SubscribeBTCSCAMWallet Test
Front page / Field guide: seed-phrase backup
elevatedField guide: seed-phrase backup

Back up your seed phrase in metal, never in a photo

Malware now scans phone galleries for recovery-phrase screenshots, then drains the wallet. A durable offline backup and a strict no-cloud rule keep the master key out of reach.

JR
Jules Renner
Community Manager · FEB 5, 2025 · 4 min read
Painting: Renaissance archive · Source: Securelist (Kaspersky)

Your recovery phrase, the 12 or 24 words a wallet shows you at setup, is the master key to every coin the wallet holds. Anyone who reads those words can rebuild the wallet on their own device and move the funds, and on a blockchain those transfers do not reverse. That makes where you write the phrase down as consequential as the hardware you bought to protect it.

Why a screenshot is a loaded gun

The clearest argument against photographing your phrase arrived in 2025. Kaspersky's Securelist team reported a crypto stealer it named SparkCat, hidden inside apps on both Google Play and Apple's App Store, that used an optical-character-recognition model to read the pictures sitting in a phone's gallery. It searched those images for recovery-phrase keywords in several languages and uploaded any that matched to its operators.

The reach was not trivial. Per Securelist, the tainted Google Play apps alone had been downloaded more than 242,000 times, the campaign had been active since at least March 2024, and it was the first stealer of its kind found inside Apple's App Store. A screenshot of your seed in the camera roll is, in practice, plaintext waiting for any gallery-reading app to collect. Kaspersky's advice was blunt: do not keep such screenshots in the gallery at all.

Write it once, in something that lasts

Paper holds up until it meets fire or water. The bitcoin custody firm Unchained recommends inscribing the words into metal, such as stamped stainless steel, so a house fire or a flood does not take the only copy with them. Its rule on the digital side is just as firm: never record a seed phrase on a computer, phone, or any internet-connected device, and, in its words, definitely not on a cloud service.

  • Record the phrase by hand, then transfer it to a stamped or engraved metal plate rated to survive heat and corrosion.
  • Never photograph the phrase, type it into an app or password manager, or place it in cloud storage, email, or notes.
  • Keep at least two copies in separate physical locations so one fire, flood, or burglary cannot erase both.
  • Store the metal backup apart from the hardware wallet, and check periodically that the words remain legible.
  • Treat anyone, or any app, that asks to see the phrase as hostile; a legitimate wallet never needs it typed into a computer.

None of this is exotic. The discipline reduces to one idea: the phrase should exist only where a remote attacker cannot reach it, and in a form that outlasts the accidents that destroy paper. Get that right and the words survive the hardware; get it wrong and, as SparkCat's victims found, the theft is silent and irreversible.

— Sources: [Securelist](https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/) · [Unchained](https://www.unchained.com/blog/seed-phrase-backup-methods-recording-paper-metal)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING