We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
What Is a Passphrase or 25th Word and How to Use It
What is a passphrase and why does a hardware wallet owner need one? Start with the basic setup: a standard hardware wallet generates a 12- or 24-word seed phrase. The classic Ledger setup and most modern configurations use 24 words. This is enough as long as the seed does not leak and nobody physically forces you to reveal everything you own.
A passphrase, sometimes called the 25th word, is an additional string applied on top of your seed phrase. It gives you a separate wallet that remains hidden even from someone who physically obtains your seed phrase by finding a steel backup plate with 24 words or a paper backup. It also remains hidden from someone who comes after you with a wrench and tries to force access out of you.
Below, we explain how this works, cover the real drawbacks that promotional materials often omit, and show how to set up a “10% in the decoy wallet, the rest in the hidden wallet” scheme step by step.
What is a passphrase and how is it different from a seed phrase?
Your 24-word seed phrase remains the main backup. Did the device break, get lost, or get damaged by water? You can use those 24 words to restore access on any BIP39-compatible wallet.
A passphrase works differently. It is a string that you choose yourself and add to your seed phrase. The wallet combines the 24 words with that string and generates a new set of private keys and addresses, different from the set generated by the seed phrase alone.
In practice, it works like this:
You can create as many hidden wallets as you want. There is only one limitation: you must remember exactly which passphrase belongs to which wallet.
This is not a password or a PIN. A PIN protects access to the device itself: if you forget it, Ledger resets after three incorrect attempts, but the seed phrase allows you to restore access. A passphrase works differently because it is part of the wallet cryptography. If you forget it, the funds in that wallet are lost permanently. There is no email reset and no support team that can recover it.
This is part of the BIP39 standard, so the mechanism is not limited to Ledger. Trezor, BitBox, Coldcard, and Keystone use the same principle. A Ledger passphrase opens the same seed-derived wallet on Trezor when the seed phrase and derivation path match.
What a passphrase gives you in practice
A hidden wallet that nobody knows about
The main purpose of a passphrase is to create a wallet that remains inaccessible even to someone who has your seed phrase.
Did someone find your steel plate with 24 words during a search, a move, or a border crossing? That is unpleasant, but not necessarily critical. If your main funds are stored in a passphrase wallet, someone who only has the 24 words will see the decoy wallet and nothing else.
Plausible deniability and protection against a “$5 wrench attack”
The term “$5 wrench attack” comes from a well-known xkcd comic. An attacker does not need to break cryptography to take your money. A $5 wrench and some time may be enough. In real life, this can mean kidnapping, a home robbery, blackmail, or coercion to reveal all your assets.
A passphrase gives you what is known as plausible deniability: the ability to credibly claim that no other funds exist. You enter the PIN for the decoy wallet, open it, and show the balance, for example $500 split across several assets. The attacker cannot prove that another wallet exists. Both wallets are real from the device’s perspective; they simply open with different PINs.
Protection if the seed phrase has already been compromised
People photograph their seed phrase “for a minute,” save it in Google Keep, or store it in a password manager. If such a copy ever falls into the wrong hands, the passphrase becomes your last line of defense.
An attacker can restore your seed phrase on their own device and reach only the decoy wallet. The hidden wallet will not open without the passphrase.
Drawbacks and risks that promotional materials rarely mention
Forget the passphrase and the funds are gone forever
This is not a password that can be reset by support. It is not something you can simply brute-force in 24 hours either. Losing the passphrase means permanently losing access.
One extra character opens a different wallet
There is no “wrong password” message. Enter “MyCat42” instead of “MyCat42!” and the device will calmly open another, empty wallet. It will look like a normal wallet, just with a $0 balance.
The funds have not disappeared. You are simply looking at a different set of addresses. This is the part that scares beginners the most.
Awkward input on devices without a touchscreen
This is more of a drawback of specific devices than of the passphrase itself, but it is worth considering. On the Nano S Plus and Nano X, a passphrase is entered with two buttons by scrolling through characters and confirming each one. A 20-character string with mixed case and special symbols can take 5–7 minutes of slow clicking.
