A user with significant cryptocurrency holdings faces a practical organizational challenge: keeping different asset categories, counterparty relationships, or investment strategies visibly separate while maintaining control over all of them from a single hardware device. One approach is to buy multiple Ledger devices, each with its own recovery seed and key management system. A more elegant alternative is to use a passphrase feature built into the device itself, which allows a single 24-word recovery seed to generate multiple independent wallets, each protected by a different additional passphrase. This approach requires understanding not only how passphrases work, but also what happens if a passphrase is forgotten and why recovery planning matters more than convenience.
The passphrase mechanism is neither a password manager nor an encryption layer applied to the device after setup. Instead, it is a cryptographic input into the derivation of all private keys—different passphrases generate entirely different key sets from the same seed. This distinction is critical because it means a user cannot simply store a passphrase in a password manager and expect the standard recovery process to work if the passphrase is lost. Before setting up passphrases, users should download and install the official application, understand the isolation each passphrase creates, and document their recovery strategy with the same care they apply to the seed phrase itself.
How passphrase-based wallet derivation works in Ledger Live
When a user sets up a Ledger device and chooses to use a passphrase, the flow begins with the recovery seed generation or import. The seed itself remains unchanged—it is still 24 words that serve as the master secret. But before key derivation, the Ledger device concatenates the seed with the user-supplied passphrase, then applies a key derivation function to produce the root key. This means that “Ledger” and “Ledger123” as passphrases generate completely different sets of private keys, even though they derive from the identical 24-word seed.
The advantage is isolation without duplication. A user can create one passphrase for long-term holding, another for daily transactions, and a third for testing or higher-risk experimentation. Each passphrase unlocks a separate wallet with entirely independent addresses, balances, and transaction histories. Within the Ledger Live application, switching between passphrases is a matter of entering the correct passphrase on the device’s secure screen, then confirming the action. The app then displays accounts derived from that passphrase, completely separate from wallets created under other passphrases.
This separation is enforced at the cryptographic level, not merely at the application interface. An attacker with access to one passphrase-derived wallet cannot derive any other passphrases or their corresponding keys. This property makes passphrases particularly useful for self custody wallet architectures where the user wants multiple isolation contexts but does not want to manage multiple recovery seeds. However, the isolation also creates a risk: if a passphrase is forgotten, the user cannot derive that wallet’s keys from the seed alone, even if they have the 24-word phrase memorized or written down.
When users perform a ledger live download and set up their device, the option to use or skip passphrases appears during the initial configuration. Choosing to enable passphrases means the device will prompt for one whenever the user wants to access accounts derived from it. The passphrase is entered on the device’s physical screen, not typed into the computer or mobile app, which means the passphrase never travels through the companion software—only the derived keys and transactions do.
Creating multiple wallets from a single seed phrase
Once passphrases are enabled on a Ledger device, the user can establish as many independent wallets as needed by simply creating new passphrases. Common organizational schemes include a passphrase for savings (the primary long-term holdings), a passphrase for active trading, a passphrase for receiving payments from a particular source or counterparty, and optionally a decoy passphrase (discussed below) for security theater or legal coercion scenarios.
Each passphrase can be as simple as a single word or as complex as a multi-word phrase. The tradeoff is between memorability and entropy. A memorable passphrase such as “birthday-2024-savings” is easier to recall but weaker against brute-force attack if the attacker also has the seed. A long, random passphrase such as “xK9mP2qL7vN4bZ6rJ8wT” is stronger but requires secure storage, which means writing it down or using a password manager—both of which introduce their own risks.
Within Ledger Live, the user can label each wallet using the passphrase feature so that the app displays “Savings Wallet,” “Trading Wallet,” and “Testing Wallet” in the interface, even though the actual passphrases remain private. When switching between them, the user enters the passphrase on the device, the device derives the corresponding keys, and Ledger Live displays the accounts and balances associated with that passphrase. The application itself does not store passphrases or keys; it only communicates with the hardware wallet and displays the results.
This architecture maintains key management isolation at the hardware level. Because the device generates all keys from the seed and passphrase, and because all transactions are signed on the device before being sent to the network, the companion software cannot steal keys or forge transactions, even if it is compromised by malware. The user’s primary responsibility shifts to protecting the recovery seed and each passphrase with the same diligence they would apply to a complete recovery phrase.
