Choose a Bitcoin wallet security setup you can recover
A secure Bitcoin wallet must prevent unauthorized spending and remain recoverable when a phone, computer, hardware wallet, backup, or trusted person is unavailable. For most long-term holders, the best starting point is a reputable hardware wallet, one offline recovery phrase, and a recovery test. Add a BIP39 passphrase or multisig only when its extra backup requirements solve a risk you actually face.

Safety rule: Never enter a recovery phrase or passphrase into a phone, computer, website, wallet coordinator, cloud form, chat, or support ticket. Enter it only directly on trusted hardware during a documented setup or recovery flow. Never photograph, upload, or share it.
Start with the failures you need to survive
Write down which events are realistic for you:
- malware changes an address on your phone or computer;
- a thief finds your hardware wallet;
- someone copies your recovery phrase;
- fire or flood destroys one location;
- you forget a passphrase or lose part of a multisig backup;
- a manufacturer, app, or coordinator becomes unavailable;
- your family cannot recover the wallet if you are incapacitated.
No design removes every risk. Complexity can reduce one risk while increasing the chance of operator error.
Compare the main wallet designs
Mobile or desktop wallet
A self-custodial software wallet is useful for learning and spending. Its keys are on an internet-connected device, so malware, fake apps, malicious browser extensions, and accidental cloud backups matter. Download only from the official source, protect the device, update it, and keep its recovery phrase offline. Do not keep all long-term savings in the wallet used for everyday payments.
Single-key hardware wallet
A hardware wallet keeps signing keys away from the companion phone or computer. The companion prepares a transaction; the hardware wallet should display and sign it only after your approval. Verify the complete receiving address, destination, amount, fee, and network on the hardware screen.
This is often the simplest recoverable cold-storage setup. However, the recovery phrase remains a single point of failure: someone who copies it can normally restore the wallet without the device or PIN. Store the device and phrase separately, and use a backup that can survive the hazards at its location.
Before funding Jade Plus, follow Secure Jade Plus before funding.
Hardware wallet with a BIP39 passphrase
A passphrase combines with the recovery phrase to create another wallet. It is not literally a 25th word: it can contain multiple words, spaces, numbers, or other supported characters. It is case-sensitive, and every exact passphrase creates a valid wallet. A typo does not produce an error; it opens a different wallet.
A passphrase can protect funds when the recovery phrase is exposed but the separate passphrase is not. It also creates a new lockout risk. Use one only if you will record it exactly, store it separately, record the intended wallet fingerprint or verified address, and test recovery. See Use a BIP39 passphrase on Jade Plus.
Assisted or collaborative custody
A provider may hold one key for co-signing or recovery. This can help with inheritance and reduce dependence on one personal backup, but introduces identity checks, fees, privacy trade-offs, service terms, and dependence on the provider. Ask which keys you control, whether you can recover without the company, what it can see, and what happens if it stops operating.
Self-managed 2-of-3 multisig
Three independent keys form one wallet and any two can spend. One lost signer does not block recovery and one stolen key cannot spend alone. The trade-off is a more demanding backup: recovery needs the wallet policy or descriptor plus enough signer backups to meet the threshold. Three devices using the same recovery phrase are one copied key, not multisig.
Use Set up 2-of-3 Jade Plus multisig and Back up and recover Jade Plus multisig only after mastering singlesig recovery.
Move up the security ladder gradually
- Separate spending funds from long-term savings.
- Use a hardware wallet for long-term holdings.
- Verify every address and transaction on its screen.
- Separate the device from its recovery backup.
- Test wallet recovery with no funds or a small test balance.
- Consider a passphrase if recovery-phrase theft is a realistic concern.
- Consider multisig if one-location or one-vendor failure is realistic and you can maintain its policy backup.
- Create an inheritance plan that another person can follow.
Choose the simplest design that addresses your risks and passes a recovery test. If exposure is only suspected, stop using the affected component, avoid revealing the suspect secret, and assess what an attacker would still need to spend. If enough signing material is confirmed exposed to authorize a spend, create a new wallet with fresh independent keys on trusted hardware, verify a receive address, and move urgently; do not delay solely for a small test when delay materially increases theft risk. Never ask anyone to inspect a wallet secret.
Next step
If you want multiple devices to protect the same wallet, learn how to set up a 2-of-3 Jade Plus multisig wallet.
Updated on: 04/08/2026
Thank you!
