Deep dive for stage 5 · Self-custody — optional · ≈6 min

The passphrase (the ‘25th word’): protection with side effects

What the optional passphrase adds to your seed phrase, what risks it carries, how to back it up and what a decoy wallet is.

IntermediateUpdated 28 September 20268 sources

In short~30 sec
  1. 01The passphrase is an addition to the seed phrase that you choose freely. Every passphrase produces its own, completely different wallet.
  2. 02Benefit: anyone who finds only your seed phrase can’t get at the funds in the passphrase wallet. It also makes a decoy wallet possible.
  3. 03Risk: forget it and it’s gone. A typo opens an empty wallet without any warning, and nobody can reset the passphrase.
  4. 04Write it down exactly and keep it separate from the seed phrase. You don’t need a passphrase to get started.

Good to read firstBacking up your seed phrase

The seed phrase is a master key: whoever finds it has access. With a passphrase, the words alone are no longer enough – but you gain a second secret that you have to back up just as carefully. We’ll explain calmly how it works – so you can decide for yourself whether you need one.

What the passphrase is

The GlossaryBIP 39 (standard for seed words)The widely used standard that turns random data into 12 to 24 words from a fixed list of 2,048 words. Your wallet calculates all its keys from these words – BIP 39 is behind most seed phrases.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary → standard, which most wallets use to generate their GlossarySeed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary →, provides for an optional extra field: the GlossaryPassphrase (the ‘25th word’)An extra word of your choice added to your seed phrase. The same words then produce a completely different wallet. This protects you if someone finds your words – but if you forget the passphrase, access is lost for good.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary →. It goes into the key calculation together with the words. If you don’t enter one, the wallet uses an empty string.[1] That gives you your standard wallet.

The nickname ‘25th word’ is misleading: the passphrase doesn’t come from the word list, you choose it freely. Provider · Hardware walletTrezor SafeHardware wallets by SatoshiLabs from the Czech Republic – Safe 3, Safe 5 and Safe 7, each also as a Bitcoin-only edition.Hardware manufacturer – no financial licence required · reviewed Sept 2026Price: Safe 3: $59 · Safe 5: $129 · Safe 7: $249 (same amounts in euros, as of Sept 2026)On the learning path: Stage 6 · Step 1 – Hardware wallets compared →Our profile →AdVisit Trezor (paid link, opens in a new window)on trezor.ioOnly buy hardware wallets from the manufacturer or an authorised reseller.*Paid link: if you sign up or buy through it, we earn a commission. Your price stays the same. How we make money →, for example, allows up to 50 characters, and upper and lower case count.[2]

The crucial point: every passphrase generates a valid wallet, but only the right one opens the wallet you want.[1] There’s no error message. If you make a typo, you end up in a different, usually empty wallet.[2]

Input Result
Seed phrase without a passphrase Standard wallet
Seed phrase + Example-never-use-7 Wallet A – this is where your funds are
Seed phrase + example-never-use-7 Wallet B – empty (one letter lower case)
Seed phrase + Example-never-use-7 Wallet C – empty (space at the end)

The passphrases in the table are examples – never use them.

What it’s good for

Protection if someone finds your backup

This is the main reason: anyone who finds only your seed phrase – a burglar, a tradesperson, a flatmate – sees only the standard wallet. That’s why the Bitcoin Design Guide recommends a passphrase for larger amounts, kept separate from the seed phrase.[3]

Camouflage: the decoy wallet

Because every passphrase opens a valid wallet, nobody can tell from the outside whether there are others – BIP 39 calls this ‘plausible deniability’.[1] The decoy wallet builds on this: one wallet holds a smaller amount, while the larger balance sits behind a different passphrase. It’s meant for extortion under threat of violence, known as a GlossaryWrench attack ($5 wrench attack)An attack using violence or threats instead of technology: criminals force Bitcoin owners to unlock their wallet or transfer bitcoin. The best protection is discretion – if nobody knows you own bitcoin, you are less likely to become a target.On the learning path: Stage 6 · Step 2 – Spotting scams →In the glossary →. Jameson Lopp lists several hundred known cases of such attacks, and many more never become public.[4]

Our assessment: a decoy wallet is a last resort, not a shield. It’s only convincing with a plausible amount and a genuine usage history, and anyone who knows the subject knows that passphrases exist. Better protection is not to draw attention to yourself as a bitcoin owner in the first place – more in Spotting & avoiding scams.

The risks

What entering it on a hardware wallet looks like

The device is made up; the process on real models is similar.

Opening a passphrase wallet (example device)

Step 1Entering it on the device: type the passphrase directly on the hardware wallet (1), not on the computer – malware could read it there.
Step 2Check: some devices show the passphrase before you confirm. Compare it character by character with your backup (1).
Step 3Recognise the right wallet: if the fingerprint (1) matches the note you made during setup, you haven’t made a typo.
Step 4Empty wallet? A different fingerprint (1) almost always means a typo, not theft. Calmly enter the passphrase again.

Illustrative example – real apps look different in detail.

The fingerprint is an eight-character short identifier, calculated from the wallet’s master public key (the first 32 bits of a hash).[6] No keys can be derived from it, but it shows you straight away whether you’ve opened the right wallet. If your wallet doesn’t display it, use the first receiving address.

Choosing a good passphrase

  • Nothing personal. Dates of birth, names, addresses or quotations can be deduced from your surroundings or appear in lists used for guessing.
  • Several random words instead of a jumble of characters. Around four to six short, randomly chosen words joined with hyphens are hard to guess and easy to write down without errors. A short string such as X7!q is easily noted down wrongly and still isn’t secure.
  • Simple characters. Not every device handles every character – Trezor, for example, only accepts ASCII, so no accented letters or ß.[2] Lower-case letters, digits and hyphens cause the fewest problems.
  • Don’t use it anywhere else, not even as a password for other services.

