Shamir backup is the best backup scheme most people can buy, and it produces the cruellest recovery cases in this business. The reason is the same in both directions: SLIP-39 does exactly what it promises. Below your threshold, the shares reveal nothing about your wallet to an attacker, and they reveal nothing to you either.
That makes "I lost a Shamir share" one of the few questions in wallet recovery with a genuine, provable, and sometimes final answer. It is worth knowing which answer you have before you spend money finding out, so this guide walks the checks in the order that actually saves cases.
Two rules first, as always. Do not type your share words into a website, however official the "recovery checker" looks. And do not hand backup material to anyone who contacted you first. See how to tell a legitimate recovery service from a scam before you share anything with anyone, including me.
First: are these actually Shamir shares?
Locked out of a wallet like this one?
I repair hardware wallets, crack forgotten passwords, and rebuild broken seed phrases — on my own bench in Denver.
Count the words on one card.
- 20 words. A SLIP-39 share for a 128-bit secret.
- 33 words. A SLIP-39 share for a 256-bit secret.
- 12 or 24 words. Not a Shamir share at all. That is a BIP-39 seed phrase, which is a completely different and usually much better situation. Skip this article and read restoring a Trezor after a lost PIN, wiped device, or broken hardware instead.
This check takes ten seconds and it redirects a surprising number of cases. People say "Shamir" because they remember the word from setup, and then produce a 24-word BIP-39 phrase.
It also matters which device you have. The Model T was the first hardware wallet to implement SLIP-39, and the Safe 3, Safe 5 and Safe 7 support it too. The Trezor Model One does not support Shamir at all. If your device is a Model One, your backup is BIP-39 by definition.
Second: what was your threshold?
This is the question the entire case turns on, and almost nobody remembers the answer.
A Shamir backup is configured as any M of N shares. When you set it up you chose both numbers, and the device very reasonably did not print them on the cards. So:
- 2-of-3, and you lost one. You are fine. You have the two you need. Nothing has gone wrong and no recovery service is required.
- 3-of-5, and you lost one. Also fine. Restore with any three.
- 2-of-2, and you lost one. The shares cannot rebuild the wallet.
- 1-of-1 (a single-share backup), and you lost it. The shares cannot rebuild the wallet.
Trezor also supports an advanced two-level scheme with groups of shares: a group threshold on top of a per-group member threshold. If your setup involved handing sets of cards to different people, you probably have one of these, and "how many do I need" has two answers rather than one.
Count the physical cards you can actually find, then try a restore with them. The device will tell you whether it has enough. This is faster and more reliable than trying to remember a decision you made years ago, and it costs nothing but care with the words.
Third, and most important: does the device still work?
If your Trezor still powers on and you still know the PIN, stop worrying about the lost share and make a new backup today.
A working device with a known PIN holds the secret. It can produce a fresh backup and the old shares become irrelevant. This is the single highest-value check on this page and the one people skip most often, because attention goes to reconstructing what was lost rather than replacing it.
Do it before the device develops a fault, before you experiment further with PIN entry, and before anything else on this list. A case that was hours away from being unrecoverable becomes a non-event.
Why nobody can rebuild your wallet from too few shares
This is the part worth understanding properly, because it is exactly where recovery scams operate.
Shamir's Secret Sharing does not split your secret into pieces the way tearing a photograph into quarters splits a photograph. Holding three quarters of a torn photo tells you most of what the photo showed. Holding fewer than the threshold number of Shamir shares tells you nothing at all about the secret. The SLIP-39 specification puts it directly:
Knowledge of fewer than the required number of parts does not leak information about the master secret.
There is no cleverness, no GPU cluster, and no expert who gets around this. It is not a password that could be guessed with enough compute, and it is not an encrypted file that could be attacked with a better token list. The information is not present in what you hold.
Which means: if you are below your threshold and the device is gone, the wallet is not recoverable from the shares. Anyone who tells you otherwise, for any fee, is running a recovery scam. The tell is simple and reliable. They will be certain, they will want money up front, and they will not be able to explain what they intend to do.
