Buying Bitcoin itself is fairly straightforward today. The harder question is: how do you store your Bitcoin over many years so that it is neither stolen nor lost through your own mistake?
This article is a practical guide from buying a hardware wallet all the way to long term key storage, for a single holding with a clean backup concept. The process and structure are described using the provider 21bitcoin and the BitBox02 Bitcoin-only hardware wallet, since we can recommend both without reservation. The concept shown here is, however, also applicable to most other providers. If you want an overview of Bitcoin providers, take a look at our comparison for buying Bitcoin and storing Bitcoin.
Introduction: Buying Bitcoin Is Easy, Storing Bitcoin Securely Is the Real Task
With Bitcoin there is no central point of contact who can reset a lost private key. Anyone who stores their own Bitcoin therefore also takes on responsibility for:
- generating the private keys,
- storing the hardware wallet,
- storing the recovery words,
- backups and their restoration,
- passwords and, where applicable, passphrases,
- transactions,
- physical security,
- privacy,
- emergency preparedness and estate planning,
- documentation.
Self custody therefore does not simply mean "I own a hardware wallet." Self custody means: I have a well thought out system with which I can control, restore, and protect my Bitcoin over the long term.
The Most Important Thing to Understand
Bitcoin does not live on the hardware wallet. The Bitcoin itself sits on the Bitcoin blockchain. The hardware wallet merely stores the secret keys used to authorize transactions.
The decisive piece of information is therefore the so called recovery phrase, recovery words, or seed. The BitBox02 uses 24 recovery words by default, a human readable representation of the secret wallet seed that can be used to restore the wallet on a new device. (1)
From this it follows:
- The BitBox can be lost. Annoying, but solvable.
- The BitBox can break. Also solvable.
- The recovery words are lost. That can mean the permanent loss of the Bitcoin.
- Someone obtains the recovery words. Then that person can, in principle, access the wallet.
That is why the recovery words are more important than the hardware wallet itself.
Understanding the Security Model
Before choosing a specific solution, you should think about which risks you actually want to protect against. There are at least two basic categories.
Loss
Examples: hardware wallet breaks, hardware wallet is lost, the home burns down, water destroys the backup, a backup is accidentally thrown away, the owner dies or becomes permanently unable to act.
Countermeasures: backing up the recovery words, robust physical backup media, several geographically separated backups, testing the restore process, estate planning, and documentation.
Theft
Examples: someone finds the recovery words, a burglar finds the backup, the microSD card is stolen, recovery words were photographed or stored digitally and compromised, an attacker obtains the keys through phishing.
Countermeasures: never store recovery words digitally, keep the device and the backup in separate locations, secure physical storage, a passphrase where appropriate, multisig for large holdings where appropriate, and consistently checking websites, messages, and support requests. Especially during the initial setup, make sure no one can see your seed: an empty room, no phones, no camera, the PC camera covered, windows that cannot be seen through, and similar precautions. It is worth being overly cautious once during setup so that you can sleep soundly afterward.
The Basic Model: Buy, Cold Storage, Backup
For a private Bitcoin investor, the architecture can initially be very simple:
21bitcoin, then BitBox02 Bitcoin-only, then transfer Bitcoin to your own wallet, then secure the 24 recovery words, then a physical backup, then keep the backup physically separate from the device, then test the restore process.
This simple structure is already quite robust when applied consistently.
Buying Bitcoin and Transferring It Securely
Buying Bitcoin via 21bitcoin
21bitcoin currently offers both professional custody and self custody options. Bitcoin can be held on the platform or transferred to your own wallet at any time, and 21bitcoin also supports an Auto Wallet Transfer. (2)
Option A: 21bitcoin as custodian. The Bitcoin initially stays with 21bitcoin.
Advantage: no seed of your own to manage, no backup management of your own, professional custody infrastructure.
Disadvantage: the private keys are not in your own hands, you are dependent on the custody infrastructure.
For professional custody, 21bitcoin states that it uses institutional infrastructure (BitGo Custody, cold storage) and offers insurance coverage of up to 250 million USD under certain conditions. (3) This solution can make sense for smaller amounts or as part of a diversified custody strategy.
Option B: Manual withdrawal to the BitBox. The classic self custody path:
- Buy Bitcoin on 21bitcoin.
- Prepare the BitBox.
