
Custody mechanics
Seedless recovery versus the wallet that holds the box
Updated 6 October 2026
That is seedless recovery. It is not a box that opens without a key.
What vendors actually mean by seedless
Two schemes carry the label in 2026. The first, popularised by a 2024 BIP-93 draft and shipped by Trezor in February 2026 as "SLIP-39 over QR", splits a seed into N shares across a user's own paper or steel cards. The wallet itself never holds a single key, so the box stays closed without the user, and a thief holding the device alone sees nothing. The second, pushed by a Coinbase pilot in June 2026, lets a third party escrow a key share. The vendor can reconstruct on the user's behalf, and the user is asked to trust the vendor, the vendor's cloud, and the vendor's staff.

Why the box metaphor still holds
Every address type on the site treats the address as the lock, the key as the opener, and the seed as the only factory key. A seedless flow that asks the user to type a seed, photograph a seed, or paste a seed into a web field is, by the site's own definitions, a request to unlock a box the user thinks is still closed. Watch-only is described elsewhere on the site as a window, not an opening, and the same rule applies in reverse: a field that accepts a seed is an opening, even if the page labels it "recovery".
The BIP-360 specification, covered on this page, assumes the seed remains a single object. Splitting the seed does not change Bitcoin; it changes the human process around it.
What SLIP-39 actually gives you
Trezor's 3-of-5 SLIP-39 default, released on 12 February 2026, lets a user keep three cards at home, one in a bank deposit box, and one with a relative, and reconstruct from any three. It is a Shamir secret share scheme, and it has the same failure mode as a single seed: lose two cards and the box stays closed forever. The wallet device sees a partial share on connection and does the recombination in memory; nothing is written to disk.
The benefit is theft resistance, not loss resistance. A house fire that takes one card and a thief that takes another are two different disasters, and a 3-of-5 threshold means the user survives both as long as the third card is somewhere else. The cost is operational: five cards, five backups, five places to lose.
What the vendor escrow model sells
Coinbase's "Recovery Key" pilot, announced 4 June 2026, stores one key share inside the exchange's HSM and requires the user to pass identity checks before reconstruction. The marketing line is "no seed to lose". The custody line is "another party holds the box".
For a small cohort this is a real improvement. For a site that teaches people to ask "who holds the box?" the answer is now: a regulated custodian, on its own terms, with its own outage schedule, its own subpoena policy, and its own bankruptcy estate. The earlier page on exchange custody covers the same territory for hot wallets; the seedless variant just moves the lock.
Where the warning still bites
Most seedless phishing in late 2026 is dressed as a recovery flow. A fake firmware update, a fake support chat, or a fake "verify your wallet" page will ask the user to type twelve or twenty-four words, and the page will claim it is the new path. The box, the lock, and the key are unchanged. A field that accepts a seed is, by definition, an opening. The vendor cannot know whether you typed words that came from your own card, a screen capture, or a clipboard, and the wallet cannot tell either.
The hard line is also unchanged. Never paste a seed into a watch-only field. Never paste a seed into a recovery field. The box, the lock, and the key are not the page, the flow, or the brand.
What to do this week
Quick answers
- Does seedless recovery mean there is no seed?
- No. The seed still exists; it is split into shares. The user or a third party holds the shares, and the wallet recombines them when needed.
- Is a vendor-held share safer than a single seed?
- It is safer against physical loss and worse against vendor failure. The box is now in someone else's hands, and the rules on this site about exchange custody apply in full.
- Can a watch-only wallet accept a seed for recovery?
- No. A field that accepts a seed is an opening, not a window, regardless of what the page calls itself. Never paste a seed into a watch-only field.