The recovery problem: why forgotten passphrases cannot be recovered
The fundamental security property of passphrases—that they generate entirely different key sets and cannot be derived from the seed—creates an asymmetry in recovery. A user who forgets their 24-word seed phrase can use their recovery sheet, physical backup, or memory to restore the device and access all passprase-derived wallets. A user who forgets a passphrase cannot use the seed alone to recover access to that wallet. There is no “forgot passphrase” link or recovery code issued by Ledger, because no centralized system controls or tracks the passphrases.
This is by design. Passphrases derive their security from the fact that knowledge of the seed does not grant access to passphrase-derived wallets. If a recovery mechanism existed, it would have to either store passphrases somewhere (creating a centralized vulnerability) or weaken the cryptographic isolation. Ledger chose not to do either. The consequence is that a forgotten passphrase is functionally equivalent to a destroyed wallet: the private keys cannot be accessed, and any funds in that wallet are stranded.
Users have lost access to funds by forgetting passphrases, and recovery is not possible. This is not a bug or oversight; it is an inherent property of the system. Therefore, passphrase management must be treated as a dual recovery problem. The user needs both the seed phrase and the list of passphrases to recover all wallets. Unlike the seed, which is often memorized or stored in a single safe location, passphrases may need to be distributed across multiple secure locations if the user fears that a single location could be compromised, lost, or destroyed.
One common approach is to store the seed phrase in one secure location (a safe deposit box, a home safe, or a divided backup across multiple trusted people) and the passphrase list in a separate, equally secure location. This way, an attacker who finds the seed cannot access the passphrases, and an attacker who finds the passphrases cannot access the seed. A third option is to memorize one or more passphrases, particularly if they are meaningful to the user (such as “firstdog-april-1989”), so that they do not need to be written down at all. However, relying entirely on memory introduces the risk that the passphrase could be forgotten, especially if years pass without needing to use it.
Security trade-offs: isolation versus complexity
Passphrases offer genuine isolation benefits, but they also increase operational complexity and recovery risk. A user managing three passphrases has three cryptographic secrets to protect instead of one, three recovery paths to test, and three potential points of failure. If the goal is merely to separate different accounts or asset categories within a single wallet, a simpler approach is to use multiple accounts within the same Ledger device under the default passphrase (or no passphrase at all), which is supported natively in Ledger Live and most blockchain applications.
However, passphrases offer a level of isolation that multiple accounts cannot. If a user is concerned that a single passphrase-derived wallet might be compromised through malware, physical theft, or coercion, a separate passphrase ensures that the attacker cannot access other passphrases or their wallets, even with full control of the device and the recovery seed. This makes passphrases appropriate for scenarios where the threat model includes partial compromise or where different wallets serve different security contexts.
A high-value holder might use one passphrase for cold storage (accessed rarely, backed up offline, possibly never entered into a network-connected device) and another passphrase for operational funds accessed through Ledger Live for regular transactions. The cold storage passphrase is designed to remain secret even if the device is physically stolen or the operational passphrase is compromised. A trader might use separate passphrases for different counterparties or strategies, reducing the risk that a mistake or a social engineering attack affecting one wallet spreads to others.
The trade-off becomes unfavorable if the user cannot reliably remember or recover passphrases, or if they are forced by circumstance to write down all passphrases in one location (defeating their isolation value). In these cases, the added security of passphrases is cancelled out by the increased recovery risk. A user should honestly assess whether they can manage multiple passphrases and recovery paths before committing to the added complexity.
The decoy passphrase strategy and its limitations
Some users of hardware wallets employ a “decoy wallet” or “duress wallet” strategy, in which a deliberately weak or memorable passphrase is created to hold a small amount of cryptocurrency. The idea is that if a user is coerced by law enforcement, border agents, or criminals to reveal cryptocurrency holdings, they can reveal the decoy passphrase, which unlocks a low-value wallet, while concealing the passphrases of larger, more valuable wallets. This strategy assumes that a human attacker will believe the revealed wallet is the extent of the user’s holdings and will not persist in demanding access to others.
This approach has significant limitations and can backfire. First, a sophisticated attacker (law enforcement with forensic tools, for example) may be able to detect that multiple passphrases exist by examining the device configuration or transaction history. Second, the strategy assumes that the decoy wallet’s balance is believable given the user’s apparent wealth, income, and lifestyle. An implausibly low balance may increase suspicion rather than satisfy it. Third, even if the decoy works as intended, the user must remember to keep it funded and active; a dormant or empty decoy wallet might be discovered during a thorough investigation.