- Generate a receiving address.
- Verify the address on the BitBox.
- Use the address as the withdrawal address on 21bitcoin.
- Carry out the transfer.
- Verify the incoming funds on the BitBox.
21bitcoin currently charges a flat fee of 1,000 sats for external withdrawals. (4) For the first transfer, always carry out a small test transaction first.
Option C: Auto Wallet Transfer. 21bitcoin offers an automated transfer to an external wallet. A hardware wallet is connected via an xPub, after which you can set a BTC threshold. Once that threshold is reached, funds are automatically paid out to your own wallet. (2) This is especially interesting for a long term savings plan: instead of withdrawing every monthly purchase individually, Bitcoin is first accumulated and then transferred automatically to your own wallet once a defined amount is reached.
Why Larger Withdrawals Can Make Sense: UTXOs
Technically, Bitcoin does not consist of a single balance like a bank account. A wallet holds so called UTXOs, unspent transaction outputs. If you receive, for example, 100 small payouts from an exchange, many individual UTXOs are created. That is not automatically bad, but it can lead to higher fees and additional complexity in later transactions.
21bitcoin therefore explicitly recommends bundling smaller purchases and transferring larger amounts to your own wallet. (2) Instead of 30 small withdrawals per month, it is often more sensible to buy Bitcoin, let it accumulate, and then transfer it to your own wallet in one larger withdrawal. That can be summarized as a simple flow:
This is especially worthwhile for small savings amounts; for larger amounts, keep a closer eye on UTXO management and how fees develop.
Understanding the xPub
An xPub is an extended public key. It makes it possible to derive new Bitcoin receiving addresses from a wallet without revealing the private key. (5) An xPub is not a private key, but it is not entirely harmless either: anyone who knows the xPub can observe the receiving addresses derived from it and, in principle, the transaction history of that wallet. An xPub should therefore neither be treated like a seed nor published unnecessarily.
If you connect a hardware wallet to 21bitcoin via its xPub, 21bitcoin can use the associated receiving addresses for automated withdrawals; the connection is verified via 2FA and a digital signature. (2)
Choosing and Setting Up the Right Hardware Wallet
Which Hardware Wallet?
For a Bitcoin only holding, the BitBox02 Bitcoin-only is an obvious choice. Both editions share the same hardware but differ in firmware: the Bitcoin-only version uses exclusively Bitcoin firmware, which reduces the codebase and attack surface, while the Multi version also supports additional cryptocurrencies. Switching between editions later is not possible because of the secure bootloader. (6)
Basic rule: anyone who only wants to store Bitcoin is well served with Bitcoin-only. Anyone who wants to manage several cryptocurrencies needs the BitBox02 Multi. For long term Bitcoin storage, as little unnecessary functionality as possible is generally attractive.
Buying the Hardware Wallet Correctly
A hardware wallet should always come directly from the manufacturer or from a clearly trustworthy source. During setup, pay attention to the device's integrity check. Also:
- only install the BitBoxApp from the official source.
- never install "firmware" from third party websites.
- never enter recovery words just because a website or app asks for them.
- never allow remote support access.
- never follow support instructions that ask for the seed.
Setting Up the BitBox
For the initial setup there are two basic backup options: standard (create the wallet, backup on the included microSD card) and advanced (skip the microSD backup, write down the recovery words directly). With the latter, the words are shown exclusively on the BitBox's own display, never on the computer. (7)
Option 1: microSD Backup
Advantages: very simple, no transcription errors, fast restoration with a new BitBox02, no electronic access to the recovery words during normal setup.
The microSD card is removed after setup and stored securely; BitBox explicitly recommends not inserting it into computers, smartphones, or other devices afterward. (8) Important: the microSD card is itself a fully functional wallet backup and must therefore be treated like a private key.
Is the microSD card encrypted? No, deliberately not encrypted with a separate backup password. (9) Anyone who gains access to a usable backup card must therefore be treated as potentially in possession of the wallet. The BitBox is not the same thing as the microSD card, the two should not be stored together.
Option 2: Writing Down the Recovery Words Directly
You can skip the microSD backup during setup and write down the recovery words directly, a significant advantage since you have an analog, human readable backup from the very start. The BitBox shows the words exclusively on its own display; they are then noted on the physical backup and verified directly on the device. (4) For a long term self custody strategy, this option is very appealing.
