Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Should you add a passphrase to a bitcoin multisig?

TL;DR

Optional. It protects against a seed leaking remotely, such as a weak seed from a faulty device or a photo of a plate. It doesn’t protect against someone finding your backups if you store it next to them, which is what I do so it can never be lost on its own.

What a passphrase is

An extra word or sentence on top of your 24 words. Seed plus passphrase opens a completely different wallet from the seed alone. There’s no wrong passphrase: every one opens a wallet, most of them empty.

What it protects against

  • A device that generated weak, guessable seeds, as with some Coldcards whose faulty firmware (in use since 2021) was exploited from 30 July 2026. An attacker who works out the seed still sees an empty wallet.
  • A seed that leaks digitally: a photo, a scan, a note in the cloud. Without the passphrase it’s worthless.

What it doesn’t protect against

If you keep the passphrase in the same box as the seed, a burglar who finds two boxes has everything, just as they would without one. You could store it somewhere else, but then it becomes a separate thing you can lose, and losing it is as bad as losing your seeds.

If you use one

  • Use the same passphrase on all three devices. Three different ones mostly give you three things to get right during a recovery.
  • At most 50 plain ASCII characters, because that’s the Trezor limit. Four to six random words works well.
  • Write it exactly: capitals, spaces and punctuation count.
  • Keep a copy with each seed, on a separate card, not on the same plate as the words.
  • Always unlock the passphrase wallet before using a device with Sparrow. The empty wallet looks perfectly normal.
  • Test it before you add real money: step 10 shows how.

More detail on the per-device settings is in step 4.