The decoy passphrase is also incompatible with certain Ledger features. For example, if a user sets up a firmware update or password reset while a decoy passphrase is active, they must reveal or re-enter the passphrase on the device, potentially in front of witnesses. The user’s operating system or network traffic might also leak metadata about which passphrases are being used, depending on how the device and software are configured.
From a legal and ethical standpoint, users should understand that using a decoy passphrase does not change the fact that they hold other wallets; it is merely a social engineering tactic. In jurisdictions where citizens have a legal obligation to disclose assets or cryptocurrency holdings, revealing a decoy passphrase does not satisfy that obligation if the decoy is incomplete. Users considering a decoy passphrase should consult legal advice in their jurisdiction before implementing one.
Testing and documentation: ensuring passphrases are usable
Before relying on passphrases for actual funds, a user should test them thoroughly. This means setting up a passphrase, funding the corresponding wallet with a small amount of cryptocurrency from a test transaction, and then verifying that the wallet can be accessed again by re-entering the passphrase on the device. This simple test confirms that the passphrase is spelled correctly, that the user can remember it reliably, and that the wallet derivation works as expected.
Documentation is equally important. A user should maintain a record of each passphrase’s purpose (e.g., “savings,” “trading,” “cold storage”) and any associated metadata such as the creation date, the approximate balance at setup, or the blockchain accounts contained in that wallet. This documentation does not need to include the actual passphrases—those should remain secret—but it should allow the user to know which passphrases exist and what they are for, so that recovery can be systematic if needed.
One effective method is to create a secure document that lists the passphrases in encrypted form or in a way that is meaningful only to the user. For example, a user might record “Passphrase 1: [first line of childhood favorite poem]” without writing down the poem itself, relying on their own memory to complete it. Another approach is to use a password manager such as 1Password or Bitwarden to store passphrases, ensuring that the password manager itself is secured with a strong master password and stored in a separate location from the recovery seed.
When testing recovery, the user should periodically verify that they can recover a wallet from the seed phrase and passphrase using a fresh device or a recovery simulation. This test should occur at least once per year and after any major change in the user’s life (relocation, change in employment, family situation) that might affect their access to stored backups. The goal is to catch recovery failures while funds are not at stake, rather than discovering the problem when recovery is urgent.
Practical setup workflow: from download to active passphrases
The complete process of setting up passphrases begins with acquiring a Ledger hardware device and downloading the official companion software. After users perform their initial ledger live download from the official Ledger website, they install the application on their desktop or mobile device, connect the hardware wallet to the computer, and follow the setup wizard to initialize the device or import an existing recovery seed.
During setup, the device prompts the user to set a PIN for physical security, then asks whether they want to use a passphrase. If the user selects “Yes,” the device will then ask for the passphrase to be entered on the physical secure screen. Once the passphrase is set, the device derives the corresponding keys and loads the initial account set in Ledger Live. The user can then send cryptocurrency to the receiving addresses for this passphrase-derived wallet, just as they would with any other hardware wallet.
To add a second passphrase, the user returns to the Ledger Live settings, selects the passphrase option, and chooses to add or switch to a new passphrase. The device prompts for the new passphrase to be entered on its screen. Once confirmed, Ledger Live displays the accounts derived from this second passphrase, which are completely independent from the first. The user can repeat this process to create additional passphrases as needed, each with its own accounts and separate balance.
Within Ledger Live, the application allows the user to view their portfolio across all passphrases by displaying all accounts and assets in a single dashboard. However, each account tab can be labeled with its passphrase context, making it clear which accounts belong to which passphrase. This labeling is a convenience feature; it does not change the underlying cryptographic isolation or affect key management on the device.
Common mistakes and how to avoid them
One frequent error is using the same passphrase across multiple devices, assuming that this provides additional security. In reality, using the same passphrase on multiple Ledger devices (or a Ledger and another hardware wallet) is less secure than using unique passphrases, because a compromise of any device could expose the passphrase, which would then grant access to the same wallet on all other devices. Users should use unique passphrases for each physical device if they own multiple devices, or else accept that all devices are only as secure as the least-protected one.
Another mistake is storing the passphrase in the same location as the recovery seed, or worse, writing it on the back of the recovery seed card. This completely defeats the isolation purpose; an attacker who finds the seed also finds the passphrases and gains access to all wallets. The seed and passphrases should be stored in separate secure locations, with the understanding that this introduces a recovery complexity trade-off.
