How do I keep my XRP wallet, keys and recovery phrase safe?
Also asked as: “How do I keep my XRP wallet and keys safe?” · “What should I do with my seed phrase?” · “Where should I store my recovery phrase?”
Confirmed Published 6 min read
Short answer
Keep the recovery phrase and private keys secret, offline and physically secure, because anyone who holds them controls the account and nobody can restore access afterward. The FBI said in September 2024 not to store seed phrases on internet-connected devices. NIST noted in 2021 that paper and digital backups alike can be lost, stolen or destroyed.
The full answer
What the recovery phrase and keys control
On the XRP Ledger, control of an account comes down to a secret. XRPL.org’s cryptographic keys page says the passphrase, seed and private key are all secrets: anyone who knows any one of them can make valid signatures and has full control over the account [3]. Most XRP Ledger software never shows the private key and derives it from the seed when it is needed, the same page says [3].
Two more points from XRPL.org set the stakes. Digital signatures are the only way to authorize a transaction, and no privileged administrator can undo or reverse one after it applies [3]. Its tutorial on disabling the master key adds that no one can restore access to an account if something goes wrong [4]. A thief with your seed looks, to the ledger, exactly like you.
Where to store the recovery phrase
The clearest government instruction comes from the FBI. Its public service announcement of September 3, 2024 says not to store logins, passwords, seed phrases or private keys for crypto wallets on internet-connected devices [1]. That rules out photos, cloud notes, email drafts and password-manager entries.
Offline storage has its own failure modes. NIST’s report 8301 (February 2021) says anyone who finds the seed words can restore the tokens on a device of their choice, and that paper and digital backups can be lost, stolen or destroyed [2]. FINRA describes a paper wallet as a piece of paper with the private keys written on it, and warns that the funds could fall into the wrong hands or be lost to destruction or accident [8].
Ledger’s CEO went further in a message of December 21, 2020, written after a customer data leak. He advised against keeping the recovery sheet in a home safe, called a bank vault much more secure, and said that not having immediate access to the backup increases resilience to physical threats [9]. That is the wallet maker’s own advice, not a regulator’s.
Where the phrase comes from matters as much as where it goes. XRPL.org says a private key should be chosen using a strong source of randomness, and that you should only use keys generated with devices and software you trust, because compromised applications can expose your secret to people who send transactions from your account later [3]. Its secure signing page calls any setup where outside sources may reach your secret key dangerous and likely to end in theft of all your XRP [5].
Why a hardware wallet’s phrase should stay out of phone apps
A hardware wallet’s protection depends on the key never leaving the device. D’CENT’s app FAQ says that on its hardware wallets the private key is generated inside the device’s secure chip and never leaves it [6]. The same FAQ says that if you have ever entered the hardware wallet’s recovery phrase into its App Wallet or any other software wallet, the two wallets share the same keys and the hardware wallet should not be treated as isolated [6]. D’CENT’s FAQ warns that entering a hardware wallet’s recovery phrase into a software wallet breaks its isolation. The D’CENT wallet drain is covered on a separate page.
Devices are not a complete answer either. FINRA notes that hardware wallets can break down, suffer defects or be lost or stolen, and are not totally immune from sophisticated hacking [8]. The checks a buyer can run are set out in whether a hardware wallet can be hacked.
How metal plates and split shares compare with paper, on theft and loss risk
Paper fails in two directions, as NIST and FINRA describe: someone can find it, or it can burn, soak or go missing [2][8].
Split backups try to handle both. Trezor’s documentation says its Shamir backup (SLIP39) is designed for the two most common risks to a wallet backup, theft and loss [7]. It creates several recovery shares, from 1 up to 16, and a set number called the threshold is needed to rebuild the wallet; the threshold cannot be set to one share [7]. Shares below the threshold leak no information about the secret, Trezor says [7]. In a 2-of-3 setup, one lost or stolen share leaves the wallet safe and usable. Lose enough shares that the threshold can’t be met, and the wallet becomes unrecoverable [7]. These are one maker’s claims about its own standard.
None of the government guidance cited on this page mentions metal backup plates.