12 or 24 Recovery Words?
The BitBox02 uses 24 words by default; a 12 word option is also available in the advanced settings. The number cannot simply be changed after the wallet has been created. For the long term strategy described here, the default setting of 24 words is recommended, not because 12 words would be fundamentally insecure, but because 24 words is the established standard.
The Recovery Words: The Most Important Secret
The recovery words must never be:
- photographed or saved as a screenshot,
- sent by email or WhatsApp,
- stored in a cloud, on a PC, on a smartphone, or in a password manager,
- entered into a browser, a website, or another wallet app,
- shared with a "support representative" or an AI.
BitBox explicitly points out that recovery words should never be digitized or entered into a computer, smartphone, website, or AI tool. (1) Rule of thumb: anyone who asks for your recovery words is not your support.
Recovery Words on Paper
Advantages: cheap, simple, offline, universally understandable. Disadvantages: fire, water, moisture, aging, mechanical damage. For smaller amounts, paper can be perfectly adequate; for a larger long term holding, steel is preferable.
Recovery Words on Steel
A steel backup protects the recovery words much better against physical impacts such as fire and water. Important: steel does not make the wallet cryptographically more secure, it only makes the backup physically more robust. A steel backup is the same recovery phrase, just on a more resilient medium.
How Many Backups?
A single backup at a very secure location is simple, but it is a single point of failure. Two backups in separate locations increase resilience, but every additional complete backup is also another place where an attacker could find the wallet. "More backups" is therefore not automatically "more secure."
Recommendation: for a larger private holding, at least two physical backups in different locations, for example location A (BitBox02), location B (steel backup of the recovery words), location C (a second backup). No one who only gains access to the hardware wallet should automatically also gain access to the backup, and vice versa.
The Backup Must Be Tested
A backup is only truly a backup once you know it works. The BitBox02 lets you display the recovery words on its trusted screen to check a written backup. (1) Check every word, the spelling, the order, and completeness; a single mistake can prevent a successful restore.
For larger amounts, the restore process should be tested in practice: secure the backup, use a second BitBox02, restore the wallet, confirm that the same addresses or balances appear, and only then transfer larger amounts. The point is not to constantly reset the wallet, but to make sure once that the emergency plan actually works.
The microSD Card in a Restore Scenario
If the BitBox breaks, the backup can be restored onto a new BitBox; the old device is not needed for this. (7) The microSD card should be removed again after the restore and stored securely.
For a genuine emergency, meaning the microSD card exists but there is no BitBox left, BitBox provides an offline procedure that can be used to extract the recovery words from the microSD backup. (10) If the recovery words are exposed to a computer in the process, you should assume they may be compromised afterward; BitBox recommends in this case transferring the funds to a newly created wallet with new recovery words.
The Most Important Rule for a Compromised Seed
If you ever think "someone may have seen my recovery words," do not hope that nothing will happen. The correct response: create a new wallet, new recovery words, a new backup, transfer the Bitcoin completely, and stop using the old wallet. BitBox describes exactly this process for dealing with compromised wallets. (18)
The Device Password and Recovery Words Are Not the Same Thing
The BitBox has a device password that protects access to the device itself. The recovery words, on the other hand, are the backup of the actual wallet secret. (11) This means:
- BitBox lost, recovery words available: new BitBox, restore the wallet.
- Recovery words lost, BitBox available: problematic.
- Recovery words stolen: the device password is no longer sufficient protection.
Understanding this distinction is fundamental.
The Optional Passphrase
The passphrase is an additional layer of security, often called the "25th word" even though it is technically not part of the recovery words. It is used together with the recovery words and, from that combination, creates a separate, hidden wallet: every distinct passphrase produces a different wallet. (12) Example: 24 recovery words without a passphrase produce the standard wallet, the same 24 words with passphrase A produce wallet A, and with passphrase B a completely different wallet B. You could hold a small amount in wallet A and your larger holding in wallet B. Someone who has the 24 words for wallet A will not automatically learn that wallet B even exists.
Advantage: Physical Separation of Secrets
If someone finds your backup, without a passphrase they get direct access to wallet A. With a passphrase they additionally need the passphrase, which can be stored separately, for example recovery words in a bank safe deposit box and the passphrase in another secure location.
