Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

BIP39 vs SLIP39 backups

TL;DR

BIP39 is the 12- or 24-word format almost every wallet understands. SLIP39 is a different standard, used by Trezor’s 20-word default, that also supports splitting a backup into shares. For a multisig with other brands, use BIP39.

BIP39SLIP39
Words12 or 24 (from a list of 2,048)20 or 33 (from a list of 1,024)
Split into sharesNoYes, optional (Shamir)
Restores on Ledger and BitBox02YesNo
Restores on TrezorYesYes
Used by this guideYes, 24 wordsNo

Why Trezor defaults to SLIP39

SLIP39 lets you later split one backup into several shares, for example 2 of 3 pieces of paper. Starting with a single-share SLIP39 backup keeps that option open. The catch is that only some wallets can restore it.

Why it’s the wrong choice here

One point of this setup is that a seed can be restored on another brand if a device or maker disappears. A SLIP39 seed can’t be restored on your BitBox02 or Ledger. With BIP39, any of your devices, or most others, can take over.

How to pick BIP39 on a Trezor

During setup in Trezor Suite, choose More options and pick the legacy 24-word backup. You can’t convert later without making a new wallet. See step 4 and 12 or 24 words.

Isn’t Shamir the same as multisig?

No. Shamir splits the backup of one seed into shares. To restore, you combine enough shares and the whole seed exists again on one device. Multisig uses separate keys that never meet, and each device signs on its own. For self-custody savings, multisig is the stronger model.