I would rather tell you this for free than take a case I cannot finish.
What "Trezor recovery failed" usually means
A failed restore does not mean a destroyed backup. In rough order of frequency:
Shares from two different backups. These will never combine, no matter how many you have. If you ever re-created a backup, or set up a second wallet, some of your cards may belong to a different secret entirely. Shares from the same backup share an identifier; mixed sets are a common and completely invisible failure.
A misread word. Handwriting is the usual culprit. The SLIP-39 wordlist is designed so that words are distinguishable by their first four letters, which helps enormously, but handwritten cards still produce misreads.
Wrong order in a grouped backup. If you have a two-level group setup, shares belong to specific groups and the device expects them assembled correctly.
A Shamir share entered where BIP-39 was expected, or the reverse. The two standards are not interchangeable and never have been. The SLIP-39 specification is explicit that converting Shamir shares into a BIP-39 mnemonic is not possible, so no amount of retrying in the wrong field will work.
Stop retrying. Wrong-attempt consequences vary by model and some of them are irreversible. Read the words back carefully first, from the cards, out loud, with someone else checking.
A damaged share is not a lost share
If a card is water-damaged, faded, partially burned, or you can read most of a share but not all of it, do not throw it away and do not treat it as gone.
The SLIP-39 wordlist has structure. Every word is unique in its first four letters, the words have a defined length range, and each share carries a checksum. Those constraints mean a share with a small number of illegible words is often reconstructible, because only a limited set of candidates fit. This is real work rather than a certainty, but it is very different from the below-threshold case, and it is worth an assessment.
The same is true for a card where you can read the words but not their order.
What to do right now
- Count the words on one card. 20 or 33 means Shamir. 12 or 24 means BIP-39 and a different article.
- Check whether the device still works and you know the PIN. If yes, make a fresh backup today and stop reading.
- Gather every card you can find, including damaged ones and ones you think belong to something else.
- Try a restore with what you have. The device tells you whether it is enough.
- Do not keep retrying a restore that fails. Read the words back carefully instead.
- Do not type share words into any website. There is no legitimate reason to.
- Photograph damaged cards rather than trying to clean or flatten them.
When to hand it over
Worth an assessment:
- Shares that are damaged, faded, or partially illegible.
- A share where you have the words but not the order.
- A restore that fails with what you believe is a complete set.
- Uncertainty about whether you are looking at Shamir shares, BIP-39, or a mix.
- A device that no longer displays anything, where the backup is incomplete. Sometimes the device is repairable, and I have swapped a Trezor Model T touchscreen to get one running again.
Not worth anyone's money:
- Fewer shares than your threshold, with no working device. This is not recoverable and no service can change that.
If you are unsure which of those you are in, describe what you have and I will tell you, free, before any contract or fee. The service path for hardware cases is Trezor recovery and repair, and for backup reconstruction generally it is seed phrase recovery.
If you are still choosing a backup scheme rather than recovering from one, my earlier piece on single-share Shamir versus BIP-39 for a Trezor covers that trade-off, and this article is a decent argument for taking the choice seriously.
Sources
- SLIP-0039 specification on share length, the M-of-N and two-level group structure, and the guarantee that knowledge of fewer than the required number of parts does not leak information about the master secret: https://github.com/satoshilabs/slips/blob/master/slip-0039.md (retrieved 2026-08-25)
- SLIP-0039 specification on the impossibility of converting SLIP-39 shares to a BIP-39 mnemonic: https://github.com/satoshilabs/slips/blob/master/slip-0039.md (retrieved 2026-08-25)
- Trezor on which models support SLIP-39 (Model T, Safe 3, Safe 5, Safe 7) and the firmware 2.7.2 requirement for Multi-share Backup: https://trezor.io/guides/backups-recovery/general-standards/slip39-faqs (retrieved 2026-08-25)
