The word key is doing a great deal of misleading work inside the phrase “private key”. A key opens a lock, and a key that is lost can be replaced by somebody who keeps a spare. A private key does none of that. It is a number, it authorises messages, and it has no locksmith, no spare and no reset. That single difference explains almost everything that follows: why a seed phrase is not a password, why there is no “forgot my password” button, and why the entire burden of security moves from a company’s support desk to whoever happens to be holding the paper.
It is worth stating at the outset what this article is not. It is not a warning, and it is not an argument for or against holding your own keys. It is an explanation of the mechanism, because the fear that surrounds self-custody and the bad advice that surrounds it both grow from the same mistake: treating a number as if it were a key.

A private key is a number, and a wallet is a tool that uses it
A cryptocurrency balance is not a file on your computer and it is not held inside your wallet app. The balance is an entry in a public ledger, and every entry is associated with an address. To move a balance you publish a message, and the network accepts that message only if it carries a valid digital signature. A private key is what produces the signature. Everything else is accounting.
Concretely, a private key on Bitcoin and Ethereum is a number between 1 and roughly 2256. The design challenge is not making the number large; it is making the number unpredictable. A key generated from a weak source of randomness is not a strong key, no matter how many digits it has, and the history of lost funds contains more weak-randomness failures than most people assume.
From the private key the software derives a public key, and from the public key it derives an address. You can share the address freely; it is what you hand out in order to be paid. You can share the public key in many contexts as well. The private key is the one piece that must never move. The phrase “not your keys, not your coins” is a compressed version of this: if someone else holds the number that signs, the balance is yours only as a promise.
This is also why a wallet never stores coins. It stores keys, and it scans the ledger for the balances those keys control. A wallet with the right key and no network connection is still the owner in every sense the protocol cares about; a wallet with a polished interface and the wrong key is a window onto somebody else’s money. For a longer treatment of that idea, see our explainer on what a crypto wallet actually holds.
The seed phrase came later, and it is a backup, not a login
The first Bitcoin wallets generated keys one at a time, and modern ones do not. A hardware wallet or a phone app that follows the standard creates a single random seed and derives every key in the wallet from it, on demand. The phrase you write down on paper is a human-readable encoding of that seed: twelve words, twenty-four words, with a checksum and a fixed wordlist.
That structure exists for one reason, and it is a backup. A seed phrase is a backup of every key the wallet will ever generate, including keys for addresses you have not used yet. It is a backup you are expected to keep, because losing it loses the wallet, and copying it is the same as copying the wallet.
The word “login” is where the trouble starts. A login is a credential that a company stores, validates and can reset on request. A seed phrase is a credential that no company stores, no company validates and no company can reset, because the company does not exist. The private key is the secret itself, and the phrase encodes the secret itself. Nothing stands behind it that could decide to give access back to you, because that authority would require someone holding a copy, and the entire point is that nobody holds a copy.
Why a seed phrase behaves like a password but is not one
The two look similar from the outside: a secret string you must have in order to get in. The properties underneath are opposite. A password lives on a server as a hash, gets compared on each login and can be changed from a settings page; if you forget it, an email arrives. A seed phrase lives only where you put it, is never compared to anything by anyone, and cannot be changed without moving every balance to a brand-new wallet that you also generate and back up. The phrase is the asset, in the same way a bearer bond is the asset.
This produces a rule that surprises people. There is no such thing as resetting a crypto account. There is only creating a new one and moving the money. If you suspect a phrase was exposed, the correct action is not to change a password but to generate a new seed, move every asset to the new addresses, and treat the old phrase as permanently compromised. The old phrase cannot be revoked; the network has no list of stolen phrases and no mechanism to honour a revocation even if such a list existed.
There is one narrowing case, and it is not really an exception. A coin held on a centralized exchange behaves like a password-protected account, because the exchange is holding the keys and the account is a login into the exchange’s internal ledger. Everything in this article applies to the exchange’s own key custody rather than to yours, which is exactly the trade-off described later under custodial arrangements.
The derivation runs one way, and only one way
The relationship between the pieces is easiest to hold in mind as a chain, with arrows that only point forward. Randomness becomes a seed; the seed becomes a master key; the master key produces private keys; each private key produces a public key; each public key produces an address. Going forward is fast and cheap, and a phone does it in milliseconds. Going backward is believed to be infeasible, and the entire security model rests on that asymmetry.

