A user downloads a non-custodial wallet, creates an account, and receives a sequence of twelve or twenty-four random words. These words—the recovery phrase—represent the most critical security asset they will ever handle. Yet many users treat the setup process as a perfunctory step between installation and immediate use. They screenshot the phrase, store it in a note-taking app, or write it down carelessly on paper that gets lost in a drawer. Months or years later, when the device fails, the wallet is uninstalled, or the password is forgotten, they discover that the recovery phrase was the only path to their funds. By then, it is often too late.
Guarda Wallet’s non-custodial architecture means the wallet application itself never holds private keys on its servers. Instead, your device generates and stores the keys locally, protected by encryption and authentication. That design is a genuine security advantage—no third party can freeze accounts or steal keys from a centralized database. However, it transfers responsibility entirely to the user. If you lose the recovery phrase and forget the password, your cryptocurrency is permanently inaccessible. This guide covers the exact process of generating, verifying, and storing recovery phrases in Guarda, along with the mistakes that lead most users to permanent fund loss.
Understanding what a recovery phrase actually is
A recovery phrase, also called a seed phrase or mnemonic, is a human-readable representation of the mathematical seed that generates all private keys in a self-custody wallet. In Guarda’s implementation, when you create a new wallet, the application generates a 12-word or 24-word phrase using a cryptographically secure random number generator. These words are not arbitrary; they come from a standardized dictionary defined by BIP39 (Bitcoin Improvement Proposal 39), an industry standard that ensures compatibility across different wallet applications.
The critical property is that the recovery phrase is deterministic. Given the same phrase, the same password (if one is set during import), and the same derivation path, any wallet software following the BIP39 standard will generate identical private keys and therefore identical addresses. This means you are not locked into Guarda forever. If you lose access to Guarda or prefer a different application, you can import the recovery phrase into another compatible wallet—Electrum, MetaMask, hardware wallets, or dozens of other applications—and regain access to the same assets.
However, the phrase also represents total access to every address and every cryptocurrency held in that wallet. Anyone with the recovery phrase and knowledge of any password you set can recreate the wallet and transfer all funds. Unlike a bank account protected by legal recourse, regulatory oversight, and anti-fraud protections, a stolen recovery phrase has no recovery mechanism. The attacker becomes the rightful owner in the eyes of the blockchain. That asymmetry is why the setup process must treat the recovery phrase as equivalent to the keys to a safe containing all your cryptocurrency.
Guarda generates the phrase on your device during wallet creation. The application displays it once on screen, often with warnings to back it up immediately. Many users read the words quickly, assume they have « saved » them by glancing, and move forward. In reality, memorization is not a viable backup strategy for a 12-word sequence, let alone a 24-word one. The phrase must be recorded in a durable, retrievable format and protected from theft, damage, and loss.
The wallet setup process in Guarda
The initial setup flow in Guarda varies slightly across platforms—web, desktop, mobile—but follows a consistent security model. When you first open the application and select « Create New Wallet » or equivalent, Guarda generates a recovery phrase and displays it on screen. This is the only moment the phrase appears unencrypted in the application interface. At this point, you have a critical decision to make: back up the phrase before proceeding, or risk losing access to any funds you later deposit.
The responsible approach is to stop immediately after seeing the phrase and complete the backup before creating addresses or receiving cryptocurrency. Open a new browser tab or window, retrieve your backup medium (paper, hardware security key, encrypted storage, or another method discussed below), and record the exact words in the exact order. Do not attempt to split the phrase across multiple locations, rearrange words, or apply any personal mnemonic system. The standard form is the only form that will work when importing into another wallet.
After backing up, Guarda will typically prompt you to verify the phrase by selecting the words in order from a randomized display. This verification step is crucial. It forces you to confirm that your backup is legible and correctly recorded rather than discovering weeks later that you missed a word or wrote it illegibly. Complete the verification without looking back at your backup if possible; if you must reference the backup, treat that as a signal that the backup is not durable or clear enough.
Once verified, the application encrypts the recovery phrase using your device’s encryption and secures it behind a password and biometric authentication (on mobile) if you enable those protections. From that point forward, you do not see the recovery phrase again unless you explicitly request to view it in a secured settings menu. The encrypted local storage is convenient for recovery if you forget a password, but it does not replace your physical backup. If the device is destroyed, stolen, or the local encryption is compromised, only the external backup can restore the wallet.
Common mistakes that lead to permanent fund loss
The most frequent error is storing the recovery phrase in a location that feels secure to the user but is neither durable nor secret. Screenshots stored on cloud services (iCloud, Google Drive, Dropbox, Microsoft OneDrive) are particularly dangerous. These are convenient because they sync automatically across devices, but they also create multiple copies on company servers, in backups, and potentially in forensic artifacts if a device is seized or stolen. A malicious actor with access to your cloud account—through phishing, credential reuse, or account compromise—can download the screenshots and drain the wallet within minutes.
Similarly, storing the phrase in password managers, note-taking apps, or email drafts creates a digital copy that persists in application databases, cached data, sync logs, and possibly third-party servers. Even if the password manager is encrypted locally, the act of typing or pasting the phrase into it often creates intermediate copies: in device RAM, in clipboard history, in search indexes, or in temporary files. The more digital the storage, the more copies exist and the more potential attack surfaces emerge.
