Punchplate safety guide
Create and protect your Bitcoin seed phrase
Your Bitcoin seed phrase—also called a recovery phrase—is the foundation of your wallet backup. Self-custody does not need to feel intimidating: create the wallet with trusted tools, keep the words private, verify the finished backup, and store it deliberately.
The short version
Four stages, completed in order
Work slowly and finish each stage before moving meaningful funds into the wallet.
-
01
Create
Use a reputable wallet with verified, current firmware and its documented setup process.
-
02
Record
Copy the words privately, in exact order, without creating a photograph or digital copy.
-
03
Verify
Mark the Punchplate, put the original words away, and test using only the finished steel backup.
-
04
Store
Separate the backup from the wallet and make a deliberate plan for loss, theft, and inheritance.
Before setup
Prepare a trusted, private workspace
- Obtain the wallet from its manufacturer or an authorized seller, and follow the manufacturer’s authenticity checks.
- Install and verify current firmware using the manufacturer’s official website and instructions before creating the wallet.
- Choose a private location where cameras, microphones, smart speakers, windows, and other people cannot observe the recovery words.
- Set aside enough uninterrupted time. Rushing, multitasking, and working in a cluttered area make transcription mistakes more likely.
Wallet creation
Generate the recovery phrase with a supported method
A reputable hardware wallet running verified, current firmware is designed to generate the cryptographic randomness needed for a secure recovery phrase. Security still depends on the device, firmware, and implementation operating as intended.
Do
- Use the wallet’s documented new-wallet workflow.
- Use the word count and backup format supplied by the wallet.
- Confirm the words on the wallet device itself.
Do not
- Choose recovery words yourself.
- Shuffle familiar words or create a memorable sentence.
- Use an online seed generator, website, spreadsheet, or ordinary computer to create the phrase.
Adding your own entropy
Some wallets provide a documented way to mix independently generated randomness—often physical dice rolls—into the wallet’s own entropy. This can provide defense in depth, but it is optional and must be done correctly.
- Use only a feature explicitly supported by your wallet and follow that model’s current instructions exactly.
- Use fair, independent, private rolls or the entropy source specified by the manufacturer. Do not fabricate a random-looking sequence.
- Meet the manufacturer’s stated minimum. Required inputs and the way they are combined differ between wallets.
- Treat the entropy sequence as secret key material. Do not photograph, save, reuse, or enter it into a networked computer.
- Never construct a seed manually unless you have the expertise to verify the complete process in a suitable offline environment.
Important: More steps do not automatically mean more security. An unsupported or incomplete method can weaken the wallet or make recovery impossible.
Private recording
Keep the words completely offline
- Record every word in its exact numbered position. Check spelling and order against the wallet display before leaving setup.
- Write and mark silently. Do not dictate the words or read them aloud around phones, computers, cameras, or voice assistants.
- Never photograph, scan, photocopy, email, text, print, or save the words in notes, password managers, cloud storage, or removable digital media.
- Never enter the phrase into Punchplate.com, a support form, chat, or a general-purpose connected computer.
- Do not accept remote help from anyone who asks to see, hear, verify, or “synchronize” the recovery words.
Before relying on it
Prove the finished Punchplate can recover the wallet
- 1
Practice with the punch tool on separate material. Adjust it until it makes a clear, controlled indent.
- 2
Mark the Punchplate privately, following the instructions for that specific plate format.
- 3
Inspect every word position and mark. Correct unclear or mistaken marks before proceeding.
- 4
Put the original written words and every other copy out of view.
- 5
Use the wallet manufacturer’s built-in backup-check feature when available, or its documented recovery procedure on a trusted signing device.
- 6
Recover using only the completed Punchplate as the source for the words. For a split or share-based plan, use only the intended set of plates; include a separately stored passphrase if the wallet requires one.
- 7
Confirm the expected wallet fingerprint, account, or receiving address. When appropriate, send a small test transaction before transferring a meaningful balance.
Do not reset your only working wallet merely to test a backup unless you understand the manufacturer’s recovery process and the risk involved. A built-in recovery-check function or a spare trusted device is preferable when available.
Optional advanced feature
Use a passphrase only with a complete recovery plan
A BIP-39 passphrase creates a different wallet from the same recovery words. It can add protection, but it also adds another secret that must be reproduced exactly.
- A passphrase is not a wallet PIN and is not a substitute for securely generated recovery words.
- Every passphrase—including a typo—can produce a valid but different wallet. Confirm the wallet fingerprint or receiving address before depositing funds.
- A forgotten, misspelled, or unavailable passphrase can permanently prevent recovery.
- If you use one, make it strong and unique, record it exactly, test it, and create a deliberate storage and inheritance plan.
- Storing it separately from the recovery words can reduce one risk while increasing another: losing either component prevents access.
If you are not confident that you or your intended successor can reproduce the passphrase years from now, do not use the feature until you have a reliable plan.
Long-term protection
Store for both security and recovery
- Keep the Punchplate physically separate from the wallet it restores.
- Choose a location protected from unauthorized access, accidental disposal, and environmental damage.
- Consider more than one secure location when loss at a single location is a meaningful risk. Each additional copy also increases the number of places that must remain private.
- Avoid labels or instructions that unnecessarily advertise the backup’s purpose to an unauthorized finder.
- Create an inheritance plan appropriate to your household and holdings. Make it understandable without placing every secret together in an unsecured document.
- Review the plan after moving, changing wallets, changing a passphrase, or changing who should be able to recover it.
Ongoing care
Maintain the setup without exposing it
- Get firmware and security information from the wallet manufacturer’s official channels, not unsolicited messages or links.
- Periodically confirm that the Punchplate is present, legible, and stored as planned without photographing or digitizing it.
- Use the manufacturer’s backup-check process when re-verification is appropriate.
- If you become uncertain about seed generation or exposure, do not share or enter the existing words online. Read the manufacturer’s current guidance and proceed calmly.
- When a new wallet is required, generate it using a verified process, back it up, test it, verify an address, move a small amount first, and keep the prior backup until migration is fully confirmed.
Final review
Before moving a meaningful balance
You should be able to confirm every item that applies to your setup.
- The wallet came from a trusted source and passed its authenticity checks.
- Current firmware was obtained and verified through official instructions.
- The phrase was generated through the wallet’s supported process.
- Any added entropy followed the manufacturer’s exact method.
- No photograph, recording, printout, cloud copy, or other digital copy was created.
- Every word and its order were checked before the original was put away.
- The completed Punchplate was inspected for clear, readable marks.
- A test recovery used only the completed Punchplate as the source for the words.
- The expected wallet fingerprint, account, or receiving address was confirmed.
- Any passphrase was recorded exactly, stored deliberately, and included in the recovery test.
- The wallet, backup, and inheritance plan do not create an obvious single point of failure.
Ready to make the physical backup?