Three secrets with different jobs
“The password is in the envelope” is an ambiguous recovery instruction. It could mean a device PIN, an app password, a wallet passphrase, or the phrase that opens an encrypted instruction file. A family member can enter the correct secret in the wrong place and still be unable to recover anything.
Use explicit names in your documentation. This guide focuses on self-custody hardware wallets and BIP-39 terminology. Other backup standards, including SLIP-39, and multisignature configurations need their own compatible recovery instructions. Do not assume that all sets of wallet words are interchangeable.
| Item | Main purpose | Does it work alone if the device is lost? | What to document separately |
|---|---|---|---|
| Device PIN | Unlocks access on that device | No | Which device it belongs to; approved recovery route if unavailable |
| Recovery phrase or wallet backup | Reconstructs wallet key material on compatible equipment | Possibly, if no additional factor or configuration is needed | Backup standard, wallet context, location reference |
| Optional wallet passphrase | Selects a passphrase-derived wallet with the backup | No | Whether one is used and how an authorized person obtains the exact value |
| App or service password | Opens a particular app or provider account | Not a substitute for the wallet backup | Which app or account it controls |
| PingVaults recovery phrase | Decrypts a PingVaults instruction vault | Only opens that instruction file with its metadata | A separate route to obtain it; never reuse a wallet seed |
What the PIN protects
Trezor’s PIN documentation describes the PIN as protection for device access. It is not the same recovery input as the wallet backup. Retry limits and recovery procedures depend on the model, so a recipient should consult the exact device’s official instructions before trying guesses.
For planning, write “device unlock PIN” rather than “wallet password.” Record that there is a recovery path if the device fails, but keep the actual PIN protected. A device that currently opens is not evidence that the backup is complete or legible.
Do not reset the only working production device just to discover whether an inheritance plan is adequate. Resolve documentation gaps while access still exists.
What the recovery phrase restores
A recovery phrase is part of the wallet’s cryptographic recovery system. It is not a customer-service reset code. BIP-39 specifies a mnemonic-to-seed process and the optional passphrase input. Wallet-generated words must retain their exact order; translating them for a relative changes the recovery material.
The words also do not tell a novice everything about the surrounding setup. Your instructions should identify the network, wallet software, account configuration, and any additional factors. A restored wallet can look unfamiliar when the wrong account or network is selected.
For a more complete storage discussion, see how to store a seed phrase for yourself and your heirs. The practical inheritance task here is to document which backup belongs to which wallet, without copying its words into a general inventory.
Why a passphrase can show an empty wallet
In a BIP-39 setup, changing the passphrase changes the derived seed. A typo can therefore lead to a valid but different wallet rather than a simple “incorrect password” message. Trezor’s passphrase instructions also emphasize exact entry, including case and spaces.
If your plan uses this feature, the record must say that it exists. Keep the exact passphrase separately protected and test the intended retrieval route. Describing it as “the usual password” or expecting a relative to guess a family saying creates an avoidable failure.
Adding a passphrase changes the operational burden. It is not an automatic recommendation for every household. The owner and recipient need to understand the extra dependency before relying on it.
Write a recovery record without exposing secrets
Here is a fictional example of the context to record. The labels refer to protected instructions; they are not real addresses or credentials.
| Record field | Example |
|---|---|
| Wallet label | WALLET-A, long-term Bitcoin holdings |
| Device | Hardware wallet; model and official guide recorded in R-01 |
| Backup | Standard confirmed by owner; protected backup reference B-01 |
| Passphrase | Used; obtain through separate procedure P-01 |
| Wallet context | Network and account details in protected configuration note C-01 |
| First check | Match a known receiving address in a private record before considering a transfer |
| Stop condition | Unexpected wallet, missing factor, or unknown software: stop and contact the designated helper |
Addresses and configuration notes can reveal financial relationships, even when they cannot authorize a transfer. Keep the record private and give each helper only the information needed for their role.
This format avoids a common gap: the owner has a backup, but the family does not know that the funded wallet uses an additional factor. It also keeps the instruction-file phrase distinct from the wallet’s spending secrets.
Test the instructions in two stages
First, run a paper walkthrough. Give the recipient the recovery record and ask them to explain which item unlocks which layer. They should be able to distinguish the device, backup, optional passphrase, and instruction vault without seeing any production secret.
Second, use a separate practice wallet and harmless instructions to rehearse the actual sequence. Record whether the expected wallet identity was confirmed, not merely whether a screen opened. Our recovery-drill checklist provides pass criteria and a printable worksheet.
A manufacturer backup-check feature serves another purpose. For example, Trezor Safe 5’s Check backup procedure compares an entered backup against the device’s stored backup. That check is useful, but it does not by itself establish that a relative can find the materials, obtain a separately held passphrase, or act with authority.
If a real recovery looks wrong
Stop before sending funds, resetting devices, or entering secrets into another tool. Check the documented wallet type, network, account, backup standard, and presence of a passphrase using official guidance. Do not treat an empty-looking wallet as proof that the funds are gone.
If the setup cannot be explained from the records, involve a qualified person through a previously verified contact route. A stranger offering to “validate” seed words in a website or chat is not a recovery procedure.
Common questions
Can changing a device PIN change my wallet?
On a wallet where the PIN only controls device access, changing that PIN does not itself choose a different passphrase wallet. Follow the manufacturer’s model-specific procedure and verify your backup first.
Is a passphrase the thirteenth or twenty-fifth word?
Those labels are informal and can confuse recipients. Write “optional wallet passphrase” explicitly and identify the backup standard. Do not append it to the mnemonic list as though it were another ordinary seed word.
Can PingVaults recover a missing wallet passphrase?
No. PingVaults can hold an encrypted map to separately protected recovery materials. It cannot reconstruct a missing wallet secret or replace a hardware-wallet backup. Review its security boundaries before choosing what to store.
