A Trezor passphrase creates a separate wallet by combining an exact string of characters with your existing wallet backup. It can protect funds if someone obtains the backup, but it also introduces a second secret that Trezor cannot recover. One different letter, space or symbol opens another valid wallet, often appearing empty without an error message.

Last reviewed: September 1, 2026. Trezor Suite, firmware and device capabilities can change. Verify current instructions in the official Trezor Knowledge Base before enabling an advanced security feature. This independent article is educational and is not financial advice.

What is a Trezor passphrase wallet?

A passphrase wallet, also called a hidden wallet, is derived from two inputs: the wallet backup created during setup and a passphrase chosen by the user. The same backup without a passphrase opens the Standard wallet. Combining that backup with a passphrase derives different private keys, accounts and addresses.

The relationship can be summarized as:

  • Wallet backup only: Standard wallet.
  • Wallet backup + Passphrase A: one separate passphrase wallet.
  • Wallet backup + Passphrase B: another separate passphrase wallet.

There is no central list of the passphrase wallets created from a backup. The wallet is calculated again when the exact combination is entered. Trezor does not need to store the passphrase to derive the same addresses later.

Passphrase vs PIN vs wallet backup

These security elements have different jobs:

  • PIN: protects access to the physical Trezor device. It does not restore a lost wallet.
  • Wallet backup: the 12-, 20- or 24-word recovery material used to restore the underlying wallet after device loss, damage or reset.
  • Passphrase: an optional additional secret that derives a separate wallet when combined with the backup.

A PIN can be changed without creating new blockchain addresses. A passphrase cannot be changed for an existing hidden wallet because changing any character derives another wallet. To move from one passphrase to another, the user creates the destination wallet, verifies it and transfers funds through normal blockchain transactions.

The passphrase is sometimes described as an extra word, but it is not simply appended to the visible recovery list. Treat it as an independent input with its own exact spelling and storage requirements.

Why every Trezor passphrase is valid

A login service can compare a password with a stored record and reject a mismatch. A hardware wallet passphrase works differently: any supported string combines with the wallet backup to derive a cryptographically valid wallet. Therefore, there is no universal “wrong passphrase” message.

For example, these inputs lead to different wallets:

  • River Stone 27
  • river stone 27
  • River Stone 27 with a trailing space
  • River Stone27

Do not use those examples as real passphrases. They illustrate why capitalization, spaces and punctuation matter. Trezor Suite currently supports standard ASCII characters with a maximum passphrase length described by Trezor as 50 characters.

Do you need a Trezor passphrase?

Most beginners do not need to enable every advanced feature. A passphrase can reduce the consequence of someone finding the wallet backup because the backup alone will not derive the protected wallet. However, losing either required secret causes permanent loss of access.

A passphrase may suit an experienced user with a defined threat model, reliable offline storage and a tested recovery process. It may be unsuitable when:

  • the user plans to rely only on memory;
  • family members or heirs would not understand the recovery process;
  • keyboard layouts or accessibility make exact entry unreliable;
  • the existing backup has never been checked;
  • the main objective can be met with separate accounts or a SLIP39 multi-share backup.

Using a passphrase is not a badge of advanced security. It is a trade-off between resistance to backup exposure and increased self-lockout risk.

How to create a passphrase wallet in Trezor Suite

1. Verify Trezor Suite and firmware

Install Trezor Suite from the official Trezor website and confirm updates through the legitimate application. Avoid downloads from advertisements, file-sharing sites or unsolicited messages. Make sure the existing wallet backup is available and has been checked using the supported Trezor workflow before changing advanced settings.

2. Enable passphrase wallets

On desktop, current Trezor guidance places the setting under Settings → Device → Passphrase. On mobile, it is under the wallet menu and device settings. The feature is normally off by default for a newly created or restored wallet.

3. Open a new passphrase wallet

Connect and unlock the Trezor, open the wallet switcher and select the option to add or open a passphrase wallet. Enter the intended passphrase exactly. Trezor Suite will derive accounts from that combination and may warn that the wallet is empty when no activity exists.

