☎ +1 214-659-1775 Signal: +1 214-659-1775 [email protected]
Mon–Fri 9:00–18:30 MT · Denver, Colorado

Lost a Trezor Shamir share? What SLIP-39 can and cannot recover

David Veksler By David Veksler Aug 25, 2026 10 min read Guides

Shamir backup is the best backup scheme most people can buy, and it produces the cruellest recovery cases in this business. The reason is the same in both directions: SLIP-39 does exactly what it promises. Below your threshold, the shares reveal nothing about your wallet to an attacker, and they reveal nothing to you either.

That makes "I lost a Shamir share" one of the few questions in wallet recovery with a genuine, provable, and sometimes final answer. It is worth knowing which answer you have before you spend money finding out, so this guide walks the checks in the order that actually saves cases.

Two rules first, as always. Do not type your share words into a website, however official the "recovery checker" looks. And do not hand backup material to anyone who contacted you first. See how to tell a legitimate recovery service from a scam before you share anything with anyone, including me.

First: are these actually Shamir shares?

Locked out of a wallet like this one?

I repair hardware wallets, crack forgotten passwords, and rebuild broken seed phrases — on my own bench in Denver.

✓ NO FEE UNTIL YOUR CRYPTO IS BACK · FREE ASSESSMENT
Get a free assessment →

Count the words on one card.

This check takes ten seconds and it redirects a surprising number of cases. People say "Shamir" because they remember the word from setup, and then produce a 24-word BIP-39 phrase.

It also matters which device you have. The Model T was the first hardware wallet to implement SLIP-39, and the Safe 3, Safe 5 and Safe 7 support it too. The Trezor Model One does not support Shamir at all. If your device is a Model One, your backup is BIP-39 by definition.

Second: what was your threshold?

This is the question the entire case turns on, and almost nobody remembers the answer.

A Shamir backup is configured as any M of N shares. When you set it up you chose both numbers, and the device very reasonably did not print them on the cards. So:

Trezor also supports an advanced two-level scheme with groups of shares: a group threshold on top of a per-group member threshold. If your setup involved handing sets of cards to different people, you probably have one of these, and "how many do I need" has two answers rather than one.

Count the physical cards you can actually find, then try a restore with them. The device will tell you whether it has enough. This is faster and more reliable than trying to remember a decision you made years ago, and it costs nothing but care with the words.

Third, and most important: does the device still work?

If your Trezor still powers on and you still know the PIN, stop worrying about the lost share and make a new backup today.

A working device with a known PIN holds the secret. It can produce a fresh backup and the old shares become irrelevant. This is the single highest-value check on this page and the one people skip most often, because attention goes to reconstructing what was lost rather than replacing it.

Do it before the device develops a fault, before you experiment further with PIN entry, and before anything else on this list. A case that was hours away from being unrecoverable becomes a non-event.

Four Shamir backup situations matched to what a lost share means and what to do A lost Trezor Shamir share means one of four things. If the device still works and you know the PIN, the secret is on the device and you should make a fresh backup today. If you set up a threshold with spares, such as two of three or three of five, nothing has gone wrong and you can restore with the shares you still hold. If you built a grouped two-level backup, a group threshold sits on top of a per-group threshold, so gather every card and let the device tell you whether it has enough. If you built a two of two or single-share backup and the device is gone, the remaining shares leak nothing about the secret by design, the wallet is not recoverable, and anyone offering to recover it anyway is running a scam. A lost Shamir share means four different things FIND YOUR ROW BEFORE YOU SPEND ANYTHING WHAT YOU SET UP WHAT THE LOST SHARE MEANS WHAT TO DO Device still works, PIN known The secret lives on the device, not only on the cards, so the lost share is not load-bearing Make a fresh backup today, before anything else on this page 2-of-3, 3-of-5, any threshold with spares Nothing has gone wrong. You still hold the number of shares you need Restore with what you have. No recovery service required A grouped, two-level backup A group threshold sits on top of a per-group one, so "enough" has two answers Gather every card and try a restore; the device says whether it has enough 2-of-2 or single-share, device gone Below the threshold the shares leak nothing about the secret, by design and by proof Not recoverable. Anyone who offers to do it anyway is running a scam
SLIP-39 does exactly what it promises, in both directions. Count the cards you physically have before you conclude anything about the ones you do not.

Why nobody can rebuild your wallet from too few shares

This is the part worth understanding properly, because it is exactly where recovery scams operate.

Shamir's Secret Sharing does not split your secret into pieces the way tearing a photograph into quarters splits a photograph. Holding three quarters of a torn photo tells you most of what the photo showed. Holding fewer than the threshold number of Shamir shares tells you nothing at all about the secret. The SLIP-39 specification puts it directly:

Knowledge of fewer than the required number of parts does not leak information about the master secret.

There is no cleverness, no GPU cluster, and no expert who gets around this. It is not a password that could be guessed with enough compute, and it is not an encrypted file that could be attacked with a better token list. The information is not present in what you hold.

Which means: if you are below your threshold and the device is gone, the wallet is not recoverable from the shares. Anyone who tells you otherwise, for any fee, is running a recovery scam. The tell is simple and reliable. They will be certain, they will want money up front, and they will not be able to explain what they intend to do.

I would rather tell you this for free than take a case I cannot finish.

What "Trezor recovery failed" usually means

A failed restore does not mean a destroyed backup. In rough order of frequency:

Shares from two different backups. These will never combine, no matter how many you have. If you ever re-created a backup, or set up a second wallet, some of your cards may belong to a different secret entirely. Shares from the same backup share an identifier; mixed sets are a common and completely invisible failure.

