep one copy off-site: a trusted relative's home or a safe deposit box.
Safes, seals, ratings Tier 2+
- UL 72 Class 350: interior stays below 350°F in a fire test; fine for metal and paper. Class 125 protects electronics and media.
- TL-15 / TL-30: resists 15 or 30 minutes of attack with common tools. Bolt it to the floor.
- Tamper-evident bags with recorded serial numbers show whether a backup was opened.
Home fortress Tier 3
- Reinforced doors and frames, window film, professionally monitored alarm with cellular backup.
- Cameras with off-site recording (PoE systems such as UniFi Protect).
- A safe room or reinforced area; a professional security assessment of home and travel habits.
- Personal defense training focused on awareness and de-escalation.
Duress plan Tier 3
- Life before bitcoin. Comply and de-escalate.
- Decoy wallet with a plausible balance you can surrender.
- Device features: Coldcard Trick PINs (duress wallet, wipe, brick); passphrase-hidden wallets on Trezor and others.
- Make "I can't" true: with keys in other cities, or a timelock, you cannot move the main stash on demand, and a credible attacker learns that fast.
- Study real cases: Lopp's list of physical bitcoin attacks.
08 Inheritance & succession
Without a plan, your bitcoin is lost at your death or incapacity. The plan has to work for someone who is grieving and not technical.
Letter of instruction All tiers
- What exists: wallet types, rough amounts, which exchanges.
- Where things are: devices, backups, descriptor, passphrase location.
- How to recover, step by step, and who to call for trusted help.
- A list of scams: nobody legitimate will ask them to type the seed online.
- Tell your executor that the letter exists and where it is.
Never put the seed in a will. In the US, a probated will becomes a public court record.
Make it followable Tier 2+
- Have a non-technical person read the letter and walk through a recovery on a test wallet.
- Record a video walkthrough stored with the letter.
- Name a crypto-literate helper ("coach") who holds no keys, so help does not create a new theft path.
Comprehensive protocol Tier 3
- Legal: crypto-aware estate attorney; trust or entity where it fits.
- Technical: multisig where heirs plus a professional co-signer reach quorum after your death, or a timelocked recovery path (Liana, miniscript) that heirs' keys unlock after a delay you keep resetting.
- Guided recovery: collaborative custody providers (Unchained, Casa) offer inheritance protocols that verify the death and assist heirs.
- Review after marriage, divorce, births, or moving.
09 Drills, updates & adaptation
| Activity | Everyday | Serious | Whale |
|---|---|---|---|
| Full restore from backup | At setup | Yearly | Yearly, per key |
| Signing drill | When you spend | Twice a year | Quarterly, every key |
| Backup site check | Yearly | Yearly | Twice a year, seals checked |
| Firmware updates | After security releases, from the official app | Wait a week unless urgent; verify signatures | Test on one key first; stagger vendors |
| Threat review | After life changes | Yearly | Yearly and after any disclosure or staff change |
| Timelock refresh | n/a | n/a | Before the recovery path matures |
10 Common mistakes
- Photo or cloud copy of the seedPhone backups sync to the cloud. One leaked photo and one breached account empties the wallet.
- Seed stored with the deviceA burglar who takes the box takes everything. Keep them apart.
- One backup, or all backups in one buildingA single fire becomes a total loss.
- Never testing recoveryA miswritten word is discovered at the worst possible time.
- Multisig without the descriptorTwo seeds are not enough without every cosigner's public key.
- Passphrase next to the seed, or nowhereNext to it adds nothing; nowhere means permanent loss.
- Pre-seeded or marketplace hardwareA device that arrives with words already printed belongs to someone else.
- Typing the seed to "fix" or "validate" a walletThis is the most common way seeds are stolen.
- Copying addresses from historyExactly what address poisoning is designed to exploit.
- SMS as 2FA or recoverySIM swaps turn a phone number into a password reset.
- Seed in the willProbate makes it public.
- All multisig keys from one vendorOne firmware bug then hits every key; mix vendors.
- Leaving coins on an exchange for convenienceConvenience ends when withdrawals are frozen.
- Bragging, merch, or unboxing videosEach one tells the world where to aim.
- Letting a timelock mature unattendedThe recovery key becomes spendable early; refresh on schedule.
11 Tools, services & resources
Inclusion is not endorsement. Check recent security disclosures before buying. For a full wallet comparison see the Bitcoin wallet cheatsheet; if access is already at risk, see the seed phrase recovery guide, the hacked-wallet rescue guide, or wallet recovery forensics.
Hardware wallets and signing devices
- Coldcard Bitcoin-only, airgapped, Trick PINs
- Blockstream Jade Bitcoin-only, QR airgap, low cost
- Trezor open source, SLIP-39 Shamir backups, multi-coin
- Ledger multi-coin; its opt-in Ledger Recover service (2023) showed firmware can export seed shares
- Foundation Passport Bitcoin-only, airgapped
- BitBox02 Bitcoin-only edition available, simple setup
- Keystone QR airgapped, large screen
- SeedSigner DIY stateless signer, stores nothing
Metal seed storage
- Cryptosteel capsule and cassette
- Blockplate stainless plates, punch marks
- Seedplate punched or engraved plates
- Coldbit steel backup options
- StampSeed DIY stamping kits
- Lopp's metal storage reviews independent stress tests
Wallet and multisig coordinator software
- Sparrow Wallet desktop, coin control, multisig
- Specter Desktop hardware-wallet multisig
- Nunchuk mobile and desktop, collaborative multisig
- Liana timelocked recovery paths (miniscript)
- BlueWallet mobile, small multisig vaults
- Electrum desktop, advanced users
Collaborative custody and inheritance services
- Unchained 2-of-3 vaults, inheritance protocol
- Casa 2-of-3 and 3-of-5 key management, inheritance
- Swan Vault guided multisig setup
Privacy and account security
- Password managers: Bitwarden, 1Password
- VPN: Mullvad, ProtonVPN
- Encrypted email: Proton Mail, Tuta
- Data broker removal: DeleteMe, Optery
- Mail forwarding: Traveling Mailbox
- Home security: SimpliSafe, Abode, Reolink
Learning
- Bitcoin.org: Secure your wallet
- Jameson Lopp's Bitcoin resources
- Physical bitcoin attack list
- Crypto custody hub MPC, institutional, post-quantum, recovery
- Local Bitcoin meetups, for hands-on help from people you can meet
12 Self-custody checklist
Progress is saved in this browser only. The tier filter at the top hides items above your tier.
Some items are hidden by your tier filter. Choose "Show all" to see them.