A seed phrase is the list of 12 to 24 ordinary words that a self-custody crypto wallet shows you at setup. Those words encode the random number from which the wallet derives every private key and address it manages. Whoever holds the words in the right order can rebuild the whole wallet on another device, which is why the phrase is both your backup and the single most valuable secret you own in crypto.
Wallet makers use different names for the same thing. MetaMask calls it a Secret Recovery Phrase, Ledger uses Secret Recovery Phrase too, Coinbase says recovery phrase, and Trezor now says wallet backup, listing “seed”, “mnemonic” and “BIP39 phrase” as older terms for it.
Where the words come from
Most wallets follow BIP-39, a Bitcoin specification assigned in 2013 that many other chains’ wallets also use. The wallet first generates a random number of 128 to 256 bits. It appends a short checksum, splits the result into 11-bit chunks and looks up each chunk in a fixed list of 2,048 words. Here is how the length of the random number maps to the length of the phrase:
| Random input | Checksum | Words |
|---|---|---|
| 128 bits | 4 bits | 12 |
| 160 bits | 5 bits | 15 |
| 192 bits | 6 bits | 18 |
| 224 bits | 7 bits | 21 |
| 256 bits | 8 bits | 24 |
The word list is built so that the first four letters identify each word, and near-duplicates such as “build” and “built” are left out. The words are a human-friendly transcription of computer randomness. BIP-39 says the scheme is not meant for phrases a person makes up, and that software should warn when a phrase fails the checksum.
To turn the words into keys, the wallet runs them through a key-stretching function (PBKDF2 with HMAC-SHA512, 2,048 rounds) to produce a 512-bit seed. Account keys are then derived from that seed. Because the derivation is deterministic, the same words always produce the same keys, in any compatible wallet.
In practice, wallet makers pick one length. MetaMask generates 12 words and notes that other wallets use 18 or 24. Ledger devices use 24. The Base app from Coinbase uses 12. Trezor devices use 12 or 24 words under BIP-39, or 20-word shares under a different standard, SLIP-39, which draws on a 1,024-word list.
Seed phrase, private key and password
These three are often confused, and they protect different things.
| Item | What it controls | If you lose it |
|---|---|---|
| Seed phrase | Every account the wallet derives from it | Without another backup, funds become unreachable |
| Private key | One account | That account can still be rebuilt from the seed phrase |
| App password or device PIN | Access to the wallet on one device | Restore the wallet from the seed phrase and set a new one |
MetaMask’s documentation describes the phrase as the master key: the accounts holding your tokens are derived from it, while the app password only unlocks MetaMask on that device and cannot recover the wallet. Ledger says three wrong PINs in a row reset the device, after which the only way back is the recovery phrase or another backup.
The coins themselves are not stored in the phrase or in the wallet app. Balances live on the blockchain; the phrase regenerates the keys that can move them. Our explainer on what a crypto wallet actually stores covers that split in more detail.
Why nobody can reset it for you
A bank can reset a forgotten login because it keeps the account. A self-custody wallet maker does not hold your phrase. MetaMask states that it cannot recover a wallet if access is lost. Coinbase says it never has access to the Base app recovery phrase, so it cannot move funds on your behalf or help you regain access. Crypto held in an exchange account works differently: the exchange keeps the keys and you sign in with a normal account login.
The same property makes a leaked phrase dangerous. Ledger warns that anyone who gets the phrase can recreate your accounts on their own device and spend the funds. The FBI gives the same advice in its cryptocurrency guidance: never share your private key or seed phrase with anyone.
How scammers go after the words
Every wallet maker cited here says its staff will never ask for your phrase. Ledger goes further: anyone trying to get your Secret Recovery Phrase should be considered a scammer, and its support team does not need it to help you. Common setups to watch for:
- A “support agent” who asks you to type the words into a form or chat to “verify” or “sync” your wallet.
- A website or pop-up that asks for the phrase to claim an airdrop or unlock funds. Ledger says it never supports airdrops and warns they can be cover for attempts to get your phrase.
- A hardware wallet that arrives with words already filled in. Ledger says the phrase never comes in the box and the recovery sheets should be blank.
Trezor’s rule is the simplest test: never enter the words anywhere unless your own Trezor device prompts you to. Coinbase tells Base app users never to paste the phrase into any website.
How to store a seed phrase
The wallet makers’ instructions overlap on a few points:
- Write it down on paper during setup, in the exact order shown, and check the spelling. Ledger suggests numbering each word and checking it against the BIP-39 list.
- Keep it offline. Ledger and Trezor say not to make digital copies: no photos or screenshots, no email or cloud files, and, in Ledger’s words, no password manager. MetaMask gives the same advice about cloud documents and password managers.
- Keep it private and protected from damage. Trezor says the physical security of the backup matters even more than that of the device, since a stolen device still needs the PIN but stolen words do not.
- Do not reorder or “scramble” the words as a homemade code. Ledger and MetaMask both advise against it.
There are exceptions to the paper-only approach. The Base app offers an encrypted iCloud or Google Drive backup protected by a password you create, and Coinbase recommends keeping a written copy as well. MetaMask’s sign-in with Google, Apple or Telegram splits the phrase into encrypted pieces stored online, recoverable with that login plus your MetaMask password. Each design moves some risk from a paper sheet to an account and a password, so understand which one your wallet uses.
The optional passphrase
BIP-39 allows an extra passphrase that is mixed in when the words become a seed. Every passphrase produces a valid but different wallet, and only the correct one opens the funds. That protects you if someone finds the words alone. The trade-off, as Trezor puts it, is a new single point of failure: forget the passphrase and even the correct words will not recover the wallet. Ledger lists the feature as recommended for advanced users only.