4. Confirm the passphrase on the device

Read the passphrase displayed for confirmation on the trusted Trezor screen. This helps detect substitution by compromised host software. Do not approve automatically merely because the computer already showed the expected text.

5. Record a verification reference

After opening the new wallet, record a non-secret identifier such as the last several characters of its first receiving address or an available wallet fingerprint. Keep the reference with recovery instructions. It does not replace the passphrase, but it helps confirm that later entry opened the intended wallet.

6. Send a small test amount

Verify the receiving address on the Trezor screen, then send a small amount. Wait for confirmation and check that the balance appears in the passphrase wallet. Do not transfer the main balance yet.

7. Close and reopen the wallet

Eject or close the passphrase wallet, then reproduce the passphrase from the offline record rather than memory. Compare the verification address and confirm that the test balance returns. This step tests spelling, storage and the complete access workflow.

Where should you enter the passphrase?

Current Trezor models offer different entry options:

  • Trezor Safe 7, Safe 5 and Model T: support direct entry using the device touchscreen.
  • Trezor Safe 3: supports on-device entry using its buttons.
  • Trezor Model One: does not support direct on-device passphrase entry; the passphrase is entered through the connected computer or phone and confirmed on the device.

On-device entry reduces exposure to a keylogger on the host. When entry occurs on the computer, carefully verify the passphrase on the Trezor display before confirming. Keep firmware current and use a trusted device with minimal unnecessary software.

Disable browser autofill for passphrase fields. Autofill can enter an unintended saved value and derive a wallet whose passphrase the user cannot reliably reproduce.

Why does Trezor show an empty wallet after entering a passphrase?

An empty wallet usually means that the combination entered does not derive addresses with the expected history. It does not prove that funds disappeared from the blockchain. The original wallet still exists under the exact backup and passphrase that created it.

Check the following without exposing either secret:

  1. Confirm the wallet backup. Make sure the device was restored from the backup associated with the missing wallet.
  2. Check capitalization. Uppercase and lowercase characters are different.
  3. Check spaces. Look for leading, trailing or repeated spaces.
  4. Check punctuation. Hyphens, apostrophes and quotation marks may differ.
  5. Check similar characters. Distinguish zero from O, one from lowercase l and uppercase I.
  6. Check keyboard layout. A changed language or layout can produce different characters.
  7. Confirm the correct coin and account. A valid wallet can have several account types and derivation paths.
  8. Compare a known address. Use a previously recorded receiving address or wallet fingerprint.

Do not send funds to a newly opened empty wallet merely because its passphrase looks close. First prove that it is the intended wallet by matching a known address.

What if you forgot the Trezor passphrase?

Trezor does not store passphrases and cannot reset or recover one. The wallet backup alone opens the Standard wallet, not a passphrase wallet. Resetting Trezor Suite, reinstalling the application or buying another device does not reconstruct the missing secret.

If the passphrase is partially remembered, the only possible path is testing likely exact variations with the correct wallet backup. Work offline and carefully document attempted variants. Avoid uploading the backup to a website or giving it to an unverified “recovery expert.” A service possessing both the backup and passphrase can control the funds.

Weak passphrases may be guessable by an attacker who has obtained the wallet backup, while strong random passphrases can also be impossible for the owner to reconstruct after loss. Security requires both sufficient unpredictability and dependable recovery documentation.

How to recover a passphrase wallet on a new Trezor

  1. Obtain the new device from a trustworthy source and inspect the packaging and setup flow.
  2. Install the official Trezor Suite.
  3. Restore the device using the correct BIP39 or SLIP39 wallet backup.
  4. Enable passphrase wallets in Trezor Suite.
  5. Enter the exact original passphrase.
  6. Confirm it on the Trezor screen.
  7. Compare a known receiving address or wallet fingerprint.
  8. Verify accounts and balances before creating a new transaction.

