Storing Your Backups

As many experienced bitcoiners know, proper storage of your private key backups are critical for safe holding of bitcoin.

GuardBlock helps you out if you lose your hardware device (also known as a bitcoin hardware wallet) and your backups, but keep in mind that we can't help until the Recovery timelock has expired. Therefore if you lose your hardware device and want to recover your coins without waiting for the timelock, having a backup of your hardware device is handy.

A backup is also needed if you have lost your hardware device and you want to move your funds out of GuardBlock without us being involved.


Disclaimer

GuardBlock provides this information as a launch-point for understanding what hardware device backups are and now to store them safely, but makes not guarantee that the advice is adequate for your specific circumstances. Do your own research using reputable sources, and ask us any additional questions, before you lock-in your final setup. Consider doing an annual revision of your setup to ensure everything is still as expected.


I have GuardBlock, why do I need to make a backup?

Most bitcoiners already familiar with self-custody and hardware devices will likely be in the habit of meticulously taking a backup of their hardware device private key, usually in the form of a seed phrase. More on that later.

With GuardBlock, since we are essentially a backup for your setup, having a backup of your seed phrase actually becomes optional. If you lost your hardware device, we can still recover your funds for you once the recovery timelock expires, which is up to 15 months. So, if you are happy to keep things simple and comfortable with a waiting period, all you need is your device and the funds safely in a GuardBlock vault, and let us know your Recovery Information, to have the basics covered.

If you want to have an option for recovering your funds sooner, or without GuardBlock's help, then having a backup of your hardware device's private key in the form of a seed phrase or on another hardware device might be something for you to include in your setup.

One thing to keep in mind is that having a physical copy of your seed phrase out there in the world is useful for self-recovery, but ultimately a security risk. A malicious actor that gets access to your seed phrase could potentially access your bitcoin. GuardBlock lets you minimise or even completely abstain from creating these backups.

What exactly is a hardware device backup?

A backup of your hardware device will be slightly different depending on the device you use. In most cases, it consists of a seed phrase of 12-24 words (and optionally an additional passphrase) which can be used to recover your private key which was generated by, and stored inside, your hardware device.

Some devices, such as the BitBox 02, get you to save the backup to an SD card for storage, rather than instructing you to write down the words yourself.

With this backup, if you lose your hardware device, you can get a new one and then use the backed up seed phrase to restore your private key to the new device. It does not necessarily need to be the exact same device, but we recommend sticking to devices that are compatible with GuardBlock, and always do your research to confirm compatibility.

There are many guides and suggestions out there regarding how best to store this backup. The simplest is handwritten on paper, placed in an envelope. More advanced users may opt to engrave it into steel to make it fire resistant. You can make multiple copies and store them separately, however each additional copy you make is another thing to keep track of - usually, fewer backups stored safely is better than many backups stored averagely. Do your own research to work out the best setup for you.

You should not enter the seed phrase into, or store it on, an internet connected device.

Ultimately, you need to find the right balance for your circumstances; considering your threat vectors, how many safe and trusted locations you have access to, and the amount of bitcoin stored. You do not want to make things too complicated that you end up getting confused yourself.

What about multiple hardware devices?

Having a 2nd hardware device is handy, so that you can restore your backup to it in case you lose your primary device but want to be back up and running quickly. However, it is entirely optional; GuardBlock is fully useable with a single hardware device.

In fact, many bitcoiners will get a 2nd device and restore their backup to it straight away, resulting in having 2 devices with the same private key. This is superior backup to a simple seed phrase, because it is also protected by a pin and the secure element of the device, and thus gives you options in regards to where it is stored. For example, you may not be comfortable leaving a plain-text backup of your seed with your friend or family member, but you might be OK with leaving them a hardware device protected with a pin (and not sharing the pin with them).


What about my GuardBlock Vault Descriptor?

Having a backup of your GuardBlock Vault Descriptor is essential for you to move your funds out of GuardBlock without us being involved.

It is not required for the final timelocked Recovery pathway where we help you to move your bitcoin to a new recovery vault.

The Vault Descriptor is important, but if an unauthorised person accesses it, they cannot touch your bitcoin. However, they can get sensitive information about your Vault setup with GuardBlock from it, so it is a privacy risk and should still be kept safe.

Some users may opt to have a copy of their Vault Descriptor saved in their secure password manager app, plus a physical printed copy, plus a copy on an SD card or USB drive that is kept with your hardware device.


What else should I include with my backup?

Optionally, you can consider including information about your setup to help jog your memory of how your setup works, and to also help inform your inheritors if you die. However, this is a careful balance - you don't want to include so much information that an attacker can piece together your precise setup and potentially gain access if they found all of your backups. These instructions may include how to contact GuardBlock for assistance with recovery.

You can reduce your risk by splitting your backup and accompanying information into different locations, or you could look at encrypting the information contained in the backup and giving the decryption password to your inheritors.

Balance is key; not too simple that an attacker can find it and understand it, and not too difficult that you or your heirs lose track and cannot find & use the information.


What else should I consider backing up separately?

You may want to have a separate backup with other information involved with your specific setup. For example, some users may opt to have a simple note of their device pin stored somewhere, just in case they forget it. Note that you should never store a backup of your pin code along with the device itself.

Put it in a completely separate physical location, ideally offsite, so that even if an unauthorised person found it they may not know what it is for. This also means that if someone found your hardware device, they will not know the pin, and since your pin backup is stored elsewhere, they should not be able to access the device.


Where and how should I store my backups?

As stated earlier, your exact setup will depend on what device you're using, what safe places you have access to, how much bitcoin you have stored, and your overall risk profile and tolerance.


A basic setup using backups could be:

  • Paper copy of your seed phrase (or SD card if your device uses that method) stored in a safe place in your house
  • An SD card or USB stick containing your GuardBlock Vault Descriptor, plus a printed copy, stored in a safe place in your house

A more robust setup might be:

  • Paper or steel engraved copy of your seed phrase (or SD card) stored in a safe place in your house.
  • A 2nd paper or steel engraved copy of your seed phrase stored in a 2nd location, ideally off-site at a trusted family member's house, or a safe deposit box. Alternatively, this could be a 2nd hardware device which you have restored your primary devices private key onto, before storing off-site, which is more secure since it is protected by a pin.
  • A copy of your GuardBlock Vault Descriptor stored with both backups.
  • A separate document with instructions for an inheritor to follow if you die, stored with your will or other important documents of a similar type.

A minimalist setup that is only enabled by using a GuardBlock vault is:

  • Your primary hardware device kept securely in your house
  • A copy of your Vault Descriptor stored securely in your house
  • Abstaining from further backups and relying on GuardBlock's Recovery feature if you lose your device.

You can then tailor your set-up with previously discussed options, such as:

  • Encrypt the USB drive or SD card with your vault descriptor and any other instructions for you or inheritors to be aware of (note if you encrypt it you then need to ensure you know the decryption password)
  • Store a backup of your device pincode elsewhere - not with the device itself

If one of your primary risk concerns is an attacker getting physical access to your seed phrase and Vault Descriptor and knowing what they are, then consider adding another layer of complexity, such as separating the locations of your seed phrase and Vault Descriptor, or placing them in a locked safe, adding encryption, etc.

However, as mentioned, be sure to understand and revise what your setup is and don't make it too complicated so that you don't lose track. You could save a secure note in your password manager with hints to remind you of your setup in case you forget.