Seed Phrase Backups: Paper, Metal, and the Mistakes That Lose Funds
A seed phrase has no undo button. Here is how paper and metal backups really work, where they quietly fail, and the habits that keep funds safe.

A seed phrase is the one part of self-custody with no undo button. Lose it and the funds behind it are unreachable. Let someone else read it and the funds are effectively theirs. Most people understand this in the abstract, then store the phrase somewhere that quietly fails months later.
This guide explains how backups work, what paper and metal each do well, and the specific mistakes that cost people money. It is for anyone who has just set up a wallet and wants to get the boring part right the first time.
What a seed phrase actually is
When you create a self-custody wallet, the software generates a long random secret and shows it to you as a list of ordinary words. From them, the wallet can rebuild every private key and every address it manages.
Two consequences follow, and almost everything else here comes from them.
First, the phrase is the wallet. Replacing a phone or losing a hardware device does not have to be a disaster, because any compatible wallet can restore your accounts from the words alone. That is why backups matter more than the device.
Second, anyone holding the words holds the wallet. There is no password reset, no account recovery, no fraud department that can pull a transfer back. Possession of the phrase is ownership of the funds.
So the phrase should only ever exist in places you physically control. It should never be typed into a website, a chat window, a search bar, or a support form. No legitimate service needs it. Ours certainly does not: TokenSpin is an informational publication, and we never ask you to connect a wallet, approve a token, sign a transaction, or enter recovery words anywhere on this site. For the wider picture, start with our wallet security basics.
Paper backups: cheap, simple, easy to ruin
Writing the words on paper is the default, and for a lot of people it is genuinely good enough. It costs nothing, works offline, and is easy to check.
The weaknesses are physical rather than technical. Paper burns, soaks, fades, tears, and gets thrown out by someone tidying a drawer. Ink from some pens fades over years or runs the moment it meets water. Thermal paper, the kind used for receipts, can go blank on its own.
A few habits carry most of the benefit:
- Write in permanent ink, in clear block capitals, and number the words so the order cannot be lost.
- Read the words back against the wallet screen, one by one, before you close the wallet.
- Keep it flat, dry and out of sunlight, inside something opaque rather than a clear folder.
- Make more than one copy, kept in separate places, so a single flood or burglary cannot take everything.
Paper does not protect against someone finding it. Nothing about the medium hides what it is. That part is down to where you put it.
Metal backups: what they solve and what they do not
Metal backups exist for one reason: fire and water. Stamping, engraving or slotting letter tiles into steel produces a record that survives conditions which would destroy paper. If your backup lives in a home rather than a bank, that is a real advantage.
What metal does not do is equally important. It does not encrypt anything and it does not hide anything. A steel plate with your words on it is exactly as readable to a thief as a sheet of paper, and rather more obviously valuable. Metal upgrades durability, not secrecy.
Stamping is also slow and unforgiving, and a mis-struck letter is permanent. Buying a backup product is itself a moment to be careful about the seller, because tampered and counterfeit security products are a known problem across the category. A reasonable middle path for many beginners is paper first, verified and stored sensibly, then metal later once the amount involved justifies the effort.
The mistakes that actually lose funds
In practice, people rarely lose a seed phrase to an exotic attack. They lose it to ordinary convenience. The recurring patterns are worth naming plainly:
- Photographing it. A photo of the words goes into a phone gallery, which usually syncs to a cloud account, which is protected by a password and an email address rather than by anything you control.
- Typing it into a notes app, spreadsheet or email draft. Once the words exist as text on an internet-connected device, they are exposed to every future breach of that account and every piece of malware on that machine.
- Keeping every copy in one building. Three copies in the same flat are one copy with extra steps, and a single copy makes any fire or house move a total loss.
- Never verifying the backup. A phrase written down wrongly looks identical to one written down correctly, right up until the day you need it.
- Telling people it exists. Flatmates and social media both widen the circle of people who know there is something worth taking.
- Entering it somewhere to fix a problem. This is the one that turns a small worry into a total loss, and it is covered below.
There is no single correct storage location, because loss and theft pull in opposite directions. Duplicates in separate places protect against fire and flood. A locked container somewhere that is not the obvious spot protects against people. Avoid anywhere others open routinely, such as a shared drawer or a desk at work.
How seed phrase scams approach you
Almost every serious loss involving recovery words begins with a person or a page persuading the owner to reveal them voluntarily. The pretexts are predictable once you have seen them.
Someone posing as support offers to fix a stuck balance if you validate or synchronise your wallet. A pop-up warns that your wallet is compromised and must be migrated immediately. A rewards page asks you to import an existing wallet to check eligibility. A fake version of a familiar app asks you to restore rather than create.
The tell is always the same: a request for the words, or for you to type them into anything at all. Real wallet software asks for your phrase only on a device you control, when you are deliberately restoring a wallet. It never needs it to verify you, unlock rewards, or resolve a fault.
Urgency is the other signal. Genuine problems survive a night’s sleep. Scams need you to act before you think, which is why they arrive with countdowns, warnings and helpful strangers. We collect current patterns in scam alerts, and the same reasoning drives how we vet anything we write about.
A short routine that works
Set the wallet up somewhere private, write the words by hand, and check them twice against the screen. Restore the wallet from the written copy before it holds anything, so you know the backup works. Move a small amount first and confirm it arrives. Then store your copies in separate places and stop touching them.
After that, the discipline is mostly refusal. Nothing legitimate will ever ask for those words, so if something does, the answer is no, however official it looks. If you are unsure about a specific request, our FAQ covers what we are asked most often.
Get The Spin
The week's vetted rewards + the scams to avoid — free, every week. Informational. Not financial advice. We never ask for your keys.