Come up with your passphrase yourself – not with online generators or websites.

If you’re choosing a new device, check with the manufacturer whether you can enter the passphrase directly on the device and which characters it accepts.

Backing up the passphrase

  1. Write it down exactly

    Clearly distinguish upper- and lower-case letters, mark spaces, and write 0 and O, l and 1 so they can’t be confused. Trezor explicitly advises writing the passphrase down.[2] Memory is not a backup.

  2. Store it separately from the seed phrase

    If both are in the same place, the passphrase protects against nothing. Keep several copies of the passphrase, just like the seed phrase, but never next to a copy of the seed phrase.[3] A seed backup never belongs on a digital device.[7] Treat the passphrase the same way: no photo, no cloud, no password manager.

  3. Note down an identifying feature

    Note the fingerprint or the first receiving address and keep the note with the passphrase or in the emergency letter, not with the seed phrase. Anyone who finds the seed phrase shouldn’t learn that there’s another wallet.

  4. Test it regularly

    Trezor advises testing access regularly.[2] Open the passphrase wallet about once a year and compare the fingerprint. The full test is explained in Testing recovery.

  5. Mention it in your emergency plan

    Your heirs need to know that there’s a passphrase and where it is. The passphrase itself doesn’t belong in the emergency letter.[3] How to set this up is explained in Inheritance & emergency plan.

Passphrase or multisig?

Both make sure that a single backup someone finds isn’t enough. GlossaryMultisig (multi-signature)A wallet in which several keys jointly control the bitcoin – for example 2 of 3. If one key is lost or stolen, the bitcoin stays safe. In return, setting it up and backing it up is considerably more demanding.On the learning path: Stage 6 · Step 4 – Inheritance & emergency plan →In the glossary → with 2 of 3 keys also survives the loss of one key, but requires backups of all keys and of the wallet configuration.[8]

Passphrase Multisig (e.g. 2 of 3)
Needed to spend Seed phrase + passphrase two of three keys
One part is lost funds lost still usable with the remaining two
Effort low, no extra device considerably higher, usually several hardware wallets

More in Multisig simply explained.

Who is a passphrase worthwhile for?

+More likely to make sense if …

  • you keep your seed phrase safe and tested
  • a backup being found would seriously hurt you financially
  • you have a second, separate place for the passphrase

−Less likely if …

  • you’re just setting up your first wallet
  • you only want to keep the passphrase in your head
  • it would make your emergency plan too complicated for your relatives

When you’re starting out, a well-secured seed phrase is the better choice than a passphrase that nobody remembers later.

Quick check

Someone finds your seed phrase. The passphrase is kept somewhere else. What can this person open?

What’s next?

Frequently asked questions

Is the passphrase the same as my hardware wallet’s PIN?

No. The PIN only locks the device. The passphrase determines which wallet is derived from your seed phrase. To restore on a new device, you need the seed phrase and the passphrase, not the old PIN.

Can I add a passphrase later?

Yes, but it opens a new, empty wallet. You then send your funds there. A passphrase can’t be changed or removed – for that, too, you move to a new wallet.

I entered the passphrase and see an empty wallet. Is my money gone?

Usually not. Most likely you made a typo: any deviation, including upper and lower case or spaces, opens a different, empty wallet. Enter the passphrase again exactly as it appears on your backup.

How long should a passphrase be?

Long enough that nobody who finds your seed phrase can guess it: no date of birth, no name, no single word. Several random words are hard to guess and easy to write down without errors. Stick to simple characters without accents.

Your knowledge blockchain

Every article you complete becomes a block in your personal chain – stored only in your browser.

View chain →
Sources8 sources · 3 publishers

The superscript numbers in the text refer to these sources.

  1. BIP 39: Mnemonic code for generating deterministic keys – Bitcoin Improvement Proposals, 10.09.2013 (accessed 28/09/2026)
  2. What is a passphrase? – Trezor Knowledge Base (accessed 28/09/2026)
  3. Backups – Bitcoin Design Guide (accessed 28/09/2026)
  4. Physical Bitcoin Attacks (list of known cases) – Jameson Lopp (accessed 28/09/2026)
  5. BTCRecover – open-source tool for password and seed recovery – 3rdIteration (GitHub) (accessed 28/09/2026)
  6. BIP 32: Hierarchical Deterministic Wallets – Bitcoin Improvement Proposals, 11.02.2012 (accessed 28/09/2026)
  7. Keeping your wallet backup safe – Trezor (accessed 28/09/2026)
  8. Multi-key – Bitcoin Design Guide (accessed 28/09/2026)

This article is for education only and is not investment, tax or legal advice.

Keyboard shortcuts

⌘K /
Open search
`
Open Bitcoin terminal
T
Toggle light/dark
?
This help

Tip: type “help” in the terminal.

Pre-launch

We’re still building – block by block.

Blockchain21 is already open, and you’re welcome to look around. We haven’t officially launched yet, though: some details are still missing, may change or don’t quite fit together yet.

Not finished yet

  • Email Messages to support@blockchain21.net don’t arrive yet. Until then, you can reach us by post – the address is in the legal notice.
  • Newsletter Sign-up opens once our mailbox is running.
  • Reader account Coming later. Until then, your browser keeps your progress.
  • Partners No partnership is active yet – providers are listed without ads.
  • Info pages The privacy policy still lacks some details.

Already in place: learning path, articles, glossary, calculators and live data.

Block 0 · Genesis — Bitcoin, too, began with block 0 As of 5 October 2026