Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Anyone who holds crypto assets in self-custody usually buys a device from a company to do it. That company can make mistakes, lose customer data, discontinue a model or one day cease to exist. From that follows an uncomfortably concrete question: does your access to the funds depend on that company?
The answer is not in the vendors' marketing. It is in three technical specifications that have been publicly available for more than ten years. They are called BIP39, BIP32 and BIP44. Anyone who understands what they set down can answer the vendor question without taking an advertising claim on trust. And anyone who knows the limits of those standards also understands why recovery on another manufacturer's hardware still goes wrong on a regular basis.
This article explains both: what the standard guarantees you, and where it leaves you on your own. At the end there is a test you can run on a quiet evening, one that gives you a solid answer instead of an assumption.
Hardware wallet vendor lock-in: what actually depends on the manufacturer
A hardware wallet is a small computer with exactly one job. It generates a random value, keeps it shielded and signs transactions with it without ever revealing it. What depends on the vendor is the firmware, the companion software on your computer and customer support. The key itself depends on the vendor only if the device departs from the open standards.
That distinction is the whole heart of the matter. Firmware, companion software and support are replaceable. A key that exists only in a proprietary format would not be. Which is precisely why it is worth reading the specification before money moves onto a device.
BIP39: how 128 to 256 bits of randomness become twelve to 24 words
BIP39 describes how a random seed value is translated into a memorable sequence of words. The specification stipulates that the initial entropy must be a multiple of 32 bits and lie between 128 and 256 bits. A checksum is formed from that entropy by appending the first ENT/32 bits of its SHA256 hash. The result is split into groups of eleven bits, and each group, as a number between 0 and 2047, points to an entry in a word list of 2048 items. The text of the specification is public and short enough to read in an evening.