The BitBox can also run a normal wallet and a passphrase protected wallet in parallel, which can be interesting for certain physical threat scenarios as a form of plausible deniability. (12) A passphrase, however, is no magic protection against every form of coercion or violence.
Disadvantage: No Recovery Is Possible
The passphrase itself cannot be recovered. If you have the recovery words but have forgotten the exact passphrase, the passphrase protected wallet cannot simply be restored; a single wrong character produces a different wallet. BitBox explicitly warns of a possible permanent loss of funds. (12) A passphrase should therefore only be used by someone who is also capable of securing it over the long term.
Introducing a Passphrase Correctly
- First secure the recovery words and verify the backup.
- Define the passphrase concept and document it offline.
- Enter the passphrase on the BitBox and check the wallet fingerprint.
- Carry out a small test transfer.
- Disconnect the BitBox, reconnect it, and enter the same passphrase again.
- Confirm that the same wallet appears, and only then transfer larger amounts.
BitBox explicitly recommends first testing a passphrase protected wallet with a small amount. (13) Important: a backup of the recovery words does not automatically include the passphrase; when using a passphrase you therefore need two separate backup systems (backup A: recovery words, backup B: passphrase), which should not be stored together.
A good passphrase should also not be a simple personal password (not "JohnSmith1985!", not "FavoriteDog123"); it needs to be hard to guess yet exactly reproducible. The BitBox supports upper and lower case letters, numbers, special characters, and spaces for this purpose. (13)
Seed Generation, Address Verification, and the First Transfer
Your Own Entropy and Dice
Advanced users may want to think about how their seed was actually generated. The BitBox02 offers, in addition to normal seed generation, a method for supplying your own entropy via dice. (14) That is technically interesting, but not automatically more secure: the BitBox's normal seed generation already uses several independent sources of entropy. For most users the standard method is therefore the more sensible choice; flawed manual entropy generation can introduce new sources of error.
The basic rule: never invent your own seed words, never use online seed generators or seed generator software from unknown sources. For most users the hardware wallet should generate the entropy; advanced methods should only be used if you fully understand what you are doing.
Anyone who wants to roll their own seed with dice should not use ordinary dice but special casino grade dice (AAA grade), which are precision calibrated. If regular game dice are used, entropy is reduced because such dice are not perfectly symmetrical and their sides are not calibrated for weight.
Always Verify Bitcoin Addresses on the Hardware Wallet
The BitBoxApp displays a receiving address, but the decisive check happens on the trusted device. BitBox explicitly recommends verifying the receiving address on the BitBox02 itself. (15) The principle: do not trust the computer, trust the hardware wallet's display.
Modern wallets generate a new address for each incoming payment for privacy reasons. BitBox names Native SegWit (bc1q...) as the default and recommended format; Taproot (bc1p...) is also available. (16) For a normal transfer from 21bitcoin to the BitBox, it is enough to use the current receiving address suggested by the BitBox and verify it on the device.
The flow for a transfer from 21bitcoin should be: open "Receive Bitcoin" on the BitBox, display the address, verify the address on the BitBox, copy the address, open 21bitcoin, start the withdrawal, paste the address, check it once more, and confirm the transfer. That reduces the risk of malware injecting a wrong address.
The First Transfer: Always Test It
Do not transfer your entire holding immediately on the first transfer. Example: for a planned transfer of 50,000 euros, first carry out a small test transaction, wait for the blockchain confirmation, check the BitBox balance and the receiving address, and only then transfer the rest. A small test transaction costs a bit more in fees, but that is cheap compared to a mistake with a five or six figure amount.
Multisig for Large Holdings
For very large holdings, single-sig can eventually reach its limits. With a normal wallet, one key is generally enough for authorization; with multisig, for example 2 of 3 keys can be required, such as key A at home, key B in a bank safe deposit box, and key C at another secure location. A transaction requires two of them.
The Advantage of 2-of-3
If one key is lost, the wallet remains usable. If one key is stolen, the wallet remains protected. If one location is destroyed, the other two keys still exist. This removes a large part of the single point of failure problem.
Multisig Is Not Simply "More Security"
Multisig creates new tasks: you must additionally store several hardware wallets, several seeds, the wallet configuration, information about the keys involved, and, where applicable, descriptors and restore instructions. That creates a new risk: the wallet can be technically secure, but after ten years no one remembers how to restore it. Multisig should therefore only be used once you fully understand the whole process.
