A metal seed backup is worth using when fire, water or long storage is a credible risk—but metal protects the record, not the wallet design. It cannot stop someone from copying the words, correct a phrase stamped in the wrong order, recover a forgotten passphrase or explain an unfamiliar scheme to an heir.
A steel plate can survive a house fire and still fail perfectly: the wrong secret may remain permanently readable to the wrong person.
The plate protects characters, not access
A metal seed backup is a physical, offline seed phrase storage device. Instead of leaving a wallet backup on paper, the owner stamps, punches, engraves or assembles the recovery words—or an exact encoding of them—into steel, titanium or another durable material. The plate stores no coins. It preserves the mnemonic information from which a compatible crypto wallet can derive its private keys.
That recovery phrase is usually a bearer secret. Anyone who obtains a complete BIP-39 seed phrase and any required passphrase can recreate the wallet without possessing the original hardware device. Making the words more durable therefore improves availability and can increase the consequence of discovery at the same time.
That distinction changes the buying question. “Is this fireproof?” is too narrow. Ask whether the complete design preserves readable data after realistic damage, whether the encoding can be reconstructed without the manufacturer, and whether one discovered object gives an attacker everything needed to spend.
Metal does not add entropy to the seed, encrypt it or create access control. A lock, seal or hidden location may delay discovery or reveal tampering, but none changes the authority carried by the recorded secret.
A material specification is not a product test
Melting point is an incomplete safety claim. A backup in a building fire may be heated unevenly, warped, struck by debris and then cooled rapidly by firefighting water. Later, moisture, salts or incompatible metals can continue damaging the surface. A plate marketed as fireproof or waterproof can avoid melting and still become unreadable.
Jameson Lopp’s open metal-backup project is useful because it tests complete products under heat and rapid cooling, corrosion and crushing. The results show why construction matters: products made from broadly similar materials can receive very different grades when tiles escape, enclosures deform or marks become difficult to recover.
The tests are comparative evidence, not certification. Lopp states that the experiments are not highly scientific and that the grading is arbitrary. An A grade means the tested sample retained its data under that methodology; it is not a guarantee against every fire, chemical exposure, product revision or installation mistake.
The encoding can fail before the metal does
Deeply stamped, engraved or center-punched marks have few moving parts. Sliding-letter, tile and capsule designs can be easier to assemble neatly, but the enclosure must keep every component in order after deformation. The correct seed phrase storage method depends as much on installation accuracy and recoverability as on alloy.
Three recording methods are common:
- Full words: easiest to interpret later, but require more space and clear permanent lettering.
- Four-letter prefixes: compact and valid for the BIP-39 wordlist because that specification was designed so the first four letters identify a word unambiguously. Do not assume the same rule applies to SLIP-39, a proprietary wordlist or another language.
- Word indices: compact, but only recoverable when the instructions identify the exact wordlist and numbering convention. A number without its standard is not self-explanatory.
Record the scheme name, word count and ordering convention without placing extra spendable secrets beside the phrase. Do not invent abbreviations. Do not rely on a company app or account as the only decoder. BIP-39 includes a checksum that can reject many transcription errors, but a checksum is not a substitute for a recovery test and cannot tell an heir which seed phrase backup system you intended.
Redundancy can multiply theft
One complete metal seed phrase beside the hardware wallet lets a thief or fire reach both. Several complete plates in obvious safes improve disaster redundancy while creating more places where the whole wallet can be copied.
Separate the signer from its backup and choose locations with genuinely different failure modes. Evaluate who controls each location, who can enter without you, whether access is logged, and what happens when you move, die or lose capacity. A bank box, home safe and relative’s house do not offer the same legal access, privacy or disaster profile.
If a BIP-39 passphrase is part of the wallet, placing it on the same plate collapses the separation. Keeping it only in memory creates a different single point of failure. The seed phrase and passphrase guide explains why the passphrase opens a different wallet rather than merely unlocking the same one.