Writing the phrase on a piece of paper and leaving it on a desk, storing it in a kitchen drawer, or keeping it in a wallet alongside your driver’s license are physical failures of a different kind. Paper is subject to water damage, fire, and theft. A wallet or drawer is often the first place someone searches if they know you hold cryptocurrency. The phrase must be stored in a location that is both physically secure and not immediately obvious to a casual observer or someone with brief access to your home.
Another critical mistake is the « just-in-case » partial backup. Some users record only the first six words of a 12-word phrase, thinking that will be enough to remember or reconstruct the rest. This is false. The words have no inherent meaning or sequence; they cannot be reconstructed from partial information. An incomplete phrase is useless and will create frustration and false confidence if the user later tries to import it into another wallet and discovers it does not work.
Users also sometimes apply personal modifications to the phrase: capitalizing certain words, adding numbers, inserting symbols, or grouping words differently than they appear on screen. These alterations destroy compatibility with the BIP39 standard. When you later attempt to import the phrase into another wallet, the application will reject it because the words do not match the standard dictionary. The modification felt like an added security step but actually guaranteed that the backup cannot be used.
Physical backup methods: durability, security, and testability
The most accessible durable backup is laminated paper stored in a secure physical location. Write or print the recovery phrase on paper (print is more legible and weather-resistant than handwriting), laminate it to prevent water damage, and store it in a locked drawer, safe, or secure deposit box. The lamination step matters because paper alone is vulnerable to humidity, spills, and gradual fading. Lamination is inexpensive and widely available. A locked safe, preferably bolted to the floor or wall, costs more but adds resistance to casual theft. A bank safe deposit box is even more secure but introduces the minor inconvenience of traveling to the bank if you need to access the recovery phrase.
For higher-value holdings, steel or titanium plate backups offer superior durability. Products such as CryptoSteel, Billfodl, or similar devices use a combination of metal tiles or characters to record the phrase in a form that survives fire, water, and physical damage far better than paper. These tools typically cost $50 to $200 but are worth the expense if you hold cryptocurrency worth more than a few thousand dollars. The trade-off is that the backup process is more tedious—you punch or arrange small metal characters instead of writing words—but the result is nearly indestructible and remains secure against casual observation.
Regardless of the physical medium, the backup must be tested without exposing the secret. The best test is to verify that your written words are legible and in the correct order, then store them away and do not reference them again unless you actually need to import the recovery phrase into another wallet. Testing on a secondary device—installing Guarda on a laptop, phone, or tablet you do not use daily, and importing the recovery phrase to verify it works—is the gold standard. This confirms that every word was recorded correctly and in the correct order before the backup is archived. If the import fails, you know immediately and can create a corrected backup rather than discovering the error years later when you desperately need to restore access.
The one method to avoid is trusting memory or expecting to reconstruct the phrase from hints. The human brain cannot reliably store a 12-word random sequence with perfect accuracy, especially over months or years. Even if you think you will remember because you saw it once and it seemed distinctive, this confidence is false. Backup for recovery, not for memory.
Securing Guarda itself after backup is complete
Once the recovery phrase is backed up and verified, the second layer of security is protecting the wallet application on your device. Guarda prompts you to set a password during or immediately after wallet creation. This password encrypts your private keys at rest on the device, ensuring that if someone physically steals your phone or computer, they cannot simply open the wallet application and drain your funds without the password.
The password should be unique, random, and long enough to resist guessing. A password of at least 12 characters, combining uppercase, lowercase, numbers, and symbols, raises the barrier to brute-force attack significantly. Avoid passwords based on your birthday, pet names, familiar phrases, or keyboard patterns. If you are concerned about forgetting a strong password, use a password manager—Bitwarden, 1Password, KeePass, or similar—to store it in an encrypted database on your device, protected by a master password or passphrase that you do remember.
On mobile devices, enable biometric authentication (Face ID, Touch ID, or fingerprint) if Guarda offers it. Biometrics are convenient and provide a meaningful security barrier against casual access by family members or someone who briefly steals the phone. Biometrics do not protect against a sophisticated attacker who can extract data from the device or someone who forces you under duress to unlock the device, but they do eliminate the attack surface of a password typed at a coffee shop or glimpsed over your shoulder.
On desktop (Windows, macOS, or Linux), the device-level encryption built into modern operating systems—BitLocker on Windows, FileVault on macOS, LUKS on Linux—provides a baseline of protection. Enable full-disk encryption if your operating system offers it, especially if the device is a laptop that leaves your home. This ensures that even if the device is stolen, the attacker cannot extract the Guarda wallet files and private keys without the device password.
The role of external backups and redundancy
For users with significant cryptocurrency holdings, a single backup of the recovery phrase creates concentration risk. If the backup location burns down, floods, or is burglarized, access to the funds is lost permanently. A common approach is to maintain two physical backups in geographically separate locations. For example, one laminated copy in a home safe and a second in a bank safe deposit box, or one at home and another with a trusted family member or friend in a different city.