Which Solution for Which Holding Size?
There is no mathematically correct euro threshold, but here is a practical orientation:
- Level 1, smaller holding: BitBox02, 24 recovery words, one solid physical backup. Entirely sufficient for many private investors.
- Level 2, medium holding: additionally steel, a second backup, geographic separation, a restore test.
- Level 3, larger holding: additionally a passphrase with separate storage, estate planning, regular restore tests.
- Level 4, very large holding: additionally consider 2-of-3 multisig, several hardware wallets and locations, a documented recovery process, estate planning, and regular tests.
Why Not Go Straight to Multisig?
Because the biggest risk for private Bitcoin investors is often not a highly skilled hacker, but their own mistake. A simple, well understood, and regularly tested single-sig wallet can be more secure than a complicated multisig structure whose workings the owner does not fully understand.
Mnemonic Split: Splitting Up the Seed?
Another option is to split the recovery words themselves (part A at location 1, part B at location 2, part C at location 3). I would advise against this as a default solution: the split is itself a security concept that must be permanently documented and understood. Anyone who genuinely needs multi-key security is usually better served with a professionally built multisig setup.
Privacy, UTXO Management, and the Human Factor
Physical Tampering and Seals
For larger holdings, physical tamper protection can be worthwhile, for example to be able to tell whether a backup container has been opened. A seal does not prevent someone from copying a seed, it only increases the chance of noticing physical access.
Privacy
Self custody is not automatically anonymous; Bitcoin transactions are publicly traceable. You should therefore avoid reusing the same address unnecessarily, merging UTXOs without reason, sharing your xPub unnecessarily, or publicly linking wallet addresses to your own identity. An xPub can be used to derive receiving addresses and thereby allows extensive insight into the history of the associated wallet. (5)
UTXO Management for Advanced Users
As a Bitcoin holding grows, at some point you should know which UTXOs exist, when they were created, what their origin and size are, whether merging them makes sense, and what the current fee environment looks like. Not every wallet transaction should follow the "select all and send" approach; UTXO management becomes more important as holdings grow.
Documentation
Besides tax documentation, covered shortly, your own restore process should also be documented, without revealing any secrets. A useful document is one that describes, in a way a trusted person or your own future self can understand:
- which hardware wallet is used and where it is located,
- at which locations backups (recovery words and, where applicable, a passphrase) are stored, without revealing the contents themselves,
- which steps are needed for a restore (for example, which BitBox variant, how many recovery words, whether a passphrase exists),
- who should be informed in an emergency and what role that person takes on.
The important point is separating knowledge from secrets: the document explains the process, but it never contains the recovery words or the passphrase itself. More on this in the "Emergency Planning and Estate" section below.
Taxes
A self custody wallet does not replace tax documentation. It makes sense to keep purchase dates and transaction histories traceable. A transfer from 21bitcoin to your own wallet is generally not a sale as long as the Bitcoin remains your own economic property. (17) That said, the exact tax treatment depends on the country, your personal situation, and the type of transaction; for larger holdings, tax documentation should be kept clean from the start. If you want to document transaction histories correctly for tax purposes, Cointracking is a good solution for that.
The Human Factor
A hardware wallet can be technically very secure. A human can still photograph the seed, click a fake link, copy a wrong address, install a fake app, call a fake support number, forget a passphrase, mislabel a backup or store it together with the hardware, or, after ten years, no longer remember how their own wallet even works. The security concept must therefore also keep working for a future state of affairs.
AI Phishing and Fake Support
Modern phishing attacks can be very convincing: perfectly worded emails, fake websites, simulated support chats, imitated voices, seemingly genuine security warnings. No support process ever justifies handing over the recovery words or passphrase. The safest rule: if an action requires entering the recovery words into a computer, browser, or website, stop immediately.
Emergency Planning and Estate
What should never be stored together: BitBox, recovery words, passphrase, and microSD in the same safe, since a single burglary would then be enough. Better is a distribution, for example location A (BitBox), location B (recovery words), location C (passphrase), location D (a second backup, where applicable); the concrete setup must fit your personal situation.