Do not create “two-factor security” by manually dividing 12 or 24 BIP-39 words into halves. The pieces may leak more information than expected, create brittle recovery and leave no standardized policy for another wallet to follow. If no one location should hold unilateral authority, use a tested multisig design or a wallet-supported secret-sharing standard. Multisig and a passphrase solve different failures; neither should be improvised by cutting a mnemonic in two.
What I would buy—and reject
I would favour the simplest design that the owner can install correctly and a future recovery person can decode without the vendor. It should have:
- deep, permanent marks that remain identifiable after surface damage;
- few parts that can shift, escape or be reassembled in the wrong order;
- capacity for the exact backup format and word count in use;
- clear, durable instructions for any prefix, grid or index encoding;
- independent destructive-test evidence for the same design or a materially equivalent construction; and
- a storage shape that fits the intended location without advertising what it contains.
I would reject a product whose case rests only on “military grade,” an alloy melting point or a vendor demonstration with no readable post-test result. I would also reject removable-character designs that can lose sequence when opened, compact encodings the family cannot explain, and any recovery process that depends on the manufacturer remaining online.
Price is secondary to installation error. A plain stainless-steel plate marked correctly can outperform an elaborate capsule assembled one position off. Practise the marking method on scrap metal or a dummy mnemonic before touching the real backup.
Installation ends with a recovery check
- Identify the format first. Confirm whether the wallet uses BIP-39, SLIP-39 or another documented scheme, the word count, and whether a separate passphrase or multisig policy is required.
- Practise with non-secret data. Test the punch, stamp depth, spacing, reading direction and enclosure before recording the live phrase.
- Record offline. Do not use a phone camera, printer, clipboard, cloud note or online conversion tool. Check every position twice against the hardware wallet’s display or original offline backup.
- Decode your own work. Put the original out of view, read the metal exactly as a future recovery person would, and reconstruct the ordered words using the documented standard.
- Use an on-device backup check where supported. Trezor’s Check backup function, for example, compares the entered backup with the secret already held by the device without replacing the active wallet. Follow the current procedure for the exact model; never type the words into a website or ordinary desktop form.
- Verify the wallet identity. Confirm that the checked backup and any passphrase correspond to a known receive address or wallet descriptor. For a controlled full restore, use trusted hardware and treat every additional device that receives the seed as a new exposure event.
If the check fails while the original signer can still spend, do not keep adding funds and do not “repair” uncertain words by guessing. Create a new wallet with a verified backup, transfer the assets, and retire the ambiguous record. The lost hardware-wallet response explains why a working signer creates a limited window to fix a failed backup safely.
Maintenance should minimize handling
Inspect after a move, flood, fire, unauthorized-access concern or change in who controls the storage location. A periodic review can also catch corrosion, missing instructions and inheritance details that no longer work. The goal is not to expose the words on a fixed calendar.
Confirm that the backup remains present, sealed or undisturbed as expected, and stored in the intended environment. Confirm separately that any passphrase, shares or multisig policy remain recoverable. When a device provides a trusted backup-check function, use the manufacturer’s current instructions before a firmware update or destructive reset. A high-value full recovery rehearsal should be planned as a security operation, not performed casually on a spare internet-connected wallet.
My judgment: buy metal for durability, then design separately for secrecy, redundancy and recovery. The best metal seed backup is not the one with the highest advertised temperature. It is the simplest independently tested record that you can mark without ambiguity, store without handing one location total control, and recover without the vendor. Durability preserves the procedure you created—including every mistake in it.
For device selection, use the hardware-wallet guide organized by threat model. It treats backup design as part of custody rather than an accessory purchased after the wallet.
Primary sources
- BIP-39: mnemonic generation, four-letter wordlist design and passphrase derivation
- SLIP-39: standardized mnemonic secret sharing and recovery format
- Jameson Lopp: comparative metal seed-storage test results
- Jameson Lopp: heat, corrosion and crushing methodology and grading limitation
- Trezor: on-device wallet backup check procedure
Product revisions and installation methods can change results; verify the current design and instructions. No affiliate link is used in this article. Educational information, not personalized financial advice.








