The two ways people actually lose self-custodied crypto are writing the phrase down wrong and storing the only copy somewhere that burns, floods, or gets thrown out. Both are backup problems rather than security problems, and both are solved before you ever hold a meaningful balance.
Record and verify your backup
- 1
Open Settings → Security → Recovery phrase and authenticate with Face ID or your device passcode.
- 2
Write every word down, numbered, on paper or a metal backup plate.
Order is part of the secret. A correct set of words in the wrong order restores nothing.
- 3
Re-read what you wrote against the screen, word by word.
Check the pairs that are easy to confuse in handwriting, and remember that BIP-39 words are uniquely identified by their first four letters.
- 4
Run the backup quiz when the app offers it, and re-enter the words it asks for.
- 5
Store copies in two separate physical locations.
Two copies in the same drawer protect against exactly one failure mode: none of them.
- 6
Set up guardian-based social recovery as a second, independent route.
Guardians hold encrypted shares, not your phrase. It is a genuine second path rather than a second copy of the first one.
Good to know
- Never store a phrase as a photo, screenshot, cloud note, password-manager entry, or message to yourself. Each of those turns a physical secret into an account-takeover risk.
- If you set a passphrase, it is a separate secret and must be backed up separately. The phrase alone will not restore a passphrase-protected wallet.
- Nobody legitimate will ever ask for your recovery phrase — not support, not a wallet, not an airdrop. Every request for one is an attempt to steal the wallet.
Frequently asked
If you still have the app installed and can unlock it, open Settings → Security → Recovery phrase and record it again immediately. If you have lost access to the device as well, the wallet can only be recovered through guardians if you configured social recovery beforehand.
No, and the app blocks screenshots on that screen for this reason. A screenshot syncs to a photo library and is then only as safe as that cloud account's password.
No. The backend never holds a seed, a private key, or anything derived from them. This is the same property that means an attacker who breaches our servers cannot move your funds either.
Get SpendTheBits
A fully non-custodial wallet for 13 chains, free on iOS and Android. Your keys never leave your phone.