Emergency Planning
A good Bitcoin system must not only work against hackers, but also if the home burns down, you end up in hospital, develop dementia, become permanently unable to act, or die and your family needs access.
Passing Bitcoin On
The biggest problem is often not "how could someone steal my Bitcoin," but rather: how can the family prove after a death that this Bitcoin exists and that they can access it? An estate concept should therefore clarify at least: that Bitcoin exists, where the hardware and backup are located, how the restore process works, whether a passphrase exists and how it becomes accessible, and who should be informed in an emergency.
No Complete Secret on a Single Document
A document saying "here is my BitBox, here are the 24 words, and here is the passphrase" is convenient for heirs, but equally ideal for an attacker. Better is a separation of knowledge and secrets: one document explains the restore process, backup A holds the recovery words, backup B holds the passphrase, and the locations are made accessible through a separate procedure.
Estate Planning Must Be Tested
A common mistake is assuming "my family knows I own Bitcoin," which is not enough. The decisive question is: can that person actually restore a wallet? For larger holdings, the process should be documented so that a trusted person can follow it in an emergency, without all the secrets having to sit in a single document.
Recommended Architecture by Holding Size
An Ideal Model for the Average Investor
Purchase (21bitcoin), then hardware (BitBox02 Bitcoin-only), then wallet (24 recovery words), then backup 1 (steel), then backup 2 (a separate secure location), then the device at yet another location, then verify the address on the BitBox for every transaction, then fully test a restore once, then prepare a restore guide for your estate.
That is relatively simple and still very robust.
An Advanced Model With a Passphrase
A BitBox with a standard wallet for smaller amounts, or as an emergency wallet (recovery words at location A, passphrase at location B), along with the main holding in a separate passphrase protected wallet (a second recovery backup at location C). This means a single discovery of the recovery words alone is no longer sufficient.
A More Professional Model: Multisig
2-of-3 with keys A, B, and C at three different locations, plus several hardware wallets, separate backups, wallet configuration, recovery documentation, estate planning, and regular testing. Here it can make sense to get professional support.
A Possible 21bitcoin Savings Plan
Monthly savings plan on 21bitcoin, Bitcoin is bought and initially accumulated on 21bitcoin, once a defined threshold is reached an Auto Wallet Transfer moves it to the BitBox, verify the new receiving address on the BitBox, then receive the Bitcoin. This matches the approach recommended by 21bitcoin of avoiding small withdrawals and bundling UTXOs. (2)
Concrete Guidance by Holding Size
| Bitcoin holding | Recommended architecture |
|---|---|
| up to about 10,000 EUR | BitBox02 + 24 words + backup |
| 10,000 to 100,000 EUR | BitBox + steel + a second backup |
| 100,000 to 500,000 EUR | additionally a passphrase, separate storage, estate planning |
| from 500,000 EUR | seriously consider multisig |
| very large family wealth | a professional multisig / estate concept |
These thresholds are not technical or regulatory limits, they are practical orientation points.
The Optimal Standard Solution
For a technically minded private investor, the following balance of security and complexity is a good starting point:
- Hardware: BitBox02 Bitcoin-only
- Purchase: 21bitcoin
- Transfer: manual or Auto Wallet Transfer
- Wallet: 24 recovery words
- Backup: steel
- Redundancy: a second physical backup
- Storage: kept in physically separate locations
- Passphrase: only once you have the corresponding wealth and enough experience
- Multisig: only for genuinely large holdings
- UTXO: bundle withdrawals
- Privacy: use new receiving addresses
- Restore: test it before moving larger amounts
- Estate: create a separate emergency plan
The Complete System in One Picture
Checklists
Setup
Before setup: BitBox from a trustworthy source, the official BitBoxApp, a quiet environment with no camera or onlookers, no cloud or online documentation, backup materials on hand.
Setup: pair the device, check the firmware, create the wallet, secure the 24 recovery words, verify the backup, safely remove the microSD card, document the device password securely.
Before the first deposit: generate a receiving address, verify the address on the BitBox, carry out a small test transfer, confirm receipt.
Backup
Recovery words complete, correct order, no spelling mistakes, not photographed, not stored digitally, not online, not in a password manager, a physical backup exists, a second backup considered, the backup and the BitBox stored separately, the microSD stored separately.
