BIP39 Passphrases and the Coldcard Incident: Protection and Recovery Limits
Understand why a separate passphrase can matter and why recovery planning must distinguish it from a PIN, seed backup or ZeroLatch phrase.
A separate secret, a separate responsibility
A BIP39 passphrase changes the wallet derived from a seed. It is distinct from a device PIN, an account password and the wallet’s seed words. Do not infer its strength from character count alone or assume any phrase provides adequate protection. The current COLDCARD guidance discusses strong, unique passphrases and the need to test the resulting wallet. Follow the applicable migration advice rather than treating a passphrase as a universal repair.
Recovery mistakes can look like an empty wallet
A recipient needs the exact intended recovery procedure and the correct wallet context. Guessing punctuation, spacing or the intended secret can lead them down the wrong path. Document the non-secret identifiers recommended by the manufacturer and test that the process reaches the intended wallet before relying on it. Keep the seed and passphrase according to your custody plan, with access appropriate to the people involved. Do not place all the ingredients into a document that is then casually emailed.
Do not add complexity without a rehearsal
Think about who will carry out recovery, what experience they have, and whom they can safely ask for help. An arrangement that depends on one person remembering an unexplained phrase may fail when that person is unavailable. Use an empty practice wallet to learn the documented process. Check the plan after moving funds, replacing a device or changing a passphrase arrangement. Avoid making a high-value recovery test the first time someone sees the instructions.
Keep the different phrases clearly labelled
A ZeroLatch Private recovery phrase unlocks a ZeroLatch delivery. It is not a Bitcoin wallet seed and must never be reused as one. Your account password signs you into the service; it is not the recipient’s Private secret. A handoff can explain where authorised recovery information is held without putting the wallet seed and every other secret into the same place.
Prepare the instructions your person would need
Keep wallet seed words and master passwords out of a general handoff message. Start with a non-secret inventory, document locations and a person to contact. ZeroLatch is an online conditional delivery service: check-ins keep a delivery on hold, and a missed deadline plus the safety period can make it eligible for release. Recipient access also depends on verification and service availability. Simple uses service-managed key recovery; Private requires a separate secret. Neither mode guarantees a financial or legal outcome.
Save the free handoff checklist, or try a fictional delivery without signup. The sample uses no real wallet data.
ZeroLatch Editorial Team
Published by ZeroLatch to explain future delivery and continuity planning. These guides are not independent reviews of our product. Read our editorial standards and corrections.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or technical advice. ZeroLatch is a software service, not a law firm. We recommend consulting with qualified professionals regarding your specific estate planning, data privacy, and security needs.
Who would know where to begin with your wallets?
See a handoff with wallet-record locations and adviser contacts. ZeroLatch can release instructions after missed check-ins and a safety period; it does not secure wallets or transfer assets. Keep recovery secrets separately.
Write my instructions →Start a free draft without an account or card. Use harmless information. See the example first.