That produces the familiar lengths. 128 bits of entropy plus four checksum bits give twelve words; 256 bits plus eight checksum bits give 24 words. In between sit the rarer variants of 15, 18 and 21 words. A 24-word sequence therefore uses the same technique as a 12-word sequence, simply with more initial randomness.
The sentence that decides the vendor question comes next. The actual seed value is computed from the word sequence using the PBKDF2 function: the word sequence as the password, the string "mnemonic" plus an optional passphrase as the salt, 2048 iterations, HMAC-SHA512 as the underlying function, 512 bits as the result. That procedure is fully deterministic and contains, at no point, any identifier of the device, the firmware or the vendor. Enter the same words into a different device that implements the same standard and you get the same 512-bit value. That is the guarantee at issue here, and it is mathematical in nature.
The checksum catches typing errors but corrects nothing
The checksum is short, and the specification itself spells out the consequence: roughly one in 256 random errors goes unnoticed, and the procedure offers no correction facility. In practice that means a mis-transcribed word will usually produce an error message, but not always. In the unlucky case the device accepts the input and generates a completely different, empty wallet. Which is exactly why every backup needs a check in which the words are actually read in once.
The word list is part of the procedure
Because the calculation runs from the word sequence itself and not from the original entropy, the same sequence of numbers in a word list of another language produces an entirely different seed value. The specification points this out explicitly and recommends the English list for that reason. Anyone who created a backup using the French or Japanese word list will later need a device that knows precisely that list. With the English list the problem practically never arises, because every serious implementation supports it.
The passphrase is a word that appears in no backup
The optional passphrase enters the calculation as part of the salt. Every passphrase therefore turns the same word sequence into its own, entirely valid wallet. A typing error in the passphrase produces no error message. It produces a different, empty wallet, because the procedure cannot distinguish between "wrong" and "different" at all.
For recovery on another manufacturer's hardware this is one of the most common pitfalls. The new device accepts the word sequence, shows an empty wallet and thereby looks like proof that portability does not in fact work. In reality only one component is missing, one the user set themselves and wrote down nowhere. How to keep a passphrase sensibly without storing it next to the words is something we described on August 8, 2026 in our article on storing a seed phrase safely.
BIP32 and the derivation path: why the same seed yields different addresses
The 512-bit seed value is not yet an address. BIP32 describes how any number of key pairs are derived from it hierarchically, and BIP44 gives that derivation a fixed order with five levels: purpose, coin type, account, change flag and address index. It is written as a chain of numbers separated by slashes, known as the derivation path.
The five levels of a BIP44 path
A typical path reads 44'/0'/0'/0/0 and denotes the first address of the first bitcoin account in the classic address format. The apostrophe marks a hardened level, from which subordinate keys cannot be computed without the seed value. The first number stands for the address format: 44 for the classic form, 49 for the nested SegWit variant, 84 for native SegWit. Change that single number and every address below it changes.
This is the most practically important point in this article. Two devices can process the same seed entirely correctly and still display completely different addresses, because they have different paths preset. The seed is right every time. A balance only becomes visible on the path where it actually sits.
The derivation path is the most common reason for an apparently empty wallet
How far practice departs from the standard is set out with remarkable candour by one manufacturer in its own developer documentation. The Ledger Live documentation on derivation paths states that by no means every wallet adheres to BIP44, that many ask the user directly for a path, and that numerous exceptions have been built in over time to absorb those deviations. For Ethereum the software therefore scans addresses under 44'/60'/0'/x and counts up to ten empty accounts before it ends the search.
The same document contains the sentence on which the practical consequence hangs: anyone stuck on an unusual path who wants to use the software has to move the balance to a conventional path using the original tool. That describes no single vendor's failing. It describes a condition the entire industry works with, because conventions only established themselves after the first implementations.
For you a plain rule follows: the derivation path belongs with the backup. A word sequence with no note of which device and which address format were in use remains recoverable, but in an emergency it costs you search time. Which devices preset which paths, and how openly the respective companion software handles them, can be looked up in our hardware wallet comparison before you settle on a model.
SLIP-0044 gives every chain its own number in the path
The second level of the path is the coin type. Which number belongs to which chain is set out in a public list called SLIP-0044. Bitcoin carries 0 there, Litecoin 2, Dogecoin 3, Ether 60, Bitcoin Cash 145, Solana 501 and the BNB chain 714. The list now runs to several thousand entries and grows with every new chain.
In practice that means two things. Holdings on different chains sit in separate branches derived from the same seed, which is why a device that does not know a chain cannot display its balance either. And some chains have switched coin type over the course of their history, or maintain several numbers in parallel. Anyone missing a balance after changing devices should know this list before assuming a loss.
The gap limit explains why software overlooks a balance that is there
Even within the correct path a trap is waiting. Wallet software scans accounts and addresses in sequence and ends the search as soon as a certain number of consecutive addresses shows no incoming payment. That cut-off is called the gap limit. BIP44 explicitly prescribes this behaviour, because otherwise the search would never end.
The consequence is unpleasant. If an address far down the list was used manually in the past, standard-compliant software can overlook it and display an empty account. The balance remains on the chain and is visible through any block explorer; only the search logic does not reach far enough. The remedy is an application in which the gap limit can be raised or a path entered by hand. Anyone who has been in this position understands why experienced users do not pick their addresses at random from the middle of a list.
Where the standard ends: Shamir shares, multisig and proprietary formats
Not every backup is a BIP39 word sequence, even if it looks like one at first glance. There are three cases you should keep apart, because they restrict portability to different degrees.

