In the world of digital assets, security is paramount. One of the challenges users face is managing their Recovery Seed, or the set of words used to restore a wallet, which acts as the key to managing all your digital assets.

Risks of Storing Recovery Seeds

When it comes to storing Recovery Seeds, we face two main risks:

  1. Loss Risk: If the Recovery Seed is lost or destroyed, you will no longer be able to access your assets.
  2. Theft Risk: If others gain access to your Recovery Seed, they can steal all your assets.


What is Shamir Backup?

Shamir Backup is a data backup method developed according to the SLIP-39 standard to enhance the security of storing Hardware Wallet Recovery Seeds. It uses the principle of dividing data into a specified number of parts, known as Shamir's Secret Sharing, invented by the renowned mathematician Adi Shamir.

Bitcast

Example of Operation

Suppose you have a Recovery Seed and want to use a 2-of-3 Shamir Backup:

Part 1:

gesture necklace academic acid deadline width armed render filter bundle failure priest injury endorse volume terminal lunch drift diploma rainbow

Part 2:

gesture necklace academic agency alpha ecology visitor raisin yelp says findings bulge rapids paper branch spelling cubic tactics formal disease

Part 3:

gesture necklace academic always disaster move yoga airline lunar provide desire safari very modern educate decision loyalty silver prune physics

1. Creating Recovery Shares:

  • The system will create 3 recovery shares.
  • Each share consists of 20 or 33 words.
  • The first three words are identical across all shares to identify them as part of the same set.

2. Distributing Recovery Shares:

  • Share 1: Stored at home.
  • Share 2: Deposited in a bank safety deposit box.
  • Share 3: Entrusted to a lawyer.

3. Recovery:

  • Only 2 out of 3 shares are needed.
  • If one share is lost, the remaining 2 shares can still be used for recovery.
  • If only 1 share is stolen, assets cannot be accessed.


Security of Shamir Backup

Protection against Brute Force Attacks

  • Unlike splitting a 12-24 word seed into two parts.
  • Having only one part does not allow for calculation of the remaining parts.
  • Even with powerful computers, brute-force attacks are not feasible.

 

SLIP-39 Standard

  • Includes data checksum verification.
  • Supports the use of a passphrase. 


 

Comparison of Shamir Backup Advantages and Disadvantages


Feature

Single Seed (BIP39)

Shamir Backup (SLIP39)

Length of word list

12, 18 or 24 words

20 or 33 words

Number of parts

1 part (single seed)

1 to 16 parts (multiple parts)

Word list used

BIP-39 standard word list

Shamir-specific word list

Minimum for recovery

All words required (1/1)

User-defined (e.g., 2/3, 3/5)

Flexibility in distribution

None (only one set)

Can be distributed to keepers or stored in trusted locations

Risk of loss/theft

Total loss if lost or stolen

Resistant to loss up to the defined threshold

Suitable for

Beginner users

Experienced users

Advantages

Can use any wallet for recovery, convenient for recovery

Strong wallet protection, requires multiple data sets for access

Disadvantages

Relies on a single part for wallet access, making it easily accessible

Requires data from multiple sources for recovery, which may take longer to access the wallet


Author's Personal View

The use of Shamir Backup depends on usage needs, as it requires storing multiple data sets to access or recover a wallet. This storage might involve multiple people, which could increase the time needed for recovery.

Personally, the author believes that using Shamir Backup still has limitations because the SLIP39 standard it uses is only supported by Trezor Model T, Trezor Safe 3, and Trezor Safe 5 for recovery. However, it's not strictly necessary to use a Trezor for recovery; one can also download other programs or tools to attempt recovery, which adds to the difficulty of recovery. Therefore, the author does not recommend Shamir Backup for beginners.


If you want to use Shamir Backup, how should you prepare?

1. Start Gradually

  • Test with a wallet containing small assets first.
  • Start with a 2-of-3 system before expanding to 3-of-5.
  • Test recovery multiple times until you understand the system.

 

2. Long-term Planning

  • Create a guide for heirs, including which tools are needed for recovery.
  • Regularly update information on recovery share holders.
  • Have a backup plan in case a recovery share holder becomes inaccessible.

 

3. Choosing Recovery Share Holders

  • Distribute to people in different locations.
  • Mix between family members and professionals (e.g., lawyers).
  • Consider entrusting some shares to trusted institutions, such as banks.



Frequently Asked Questions (FAQ)

 

1. Is it necessary to use a Trezor for recovery?

Not necessarily, as Shamir Backup uses the open SLIP-39 standard. You can use:

  • Hardware wallets that support SLIP-39.
  • Software wallets that support this standard.
  • Reliable open-source tools.

 

2. What are the risks of using Shamir Backup?

  • Management is more complex than using a regular seed.
  • Multiple recovery shares must be stored.
  • If more recovery shares are lost than specified, recovery is impossible.
  • The custodians of the recovery shares must be truly trustworthy individuals.

 

3. How can I test if the recovery shares work?

  • Attempt recovery with the minimum required recovery shares.
  • Test with a wallet that has no assets first.
  • Verify that each recovery share is clearly legible.
  • Document the recovery process for future reference.

 

4. Should I choose 2-of-3 or 3-of-5?

  • 2-of-3 is suitable for general users, easier to manage.
  • 3-of-5 is suitable for high-level security but requires managing more shares.
  • Consider based on asset value and management capability.

 

5. How can I prevent recovery share custodians from colluding?

  • Distribute recovery shares to people who don't know each other.
  • Add a passphrase as an additional layer of security.
  • Do not disclose the total number of shares to the custodians.

 

6. How important is a Passphrase?

  • It is a very important additional layer of security.
  • Even if someone collects all recovery shares, they still need the passphrase.
  • You can create decoy wallets with different passphrases.
  • The passphrase should be stored separately from the recovery shares.


Conclusion

Shamir Backup is an algorithm that enhances the security of storing digital assets. Although it is complex to manage, with good planning and thorough understanding of the system, you can protect your digital assets with greater confidence. The author does not recommend Shamir Backup for beginners due to its complexity in access and management.

 

Data sources:

What is Shamir Backup?

Dev Corner: A Detailed Guide to Shamir Backup

Leave a comment

Please note, comments need to be approved before they are published.

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.