A third error is creating passphrases that are too short or based on predictable information such as birthdates, pet names, or other personally identifiable details that an attacker could guess or infer. While a passphrase does not need to be as random as a cryptographic key (because the attacker would need the seed to derive keys), it should still have sufficient entropy to resist dictionary attacks or social engineering. A passphrase of at least 8–10 characters, incorporating a mix of words, numbers, or special characters, is a reasonable minimum.
Users sometimes also forget to test their passphrase recovery before relying on it for significant funds. They set up a passphrase, transfer a large amount of cryptocurrency to it, and then months or years later discover that they can no longer remember the correct spelling or format. Testing recovery with small amounts, before committing funds, is essential. Similarly, users should avoid the temptation to “optimize” recovery by memorizing only one location’s worth of backups; a fire, flood, or theft could destroy both the seed and the passphrase list simultaneously.
When passphrases make sense and when they don’t
Passphrases are most valuable for users who meet certain criteria: they have substantial cryptocurrency holdings that justify the additional security complexity, they can reliably manage multiple recovery secrets, they want cryptographic isolation between different use cases or counterparties, and they understand the recovery implications of forgotten passphrases. A user with a small amount of cryptocurrency in a single wallet, who manages their private keys only for routine transactions, likely gains more benefit from simplicity than from passphrase isolation.
Passphrases are particularly appropriate for users who expect their device or keys might be stolen or coerced and who want to ensure that a single compromise does not expose all holdings. They are also useful for users who want to separate daily operational funds from long-term cold storage, keeping them on the same device but ensuring that a malware infection affecting the operational account cannot compromise the savings account.
Passphrases are less appropriate for users who cannot reliably secure and recover multiple secrets, who operate primarily through a single self custody wallet without complex isolation needs, or who lack the operational discipline to test recovery procedures regularly. For these users, the added complexity and recovery risk may outweigh the security benefits. A single, well-protected recovery seed with multiple accounts under the default passphrase (or no passphrase) is often a better match.
Users who already use strong hardware wallet practices—keeping devices in secure physical storage, using strong PINs, backing up seeds offline, and avoiding network exposure—should consider whether additional passphrases would genuinely improve their threat model or merely increase operational burden. In some cases, the answer is clear (a trader managing multiple strategies, a high-net-worth individual with substantial holdings). In others, the simpler approach may be more secure because it is easier to execute correctly and less likely to be forgotten or mishandled during recovery.
Frequently asked questions
Do I need to use a passphrase with my Ledger device?
No. Passphrases are optional. Users can operate a Ledger device without passphrases and derive multiple accounts from a single recovery seed using the standard account derivation path. Passphrases are most useful if you want cryptographic isolation between different wallets or security contexts. If you only need to separate accounts for organizational purposes, you can use multiple accounts within a single wallet without passphrases.
What happens if I forget a passphrase?
Access to that passphrase-derived wallet cannot be recovered. There is no “forgot passphrase” option or recovery code because passphrases are not stored or managed by Ledger. If you forget a passphrase, the private keys derived from it are cryptographically inaccessible, and any funds in that wallet are stranded. This is why documenting and testing passphrases before committing funds is essential, and why storing passphrases securely alongside your recovery seed is critical.
Is it safe to use a passphrase-based decoy wallet?
A decoy wallet can be detected by sophisticated attackers through device forensics or transaction analysis. It may also violate legal obligations to disclose assets in some jurisdictions. If you are considering a decoy passphrase for security or legal reasons, consult legal advice in your jurisdiction first. Even if a decoy is technically feasible, it is only as effective as your ability to make it believable and to maintain it realistically over time.
Can I access multiple passphrases at the same time in Ledger Live?
No. Ledger Live displays accounts from one passphrase at a time. To switch between passphrases, you enter the new passphrase on the physical device screen, and the app then displays the accounts derived from that passphrase. You cannot view balances or perform transactions across multiple passphrases simultaneously; you must switch between them by re-entering the passphrase on the device.
Do I need to store my passphrase with my recovery seed?
No, and keeping them together defeats the purpose of isolation. Ideally, store your recovery seed in one secure location and your passphrases in a separate, equally secure location. This way, an attacker who finds only one location cannot access the complete set of wallets. If both are stored together, the isolation benefit is lost, but recovery is simplified if you cannot access both locations separately.