This is the same structure that protects your messages and your bank site, and the mathematics is older than Bitcoin by decades. The practical consequence for a user is narrow but important: because the address is derived from the public key, and the public key is derived from the private key, publishing an address reveals nothing that helps an attacker find the private key. That is why you can post a receive address in public without fear, and why the danger lives entirely in the private key and the seed phrase that encodes it.
The one-way property also explains why “extract the private key from the address” shows up only in scams. No tool recovers a key from an address, not from a police lab and not from a quantum computer running today. The real attacks sit at the endpoints, and the next two sections are about those.
What actually happens when a seed phrase is lost
Nothing happens on the network, and that is precisely the problem. The balance stays on the addresses, visible to everyone, untouched. The blockchain has no concept of a user who has misplaced a backup, and no party has the standing to override a signature that will never arrive. The assets are not frozen, seized or deleted; they are simply unreachable by the only party who ever had authority over them.
This differs from losing a bank card, and the difference is instructive. A bank card is a credential to a relationship. The relationship survives the card, and the bank issues another one. A seed phrase is not a credential to a relationship; it is the relationship. When it is gone, there is no counterparty left to ask.
There is a narrow set of partial recoveries worth knowing, because people misdescribe them. If the device still works and is still unlocked, the funds can be moved to a new wallet even when the paper backup is gone, so the phrase is not needed for daily use, only for recovery. If the phrase is partly intact, some wallets accept a passphrase the user added on top of the words, and forgetting that passphrase is indistinguishable from losing the phrase. And if the balance sits on a custodial exchange, the recovery path is an account reset, because the exchange is the key holder and the user is a customer. None of these is a way to reset a self-custodied phrase, because no such way exists.
What happens when somebody else gets the phrase
The mirror image is faster and more brutal. A seed phrase in another party’s hands is complete, transferable authority over every address the wallet controls. There is no second factor to satisfy, no rule that a transfer to a new address is suspicious, and no window during which the legitimate owner can object. The first transaction that reaches the network wins, and the network records it as valid, because from the protocol’s point of view it is valid.
This is why the exposure of a seed phrase is treated as total compromise even before any money moves. A cautious attacker may wait. A common pattern is to sweep the wallet the moment a large deposit arrives, which means a person who believes the phrase is “not really a problem” can discover otherwise at the worst possible moment. There is also a well-known trick in which the thief, holding a phrase, leaves small balances in place and waits for the owner to migrate, then sweeps the new address using the same seed. The only clean response is to move to a seed the attacker has never seen.
How attackers actually obtain keys
Almost nobody is attacked by cryptographic brute force, because none is possible in the relevant sense. Attacks happen where keys are handled, and they fall into three rough families.
The largest family is client-side. A phishing site that imitates a wallet, a fake app bought from a search ad, a browser extension that asks for the phrase “to verify” the wallet, a screenshot that ends up in a cloud backup: all of these hand the secret to somebody else while the cryptography is working perfectly. The second family is weak randomness at generation time, where a poorly seeded device produces a key another party can guess; this is rarer in modern wallets and is the reason “use a wallet that is well reviewed” is not empty advice. The third family is human: coercion, a phrase photographed and left in a phone gallery, a phrase typed into a computer that logs keystrokes, a phrase stored in a note-taking app that syncs to the vendor’s servers.
Notice what is absent from that list. There is no entry for “hacked the blockchain”, because the ledger was never the soft target. There is no entry for “guessed the private key”, for the same reason. Every real loss is a handling failure somewhere between the randomness and the drawer.
Twelve words or twenty-four, and what the number buys
A seed phrase is a fixed-length encoding of a fixed amount of entropy. Twelve words encode 128 bits, and twenty-four words encode 256 bits. The extra words double the length of the phrase and square the size of the space an attacker would have to search if guessing were the chosen method.

That comparison is real and almost entirely beside the point in practice. Both 128-bit and 256-bit seeds sit far outside the range of any computation that can be performed, and the failure that actually occurs is a person photographing the phrase, emailing it or reading it aloud on a video call. Choosing twenty-four words over twelve is reasonable, and choosing a good storage method over a bad one is vastly more important. Someone who writes twelve words on steel and keeps them offline is in a stronger position than someone who writes twenty-four words in a phone note.
How to store a seed phrase without turning it into a liability
The goal is to make the phrase survivable and unstealable at the same time, and the two goals pull against each other. The standard practices are a compromise between them.
Write it down before the device is used, and verify the transcription, because a backup written from memory is a backup that has already failed once. Keep it offline: paper in a drawer beats a photo in a gallery, and a note in a cloud service is the worst of the common options, because it is a copy of the wallet held by a company whose security you do not control. Weigh the physical risks separately from the digital ones; paper burns and floods, which is why stamped metal plates exist and why they are popular with people who hold meaningful amounts.

