Stefan Thomas was early enough to be paid 7,002 bitcoin for making a video explaining how Bitcoin works. He put the keys in an encrypted IronKey drive, wrote the password on a piece of paper, and lost the paper. By January 2021, when the New York Times told his story, he had used eight of the drive's ten permitted guesses; two wrong attempts remained between him and the drive encrypting its contents forever. Nothing attacked him. No one stole anything. A security measure he added himself, protecting against a thief who never came, stood between him and his own money — which is precisely the trade every passphrase user makes, and why this module spends as much time on the cost as on the benefit.
Mechanically, the BIP39 passphrase is simple: an arbitrary string of your choosing — letters, numbers, spaces, case all significant — combined with the seed words to derive the wallet. It is often called the "25th word", which undersells it: it is not from any wordlist, and it changes everything. Seed plus passphrase produces a completely different wallet from the seed alone, and from the same seed with any other passphrase. Crucially, there is no checksum and no error message: every passphrase is "valid", every one opens a real wallet, and only the exactly correct one opens yours. A single mistyped character presents you with a pristine, empty wallet and no hint of what went wrong.
What it defends against is specific and physical: discovery of the seed itself. A burglar who finds your steel plate, a visitor who photographs it, a relative who reads what they were not meant to, a safe-deposit box opened by someone else's court order — with a passphrase in play, the words alone open an empty room. The standard formalises the companion trick: because every passphrase yields a valid wallet, you can keep a small, sacrificial balance on the bare seed as a decoy, giving a coercer or a thief something to find that ends the search. For holders whose realistic threat is physical exposure of the backup, this is genuine, structural protection.
Now the bill. The passphrase is a second single point of failure, and a crueller one than the seed: the seed has a checksum, a wordlist and a stamped plate; the passphrase has your discipline and nothing else. If it is never written down, you have reinvented Stefan Thomas's IronKey — a memory standing guard over your savings, degrading on its own schedule. If it dies with you, your heirs inherit a steel plate that opens the decoy. The doctrine is unambiguous: the passphrase gets its own durable backup, stored separately from the seed — different location, different discovery path — because a burglar who finds both plates in one safe has been handed the whole trade for free.
Choose it like an engineer, not a poet. Length beats cleverness: a five-or-more word phrase of unrelated words is both stronger and more transcribable than l33t-speak mangling you will mistype under stress. No birthdays, no family names, no quotes a biographer could guess. Do not "rotate" it casually — a passphrase change is not a password change; it derives a brand-new wallet, and the coins must actually move on-chain from the old one, with all the fee and privacy consequences of any migration. And test the whole arrangement with pocket change first: fund the passphrased wallet small, wipe, restore seed and passphrase from their separate backups, and confirm the same addresses return before real size ever touches it.
The verdict this school stands behind: the passphrase is a power tool, not a default. Reach for it when the seed's physical exposure is a live risk — shared households, third-party storage locations, meaningful sums — and when you can honestly operate the discipline of two separated, documented backups. Skip it when the honest assessment says the bigger risk is you: a forgotten string has orphaned at least as many coins as burglars have stolen plates. Security that outruns your ability to operate it is not security; it is a countdown with your own name on it.
INTERACTIVE · THE SETUP LADDER
Where are you on the climb?
Tick only what you have genuinely drilled — bought is not built. One rung at a time, funded small, until the drill is boring.
Coins on your own signing device, seed on stamped metal in two places — and you have wiped the device and recovered from the steel alone.
A BIP39 passphrase with its own written backup, stored apart from the seed — and a small-value recovery test has proven both halves.
Keys on a signer that never connects; PSBTs cross by QR or SD card; every spend is read on the signer's own screen before approval.
A full node you run, with your wallet pointed at it and public servers disconnected — your addresses no longer leave the house.
A 2-of-3 across vendors and buildings, descriptor backed up everywhere a key is, with a spend AND a two-key recovery both rehearsed.
A sealed letter that points without containing, an executor who has walked the plan end to end, and an annual review in the calendar.
“Complexity is the worst enemy of security.”
“The described method also provides plausible deniability, because every passphrase generates a valid seed (and thus a wallet) but only the correct one will make the desired wallet available.”
READING LADDER
Climb at your own pace.
FIELD TEST · SIGN-IN REQUIRED
Take the quiz. Track the curriculum.
The module text is open to everyone: no account required to read. The 3-question field test and the curriculum-wide graduation stamp need a free account so we can record your progress.
SIGN IN TO TAKE THE QUIZFREE · NEW ACCOUNT TAKES 30 SECONDS
