Industry InsightsSeptember 22, 2026

Stop Treating Your Seed Phrase Like a User Password

One phrase written on one card fails the first time a colleague needs signing access, an auditor asks who can move funds, or the person holding it hands over to a successor. At a business holding customer balances, a better hiding place stops helping early. Seed phrase storage is the set of controls a company puts around the words that derive every private key in its wallet. The control that holds is key material split so that no single copy, and no single person, can move or lose the whole balance. In 2024, private key compromises accounted for the largest share of stolen crypto, at 43.8%. Most published advice on this topic is written for someone protecting their own savings. You are protecting other people's. The two problems look identical for about ten minutes and then stop resembling each other completely. What does seed phrase storage actually protect? Failure. The operations lead treats the recovery phrase as a password for one wallet, and stores it the way passwords get stored: one copy, one location, one person who knows where that location is. Why it happens. The mnemonic looks like a credential, so it gets filed like a credential. The specification says otherwise. Under BIP-39, the mnemonic standard, entropy is encoded as words with a checksum and the mnemonic is then stretched into a binary seed. That seed feeds BIP-32, the hierarchical deterministic scheme, where one master seed deterministically derives a whole tree of child key pairs. A seed phrase generated under BIP-39 is the root of every address the wallet will ever produce, not a login for one of them. If your team has not internalised that, start with the plain-language version of what a seed phrase is and why losing it ends the wallet. What to do instead. Write down, in one page, what the phrase controls: every deposit address customers pay into, every sweep destination, every withdrawal signing key derived below it. Then stop calling it a backup and start treating it as key material with a lifecycle: generation, storage, use, rotation, destruction. Each of those five stages needs a named owner. Right now, in most small platforms, all five are the same person, and that person is reading this. What it costs you. That share came out of roughly $2.2 billion stolen from crypto platforms across 303 individual hacking incidents in 2024. The pattern held into the following year: attacks on private key infrastructure and signing processes at centralized services accounted for 88% of losses in Q1 2025, inside a year where over $3.4 billion in crypto was stolen from January through early December 2025. Those numbers describe platforms with staff, not individuals with hobbies. Why does one written seed phrase backup fail on a team? Failure. The single written copy has to be simultaneously reachable and unreachable. Reachable enough that the treasury sweep happens when the person who holds it is on a plane. Unreachable enough that a cleaner, a contractor or a disgruntled leaver cannot photograph it. Why it happens. Separation of duties is the control every auditor expects on money movement, and a single seed phrase makes it arithmetically impossible. Whoever can read the words can derive every key and sign every withdrawal alone. A single written seed phrase gives every holder of that paper the full balance, with no reviewer and no record of who used it. What to do instead. Look at a normal Tuesday. Without split key material: deposits have piled up over the weekend, the sweep to cold storage is due, and the ops lead who holds the phrase is out sick. The finance lead knows the safe code, because someone had to. Two people now have unilateral, unlogged authority over the full balance, and neither event appears anywhere a reviewer could find it. When the ops lead returns, nothing in the system says whether the phrase was read while they were away. With split key material: the sweep is a routine action that a second reviewer approves from a phone, the approval expires if nobody acts on it, and the dispatch record shows who reviewed what and when. Nobody had to open a safe. Nobody gained the ability to act alone. What it costs you. A named example is more instructive than a category: read the breakdown of the Drift Protocol private key compromise for how quickly a key event becomes a balance event. The internal version of this, the failed recovery where nobody stole anything and the funds are simply gone, is the failure mode nobody publishes numbers for. There is no disclosure obligation and no attacker to name, so we cannot tell you what it typically costs a small platform, only that the money is as gone as it would be after a theft. Is a metal seed phrase backup worth buying? Failure. The team reads about fire and water damage, buys a metal seed phrase backup plate, stamps the words in, and files the whole question as solved. Why it happens. Durability is the easiest part of the problem to buy. It arrives in a box, it has a price, and it produces a visible artefact you can show a director. The failure modes it fixes are real, and the failure mode it does nothing about is the one that empties the account: a complete copy of the phrase, held by one person, readable by anyone who gets thirty seconds alone with it. What to do instead. Buy the plate if your only copy currently lives on paper, then treat that purchase as the smallest item on the list. Metal changes what survives a flood. It does not change how many people can act alone, and it makes theft slightly easier to conceal, because a stamped plate returned to a drawer looks untouched. If the plate is going into a vault, decide the cold side of your setup properly first: the trade-offs are laid out in the comparison of hot and cold wallet models for institutions. We would split the shards before buying a better safe. A durable single copy is still a single copy. What it costs you. Nothing directly, which is the trap. Money spent on durability reads as money spent on custody risk, and the board stops asking. Meanwhile the personal-holder advice that recommended the plate keeps circulating: 158,000 personal wallet compromises in 2025 totalled $713 million, and that category grew from 7.3% of total stolen value in 2022 to 44% in 2024. That is a large, loud population whose advice is written for one owner, one device and no colleagues. Your controls have to survive a headcount. [[screenshot: coinsdo-coinwallet-export-seed-phrase-01 - exporting a wallet's seed phrase, with the safety warnings shown before the words appear]] How do you store a seed phrase when three people need access? Failure. The team answers "three people need access" by making three copies. Now three people can each move the entire balance, and the probability of one of those copies leaking has tripled. Why it happens. Copying is the only tool a single phrase gives you. The mnemonic is atomic by design: partial knowledge of it is worthless, full knowledge of it is total. Any distribution scheme built on top of the words themselves multiplies whole-balance risk with every copy. What to do instead. Move the split down a level, into the key material, so that possession of one piece confers nothing. Three mechanisms are worth separating clearly, because vendors blur them constantly. Key shards. The CoinGet deposit client is available in a sharded-key configuration, with restore support, so the deposit-collection side of the platform runs without any single stored copy of a full key. Deposit addresses are checked as legitimate before funds are attributed to them, and collected funds route automatically to cold storage rather than accumulating in a hot balance somebody has to babysit. Approvals. Splitting keys without splitting authority only moves the problem. CoinSend lets an operations team define reviewer tiers, thresholds, and escalation logic for high-value transactions, with granular roles per sub-account and a main account that controls each sub-account's login session validity. Approvals carry configurable expiry times, visible on each dispatch record, so a request left hanging overnight dies instead of waiting. Reviews are signed with RSA and HMAC-SHA256 and can be actioned from mobile, PC or a browser extension, which is what makes a two-person rule workable when one of those people is in a different timezone. What it costs you. Migration is a project, not an afternoon. The offsetting number is that client-side wallets deploy on Android or PC/cloud in under 3 minutes, so the technical step is rarely what stalls this. What stalls it is nobody wanting to own the decision. What seed phrase storage best practices survive an audit? Failure. The procedure exists in the ops lead's head, the recovery has never been tested, and the first real restore attempt happens on the worst day of the year. Why it happens. Recovery is the one step in the key lifecycle nobody rehearses, because rehearsing it feels like inviting the event. Untested restores lose funds without anyone attacking, and because nobody files a public disclosure when their own procedure is what failed, this is the failure mode nobody publishes numbers for. What to do instead. Five practices, in the order I would put them in place. Rehearse the restore on a schedule, using the actual documented steps, with somebody other than the author doing it. Restoring a previous CoinGet client is a defined flow, and the person who will do it at 3am should have done it once at 3pm. Name an owner for each lifecycle stage, and make sure generation and approval are never the same person. Set approval thresholds by value, not by convenience, and check the expiry times are short enough that a stale request cannot be revived a week later. Keep the signing trail somewhere a reviewer can read without asking the ops lead for it. An audit trail that requires the audited party's cooperation is not an audit trail. Confirm who holds the keys contractually as well as technically. CoinsDo never holds your private keys, and assets stay portable even if the partnership ends, which is the property that separates infrastructure from custody. The distinction matters more than most teams assume, and it is set out in the comparison of self-custody and exchange-held wallets. Frequently asked questions about seed phrase storage How should a company store a seed phrase for its hot wallet? A company should stop storing one complete phrase and move to split key material, where each holder controls a shard or share that is useless alone. Pair the split with approval thresholds so that moving funds requires a second named reviewer, not just possession. Is a metal seed phrase backup better than paper? A metal seed phrase backup survives fire and water better than paper, so it improves durability. It does not reduce the risk that matters most to a business, because the plate still holds one complete phrase that one person can read and use alone. What is the safest seed phrase storage setup for a team? The strongest setup for a team removes the single complete copy entirely. Use sharded or threshold key material for signing, route collected deposits to cold storage automatically, and require a second reviewer with an expiring approval before any high-value withdrawal leaves the platform. Can key shards be restored if one device is lost? Yes. The CoinGet client's sharded-key configuration includes restore support, and CoinWallet supports threshold-gated MPC device replacement when a signer loses a device. Both paths are designed so that losing one holder's device does not lose the wallet. Who should hold the seed phrase at a crypto exchange? No single person should hold a complete phrase at a platform running customer funds. Split the key material across named holders, separate the people who generate keys from the people who approve movements, and record every approval where a reviewer can read it. What I would do first Pick the wallet holding the most money and count how many people could empty it acting alone. If the answer is one, that is the finding, and it does not need a project plan to fix. The next action is a thirty-minute conversation about which of the three splits fits your setup: sharded deposit collection, threshold signing, or approval tiers on withdrawals. Most teams need two of the three, and almost nobody needs a better safe. If you want the deposit and withdrawal side mapped against your current setup, start with the wallet infrastructure overview.