The physical Trezor is replaceable. The required recovery material is not. A compatible wallet can derive the same keys from the same standardized backup and passphrase, but entering secrets into a software wallet exposes them to the security of that computer. Prefer a trusted hardware recovery workflow.

How to store a Trezor passphrase safely

Trezor’s current support guidance recommends writing down the passphrase and storing it separately from both the device and wallet backup. Preserve every character exactly and consider an additional physical copy in another secure location.

Avoid:

  • photos or screenshots;
  • email drafts and cloud notes;
  • ordinary files on a computer or phone;
  • labels that reveal where the matching wallet backup is stored;
  • memory as the only recovery method.

Separation reduces the chance that one theft exposes both secrets, but excessive separation can make recovery or inheritance impossible. Document a process that an authorized person can understand without placing both secrets together.

Trezor passphrase vs SLIP39 multi-share backup

A passphrase and SLIP39 solve different problems. A passphrase adds another required secret and creates a distinct wallet. SLIP39 multi-share divides the wallet backup into cryptographic shares and defines a threshold, such as any three of five shares, for restoration.

With multi-share backup, losing fewer shares than the allowed threshold does not necessarily destroy access. With a passphrase wallet, losing the passphrase causes loss even when every backup share is available. A passphrase can be combined with SLIP39, but that combination still makes the passphrase a single point of failure.

Do not manually split a BIP39 word list into fragments as a substitute for SLIP39. A proper threshold scheme is designed so that fewer than the required shares do not reveal the recovery secret.

Common Trezor passphrase mistakes

  • Sending a large balance before testing re-entry.
  • Assuming Trezor can reset a forgotten passphrase.
  • Using an easy personal phrase that can be guessed.
  • Creating a random secret without making a reliable physical record.
  • Entering the passphrase into a phishing site or fake Trezor Suite.
  • Ignoring spaces, case or keyboard-layout changes.
  • Confusing a new account inside one wallet with a separate passphrase wallet.
  • Failing to record a known address for later verification.
  • Leaving heirs with two secrets but no recovery instructions.

Frequently asked questions

Can a Trezor passphrase be changed?

Not for an existing wallet. A different passphrase derives a different wallet. To use a new one, verify the new wallet and transfer assets to it through normal transactions.

Does Trezor store my passphrase?

No. It must be provided again to derive the same hidden wallet. Trezor cannot retrieve it from the device or its servers.

Why is my Trezor passphrase not working?

Every supported passphrase technically works, but a spelling, capitalization, spacing or keyboard-layout difference derives another wallet. Compare the entry with the offline record and a known address.

Can I have multiple Trezor hidden wallets?

Yes. Each unique passphrase combined with the same wallet backup creates a distinct wallet. Managing many secrets increases the risk of confusion and loss.

Can Trezor recover a forgotten passphrase?

No. Support cannot reset or reconstruct it. Anyone claiming guaranteed recovery may be attempting to obtain the wallet backup.

Can I restore a passphrase wallet without the original device?

Yes, using the correct wallet backup and exact passphrase on a compatible replacement. Verify known addresses before moving funds.

Is a Trezor passphrase safer than a seed phrase alone?

It can protect against backup exposure, but it also adds permanent self-lockout risk. Whether it is safer depends on the threat model and recovery discipline.

Should a beginner use a passphrase wallet?

Usually only after understanding backups, testing recovery and deciding that the additional threat protection justifies another irreplaceable secret.

Final takeaway

A Trezor passphrase wallet provides meaningful separation from the Standard wallet, but it offers no password-reset mechanism. The safest workflow is deliberate: verify the official software, record the exact passphrase offline, confirm it on the device, send a small test and prove that the same wallet can be reopened before transferring significant funds.

For current instructions, consult Trezor’s official passphrase wallet setup guide, hidden-wallet troubleshooting guide and Passphrase FAQ.

Visit Trezor ↗Official website