Passphrase
Only use it if you genuinely master it: recovery words already securely backed up, the passphrase defined offline and backed up separately, no digital copy, the wallet fingerprint checked, a small test transfer carried out, the wallet reopened and the passphrase successfully restored, the emergency and estate plan updated.
Larger Holdings
Two physical backups, geographic separation, a steel backup, a passphrase considered, estate planning, UTXO management, the xPub not shared unnecessarily, a restore test, an emergency plan, multisig where appropriate.
What to Never Do
Photograph the seed, email it, or upload it to the cloud. Enter the seed into ChatGPT or another AI, into a website, or into a normal app. Tell the seed to a support representative. Store the seed together with the BitBox. For a large holding, keep the passphrase only in your head. Transfer a large sum before the test transaction has succeeded. Verify an address only on the computer. Use a complicated security setup that you do not understand yourself.
Conclusion: The Right Balance Between Security and Simplicity
A good Bitcoin self custody solution is not made of a single product. It consists of several coordinated security measures:
- Trustworthy key generation
- a secure hardware wallet
- a correct backup
- physical robustness
- spatial separation
- secure transaction verification
- protection against phishing and social engineering
- sensible UTXO management
- an optional passphrase
- multisig for very large holdings
- a tested restore process
- estate and emergency planning
The most important principle is this:
Bitcoin security is not a one time setup task. It is a lasting system of key generation, storage, backup, restoration, and human discipline.
For most private investors, a BitBox02 Bitcoin-only with 24 recovery words, at least one robust physical backup, spatial separation, and a tested restore process is the most sensible starting point. As wealth grows, this system can be expanded step by step with a passphrase, additional backups, UTXO management, estate planning, and finally multisig.
The rule always holds:
As simple as possible, but as secure as necessary.
Sources
Alongside the official BitBox and 21bitcoin documentation, information and context from the following explainer videos on hardware wallets and self custody also went into this article:
- Hardware-Wallet erklärt! (Blocktrainer)
- Die 5 Level der Bitcoin Aufbewahrung (Der Bitcoin Podcast)
- Diese 7 Fehler kosten dich deine Bitcoin in Self-Custody (Der Bitcoin Podcast)
- Die 5 größten Bitcoin-Fehler! (Blocktrainer)
- Verlorene Bitcoin & Crypto Wallets wiederherstellen! (Blocktrainer)
- Wallets & sicheres Verwahren von Bitcoin, Stadicus (Blocktrainer)
Written sources:
- https://bitbox.swiss/
- https://support.bitbox.swiss/en_US/wallet-backup/choose-bitbox02-backup-method
- https://support.bitbox.swiss/en_US/advanced/bitbox02-setup-no-microsd
- https://support.bitbox.swiss/en_US/recovery-words-seed/how-to-view-recovery-words-bitbox02
- https://21bitcoin.app/en/feature/wallet
- https://21bitcoin.app/en/security
- https://21bitcoin.app/en/fees
- https://support.bitbox.swiss/en_US/accounts/extended-public-key-formats
- https://blog.bitbox.swiss/en/why-is-there-a-bitcoin-only-edition-of-the-bitbox/
- https://support.bitbox.swiss/en_US/microsd-card/how-to-restore-bitbox02-microsd-backup
- https://support.bitbox.swiss/en_US/basics-/bitbox02-setup-microsd-backup
- https://blog.bitbox.swiss/en/why-microsd-backups-should-not-be-encrypted-by-default/
- https://support.bitbox.swiss/microsd/emergencia-recuperacion-backup-bitbox
- https://support.bitbox.swiss/en_US/device-password/device-password-vs-optional-passphrase
- https://support.bitbox.swiss/en_US/optional-passphrase/understanding-bitbox02-optional-passphrase
- https://support.bitbox.swiss/en_US/optional-passphrase/set-up-bitbox02-optional-passphrase
- https://support.bitbox.swiss/en_US/wallet-foundations-recovery/create-bitcoin-wallet-own-entropy
- https://support.bitbox.swiss/en_US/identify-official-bitbox-websites-avoid-phishing
- https://support.bitbox.swiss/en_US/basics-/how-to-receive-bitcoin-bitbox02
- https://blog.bitbox.swiss/en/what-are-bitcoin-address-types/
- https://21bitcoin.app/en/blog/how-can-you-store-your-bitcoin-and-what-is-a-wallet