Last updated: December 18, 2026
- A recovery phrase is 12–24 words drawn from a fixed list of 2,048 English words. The last word is a checksum that catches typos.
- The phrase deterministically derives every private key your wallet will ever use — whoever holds it owns the funds.
- Store it offline only: paper or metal. Never screenshots, cloud notes, email, or password managers.
- No legitimate service will ever ask for your phrase. Anyone who does is attempting theft.
- An optional passphrase — the "25th word" — derives a separate set of wallets. Powerful, but a second secret to lose.
Every self-custody wallet eventually shows you a list of words and tells you to write them down. Most people do it without ever learning what the words are — which is exactly how they end up in a screenshot, a notes app, or a phishing form. Here is the thirty-second version: the words are the wallet, and everything else follows from that.
What BIP-39 actually is
Your recovery phrase — also called a seed phrase or mnemonic — is produced by BIP-39, the standard most wallets use to turn randomness into words. The wallet generates a large random number, encodes it as 12 to 24 words pulled from a fixed list of exactly 2,048 English words, and computes one final word that acts as a checksum over all the rest.
That last word matters more than people realize. Because it is calculated rather than chosen, a mistyped or reordered phrase almost always fails validation — the wallet rejects it instead of silently opening the wrong wallet. It is a typo detector built into the standard, and it is why wallets can warn you when a word is out of place.
The important mental model: the phrase is not a password to an account and not a hint that unlocks your keys. It is a human-readable encoding of the secret number your keys are made from.
One phrase, every key you will ever own
The phrase feeds a derivation standard (BIP-32) that turns one seed into a tree of keys. Every account, every chain, every address your wallet generates — past, present, and future — comes from those same words.
Two consequences follow. First, anyone who obtains the phrase can re-derive all of it on any compatible wallet, from anywhere, without your device or your knowledge. Second, nobody can help you recover it: there is no reset flow, no recovery desk, and no company holding a copy. If the phrase is lost and your device dies in the same week, the funds are unrecoverable — permanently, and by design. That finality is the price of actual self-custody.
How to store it: paper and metal, offline only
Write the phrase on paper during setup, word for word, in order — then verify the backup by actually reading it back, not by assuming your handwriting was fine. Paper is the baseline; its weakness is physical. Fire, water, and time all destroy it, which is why many holders stamp or etch the words into steel plates. A metal backup survives a house fire; a notebook does not.
Two copies in two separate locations cover both theft and disaster. And keep the scheme boring: elaborate hiding places, split phrases, and coded hints mostly produce owners who lock themselves out. A plain, well-stored copy you can still find in ten years beats a clever one you cannot.
The never list
No internet-connected storage is safe enough for a phrase, because the phrase is worth everything the wallet holds:
- Screenshots or photos — camera rolls sync to the cloud automatically.
- Notes apps, cloud drives, email drafts, or messages to yourself.
- Password managers — they sync remotely by design.
- Typing it into any website, form, or "wallet verification" page.
- Keep the phrase on paper or metal, physically offline.
- Read a written backup back once before trusting it.
- Keep copies in two separate, physically secure locations.
- Treat every request for the phrase as an attack in progress.
One rule overrides all the others: no legitimate wallet, exchange, or support agent ever asks for your recovery phrase. There is no scenario in which sharing it fixes a problem. Whoever asks for it is stealing, whatever the story sounds like.
The optional "25th word"
BIP-39 supports an optional passphrase that you choose yourself — often called the 25th word. It is not drawn from the wordlist: it is any string of characters, and it is case-sensitive down to spaces and punctuation. Adding one derives a completely separate set of wallets from the same phrase.
Its strength and its danger come from the same property: there is no such thing as an incorrect passphrase. Every input produces a valid wallet — a typo simply produces a different, usually empty, one. That makes a passphrase an excellent decoy (an attacker holding only your phrase finds empty default wallets) and a real hazard for the forgetful. Store the passphrase separately from the phrase; lose it and that wallet set is gone, with no way to prove it ever existed. If you are new to self-custody, master the plain phrase first.
What a phrase cannot fix
A recovery phrase is a single point of failure: one secret guarding everything. Stored perfectly, it still does nothing about what you sign or where you paste — those are separate failure modes, covered in our guide to off-chain threats like clipboard malware and dust attacks.
It also attracts a scam of its own: "recovery services" that promise to retrieve a lost phrase for a fee, or that ask you to "verify" yours first. A lost phrase is mathematically unrecoverable — no tool or firm can brute-force the entropy behind those words. Anyone claiming otherwise is the attack.
Nova's side of the deal: when you create or import a wallet, Nova derives keys entirely on-device — air-gapped phrase input, validated locally, zero telemetry. Your phrase is never transmitted, logged, or stored anywhere but where you put it. What it cannot do is remember it for you.
Nova validates your recovery phrase locally — air-gapped input, an audited BIP-39/32 implementation, and reproducible builds you can verify. Create a wallet with no account, no KYC, and nothing phoning home.