Skip to content

Satoshi Statue for Vienna · Soft cap reachedSupport the fundraiser

Secure Bitcoin Storage

How to store Bitcoin safely, from wallets and backups to best practices.

Last updated 10. September 2026

Share article:

Self-custody

Bitcoin gives you real digital ownership. With self-custody, protecting your keys and backups is up to you.

On an exchange, you don’t hold bitcoin yourself. You trust a third party. The risks: platform failures, hacks, honeypots, and fraud. Regulation provides some protection, but never zero risk.

This guide explains how to take full control of your bitcoin.

1. Why self-custody?

“Not your keys, not your coins.”

We recommend holding your bitcoin in self-custody. You hold the keys, receive and send payments directly, and can access your bitcoin without relying on a bank or exchange.

Custodial (Exchange) Non-Custodial (Own Wallet)
Who holds the keys? The platform You
Custodian insolvency Loss possible, depending on custody arrangements and law No custodian
Access Provider can block it You control the funds with your keys
Responsibility Platform You

Rule of thumb: Think of your wallet like a physical wallet. You carry what you need for daily life. Anything beyond that belongs in the vault: a hardware wallet in self-custody.

2. Your first wallet

Hot wallet (app): for getting started

For smaller amounts (a few hundred euros), a good software wallet on your smartphone is enough. Free, quick to set up, practical for everyday use.

Important: Only use established open-source wallets. Open source doesn’t guarantee security, but it means anyone can audit the code. Vulnerabilities surface faster than in closed-source apps where only the vendor sees the code.

Hardware wallet: for larger amounts

Once the amount would hurt to lose, use a hardware wallet. These are physical devices that never connect your private keys to the internet.

Buying rule: Only order directly from the manufacturer or authorized resellers. Never through Amazon or eBay.

3. Setup & backup

Hardware wallet step by step

  1. Buy: Only from the manufacturer or authorized resellers
  2. Inspect: Check packaging for tampering
  3. Software: Download only from the official website
  4. Set up: Follow the manufacturer’s instructions
  5. Backup: Write down 12 or 24 words

The golden backup rule

Your backup (the “seed phrase”) is your wealth. Whoever has these words has your bitcoin.

DO: Write on paper, store in a safe place, use a steel plate for larger sums.

DON’T: Take a photo, save in the cloud, send via email or chat, show anyone.

The test restore

Check the backup before depositing larger amounts. Use the manufacturer’s built-in backup check where available. Do not start by wiping a wallet that already holds funds. Restoring on a trusted spare device with a small test amount is another option.

For a hardware wallet, enter backup words only through its designated recovery procedure, never into a website or an ordinary desktop app. Follow the instructions for your exact model, such as Trezor’s guidance on checking a backup.

When sending: Compare the entire receiving address with a trusted source, including on the hardware wallet’s display where applicable. Checking only the first and last characters is insufficient: attackers deliberately create lookalike addresses. A small test payment can be an extra check, but cannot replace verifying the full address.

The Privacy article explains how to use Bitcoin not only securely but also privately.

4. Scam prevention

The one rule that protects you

Never enter your 12/24 words except to restore your own wallet on a trusted device.

The most common scams

“Double your Bitcoin” Nobody doubles your money. Nobody. Ever.

Fake support Real wallet manufacturers never ask for your seed. Anyone who does is a scammer.

Phishing websites Check URLs with care. One wrong letter is all it takes. Bookmark the real sites.

“Help, I’m locked out” Exchanges and wallets don’t contact you via DMs on social media.

Unsure? Ask first.

Our scam check is there before you send money. Send us the link, the offer, or the screenshot. We’ll give you an honest assessment, free and confidential.

Already lost money? Go to the police as soon as possible. We can’t recover lost bitcoin, but authorities can investigate.

5. For advanced users

The passphrase

A strong passphrase can add protection to your seed. A short or guessable one does not reliably protect a stolen seed. Recovery requires both exactly as entered, so back up the passphrase securely and separately too.

Watch out for typos: Every passphrase, even a wrong one, generates a valid wallet. If you mistype it, you’ll end up in an empty wallet and may not notice until you try to restore your backup. After setup, check the master fingerprint of your hardware wallet and note it alongside your backup. This lets you verify you’re in the right wallet.

Multisig

With multisig, you need multiple keys (e.g., 2 of 3) to sign a transaction. An advanced option for larger amounts, businesses, and inheritance planning. Back up the wallet configuration, such as its output descriptor, as well as the required keys; individual seed backups may not be enough for your setup.

Miniscript and time-locked safety nets

Miniscript extends what multisig can do: you can set conditions like a recovery key that activates after a set period, so someone else can recover the funds if you lose your main key. Useful for inheritance planning and long-term storage. The software Liana makes such setups accessible to end users.

FAQ

Can I lose my bitcoin if my phone breaks?

For an on-chain wallet, a broken device does not automatically mean lost bitcoin. A complete backup, plus any passphrase and wallet configuration, can restore access. Lightning and other wallet models may require additional recovery steps.

My backup was stolen. What now?

Create a new wallet and transfer all bitcoin there. The thief has access the moment they enter the words. Every minute counts.

Where should I store my backup?

Not at home in a desk drawer. Fire, break-ins, water damage: all common causes of loss.

Better: bank safe deposit box, fireproof safe, or distributed across multiple locations.

For larger sums or organizations: multisig, so no single location and no single person holds all the keys.

What’s the difference between seed phrase and passphrase?

The seed phrase (12 or 24 words) is your base backup. The passphrase is an optional additional password that generates a different wallet. Both together provide the strongest security but also the most responsibility, because you need both to access your bitcoin.

Are there alternatives to the classic seed phrase?

Yes. Trezor devices support SLIP39 (Shamir Backup), which splits your seed into multiple parts, for example 3 of 5. You only need a certain number of parts to restore. This is a backup method, not multisig (which concerns transactions). The downside: SLIP39 is not compatible with the BIP39 standard most wallets use. You can’t restore the backup in an arbitrary wallet.

Talk it through at a meetup

Bring your questions about wallets, backups and self-custody.

Subscribe to our newsletter

Updates on Bitcoin, events, and the association’s positions.