Bitcoin seed phrases are the single key to your entire wallet. Twelve or twenty-four words, written in the right order, give anyone who holds them unconditional access to every coin you own. That makes storing them correctly one of the most consequential decisions a Bitcoin holder faces. And yet, a surprisingly common mistake is saving those words to a cloud service like Google Drive, iCloud, Dropbox, or a notes app that syncs online. It feels safe. It's genuinely not.
Why cloud storage is the wrong place for a seed phrase
The appeal is obvious. Cloud storage is encrypted, backed up, accessible from any device, and you're unlikely to lose it in a house fire. For most files, it's an excellent choice. A seed phrase isn't most files.
Cloud accounts are protected by a username and password, and usually a phone number for recovery. All three of those can be compromised without anyone ever touching your device. Phishing attacks steal credentials daily. Data breaches at major providers have exposed account details for hundreds of millions of users. And if an attacker pairs a leaked password with a SIM swap attack on your Bitcoin account, they can bypass two-factor authentication and read every file in your cloud storage inside minutes.
Your seed phrase, once exposed, is not recoverable. You can change a password. You can get a new phone number. You cannot change a seed phrase without moving your entire Bitcoin balance to a new wallet first, and if the attacker moves faster than you do, the balance is gone.
The specific attack vectors to understand
Three routes account for most cloud-related seed phrase thefts.
- Credential stuffing. Attackers take username and password combinations leaked in past data breaches and try them against cloud services. If you reused a password, they're in.
- Phishing. A convincing fake login page for Google, Apple, or Dropbox captures your credentials in real time. These pages are often indistinguishable from the real thing.
- Device compromise. Malware on your phone or laptop can silently read cloud-synced files, including anything in your Notes app or Documents folder.
None of these require a sophisticated attacker. Credential stuffing tools are freely available. Phishing kits are sold for under $50 on dark web markets. The barrier to attacking someone's cloud storage is genuinely low.
What about encrypted files in the cloud?
Encrypting the file before uploading it adds a layer of protection. If you use a strong passphrase with a tool like VeraCrypt or 7-Zip AES-256 encryption, someone who accesses the file still needs to crack the encryption. That's a real barrier. But it doesn't solve the problem entirely.
The passphrase itself now becomes a target. If it's stored anywhere near the encrypted file (another document, an email, a notes app), the protection collapses. If the passphrase is weak or reused, brute force becomes viable. And if you forget the passphrase, you've locked yourself out of your own backup.
Encryption in the cloud is better than plaintext, but it turns one vulnerability into two: the cloud account and the encryption passphrase. Most holders aren't well-served by this complexity.
The right way to store a seed phrase
Physical storage is the correct answer. Your seed phrase should exist in the real world, not on any network-connected device or service. That means writing it down on paper, or better, stamping it onto a metal backup.
Paper is cheap and immediate, but it burns, floods, and degrades. A dedicated metal backup, using engraving tools or stamped letter plates, survives fire, water, and decades of storage. McLeod Pacific Investments covers the full process of storing Bitcoin seed phrases on metal backups, including the materials worth considering and how to organise the storage safely.
Location matters as much as the medium. A seed phrase sitting in a drawer at home is only as secure as your home. Consider a fireproof safe, a bank safe deposit box, or splitting the backup across two secure physical locations. Splitting a 24-word seed phrase into two halves and storing them separately is one approach, though it adds complexity to recovery.
What about password managers?
Password managers are genuinely excellent tools for Bitcoin account credentials. McLeod Pacific Investments has written in detail about how to safely use a password manager for Bitcoin accounts, and the guidance holds: a good password manager protects your exchange login, your email, and your two-factor recovery codes.
But a seed phrase is a different class of secret. A password manager is software, connected to the internet, and accessible through credentials that can be phished or leaked. Keeping your seed phrase out of any software, including a password manager, is the cleaner security posture. The risk of a password manager compromise is low but non-zero. The consequence of a seed phrase leak is total and irreversible.
A checklist before you store anything
Before you write down or secure a new seed phrase, run through these steps. Write it down by hand, never type it. Check each word against the BIP-39 wordlist to confirm you've recorded it accurately. Store the physical backup somewhere it won't be seen by casual visitors. Never photograph it with a phone. Never speak it aloud near a smart speaker or device with a microphone. Verify the backup actually works by restoring your wallet to a fresh device before you rely on it.
That last point is the one most people skip. A seed phrase backup you've never tested is a seed phrase backup you don't actually know works. Test it once when you set up the wallet, then store it and leave it alone.
The convenience trap
Cloud storage feels safe because it's familiar and because it works flawlessly for everything else. That familiarity is the trap. Bitcoin's security model is deliberately different from how most digital services work. There is no customer support, no account recovery, no password reset. The seed phrase is the account. Protecting it requires treating it differently from everything else you store digitally, not because cloud services are bad, but because the stakes attached to those twelve words are unlike anything else in your financial life.
Physical, offline, tested. Those three words are the right storage policy for a Bitcoin seed phrase, and no amount of cloud convenience changes that.