A misread word. Handwriting is the usual culprit. The SLIP-39 wordlist is designed so that words are distinguishable by their first four letters, which helps enormously, but handwritten cards still produce misreads.

Wrong order in a grouped backup. If you have a two-level group setup, shares belong to specific groups and the device expects them assembled correctly.

A Shamir share entered where BIP-39 was expected, or the reverse. The two standards are not interchangeable and never have been. The SLIP-39 specification is explicit that converting Shamir shares into a BIP-39 mnemonic is not possible, so no amount of retrying in the wrong field will work.

Stop retrying. Wrong-attempt consequences vary by model and some of them are irreversible. Read the words back carefully first, from the cards, out loud, with someone else checking.

A damaged share is not a lost share

If a card is water-damaged, faded, partially burned, or you can read most of a share but not all of it, do not throw it away and do not treat it as gone.

The SLIP-39 wordlist has structure. Every word is unique in its first four letters, the words have a defined length range, and each share carries a checksum. Those constraints mean a share with a small number of illegible words is often reconstructible, because only a limited set of candidates fit. This is real work rather than a certainty, but it is very different from the below-threshold case, and it is worth an assessment.

The same is true for a card where you can read the words but not their order.

What to do right now

  1. Count the words on one card. 20 or 33 means Shamir. 12 or 24 means BIP-39 and a different article.
  2. Check whether the device still works and you know the PIN. If yes, make a fresh backup today and stop reading.
  3. Gather every card you can find, including damaged ones and ones you think belong to something else.
  4. Try a restore with what you have. The device tells you whether it is enough.
  5. Do not keep retrying a restore that fails. Read the words back carefully instead.
  6. Do not type share words into any website. There is no legitimate reason to.
  7. Photograph damaged cards rather than trying to clean or flatten them.

When to hand it over

Worth an assessment:

Not worth anyone's money:

If you are unsure which of those you are in, describe what you have and I will tell you, free, before any contract or fee. The service path for hardware cases is Trezor recovery and repair, and for backup reconstruction generally it is seed phrase recovery.

If you are still choosing a backup scheme rather than recovering from one, my earlier piece on single-share Shamir versus BIP-39 for a Trezor covers that trade-off, and this article is a decent argument for taking the choice seriously.

Sources

Shamir share questions

I lost one Trezor Shamir share. Can I still recover my wallet?

It depends entirely on your threshold, and most people do not remember setting one. A SLIP-39 backup is configured as "any M of N shares." If you built a 2-of-3 and lost one share, you still hold the two you need and nothing is wrong. If you built a 2-of-2, or a single-share backup and lost the single share, the shares alone cannot rebuild the wallet.

Count what you physically have before concluding anything. The number of share cards you find is not the same as the number you need.

Can a recovery service reconstruct a seed from fewer shares than the threshold?

No, and anyone who says otherwise is lying to you. This is not a matter of effort, hardware, or expertise. Shamir's Secret Sharing is built so that holding fewer than the threshold number of shares reveals nothing about the secret. The SLIP-39 specification states it plainly: "Knowledge of fewer than the required number of parts does not leak information about the master secret."

An unrecoverable case is a real outcome, and a service that will not say so is selling you something else. See how to tell a legitimate recovery service from a scam.

How many words should a Trezor Shamir share have?

20 words for a 128-bit secret, 33 words for a 256-bit secret. If your cards have 12 or 24 words, you do not have Shamir shares at all; you have a BIP-39 seed phrase, and that is a completely different and often much simpler situation.

Word count is the fastest way to identify what you are holding, and it is worth checking before you do anything else.

Can I turn my Shamir shares into a normal 12 or 24 word seed phrase?

No. SLIP-39 and BIP-39 are separate standards and the conversion does not exist in that direction. The SLIP-39 specification is explicit that converting SLIP-39 shares to a BIP-39 mnemonic "is not possible due to the overly coupled design of BIP-39 and its use of a one-way derivation function."

This is why entering Shamir words into a BIP-39 field fails, and why that failure is not evidence your backup is wrong.

My Trezor recovery failed with shares I am sure are correct.

Stop retrying and work through the likely causes in order. Shares from two different backups mixed together will never combine, and this is more common than it sounds when someone has re-created a backup at some point. A misread word is next, and handwriting is usually the culprit. Then: shares entered in the wrong order for a grouped backup, or a Shamir share entered where the device expected BIP-39.

Repeated failed attempts have consequences on some models, so it is worth pausing to read the words back carefully rather than trying again immediately.

My device still works and I know the PIN, but I lost a share. What should I do?

Act now, while the device works. A functioning Trezor with a known PIN can create a fresh backup, which makes the lost share irrelevant. This is the single most valuable thing to check and the most commonly missed, because people fixate on reconstructing the old backup rather than replacing it.

Do it before the device fails, before the battery of an unrelated crisis, and before you keep experimenting with PIN entry.

Which Trezor models support Shamir backup?

The Model T was the first hardware wallet to implement SLIP-39, and the Safe 3, Safe 5 and Safe 7 support it as well. The Trezor Model One does not. Multi-share Backup requires firmware 2.7.2 or newer.

If you have a Model One, your backup is BIP-39 and the whole Shamir framing does not apply to your case.

David Veksler

David Veksler

Founder of WalletRecovery.info. Working in Bitcoin since 2013; recovering wallets for clients since 2017 through Veksler Consulting LLC (Colorado, USA). About David →

Locked out of your wallet?

Describe your situation and I'll tell you — for free — whether recovery is realistic. No fee until your coins are back.

Get a free assessment
+1 214-659-1775 · [email protected] · Mon–Fri 9:00–18:30 MT · Denver, Colorado