In short
A passphrase is an extra word or sentence of your own, added on top of the seed phrase. It opens a different wallet; the seed alone opens an empty one, with no error message. Heirs who don’t know a passphrase exists conclude the coins are gone. If you use one, write it down exactly, keep it apart from the seed, and make sure the letter of instruction says it exists.
What a passphrase is
The standard that defines seed phrases, BIP-39, lets the owner add a passphrase of their choosing; the standard sets no length, the devices do. Technically the passphrase is mixed into the seed words to produce the wallet’s keys, and the standard spells out the consequence: “every passphrase generates a valid seed (and thus a deterministic wallet) but only the correct one will make the desired wallet available” (BIP-39). Leave it empty and you get the normal wallet. Type anything else and you get a different, usually empty, wallet.
Wallet makers each have their own name for it:
| Maker | What they call it | Where it’s entered |
|---|---|---|
| Trezor | Passphrase, “passphrase wallet” (formerly “hidden wallet”) | On the device (Safe 3, 5, 7, Model T) or in Trezor Suite; up to 50 characters (Trezor) |
| Ledger | Passphrase, “25th word” | On the device; either temporary or attached to a second PIN; up to 100 characters (Ledger Academy) |
| BitBox02 | Optional passphrase | On the device, after enabling it in the app’s expert settings (BitBox) |
| Coldcard | Passphrase | On the device; up to 100 ASCII characters (Coldcard) |
| Keystone 3 Pro | Passphrase wallet | On the device, each time; the device doesn’t store it (Keystone) |
Whatever it’s called, every character counts. “Hello World” and “hello world” are different wallets, and so are versions with and without an extra space: “every character matters” (Trezor).
Why it matters for inheritance
A passphrase protects you against a thief who finds your seed. It also protects your coins against your heirs, unless they know three things: that a passphrase exists, what it is, and that it’s not the same as the PIN.
The usual failure looks like this. Your heirs find the metal plate with 24 words, buy a new hardware wallet, restore the seed, and see a balance of zero. Nothing says “this wallet has a passphrase”. They conclude the coins were sold or stolen, or they type the words into a website that promises to “scan all accounts”, which is how the seed ends up with a scammer. Found a hardware wallet or seed phrase? tells heirs to look for a passphrase before concluding anything, but only you can make sure there’s something to find.
The makers are blunt about what happens when the passphrase is lost. Ledger: “If you forget your passphrase, access to the associated hidden wallet is permanently lost, as Ledger does not store or back up passphrases” (Ledger Academy). Trezor: “If you lose your passphrase, you lose access to your passphrase wallet and its funds” (Trezor). No company can help, and neither can a recovery service, unless you remember most of it.
A PIN is not a passphrase
The PIN unlocks the device. If it’s forgotten, the device can be wiped and restored from the seed words; nothing is lost. The passphrase is part of the wallet itself. BitBox puts the difference in one line: the device password “is not required in order to restore your wallet from your wallet backup”, whereas the passphrase “is required” (BitBox). Heirs who have the PIN and the seed, but not the passphrase, have an empty wallet and a working device.
Storing it so heirs can use it
- Write it down, exactly. Every character, with capitals and spaces made obvious. Print rather than cursive. A passphrase that exists only in your head dies with you.
- Keep it apart from the seed. The point of a passphrase is that the seed alone is useless. Putting both in the same envelope removes that. The common pattern: seed on metal at home, passphrase in a sealed envelope with your lawyer, notary or a relative in another town. See where to keep seed phrases and secrets.
- Say in the letter of instruction that it exists. Not what it is: “This wallet uses a passphrase (Ledger calls it the 25th word). It’s in the envelope our solicitor holds. Without it the wallet looks empty.”
- Test it. After entering a passphrase, the wallet shows a fingerprint or a first receiving address. Compare it with the one you noted when you set the wallet up. Coldcard says plainly that this comparison is “the only way to verify your passphrase is correct” (Coldcard). Write that fingerprint or address on the recovery sheet, so your heirs can check they’ve got it right too.
- Never type it into a computer, website, password manager or chat. Same rule as the seed.
Do you need one at all?
For a wallet that will outlive you, a passphrase is a trade: more protection against theft, less protection against loss and confusion. Unchained, which runs multisig vaults for a living, says most people skip it: “Most bitcoin users set up multisig wallets without passphrases because multisig already eliminates a given hardware wallet or seed phrase as a single point of failure” (Unchained). If you hold bitcoin and want protection against a found seed, a multisig with a trusted keyholder gives you that without a secret word that nobody else knows; the sister site weighs passphrase against multisig in detail.
If you keep the passphrase, keep it simple: a few words you can write unambiguously, not a sentence with punctuation your heirs will mistype.
Next: Inheritance methods compared.