Bitcoin Security via Self Sovereignty

Self-Sovereignty Steps When Securing Your Bitcoin

It’s not easy being your own bank. But with diligence, redundancy, and constant learning, it is possible. There’s no “one right way.” Stackers of different stripes will approach risk differently.

1.Never, ever put your seed phrase on an internet-connected device.

Assume all connected devices are compromised even if they aren’t.

2.Your seed phrase should only ever interact with a hardware signing device (e.g. ColdCard, Jade, Passport).

Software wallets are for watching or verifying, not signing.

3.Separate your stack not just by UTXOs, but by wallets (seed phrases).

Example: If you own 5 BTC, you might use two separate wallets with 2.5 BTC each, or a 3–1–1 split. This limits exposure if one wallet is compromised.

4.If using multisig, back up not only the seed phrases but also the derivation paths and quorum setup.

You’ll need more than just keys to reconstruct a multisig wallet.

5.For single-sig setups with large value, consider Shamir’s Secret Sharing (SSS).

It splits your seed into multiple shares, requiring a threshold to recover it. Useful for geographic or social distribution.

6.In multisig, use different brands/models of signing devices.

For example: one ColdCard, one Jade, one Passport. This reduces single-vendor risk.

7.Always use your signing devices in air-gapped mode.

QR codes, microSD cards, NFC. Never USB-connected unless absolutely necessary.

8.Stamp your seeds and recovery info into durable materials like steel or titanium.

Paper burns. Plastic melts. Steel survives.

9.Pre-generate receive addresses to reduce how often you use your signing devices.

Example: If you DCA monthly, create 12 addresses at once and use them throughout the year. No need to unseal the vault each time.

10.Always use your own node for receiving and sending transactions.

Third-party nodes can lie, spy, or censor.

11.Verify your transactions through your own node’s mempool before and after sending.

Don’t trust only the wallet interface.

12.Verify software integrity: compile it yourself or use signature verification.

Example: Sparrow Wallet includes built-in PGP signature verification (except on Start9)

13.Use only well-established, community-audited software and hardware.

Avoid obscure wallets or bleeding-edge devices unless you deeply understand the risks.

14.Buy hardware directly from the manufacturer or a known, reputable distributor.

Avoid used or third-party-market hardware. Supply chain attacks are real.

15.Never act alone when unsure. Reach out to a trusted individual or community (via secure channels) before making big irreversible decisions. Don’t crowdsource on public forums. 

16.If using a hot wallet, limit the amount stored and use only wallets with strong reputations. Treat it like cash in your pocket not your life savings.

17.Geographically separate critical pieces of your setup.

For both multisig and SSS, don’t store all keys/shares in one place. Spread them among homes, banks, or trusted individuals.

18.Use passphrases and strong PIN codes. BIP-39 passphrases add a second layer of protection on top of your seed phrase. (just don’t forget it)

19.Set up decoy wallets (“duress wallets”) as plausible fallbacks.

If coerced, you can reveal a wallet with a small balance. Just make it believable.

20.Use self-destruct or duress features where supported.

Some hardware wallets allow nuking the wallet with a specific PIN.

21.Regularly test your backups.

Try restoring from your seed or SSS shards in a safe environment. Don’t assume, they must actually work.

22.Plan for inheritance.

Your Bitcoin is only yours while you’re alive. Securely document instructions for trusted heirs. Consider time-locked multisig, lawyers, or dead man’s switches.

23.Avoid taking photos of seed phrases, QR codes, or keys, even temporarily.

Photos sync to cloud storage, persist in backups, and leak metadata.

24.Never trust your computer screen, verify on-device.

Only trust what your hardware wallet displays before signing. Don’t assume the app or UI isn’t compromised.

25.Keep logs of your firmware versions and software setups.

Helpful for future recovery, especially if certain features or bugs are version-specific.

26.Understand which standard your wallet uses: BIP-39, BIP-85, SLIP-39, etc.

ColdCard, for instance, can derive many wallets from a single seed using BIP-85.

27.Avoid browser-based wallets and extensions.

Browsers are complex, risky environments. Use standalone desktop apps like Sparrow or Specter.

28.Treat xpubs almost as sensitively as seeds.

A leaked xpub reveals all addresses and balances. Share only when necessary.

Did you find this article helpful? If so, consider sending a tip via Bitcoin. Nostr: npub1vmrqfy3sl8sedde67u0knkmam2u8sc5e3dd5ph282zak2zulh6uq3r4js8 LN Tips: brewsbitcoin@strike.me Thanks for your support. Doug

bc1qe5yrg7nf7cxp4g9gq5sw6kwhshk04tmnud529f

Leave a Reply