3. Back up your seed and passphrase on metal.
4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.
I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.
2 places: A safe in your home and a safe deposit box at the bank.
Personally, I would not want to consider a bank safe deposit box at a bank to be completely under my control, so I would not want to store anything valuable there, such as my total stash of bitcoin or even large portions of my bitcoin, even though if it were just part of the formula to access, then maybe it would be o.k, such as 1/3 of the passphrase and/or 1/3 of the seedwords or maybe the instructions for how to do it, but not having enough information merely from the instructions being there.
6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.
What if your house burns down? I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?
Your seed and passphrase should be backed up on metal in 2 places: A safe in your home and a safe deposit box at the bank. Your documentation for your wallet should be in 2 places too. This is especially true for anybody doing multisig.
Bitcoin self custody comes with self responsibility.
I am personally not comfortable with your proposed set up in that you seem to be suggesting 2 places for instructions and 2 places for instructions (documentations) and maybe you are even suggesting that those two places would be different, so then is that 4 places? Also, with the way that you are proposing, it seems to me that an infiltration of any of the one of the locations may well mean that your whole stash could be taken. That sounds too risky to me.
Those who aren't prepared to do it right or don't have the means to do it right should buy ETFs instead. It makes me sad to say that, but self custody needs to be done right.
I am not against the idea that some people might not be able to handle self-custody, so they may well hold bitcoin in some 3rd party arrangement, whether that is the spot ETFs, bitcoin on exchanges, bitcoin in treasury companies, and yeah, some of those ways of holding price exposure to bitcoin are more capable of in-kind redemption, which surely bitcoin gets a lot (if not all?) of its power from the ability to self-custody and to be able to transact without permission.
Accordingly, it seems practical for the empowerment of bitcoin (so our bitcoin value does not go to zero or become the same as every other shitty 3rd-party controlled and manipulated financial product) to try to promote the practice of self-custody, even if guys are not putting all of their stash into self-custody. There are some folks who might not be capable of self-custody but then there are others who are just not ready and/or willing to learn, and surely it can be difficult to suggest that someone in their 60s, 70s or 80s have to learn different ways to hold and store their value - especially if they are not technically inclined (or technically curious), and some people have busy lives that make it challenging to prioritize learning about ways to self-custody bitcoin..
which yeah is also one of the faults that the Cold Card breach brought out, since many folks did not even want to use their Cold Card wallet because they thought that it was not very user-friendly, yet at the same time, the lack of user-friendliness may well could have caused them to conclude (wrongly we subsequently found out) that the behind the scenes operations in Cold Card were done in secure ways.. and yeah, a lot of normies got punished for that assumption, which so many of us are starting to speculate that there may well could have had been some intentionality (in the maliciousness) of the breach since the extent to the recklessness has become so obviously clear given their ongoingly ignoring and/or poo-pooing complaints that specifically were about the security of the key generation that went back to 2021-ish. ..... so guys took a lot of steps to secure their key but then assumed that the generation of the key was sufficiently robust, and ends up being quite painful, including perhaps scaring some folks away from considering the benefits (to self and benefits to the system) of self-custody.
Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else. So, question of the day is: how many new wallets were created, over how many users, over how many sold devices, over 5+ years?
And this factors in boot time, menu interactions, and any USB activity. So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?
Of course, if a guy created a wallet that already had fund in it, then surely the obvious conclusion is that the already existing bitcoin is not his. Yet, there is no one stopping him (except his own moral compass) from taking what is someone else's.
It is not a difficult question, even though some folks find it as a dilemma because they let their greed override logic.
Maybe if there were 100 bitcoin in there, then just take half, right? Or maybe no matter what, take 15% as a bounty, which should warn the "actual owner"? maybe send a private message to the actual owner? Something like this: "I took 15% of your coins as a 'finder's fee" bounty, and I am going to give you 3 months to remove your remaining coins, otherwise I am going to take another 15%." I suppose that it does not have to be all or nothing, even though it is morally questionable to take coins that are not yours, but at the same time, it could take the owner a year or more before he noticed that some coins had been taken from his wallet. There isn't any obligation that we need to ongoingly watch the addresses within our wallets.
I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.
Is it easier to add a message to your transaction or set a passphrase in your wallet?
Maybe you didn't explain it to me well, but that's not what I meant.
What I wanted to say is that you usually don't need to make a 25th word to make the seed safe.
She is already safe with the 24 words if it is well done
So I understand why not everyone creates an extra word.
Until today, nothing like this had happened in hardware wallets, even those that are less popular.
Less was expected to happen in one as popular as Clodcard.
I am pretty sure that I recall, historically, hearing about all kinds of claims from individuals about their having had lost their coins. Of course, many of the times, we may well just chalk it off to user-error, even though in the case of some of the close source wallets, sometimes we might be skeptical about some insider knowledge that is allowing the swiping of coins and blaming the users.