The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Paper Wallet with a Single Key: The Printed Storage Method Compared with the Seed Phrase

A paper wallet carries a single private key on paper, and that is exactly where its weaknesses lie: printers, change, misread characters. What the storage method achieves, where it fails and how to wind up an old sheet safely.

Yellowed sheet of paper folded several times with a grid of black squares, torn at the edges and marked by water stains
13 min read
Share:

A paper wallet is a sheet of paper with a single private key and the matching bitcoin address printed on it. For a few years that counted as the safest way to store coins, because the key touched no device and no network. Today developers and wallet makers advise against this form of storage, and not because of the idea behind it but because of the many points at which it goes wrong in practice. The Bitcoin Wiki lists it as an obsolete and insecure method that was widespread between 2011 and 2016.

This article explains what is actually written on such a sheet, which six weak points the storage method has, and how to wind up an existing paper wallet today without losing coins along the way. Where your key is best kept, if not on paper, is covered in the second half.

What a paper wallet is: a printed key pair with no wallet functions

The name is misleading. A wallet in the usual sense is a program that manages keys, knows the balance and builds transfers. A paper wallet can do none of that. It carries two strings of characters: the address someone can send bitcoin to, and the private key with which those coins can be spent again. Usually both also appear on the sheet as a QR code, so that they do not have to be typed out.

A private key is simply a very large random number. Anyone who knows it can dispose of the coins at the matching address, with no password, no account and no further question asked. That is precisely why everything about this form of storage comes down to how the key came into being and who set eyes on it along the way.

The difference from a seed phrase

A seed phrase is a sequence of twelve or twenty-four words from which a wallet derives as many keys as it needs, rather than just a single one. The standard behind it is called BIP-39, the derivation itself BIP-32. You copy the words down by hand, no printer is involved, and the wallet generates a fresh address for every incoming payment. That difference sounds technical, but it explains almost all the problems below.

In those years there were no widely available hardware devices and no established word list. Anyone wanting to put coins away for the long term had the choice between a program file on a computer that was attached to the network and a printout that went into the safe. The printout looked like the lesser evil, and websites that generated such key pairs in the browser made it convenient.

On top of that came the physical variant: metal coins with a private key stuck under a hologram. It was for exactly this purpose that BIP-38 was created in 2012, a standard that encrypts a private key with a passphrase so that a printed sheet is not immediately loot if somebody finds it. That the same standard today carries, in its official comment line, the note that implementing it is unanimously discouraged says a great deal about the road the industry has travelled since.

Opened office printer with the paper tray pulled out and a sheet half drawn in, backlit
Every printout sends the private key through a device that can store it: the reason why word lists are written out by hand.

The printer as a weak point: spooled jobs, the network and shared devices

To get a key pair onto paper, it has to go through a printer. Many office machines have a built-in hard drive and file every print job there. Anyone who later reads out that device finds the key in plain text. Machines in offices, schools or copy shops log jobs centrally as well, and with a wireless connection the job travels unencrypted through the air if the network is poorly secured.

This gap cannot be configured away, it belongs to the method. A seed phrase avoids it entirely, because the words appear on the device that generated them and travel from there onto paper or metal by hand. What such a record should look like is set out in our guide to storing a seed phrase safely.

One key, one address: address reuse and the trail in the blockchain

A paper wallet has exactly one address. Anyone using it more than once collects every payment in one place, and because every transfer stands publicly in the blockchain, any observer can read off the entire holding and the whole payment history at that address. With a modern wallet every incoming payment gets a new address, and the connection between the payments is considerably harder for outsiders to establish.

There is also a practical point that is often overlooked: the sheet itself does not know whether any money has arrived at all. To see the balance you have to look the address up with a blockchain explorer, that is, with an outside service that can remember who took an interest in which address.

The change problem: after a partial payment the remainder sits on a change address

This is where owners most often lose money. A bitcoin transfer always spends the entire amount sitting at an address and sends the part that is not needed back to a new address as change. This change address belongs to the software that built the transfer, not to the paper.

So anyone who imports the key into a wallet, sends a partial amount and then believes the remainder is still sitting on the sheet is mistaken. The remainder sits in the software. If that software is lost and the paper was kept as a supposed backup, the change is no longer reachable.

Importing and sweeping are two different things

When importing, a wallet takes on the foreign key and manages it alongside its own. The key remains a one-off, though, and is not covered by that wallet's seed phrase. Anyone who destroys the paper afterwards and later restores the wallet from its words no longer has the imported key. When sweeping, by contrast, the wallet transfers the entire amount from the old key to an address of its own that belongs to the seed phrase. After that the paper is worthless, and that is precisely the aim.

Misread characters, water damage and QR codes: weak error correction on paper

A private key is usually printed in small type. A capital B and an eight, a one and a lower-case L look almost the same in many typefaces, and a single character read wrongly makes the key useless. The format does contain a checksum that reports the error, but no tool for lay users that corrects it.