What a passphrase (extra word) is, and whether it adds safety or new ways to lose access
The word “passphrase” means different things in different places. In XRPL.org’s own diagram of key values, a seed can be generated from a passphrase or from another source of randomness, and the page lists the passphrase among the secrets that give full control [3].
No source cited here documents an optional extra-word passphrase on hardware wallets, so this page does not describe that feature. The aim is that a found recovery phrase alone is not enough. The cost is a second secret that must never be forgotten, because XRPL.org is clear that no one can restore access to an account [4].
How to tell if a phrase has already been exposed
There is no reliable sign. XRPL.org says a compromised application can expose a secret that is then used to send transactions later [3], so a quiet period proves little.
The official responses to past exposures assume the worst. After malicious versions of the xrpl.js code library were published on April 21, 2025, XRPL.org said on April 28 that anyone who had installed them should assume their wallets were compromised and follow its key-rotation guidance; it added that no downstream effects had been reported by then [11]. XRPL.org’s tutorial says disabling the master key is the step to take if the master key may have been compromised, and warns to confirm first that a regular key or multi-signing list works [4]. D’CENT’s FAQ likewise treats a hardware wallet whose phrase entered software as no longer isolated [6].
How the XRP Ledger can reduce reliance on one phrase, and how heirs fit in
The ledger has built-in options. XRPL.org says you can keep the master key enabled but offline, out of reach over the internet but available in an emergency [3]. With multi-signing, a holder can name 1 to 32 addresses that can authorize transactions, including when the holder is unavailable [10]. If the owner loses a private key, XRPL.org’s example has friends on the signer list multi-sign a replacement regular key [10]. NIST’s report says multi-signature wallets can restore access after keys are lost as long as enough keys remain [2]. TRM Labs (May 23, 2025) says requiring several approvals makes coercion alone much harder to succeed [13]. The setup details and risks are on XRP Ledger account security features.
Heirs need a path that does not leak the secret during your life. A Rotfleisch & Samulovitch article on Mondaq (June 15, 2026) says crypto ownership often depends entirely on access to keys and recovery phrases, and that seed phrases should generally not go in a will because wills may become public in probate [14]. The same article warns that multi-signature wallets can complicate an estate if succession steps are not documented [14]. More on this is in what happens to XRP at death.
The case against piling on precautions
The strongest objection is that each layer adds a way to lose everything. NIST says backups of any kind can be lost or destroyed [2]. Trezor says too few surviving shares means an unrecoverable wallet [7]. The Mondaq article says multi-signature arrangements can trip up executors [14]. Since nobody can restore access [4], a holder’s own mistake can cost as much as a theft. That side of the ledger is set out in losing XRP without being hacked.
Privacy also limits what storage alone can do. The FBI’s February 8, 2022 announcement advises against advertising crypto holdings on social media and forums [12]. Chainalysis reported on August 6, 2026 that most violent attacks it assessed were premeditated, with victims picked through exposed information such as data breaches and social-media activity [15].
What we know
- XRPL.org’s cryptographic keys page (last updated around June 2026) says the passphrase, seed and private key are secrets, and anyone who knows any of them has full control over the account.
- The same XRPL.org page says no privileged administrator can undo or reverse a transaction once it has applied, and anyone who knows your seed or private key can authorize any transaction the same as you.
- XRPL.org’s undated tutorial on disabling the master key says no one can restore access to an XRP Ledger account if something goes wrong.
- The FBI’s public service announcement of September 3, 2024 says not to store logins, passwords, seed phrases or private keys for crypto wallets on internet-connected devices.
- NIST’s report 8301 (February 2021) says anyone who finds the seed words can restore the tokens, and that both paper and digital backups can be lost, stolen or destroyed.
- D’CENT’s app FAQ says that if a hardware wallet’s recovery phrase was ever entered into its App Wallet or any other software wallet, the two share the same private keys and the hardware wallet should not be treated as isolated.
- Trezor’s documentation on Shamir backup says shares below the threshold leak no information about the secret, and that losing so many shares that the threshold cannot be met leaves the wallet unrecoverable.