Read article →14 mins read
Stop Treating Your Seed Phrase Like a User Password
8 articles

Latest articles

[Press Release] CoinsDo to Exhibit at WebX 2026

2 mins read

[Press Release] CoinsDo to Exhibit at WebX 2026

[Press Release] CoinsDo Issues Warning Against Impersonation and Scam Websites

3 mins read

[Press Release] CoinsDo Issues Warning Against Impersonation and Scam Websites

[Press Release] CoinsDo Announces Participation in Money20/20 Las Vegas

2 mins read

[Press Release] CoinsDo Announces Participation in Money20/20 Las Vegas

[Press Release] BTCC Exchange Partners with CoinsDo to Enhance Cryptocurrency Services

2 mins read

[Press Release] BTCC Exchange Partners with CoinsDo to Enhance Cryptocurrency Services

[Press Release] CoinsDo to Unveil Proprietary Solution Disrupting USD$1 billion Crypto Asset Management Market at Paris Blockchain Week

2 mins read

[Press Release] CoinsDo to Unveil Proprietary Solution Disrupting USD$1 billion Crypto Asset Management Market at Paris Blockchain Week

[Press Release] CoinsDo to Unveil Transformative Digital Asset Management Solutions at European Blockchain Convention in Barcelona

3 mins read

[Press Release] CoinsDo to Unveil Transformative Digital Asset Management Solutions at European Blockchain Convention in Barcelona

[Press Release] CoinsDo Announces Participation in TOKEN2049: Spotlight on Digital Asset Custody Solutions and the Future of Web3

2 mins read

[Press Release] CoinsDo Announces Participation in TOKEN2049: Spotlight on Digital Asset Custody Solutions and the Future of Web3

CoinsDo Debuts New Multi-Party Computation (MPC) Feature to Enhance Wallet Security

2 mins read

CoinsDo Debuts New Multi-Party Computation (MPC) Feature to Enhance Wallet Security