There are more advanced patterns for larger holdings, and each trades convenience for a different kind of safety. A stamped-metal backup survives fire and water. Splitting a phrase across locations, or adding a passphrase kept separately, means one discovery does not compromise everything, at the cost of a more complicated recovery. A Shamir-style split, in which several shares are required to reconstruct the phrase, removes the single point of failure entirely but adds its own procedure to get wrong. The right choice depends on the size of the balance and the patience of the owner, and a plan too clever to be executed reliably under stress is not a safer plan.
Hardware wallets, passphrases and shared custody
A hardware wallet changes where the secret lives. The key is generated on the device and, in normal use, never leaves it; the device signs a transaction on request and hands back the signature rather than the key. This removes an entire category of client-side attacks, because a compromised computer cannot ask the device for a key it does not have. It does not remove the category of human error, because the seed phrase still exists on the paper you wrote it on, and no chip protects the paper.
A passphrase, sometimes called the twenty-fifth word, is an additional secret mixed into the derivation. It produces a different wallet from the same twelve or twenty-four words, which allows a decoy arrangement: a phrase held under mild duress opens the decoy wallet, and the real one needs the passphrase as well. The value of this is narrower than the drama suggests, and it depends entirely on the phrase and the passphrase being stored apart. Kept together, the passphrase adds a few characters of difficulty to a secret that is already exposed. For institutions, the equivalent tool is a hardware security module, a hardened device that holds keys and does not disclose them; our note on why the key never leaving the box was never a full guarantee covers where that model still leaves a seam.
The largest holdings are usually not protected by one key at all. A multisignature arrangement requires several keys to approve a transaction, so a single lost device or a single stolen phrase moves nothing. This is how exchanges and treasuries hold reserves, and it is increasingly available to individuals through collaborative custody, where a provider holds one key and the user holds the others. The trade-off is that the provider becomes a counterparty for availability, even though it is not a counterparty for custody.
The trade-offs people are not always told
Self-custody is a transfer of responsibility, not a free upgrade, and an honest version of the advice says so. The upside is that the failure modes are ones you can see and control; the downside is that they are yours alone. A custodial exchange can be hacked, mismanaged or frozen by a regulator, and those risks sit outside your control. A self-custodied wallet cannot be frozen by anyone, which also means it can be lost by anyone, including you.
Two problems have no clean technical solution and deserve to be named. The first is inheritance: if the owner dies without leaving the phrase in a form the heirs can use, the assets are lost permanently, and there is no estate process to fall back on. The second is incapacity, the case where the owner is alive but cannot operate the wallet. Collaborative custody and legal arrangements address these by introducing a second party, which reintroduces a small amount of the counterparty risk that self-custody was chosen to avoid. No arrangement removes both risks at once; there is only a choice about which one to carry.
The distinction worth keeping
A private key is a number that authorises transfers. A seed phrase is a backup of every such number a wallet will generate. Neither is a password, neither is a login, and neither can be reset by anybody, because resetting would require an authority that holds a copy, and the absence of that authority is the entire design. A wallet is a tool that holds keys; the coins, strictly speaking, never leave the ledger.
Read that way, the technology stops looking exotic and starts looking like a bearer instrument with good mathematics and no customer service. The mathematics is as strong as anything in modern cryptography. The customer service is the part you supply, and the reason the advice is so repetitive is that the failures are so repetitive too. The goal is not to be clever; it is to make the phrase survive a fire and stay out of a screenshot, which are the two most common ways a well-built wallet still ends up empty.
Frequently asked questions
Is a seed phrase the same thing as a private key?
No. A private key is a single number that signs for a single address. A seed phrase is a backup from which every private key in a wallet is derived. One wallet has many private keys and one seed phrase, and the phrase is the more valuable secret because it reconstructs all of them.
Can a seed phrase be reset or recovered by support?
No. No company stores it, no service validates it and no support team can regenerate it, because the phrase is the secret itself rather than a credential to an account. The only valid recovery path is having written it down in the first place.
What if I lose the phrase but still have the device?
You can keep using the wallet and you can move the balance to a new wallet, as long as the device still works and is still unlocked. What you cannot do is recover the wallet if the device fails, which is why the phrase is a backup for the device rather than a substitute for it.
Should I ever store a seed phrase online?
Storing it online converts a self-custodied wallet into a custodial one, with the added problem that the custodian is a company you did not choose and cannot audit. A password manager, a cloud note, a photo gallery and an email draft all count as online. The phrase belongs offline, ideally on something that survives the physical failure modes of your home.
How many words should a seed phrase have?
Twelve words, which encode 128 bits, are already far beyond brute-force attack; twenty-four words encode 256 bits. The choice matters far less than the storage method, because the realistic point of failure is how the phrase is kept, not how many words it contains.
What is the twenty-fifth word, and do I need one?
A passphrase is an optional extra secret mixed into the derivation, producing a different wallet from the same words. It is useful only if it is stored apart from the phrase, and it adds a real risk of its own: forgetting the passphrase loses the wallet just as completely as losing the phrase.
Sources and further reading
The BIP-39 standard defines how a seed phrase is generated from entropy and how it is turned back into a wallet seed, and BIP-32 defines the hierarchical derivation that produces many keys from one seed. Both are public specifications rather than vendor documents, and both are worth reading once in full.
For the wider context, see our explainer on what a crypto wallet holds, and for the limits of hardware custody in an institutional setting, see the analysis of a key that never left the box. The mechanics that leave a balance visible but unreachable are the same mechanics that make a stablecoin a receipt rather than a coin, and the same absence of a counterparty that this article describes is the subject of our map of what DeFi reproduces and what it drops.







[…] and the general checklist is in ten checks a ranking cannot do for you. For the custody side, see the explainer on private keys and seed phrases and what a crypto wallet actually holds. The difference between a claim and a coin is developed in […]