If you store a backup with someone else, the security relationship must be explicit and trustworthy. Do not leave a recovery phrase with someone who does not know what it is or does not understand the responsibility. The ideal scenario is a spouse, adult child, or close family member who would only access the phrase if you become incapacitated or deceased, and who understands that the phrase must be treated as equivalent to a house key. Written instructions should accompany the backup, explaining what it is and how to use it in case of emergency.
Splitting the recovery phrase across multiple locations—for instance, storing the first six words in one place and the second six words in another—is tempting but introduces a different risk. If one location is compromised, the attacker now has half the phrase and can attempt to brute-force the remaining half. With modern computing, this is faster than it should be comfortable. A full, unmodified phrase in one secure location is more defensible than a split phrase that creates new attack surfaces.
Digital backups encrypted with a strong password and stored in geographically redundant cloud locations are possible but less straightforward. If you store an encrypted backup (using VeraCrypt, 7-Zip with AES-256, or similar), you create a new dependency: the password to decrypt the backup. If you forget that password, the encrypted file is useless. Document the decryption method and password in a separate secure location, and test the process periodically to ensure it works.
Verifying Guarda before entering your recovery phrase
If you are importing an existing recovery phrase into Guarda—because you previously used another wallet or you are restoring a wallet after reinstalling the application—verify that you are using a legitimate version of the software. Download Guarda only from official sources: the official website for desktop applications, the Apple App Store or Google Play Store for mobile, or the official Chrome Web Store for the browser extension. Avoid third-party app stores, direct APK downloads, or executable files from unofficial links. A counterfeit version of Guarda that looks identical to the real application but steals your recovery phrase the moment you enter it would be trivial to create and distribute.
On desktop, check the digital signature or code-signing certificate if Guarda provides one. On mobile, verify the publisher name and look for the official checkmark or verified badge. For the browser extension, confirm that it is published by the official Guarda account, and review the permissions it requests—a legitimate wallet should not request access to your browser history, passwords, or other sensitive data unrelated to blockchain interaction.
You can obtain the current download links from the Guarda Wallet download page, which maintains official distribution points. Before importing the recovery phrase, create a new test wallet in Guarda to verify that the application’s basic functionality works and that you are comfortable with its interface. Familiarize yourself with where private keys are stored (locally on your device, not on Guarda’s servers), how the password encryption works, and how to access settings to view or adjust security options.
Ongoing security maintenance and review
After the initial setup, the wallet is not a « set and forget » tool. Periodic review of your security posture is appropriate, especially if circumstances change. If you move to a new home, your safe or storage location may be less secure; evaluate whether a bank safe deposit box or new physical location is warranted. If you acquire significantly more cryptocurrency, revisit the decision about backup redundancy and whether a hardware wallet or additional security measures are justified.
Guarda periodically updates its application with security patches and new features. Ensure you are running the latest version by checking the application’s settings or your device’s app store. A delayed update leaves you vulnerable to known issues that may affect private key management or authentication. Updates are also when you should verify that the publisher and code signatures are still correct; legitimate updates should come from the same official source as your original installation.
If you believe your recovery phrase has been compromised—you accidentally revealed it to someone, shared it in a phishing attempt, or suspect it was seen by an observer—you must act immediately. Create a new Guarda wallet with a fresh recovery phrase, transfer all funds from the old wallet to addresses in the new wallet, and store the new recovery phrase with the same security as the original. The old recovery phrase is now publicly known and anyone could access it, so the old wallet is compromised even if the theft has not yet occurred. Speed matters because the attacker may be monitoring the wallet and transferring funds out as soon as you leave.
Document your backup location and recovery procedure somewhere accessible to a trusted person or executor of your will. If you pass away without leaving instructions, your heirs may not know that cryptocurrency management is possible or that the recovery phrase is the key to accessing significant assets. A simple letter explaining the existence of the wallet, where the recovery phrase is stored, and basic instructions for accessing it can prevent permanent loss of funds and family confusion or conflict.
Frequently asked questions
If I lose my recovery phrase but remember my Guarda password, can I access my funds?
Not through another device or if your current device fails. The password encrypts your private keys locally on your device, but only the recovery phrase allows you to restore access on a different device. If the device is lost or the local encryption fails, the password alone is insufficient. You must have the recovery phrase backed up in an external location.
Is it safe to write my recovery phrase by hand, or should I print it?
Handwriting is acceptable but less reliable than printing. Handwriting can be illegible, fade over time, or become difficult to read later. If you handwrite, use permanent ink and verify legibility immediately. Printing followed by lamination is more durable and resistant to water damage. Use a printer that will be discarded or thoroughly cleaned afterward to avoid copies remaining in its memory.
Can I share my recovery phrase with a family member for safekeeping?
Yes, but only with someone you trust completely and who understands the responsibility. The person holding the phrase can access all funds in the wallet, so they must be aware of that power and committed to protecting it. Written instructions should explain what the phrase is and how to use it in case of emergency. Do not share the phrase with multiple people or divide it among multiple people; each copy increases the risk of compromise.