Foundations

Test your recovery without risking your coins

A backup you have never restored is a guess. Here is how to prove it works, including which method to use when you only own one device and it already holds funds.

Intermediate About 25 minutes Updated Aug 17, 2026
RecoveryBackups

Writing down twelve or twenty-four words feels like the hard part is over. It is not. Until you have restored from those words and watched the correct wallet reappear, you do not have a backup — you have a hypothesis, and the test will otherwise be run for you at the worst possible time.

The good news is that this is a genuinely finishable task, usually under half an hour. The bad news is that the obvious way to do it — wipe the device and type the words back in — is also the one way to turn a bad backup into an immediate, permanent loss. So the first decision is which method you use.

Two hardware wallets side by side on a desk, one powered on mid-restore, the other switched off. A seed card sits between them.

Image to come

A restore performed deliberately, while everything still works, is the only version of this that is safe.

Before you start

  • Your written recovery words, and any passphrase you set.
  • The device the wallet lives on, or a second one you can wipe.
  • Somewhere private. This is the one routine task where the words are out on the table.
  • Your wallet's master fingerprint or first receive address, noted down beforehand — that is what you will be checking against.

Pick the method that matches what you own

All three prove the same thing. They differ entirely in what happens if the backup turns out to be wrong.

Safest

Built-in backup check

You need
Nothing extra. Most devices include one.
If the backup is bad
It tells you and leaves the wallet untouched. Safe to run any time.
Most thorough

Restore onto a second device

You need
A spare signing device, wiped.
If the backup is bad
It tells you and leaves the original wallet untouched.
Do not use

Wipe the only device

You need
Nothing extra.
If the backup is bad
The wallet is gone. There is no third copy to fall back on.
  • Never wipe a device that holds funds in order to test its backup. That is not a test — it is betting the wallet on the answer, and you only find out you were wrong once it is already unrecoverable.

If your device has a built-in check, use it. That covers most people, most of the time, and it is the only method with no downside.

Method one: the device's own check

Most signing devices include a function that lets you type your recovery words back in and tells you whether they match the key already stored on the device. Nothing is overwritten and nothing leaves the device — it is comparing, not restoring.

The feature goes by different names. Trezor calls it a backup check, Ledger ships it as a recovery check application, and other makers use wording like verify seed or check backup. If you cannot find it, search your device maker's documentation for those phrases before assuming it is absent.

  • Find the check in the device's menu or its official companion app.
  • Enter the words from your written backup — not from memory, and not from a copy you made later.
  • Read the result. A pass means the words on that card reproduce the key on that device.
  • If you use a passphrase, run the check for the passphrase wallet as well. See the section below.

Note what this does and does not prove. It confirms your written words match this device's key. It does not confirm you can rebuild the wallet somewhere else — for that you want method two, at least once, before the amount gets serious.

Method two: restore onto a second device

This is the real thing: a full rehearsal of what you would actually do if the first device were lost, stolen, or dead. It needs a spare device, which is the only reason it is not the default advice.

  • Wipe the spare device, or use one that has never been set up.
  • Choose restore or import rather than create new.
  • Enter the words from your written backup, in order.
  • Add the passphrase if your wallet uses one.
  • Compare the result against what you noted earlier — see the next section for what to compare.

A second-hand or older device is fine for this. It does not need to be the same brand as your original, as long as it supports the same standard and the same address type. If it is a different brand, an address-type mismatch is the most likely reason for a result that looks wrong but is not — again, see below.

What actually counts as proof

"It seemed to work" is not a result. You are looking for a specific value to match, and you need to have written it down before you started so you are not comparing against a memory.

  • Master fingerprint. An eight-character code identifying the wallet. The cleanest check — if it matches, everything derived from it will too.
  • First receive address. Compare the whole string, not the first and last few characters.
  • Balance and history. Load the restored keys into a watch-only wallet and see whether the expected coins appear.

The fingerprint is the best of the three because it is short enough to compare reliably and specific enough that a match is conclusive. Most wallet software displays it in the wallet's settings or information panel; most hardware devices can show it on screen.

Note it down before you start

Half of failed recovery tests are people trying to remember what the address was supposed to look like. Write the fingerprint or first address on paper before you begin, separately from the recovery words themselves.

If it does not match

Do not panic, and do not wipe anything. A mismatch usually means the test was set up differently from the original wallet, not that your backup is worthless. Work through these in order.

  • Address type. Restoring as Legacy when the original was Native SegWit produces a completely different-looking set of addresses from the same correct words. This is the most common cause by a distance.
  • A missing passphrase. Without it you get the wallet that exists at the words alone, which is a real, valid, empty wallet. It looks exactly like a failure.
  • Word order. Two transposed words give a completely different wallet, and the checksum will often still accept it.
  • A misread word. Handwriting confusions and near-identical BIP39 words are common. Check each word against the official wordlist.
  • Derivation path. Some wallets default to different paths. If the software lets you specify one, match the original.

If you work through all of that and it still does not match, treat the backup as unreliable. The correct response is not to keep trying — it is to generate a brand-new wallet on a device you trust, back that one up carefully, test it, and then move the funds across while you still can. You have caught the problem at the only moment when it is fixable.

A passphrase changes what you are testing

If you use a BIP39 passphrase, your words alone do not lead to your wallet. They lead to a different one. The passphrase is not a password on top of the seed — it selects an entirely separate wallet from the same words.

That has two consequences for this drill — and passphrases have a guide of their own. The test must include the passphrase, typed exactly, or it proves nothing about the wallet you actually use. And the passphrase itself needs the same durability as the words: recorded somewhere it will survive you forgetting it, and stored separately from the seed card so that finding one does not hand over both.

When to run it again

This is not a one-time ceremony. Anything that changes the setup invalidates the previous result.

  • After any firmware update that touches key handling or backup format.
  • After adding, changing, or removing a passphrase — you now have a different wallet.
  • After moving or recopying the backup, including onto metal.
  • After changing the wallet's structure, such as moving from single-signature to multisig.
  • Periodically regardless — once a year, alongside checking the backup is still legible and undamaged.

For a multisig wallet the drill is larger and the failure mode is different: you must also back up the wallet configuration, and rehearse recovery using only the threshold number of keys. Keys alone will not rebuild a multisig, and discovering that during a real recovery is the worst version of this lesson.

This is stage five of the path

If you arrived here without a wallet yet, Start Here covers the four stages before this one. This drill is the one that turns all of them from intentions into something you have actually checked.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.