CatBitcoin
Five paper cards in a row on a shelf, each stamped with a number, lit by daylight from a side window.

Custody mechanics

Seedless recovery versus the wallet that holds the box

Updated 6 October 2026

That is seedless recovery. It is not a box that opens without a key.

What vendors actually mean by seedless

Two schemes carry the label in 2026. The first, popularised by a 2024 BIP-93 draft and shipped by Trezor in February 2026 as "SLIP-39 over QR", splits a seed into N shares across a user's own paper or steel cards. The wallet itself never holds a single key, so the box stays closed without the user, and a thief holding the device alone sees nothing. The second, pushed by a Coinbase pilot in June 2026, lets a third party escrow a key share. The vendor can reconstruct on the user's behalf, and the user is asked to trust the vendor, the vendor's cloud, and the vendor's staff.

A laptop on a kitchen counter with a blurred login screen, the keyboard reflecting a window in a quiet room.

Why the box metaphor still holds

Every address type on the site treats the address as the lock, the key as the opener, and the seed as the only factory key. A seedless flow that asks the user to type a seed, photograph a seed, or paste a seed into a web field is, by the site's own definitions, a request to unlock a box the user thinks is still closed. Watch-only is described elsewhere on the site as a window, not an opening, and the same rule applies in reverse: a field that accepts a seed is an opening, even if the page labels it "recovery".

The BIP-360 specification, covered on this page, assumes the seed remains a single object. Splitting the seed does not change Bitcoin; it changes the human process around it.

What SLIP-39 actually gives you

Trezor's 3-of-5 SLIP-39 default, released on 12 February 2026, lets a user keep three cards at home, one in a bank deposit box, and one with a relative, and reconstruct from any three. It is a Shamir secret share scheme, and it has the same failure mode as a single seed: lose two cards and the box stays closed forever. The wallet device sees a partial share on connection and does the recombination in memory; nothing is written to disk.

The benefit is theft resistance, not loss resistance. A house fire that takes one card and a thief that takes another are two different disasters, and a 3-of-5 threshold means the user survives both as long as the third card is somewhere else. The cost is operational: five cards, five backups, five places to lose.

What the vendor escrow model sells

Coinbase's "Recovery Key" pilot, announced 4 June 2026, stores one key share inside the exchange's HSM and requires the user to pass identity checks before reconstruction. The marketing line is "no seed to lose". The custody line is "another party holds the box".

For a small cohort this is a real improvement. For a site that teaches people to ask "who holds the box?" the answer is now: a regulated custodian, on its own terms, with its own outage schedule, its own subpoena policy, and its own bankruptcy estate. The earlier page on exchange custody covers the same territory for hot wallets; the seedless variant just moves the lock.

Where the warning still bites

Most seedless phishing in late 2026 is dressed as a recovery flow. A fake firmware update, a fake support chat, or a fake "verify your wallet" page will ask the user to type twelve or twenty-four words, and the page will claim it is the new path. The box, the lock, and the key are unchanged. A field that accepts a seed is, by definition, an opening. The vendor cannot know whether you typed words that came from your own card, a screen capture, or a clipboard, and the wallet cannot tell either.

The hard line is also unchanged. Never paste a seed into a watch-only field. Never paste a seed into a recovery field. The box, the lock, and the key are not the page, the flow, or the brand.

What to do this week

Quick answers

Does seedless recovery mean there is no seed?
No. The seed still exists; it is split into shares. The user or a third party holds the shares, and the wallet recombines them when needed.
Is a vendor-held share safer than a single seed?
It is safer against physical loss and worse against vendor failure. The box is now in someone else's hands, and the rules on this site about exchange custody apply in full.
Can a watch-only wallet accept a seed for recovery?
No. A field that accepts a seed is an opening, not a window, regardless of what the page calls itself. Never paste a seed into a watch-only field.