If you plan to access the hidden wallet every day, this quickly becomes annoying. Touchscreen devices such as Stax and Flex are easier to use because the keyboard is displayed directly on the screen.
The decoy wallet must look believable
If the attacker understands crypto, they know about passphrases. A wallet with $5 in a single USDT balance does not look like “everything you own.”
The decoy wallet should look like a real wallet owned by someone who holds crypto: a credible amount, several assets, and transaction history. Otherwise, plausible deniability does not work.
Inheritance becomes more complicated
If you use a passphrase and die unexpectedly, your heirs may receive the seed phrase, restore the decoy wallet, see $500, and assume that this is everything.
The funds in the hidden wallet may remain there forever. Plan for this in advance with written instructions, a separate location for the passphrase backup, or a trusted person who at least knows that it exists.
How to build a “10% in the decoy wallet, the rest in the hidden wallet” setup
This setup uses one seed phrase but two working wallets on the same device. The decoy wallet opens with the main PIN and contains the funds you are prepared to “give up” under coercion. The main wallet opens with a different PIN together with the passphrase and contains the rest.
How much should you keep in the decoy wallet?
There is no rigid rule, only plausibility. If the main wallet contains $50,000 in total, a $50 decoy wallet looks suspicious. A $5,000 decoy wallet already looks more like the wallet of someone who “dabbles in crypto.”
A reasonable guideline is 5–15% of the total. But the amount is not the only factor:
Where to store the passphrase
Store the passphrase separately from the seed phrase. If you write both on the same sheet of paper, the entire point disappears: whoever finds the sheet gets both the seed and the passphrase.
Options:
For a long or rarely used passphrase, you still need at least one paper backup in a secure location. If you are not confident that you can preserve the passphrase for 5–10 years without losing it, it may be better not to enable it at all. Losing some funds because of a leaked seed phrase is painful, but losing everything because of a forgotten passphrase is worse. We covered the basic backup methods separately in “Seed phrase storage: 5 safe methods in 2026”.
When a passphrase is enough and when multisig is a better choice
A passphrase is an additional layer on top of a single-signature wallet. For amounts up to $100,000 and a disciplined backup strategy, this may be enough.
If the amount is larger or you want to eliminate a single point of failure, consider multisig, for example a 2-of-3 setup using three different devices stored in three different locations. Multisig is more explicit: there is no hidden secret that you might forget. Instead, there are several independent keys, without which a transaction cannot be made.
How to set up a passphrase: general logic and a Ledger example
The passphrase mechanism works the same way on all BIP39-compatible devices, including Ledger, Trezor, BitBox, Coldcard, and Keystone. Only the menu names and input methods differ. The general process is the same: update the firmware, make a test transaction to the regular wallet without a passphrase, enable passphrase protection in the security settings, select a mode, either a passphrase attached to a separate PIN or a temporary passphrase, set and confirm the passphrase, verify that the hidden wallet produces different addresses, and only then move the main funds. On Trezor, this is under Settings → Passphrase. Coldcard has a separate menu item, while BitBox exposes the option in its app. Below, we use Ledger as the example because it is the most common device. You can cross-check the steps against the official Ledger guide.
These instructions are current as of May 2026 for Ledger Nano S Plus, Nano X, Stax, and Flex. The companion app is now called Ledger Wallet: the new name replaced Ledger Live in autumn 2025, and the old brand was fully retired by November 2025.
On the Nano S Plus and Nano X, input is handled with two buttons. On Stax and Flex, you type directly on the screen. The logic is the same; only the interface differs.
What to prepare before you start
Make a test transaction before setup
Before setting up the passphrase, send a small amount, around $10–20, to the regular wallet that works without a passphrase.
This is your safety check. If something goes wrong after setup, you will know that the seed phrase and device were working correctly beforehand.
Open the passphrase menu
On the device, go to Settings → Advanced → Set passphrase. Ledger will display a warning. Read it carefully because it covers important details. The device will then offer two modes.
Attach to PIN. This creates a second PIN that opens the passphrase wallet. The first PIN opens the decoy wallet; the second PIN opens the main wallet. The passphrase is stored on the device and attached to the second PIN until you change it or reset the device. This mode is suitable for everyday use.
