How to Export Your DPW Seed Phrase
Welcome to the guide on exporting a seed phrase from a Digital Paper Wallet (DPW) in UnoLock CybVault. The DPW is a non-custodial, multi-currency cryptocurrency wallet generator designed with a strict zero-knowledge principle, ensuring UnoLock never has access to your private keys or mnemonic seed phrases. Exporting your seed phrase is a deliberate security ceremony known as the Key Extraction Protocol (KEX), which protects against risks like malware, coercion, and unauthorized access.
This process involves splitting the 24-word mnemonic phrase into two 12-word halves, requiring authentication and offline mode for each half to minimize exposure. It's essential for importing your DPW into external transaction wallets (e.g., Ledger, MetaMask, Phantom Wallet) while maintaining security.
Why Exporting a DPW Seed Phrase Is Important
- Non-Custodial Control: UnoLock's DPW ensures you remain the sole custodian of your secrets. Exporting allows safe transfer to hardware wallets for transactions, without exposing plaintext keys to the internet.
- Security Against Threats: The KEX protocol mitigates risks like keyloggers or man-in-the-middle attacks by enforcing offline decryption and multi-layered encryption.
- Compatibility: Exported seed phrases (BIP-39 compliant) can be imported into supported wallets like Ledger Nano S/X, Trezor, Trust Wallet, MetaMask (ETH/ERC-20), or Phantom Wallet (Solana).
- Resilience: Built with post-quantum preparedness and quadruple encryption, this process aligns with UnoLock's defense-in-depth model, protecting against current and future threats.
Important Security Note
Never export your seed phrase on a compromised device or while online. Always perform this in a secure environment. Once exported, store the full phrase offline and never share it. UnoLock cannot recover lost phrases.
How the DPW Seed Phrase Export Works
The DPW architecture uses a multi-layered security model: - Secret Splitting: The 24-word mnemonic is split into two independent 12-word halves, preventing a single exposure from compromising the full phrase. - Quadruple Encryption: Each half is protected by four layers: client-side master key encryption, server-side re-encryption, envelope encryption, and AWS S3 server-side encryption (SSE) with AES-256. - KEX Protocol: Decryption requires FIDO2/WebAuthn authentication, PIN entry, and offline mode. The system validates key-pairs internally using standards like BIP-39 and BIP-32. - Ephemeral Handling: After viewing, the app forces a reload to purge memory traces.
This ensures zero-knowledge: UnoLock servers store encrypted blobs but cannot decrypt them.
Prerequisites
- An authenticated UnoLock session on a Sovereign or HighRisk tier (DPW is available in these tiers).
- A secure, trusted device (e.g., no malware).
- A hardware wallet ready for import (e.g., Ledger).
- Backup paper and pen for writing the phrase (do not store digitally).
Step-by-Step Guide
Follow these steps carefully to export your DPW seed phrase.
-
Authenticate into UnoLock
Open the UnoLock app and authenticate using your biometric or FIDO2 method. Ensure you're in a secure environment. -
Open Your Safe
Navigate to "Open Safe" and authenticate in to access your vault. -
Access the Wallet Menu
In the main menu, go to "Wallet" and select the Digital Paper Wallet (DPW) you want to export the seed phrase from. -
View the Wallet
Click "View" to open the wallet details. -
Initiate Seed Phrase Recovery
Click "Show Recovery Phrase," then confirm by clicking "Show Recovery Phrase" again. You'll be presented with the Key Extraction Protocol (KEX) overview. -
Export the First Half of the Seed Phrase
- Select "First Half."
- Authenticate using your FIDO2/WebAuthn key and enter your UnoLock PIN.
- Go offline: Disconnect your internet connection or enable airplane mode on your device.
- Confirm you're offline by clicking "I am Offline."
- The first 12 words of your seed phrase will appear. Write them down securely on paper.
-
Click "Close" to exit the view.
-
Go Back Online and Re-Authenticate
Reconnect to the internet and log back into UnoLock. Authenticate into your safe again to continue. -
Export the Second Half of the Seed Phrase
Repeat steps 3–5 to return to the wallet view. - Select "Second Half."
- Authenticate with FIDO2 and PIN.
- Go offline again and confirm.
- The second 12 words will appear. Write them down to complete the full 24-word phrase.
-
Click "Close."
-
Import the Seed Phrase into Your Transaction Wallet
Use the full 24-word phrase to import into a compatible wallet (e.g., Ledger Nano S/X, Trezor, Trust Wallet, MetaMask for ETH/ERC-20, or Phantom Wallet for Solana). Follow the wallet's import instructions carefully. -
Secure Your Phrase
Store the written phrase in a safe, offline location (e.g., a physical vault). Never store it digitally or share it.
Troubleshooting
- Offline Confirmation Fails: Ensure your device is fully disconnected (check Wi-Fi and cellular). The app enforces this to prevent online exposure.
- Authentication Errors: Verify your FIDO2 key is registered. Use LockoutGuard if locked out (see LockoutGuard Setup).
- Wallet Not Visible: Ensure you're on Sovereign or HighRisk tier. Upgrade if needed (see Upgrade Safe).
- Phrase Validation: After import, verify the wallet address matches your DPW to confirm accuracy.
Security Considerations
- Why Offline Mode?: Prevents real-time attacks like malware capturing the phrase during display.
- Split-Trust Recovery: Viewing halves separately on different devices adds protection against single-device compromise.
- No Recovery by UnoLock: Due to zero-knowledge design, UnoLock cannot reconstruct or recover your phrase, responsibility lies with you.
- Post-Quantum Resilience: The KEX protocol uses lattice-based encryption, safeguarding against future quantum threats.
For more on DPW security, see Digital Paper Wallet (DPW) Security. If issues persist, join our Reddit community or contact support. Own your digital destiny with UnoLock.