Survey 04Self-custody
SEED PHRASE BACKUP · THRESHOLD 2/3
2026Open source
Seed phrase backup

Not one metal plate. Not one drawer.

Back up your wallet seed phrase across places no single fire, flood, or theft can reach. Any threshold restores it. We never see the words.

key iHOME iiTRUSTED iiiDEPOSIT BOX N S FIG. 01
§ I · Failure terrain

Where most backups fail.

Elevationi.

The paper in the drawer.

A handwritten phrase folded into a book, taped behind a frame, hidden under a floorboard. Single location, single fate. House sells, drawer empties, dies with the moving truck.

Elevationii.

The metal plate in the safe.

Steel survives fire. Steel does not survive being the only one. Forgotten combinations, lost keys, drilled-open safes, household disagreements about who can open it. One plate is one fate.

Elevationiii.

The split across untrusted places.

Two halves of the phrase in two locations. Either half compromised, the whole is closer to gone. This is not a threshold scheme. It is two single points of failure, stacked.

§ II · Procedure

Set the bearing. Plot the cache.

Bearing 001

Encrypt the phrase locally

Your seed phrase is encrypted with AES-256-GCM on your device. The ciphertext is meaningless without the key.

Bearing 002

Split into three shares

The encryption key divides into 3 shares using Shamir's Secret Sharing. Threshold 2 of 3. Any single share alone is noise.

Bearing 003

Plot the three caches

Home safe. Trusted person. Bank deposit box. Any two caches reconstruct the key. Any one loss is survivable.

One drawer is one fate. Three caches, with a threshold, is a backup.
§ III · Cryptography

Two layers, one guarantee.

A symmetric cipher and a threshold scheme, applied in order. The cipher protects classified material. The scheme is from a 1979 paper by Adi Shamir. Both are open and verifiable.
Stratum I · surface layer

AES-256-GCM encrypts the phrase.

Authenticated symmetric encryption. GCM mode detects tampering on recovery. The ciphertext alone is meaningless and indistinguishable from random noise without the encryption key.

then
Stratum II · bedrock

Shamir splits the key.

Each share is a point on a polynomial over GF(256). K points reconstruct it, fewer than K reveal zero information about the key. Provable, not promised. 51 verified test vectors published.

§ IV · Server state

We hold zero.

Phrase
000°

Never transmitted. Encrypted on your device. We receive no data that could reconstruct it.

Key
000°

Generated locally. Split locally. Never crosses the wire. Not stored, not seen, not held.

Shares
000°

Produced in your browser. Rendered to your shard cards. None reach our servers in any form.

§ V · Recommended setup

Three locations. Any two recover.

A typical 2-of-3 for a self-custody wallet. Survives any single fire, flood, theft, or disagreement, without ever trusting one location alone.

N 41°i.W 087°
Home safe
Fireproof safe at your primary residence. Sealed envelope, signed with date.
Share 01 / 03
N 41°ii.W 087°
Trusted person
A spouse, sibling, or close friend in a separate household. Verified channel only.
Share 02 / 03
N 42°iii.W 088°
Bank deposit box
A neutral institutional party in a different city, separate jurisdiction.
Share 03 / 03
Any 2 of 3 reconstruct the phrase. No single loss is fatal.
§ VI · Field notes

Questions from the trail.

i
Your shard cards still recover the phrase. The recovery tool ships inside your archive and runs offline. The cryptography is open source. The scheme is designed to outlive us.
ii
Yes. BIP-39, SLIP-0010, hardware wallet recovery phrases, raw hex, anything in plain text. The product encrypts whatever you hand it.
iii
For most self-custody, yes. It survives any single location loss and keeps the recovery friction low. For higher-value wallets, scale to 3-of-5 with additional locations.
iv
Yes. A new ceremony issues new shares and the old ones become useless. Some people rotate annually as a discipline. The Annual Review Checklist included with Guardian and Legacy walks this through.
END OF SURVEY

Plot the caches before you need them.

Try the real cryptography on a throwaway phrase. No signup. When you are ready, the plans are one step away.