Set temporary passphrase. The passphrase remains active until the device is powered off. Every time you want to access the hidden wallet, you need to enter it again. This is the more paranoid mode: the passphrase does not remain stored in the device memory while it is idle. It is convenient if you access the wallet once a month.
Set up Attach to PIN
The device now works as follows: PIN1 opens the decoy wallet based on the 24 words. PIN2 opens the main wallet based on the same 24 words plus the passphrase.
Check that everything works
If the test transaction arrives successfully, the setup is correct. You can then gradually transfer funds to the main wallet while leaving 5–15% in the decoy wallet for plausibility.
Common mistakes when using a passphrase
Writing the passphrase on the same sheet as the seed phrase. This is the most common mistake. It defeats the entire purpose: whoever gets the sheet gets both the seed and the passphrase.
Using a dictionary word or a single word from the BIP39 list. A passphrase made of one or two short words from a known list can realistically be brute-forced. It should be sufficiently complex, with mixed case, numbers, special characters, and no obvious word.
Skipping the test transaction after setup. This is a classic mistake: you set up a passphrase, transfer $20,000, enter the string incorrectly a month later, and see an empty wallet. A test transaction before moving the main balance catches errors early.
Relying only on memory when that is risky. “I will definitely remember it” often ends with trying different variations a year later. If the passphrase is long or you rarely access the wallet, keep at least one paper backup in a secure location.
Failing to tell your heirs that the passphrase exists. If only you know about the passphrase and it is not documented anywhere in your crypto inheritance plan, the hidden-wallet funds may remain there forever. Your heirs do not necessarily need to know the passphrase itself, but they need instructions on where to find it.
The bottom line
A passphrase is not necessary for everyone, and that is fine. It addresses two specific scenarios: physical coercion, when you need to reveal “everything” without putting your main funds at risk, and a leaked seed phrase that remains harmless because the passphrase is still known only to you.
At the same time, the cost of a mistake is high. Forget the string, mistype a single character, or leave no instructions for your heirs, and access to the funds is gone. No support team can help, because that is the entire point of the mechanism.
Here is the simple way to decide whether this tool suits you. If the amount is below $100,000 and you are ready to maintain two independent backups for years, storing the seed separately from the passphrase, then a passphrase may be justified. If you doubt your backup discipline, start with a properly secured seed phrase without a passphrase. That is safer than enabling a passphrase and losing it. If the amount is large or you need to eliminate a single point of failure, consider multisig.
Add a passphrase only when you know exactly how you will preserve it for years, not just for a month. If you are confident in that plan, the “10% in the decoy wallet, the rest in the hidden wallet” setup provides real protection both during a search and against someone armed with a wrench.
Related Posts
What Is a Mnemonic Phrase? BIP39 Word List
What is a mnemonic phrase? This is a question our customers often ask us. Let’s figure it out. A mnemonic phrase is a group of words that provides access to your assets and serves as a backup for your crypto wallet. It is also often called a seed phrase or BIP39 phrase. A phrase can …
What Is Shamir Backup and SLIP39?
Welcome! In this article, we will explain how Shamir Backup works. We will look at why it is one of the best ways to protect your crypto investments, compare the SLIP39 and BIP39 standards, and answer the question: “How can you protect your cryptocurrency from theft and sleep better at night?” I will try to …
Best private messengers with end-to-end encryption. Top apps in 2026
The best private messengers 2026 protect conversations with end-to-end encryption, but not every popular app is genuinely private. Many services store messages on a server in plaintext: the company that owns the service can read them, hand them over under a warrant, or lose them in a data breach. Private messengers do not. There is …
How to Avoid Crypto Scams: 10 Fraud Schemes That Work in 2026
From “trust, but verify” to “do not trust — verify”. $14 billion. That is how much crypto scammers received in 2025 according to confirmed on-chain data from Chainalysis. The real figure is higher: analysts expect the total to exceed $17 billion as new wallets that were not previously flagged as fraudulent continue to be identified …