The first is the Shamir procedure under SLIP-0039, in which the secret is split into several shares and a minimum number of them suffices for recovery. Such shares look like a word sequence but follow a different procedure and work only on devices that support precisely that procedure. The second case is multisig setups, where several keys sign together: there, in addition to the words, you need the wallet descriptor with all public keys and the rule for how many signatures are required. Without that file the balance cannot be reached with the words alone, and experience shows it goes missing more often than the words themselves. The third case is devices that store the key exclusively in a proprietary format and never hand it out as a readable word sequence.
Before you buy, a single question settles it: does the device output a BIP39 word sequence that can be read into another manufacturer's hardware? If the manual gives only a proprietary term for the backup, with no reference to an open standard, that is reason to look more closely.
What a vendor failure means in practice, and what it does not
This newsroom's own coverage of recent weeks includes several cases in which a provider let its customers down. On July 31, 2026 we reported on a firmware flaw that made generated seeds computable. On August 13, 2026 the subject was a data breach at a service provider that exposed the names and home addresses of a wallet manufacturer's customers. On the custody side at trading venues the question is sharper still, because insolvency law comes on top of the technology there; when custodied coins can be segregated from the estate is something we set out separately on August 18, 2026.
For self-custody a sober balance can be drawn from this. A data breach affects your privacy and raises the risk of targeted fraud attempts by post, phone or email, but it does not touch your key. A manufacturer's insolvency ends firmware maintenance and support, yet leaves a standard-compliant seed untouched; the device becomes a discontinued model, the balance does not. It only becomes serious in the third case, a flaw in the generation of the random value. No standard helps against that. There the only option is moving to a freshly generated seed, and promptly.
The common line that the coins are on the blockchain and not on the device is therefore both correct and incomplete. It holds precisely when the seed was generated cleanly and follows the open standard. Both can be checked, and without specialist knowledge.
The recovery test: how to check today whether your backup holds tomorrow
A backup that has never been read in is an assumption. The following test turns it into a finding. It takes about twenty minutes and costs nothing beyond the network fees on a minimal transfer.
The test with an empty account
First get hold of a second, open-source wallet application on a device you will reset afterwards, and enter your word sequence there along with the passphrase. In that software select the same derivation path your main device uses. Then compare the first receiving address with the address your main device shows in the same position. If both strings match, portability is proven: your balance depends on the word sequence and the path, on no company.
If you want it stricter, send a minimal amount to an address derived exclusively from the backup, and send it back from there. That tests the signature too, not merely the address display. Reset the test device afterwards and remove the software.
Two details go into your notes alongside the words at the end: the full derivation path and the number of words. The passphrase belongs somewhere else, otherwise you defeat its purpose. Anyone already settling what should happen to access in an emergency should add this note straight into their estate documents.
Checking seed recovery: what to take away
- Run the recovery test before you need it. Read your word sequence into a second, independent application once and compare the first receiving address with that of your main device. Which programs are open source and permit custom derivation paths is set out in our software wallet comparison.
- Note the derivation path with the backup. The words alone are technically enough; the path saves you hours in an emergency. When you next buy a device, check that the vendor presets conventional paths and outputs a BIP39 word sequence; the models in our hardware wallet comparison differ markedly on this.
- Separate trading holdings from custody holdings. What you intend to hold long term in self-custody does not belong permanently on a trading account, because none of the standards described here works in your favour there. Which trading venues are regulated and what their withdrawal routes look like is shown in our crypto exchange comparison.
(As of August 19, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
- D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
- Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 16, 2026 4:12 AM

Wallet Drops a Network: How to Rescue Your Coins Before the Deadline
Phantom is ending Sui support on September 24, 2026, and Trust Wallet has already removed 25 networks: five shutdowns of this kind in four weeks alone. What really happens to your balance, which two routes you have before the deadline and where the move most often fails.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
September 26, 2026 7:34 AM

Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 31, 2026 1:22 PM

Cosmostation Wallet Shutdown on September 1: What Cosmos Wallet Users Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: Cosmostation had announced it would discontinue its wallet apps on September 1, 2026, leaving only the export of the recovery phrase and the private key. This article describes the situation before the deadline and how to move Cosmos holdings, including delegated ATOM.
September 19, 2026 1:23 AM

Hardware wallet lost: how to rescue your coins and what the tax office accepts
Your hardware wallet is gone, your coins are still on the blockchain: all that matters is whether you still have your recovery phrase. What goes wrong during a restore, and why the tax office as a rule does not recognise permanently lost access as a loss under Section 23 of the Income Tax Act.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 2, 2026 7:44 AM

MyDoge Ends Doginals and DRC-20 Support: What Holders Should Know After September 17
Recap as of September 27, 2026: infrastructure provider Maestro had announced it would discontinue its Dogecoin services on September 18, 2026, with MyDoge withdrawing support for Doginals and DRC-20 a day earlier. Our own survey of September 2 showed that nothing about the shutdown could be found on the public pages of those involved.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 11, 2026 1:26 PM

Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
Alby confirmed a critical flaw in Alby Hub v1.7.0 through v1.18.5 on September 9, 2026; it is only exploitable if the management interface sits openly on the internet. What to check on your node, why the fix is a good twelve months older than the warning, and which step comes before the update.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
More from CryptoTicker