QR codes are not built for that either. The patterns tolerate a little dirt, but water, heavy creasing and folding make them unreadable. A word list is far more forgiving at this point: words remain legible even in poor handwriting, and the list is chosen so that the first four letters identify a word unambiguously.

A third point concerns the formats themselves. Whether a wallet understands an old key depends on the notation it was printed in. There have been cases in which coins were initially stuck after a format change. How differently manufacturers handle standards is shown in our article on restoring a seed phrase with a different manufacturer.

Hand holding a small metal device with a dark display above a desktop, next to a metal plate with punched rows of dots
Device plus word list on metal: the job of the printed sheet is split across two parts, both of which are replaceable.

BIP-38 and passphrase encryption: a standard its own developers advise against

BIP-38 was the attempt to fix the paper's biggest weakness. The private key is encrypted with a passphrase and printed as a string of 58 characters, protected by a procedure that makes brute-force attacks expensive. Anyone finding the sheet can do nothing with it without the passphrase.

The price for that is a second secret that can be lost just as easily as the first, and a dependency on software that still handles the format. The BIP-38 specification states in the header of its comments that implementing it is unanimously discouraged. A technical community can hardly bury a procedure of its own making more clearly than that.

Sweep instead of import: winding up an existing paper wallet safely

If there is still a printed sheet in your drawer, the cleanest route is to move the entire amount into a modern wallet and to treat the paper afterwards as done with. For that you need a wallet that can sweep, and a little calm.

  1. Set the destination wallet up completely and back up its seed phrase before you even pick up the old key. Which programs are candidates for that is set out in our comparison of software wallets.
  2. Look at the holding of the old address in a blockchain explorer, so that you know which amount has to arrive.
  3. In the new wallet, expressly choose the function for sweeping, not the one for importing, and enter the private key from the sheet.
  4. Wait for the transfer to be confirmed and make sure the old address is empty afterwards and the amount, less the network fee, is in the new wallet.
  5. Destroy the sheet only once that reconciliation adds up. As long as something is still sitting at the old address, the paper is the only way in.

What matters is the place where you enter the key. Never type it on someone else's computer, and never on a website that offers to build the transfer for you. From the moment of entry the key is known on that device, which is why the address counts as permanently burned afterwards.

Seed phrase and hardware wallet: today's alternatives to paper storage

The job the paper was meant to do is handled today by two building blocks. A hardware device generates and keeps the keys without ever releasing them, and signs transfers on the device itself. The seed phrase serves as the backup should the device break, be lost or be replaced. The two together keep the key away from every printer and every browser.

The difference between a permanently connected wallet on a phone and separated storage remains in place, and for the choice it matters more than the brand of the device. How the two forms differ is something we took apart in our article on hot wallets and cold wallets. Which devices are available in Europe and what they cost is shown by our hardware wallet comparison.

Tax and proof in Germany: what applies when winding up an old paper wallet

A sweep is not a sale. You are transferring coins between two addresses that both belong to you, and no change of ownership takes place. For the holding period under section 23 of the Income Tax Act, what therefore still counts is the day on which you originally acquired the coins, not the day of the transfer. Tax only arises on a sale within a year of acquisition, and gains remain tax-free if the total gain from all private disposal transactions in a calendar year stays below 1,000 euros.

Harder than the legal position, with old holdings, is the proof. Anyone who printed a sheet in 2014 rarely still has the purchase receipts. So collect everything that supports the acquisition date: the time of the first payment to the address from the explorer, old bank statements, confirmation emails from the exchange of the day. Tools that document such holdings on a lasting basis are set out in our comparison of crypto tax tools and portfolio trackers. This section is no substitute for tax advice, and with old holdings carrying large gains a trip to a specialist is worth the money.

When a printed sheet still turns up anyway

The form has not vanished entirely. Some cryptocurrency cash machines print customers without a wallet of their own a receipt carrying a key, and at trade fairs or as gifts, metal coins with a key under the hologram are still going round. For these cases the same rule applies as above: the receipt is a means of transport, not a store. Anyone who receives one moves the amount promptly into a wallet of their own.

A second case is inheritances and house clearances. If such a sheet turns up, a look in the explorer is worth it before it ends up in the waste paper. The reverse also holds: a sheet whose address is empty has no value, even if it once did.

Paper wallet: How to proceed now

  1. Look at the holding and prepare the destination. See in an explorer whether anything is still sitting at the address, and set the new wallet up beforehand. The candidates are in our comparison of software wallets.
  2. Wind it up with a sweep. Move the entire amount to an address of your new wallet and destroy the paper only after the reconciliation. For larger amounts the key belongs on a separate device, as the hardware wallet comparison shows.
  3. Document the acquisition. Record the date, the number of coins and where they came from, while you can still gather the receipts. The tools for that are in the comparison of crypto tax tools.

(As of October 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Frequently asked questions about paper wallets

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

Related articles

Which topics should we dive deeper into?

Select what genuinely interests you. Your picks feed directly into our editorial planning.

Crypto news that's actually worth your time.

Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.

Subscribe

More on this topic

View All

More from CryptoTicker