- XRPL.org reported on April 28, 2025 that malicious xrpl.js versions published on April 21, 2025 were built to capture secret keys, and said anyone who installed them should assume their wallets were compromised and rotate keys.
- XRPL.org’s multi-signing documentation says a holder can delegate the power to send transactions to a group of 1 to 32 addresses who can act if the holder is unavailable.
What we reason Analysis
- Every extra copy, share or hiding place changes which risk dominates rather than removing risk. NIST’s report 8301 says any backup can be lost, stolen or destroyed, and Trezor’s Shamir documentation shows a split backup protects against one lost or stolen share but becomes unrecoverable once too many are lost.
- A remembered extra secret, such as a passphrase, adds a way to lose access as well as a barrier to theft. XRPL.org lists the passphrase among the secrets that give full control and says no one can restore access to an account, so forgetting any secret needed to sign has no fallback.
- No test can prove a phrase has never been copied. XRPL.org says anyone holding the seed signs exactly as the owner does, and its key page warns a compromised application can expose a secret that is used later; this is why both XRPL.org’s xrpl.js disclosure and D’CENT’s FAQ treat any phrase that touched suspect software as compromised.
- A phrase typed into any online app takes on that app’s weaknesses. D’CENT’s FAQ says the hardware wallet stops being isolated once its phrase enters software, and XRPL.org’s secure signing page calls any setup where outside sources can reach the secret key dangerous.
What's still open
- As of October 1, 2026, no government agency, regulator or peer-reviewed study has published a comparison of metal backup plates with paper, or guidance on storing backup copies in separate locations.
- As of October 1, 2026, no government agency has published guidance for individual holders on the optional extra-word passphrase that some hardware wallets offer.
- As of October 1, 2026, no Canadian or US regulator has published a guide for individuals on passing crypto keys to heirs.
In plain English
Your recovery phrase is the master key to your XRP: whoever has it can move the coins, and nobody can undo the transfer or give you a new one. The FBI advises against keeping it on a phone, computer or online account. Keep it written down somewhere physically safe and never type a hardware wallet’s phrase into an app. Every way of backing it up can fail, either by being found or by being lost, so each choice is a trade-off.
Key terms
Sources
- North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Techniques (PSA) — FBI Internet Crime Complaint Center, Tue Sep 03 2024 00:00:00 GMT+0000 (Coordinated Universal Time) Primary
- NISTIR 8301: Blockchain Networks: Token Design and Management Overview — National Institute of Standards and Technology, 2021-02 Primary
- Cryptographic Keys — XRPL.org, undated Primary
- Disable Master Key Pair — XRPL.org, undated Primary
- Secure Signing — XRPL.org, undated Primary
- FAQ: DCENT App — D'CENT (IoTrust), undated Company-reported
- What is Shamir backup? — Trezor, undated Company-reported
- Cryptocurrency Storage — FINRA, undated Primary
- Message by Ledger's CEO: Update on the July data breach — Ledger, Mon Dec 21 2020 00:00:00 GMT+0000 (Coordinated Universal Time) Company-reported
- Multi-Signing — XRPL.org, undated Primary
- Vulnerability disclosure report: xrpl.js, April 2025 — XRPL.org, Mon Apr 28 2025 00:00:00 GMT+0000 (Coordinated Universal Time) Primary
- Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public (PSA) — FBI Internet Crime Complaint Center, Tue Feb 08 2022 00:00:00 GMT+0000 (Coordinated Universal Time) Primary
- The Rise of Wrench Attacks and Crypto-Related Violent Crime — TRM Labs, Fri May 23 2025 00:00:00 GMT+0000 (Coordinated Universal Time) Company-reported
- Crypto Estate Planning in Canada: CRA Tax Treatment on Death, Wills and Inheritance — Mondaq (Rotfleisch & Samulovitch), Mon Jun 15 2026 00:00:00 GMT+0000 (Coordinated Universal Time) Secondary
- Violent crypto wrench attacks in 2026 — Chainalysis, Thu Aug 06 2026 00:00:00 GMT+0000 (Coordinated Universal Time) Company-reported
- 21shares XRP ETF (TOXR) — 21shares, 2026-09-29 Company-reported
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
