Codex32 and Shamir Backups on COLDCARD
Your seed backup has a problem that more copies cannot fix.
One copy is a single point of failure: lose it, lose the coins. Make a second copy and that is fixed, at the cost of doubling the number of places somebody can find the whole secret. Three copies, three places. Redundancy and secrecy pull against each other, and every copy you make buys one by spending the other.
Shamir Secret Sharing breaks that trade. Split the backup into several shares and set how many are needed to rebuild it. Fewer than that number reveal nothing about the secret.
COLDCARD can now split the BIP-39 seed words you already use into Shamir shares. Same wallet, same addresses, no coins moved. It ships in firmware 5.6.3 (Mk4/Mk5) and 1.5.3Q (Q).
Threshold Beats More Copies
| Backup plan | Survives losing | Compromised by |
|---|---|---|
| 1 copy | nothing | 1 find |
| 3 copies | 2 | 1 find |
| 2-of-3 shares | 1 | 2 finds |
| 3-of-5 shares | 2 | 3 finds |
Three copies in three places is three chances for one burglary — or one curious relative — to walk off with everything. A 3-of-5 split survives two destroyed shares and still defeats whoever reaches two of the five — so one share can sit with a lawyer, one in a deposit box, one at home, and no single visit is enough.
COLDCARD makes 2 to 9 shares, with any threshold from 2 up to the total. Unlike Seed XOR, which needs every part, you choose the redundancy. Pick the smallest arrangement you can actually store, explain to your heirs, and test.
BIP-93, Natively
BIP-93 defines Codex32: an encoding for wallet secrets with a strong checksum and Shamir sharing built in, designed so a checksum can be verified — and shares recombined — with pen, paper, and printed tables.
On a COLDCARD with a PIN and no wallet, the new Codex32 menu covers the
lifecycle: Generate a new MS1 secret,
Import Codex32,
Shamir Recover from a threshold of shares,
Derive Shares, and
Calculate Checksum.
Derive Shares is the one people underestimate. Lose a share from a 2-of-3 and
any two survivors reproduce exactly that missing share. The set stays valid and
the shares already sitting in other locations do not have to be replaced.
The Part That Usually Costs You an On-Chain Move
Standard Codex32 (MS1) starts with its own wallet secret format. SLIP-39 can
technically convert an existing BIP-39 wallet through Trezor’s command-line
tool, but Trezor Suite does not support it and Trezor recommends creating a
new wallet and moving the funds instead.
For most existing BIP-39 users, that means paying transaction fees, rebuilding
their wallet setup, and potentially linking addresses on-chain — a cost in
money, effort, and privacy just to improve a backup.
So we extended Codex32. COLDCARD can split an existing BIP-39 seed directly into Codex32 shares—without creating a new wallet or moving coins. The checksummed strings can be recorded on paper or steel. The format is chosen from whatever wallet is already active:
| Active wallet | Format | A threshold of shares restores |
|---|---|---|
| BIP-39 seed words | CW1 |
Your original 12, 18, or 24 words |
| Extended private key, including an active passphrase wallet | CX1 |
The chain code and private key |
| BIP-32 master seed | MS1 |
The master seed bytes — standard BIP-93 |
CW1
encodes the entropy behind your English BIP-39 words. Each share is
48 characters for a 12-word wallet, 61 for an 18-word wallet, or 74 for a
24-word wallet,
displayed in numbered groups of four for copying.
Recover a threshold of them and you get those same words back, usable with
SeedQR, Seed XOR, passphrases, and every other word-based feature.
A of a split 12-word wallet: 48 characters, starting CW1.Nothing moves on-chain. Your existing words, XPRV, and encrypted .7z backup
all stay valid. You are adding a recovery path, not replacing one.
CX1
covers the case BIP-39 words cannot: split while a BIP-39 passphrase wallet
is active and the shares carry that wallet’s derived keys. Recovery restores
it without asking for the passphrase. It does not restore the words or the
passphrase — that is the feature, and also the limit.
The honest caveat, which the device puts on screen before you start: CW1 and
CX1 are
ours, not BIP-93.
Recovery needs COLDCARD, or software that explicitly supports the prefix —
MS1 support alone is not enough. If you want a standards-only backup, use
MS1.
How a Split Works
With the wallet you want to back up active:
Advanced/Tools > Danger Zone > Seed Functions > Shamir Split
(step by step, with screenshots)
Choose the number of shares, choose the threshold, confirm the format notice, and the set appears. Each share can be written down from numbered four-character groups, or exported by QR, NFC, MicroSD, or Virtual Disk.
QR, NFC, MicroSD, and Virtual Disk exports contain plaintext shares. Keep fewer than the recovery threshold in any one place. Before relying on the backup, recover from the copies you will store and confirm both the expected wallet fingerprint and a known receive address. A valid checksum confirms a well-formed share; it does not prove that the share recovers the intended wallet.
Shamir shares protect your backup; they do not turn your wallet into multisig.
See the Codex32 guide for storage precautions and recovery instructions.
Where to Read the Details
Codex32 and Shamir Secret Sharing arrive in Mk4/Mk5 v5.6.3 and Q v1.5.3Q.
- Every workflow, format, file rule, and troubleshooting case: COLDCARD Codex32 & Shamir guide
- The specification: BIP-93
Split your backup. Keep your wallet.
Artwork from the Codex32 booklet, illustrated by Micaela Paez under the MIT License.
Enjoy 10% off when you pay with Bitcoin at checkout.