Trezor Passphrase Feature with Rabby: How to Create Hidden Accounts Without Breaking Your Backup Strategy

A Trezor hardware wallet user with a standard seed phrase can generate an unlimited number of hidden accounts by adding a passphrase to the device. This feature is powerful: the same twelve or twenty-four words, combined with a passphrase known only to the user, creates an entirely separate wallet tree that shares no addresses with the standard derivation. But importing that hidden wallet into Rabby—or any other software wallet—requires understanding a critical limitation. The passphrase-protected account cannot be recovered through seed phrase import alone. Recovery requires either re-entering the passphrase on the Trezor device itself or accepting watch-only access in the software wallet, neither of which preserves the full hierarchical recovery that ordinary seed phrase import provides.

This constraint matters because many users expect their backup strategy to work the same way regardless of how they add accounts to their wallet interface. A passphrase-protected Trezor account breaks that assumption. If you import your twelve-word seed into Rabby without the passphrase information, the hidden accounts will not appear. If you lose the passphrase, those accounts are effectively inaccessible unless you maintain a separate record—which introduces its own security problem. Understanding the mechanics prevents both operational failure and the false confidence that a written backup can restore everything.

How Trezor passphrases generate separate wallet hierarchies

A Trezor device implements BIP39, the standard that converts a seed phrase into a master private key. From that key, a derivation path—a sequence of numbers and directions—determines which child keys are generated. The standard Trezor derivation for Ethereum accounts follows a specific path, producing the same addresses every time the device is connected using only the seed phrase and the device itself.

A passphrase adds an extra cryptographic input to that process. Instead of deriving keys directly from the seed phrase, the Trezor first combines the seed phrase with the passphrase to create a different master key. That new master key then follows the same derivation path, producing entirely different child addresses. Crucially, the device does not store the passphrase. The user must enter it each time they want to access the hidden accounts. If the passphrase is never written down or backed up separately, knowledge of the seed phrase alone is insufficient to recover those accounts.

This design is intentional. Trezor calls the hidden wallet a “plausible deniability” feature. An attacker who obtains your seed phrase can access the standard accounts but not the hidden ones unless the passphrase is also recovered. Someone with access to your device can see which accounts are in use, but they cannot see the hidden accounts or their contents without the passphrase. The trade-off is that you become the sole holder of recovery responsibility for those accounts. No hardware device, software wallet, or backup service can regenerate them without the passphrase.

Why seed phrase import does not restore hidden accounts

When you import a twelve or twenty-four word seed phrase into Rabby Wallet extension, the software performs a deterministic derivation using the imported words and the standard derivation path. It produces the same addresses that the Trezor generates under normal use. This works perfectly for standard accounts because no additional secret is involved beyond the seed phrase itself.

Hidden accounts require a different input. The passphrase must be known at the time of import, or imported separately, for Rabby to derive the correct hidden addresses. But Rabby’s seed phrase import interface does not include a passphrase field. There is no mechanism to enter the additional secret alongside the seed words. Importing the seed phrase will only recover the standard accounts, not the hidden ones. If you have hidden accounts on your Trezor and you later import only the seed phrase into Rabby, those accounts will not appear in the imported wallet. You will not receive an error message; the software will simply derive and display the standard accounts.

This limitation is not a bug; it reflects a fundamental architecture choice. Rabby is a browser extension designed for user convenience. Prompting every user to decide whether they have passphrase-protected accounts and asking them to enter an additional secret would complicate the import flow and potentially encourage poor passphrase storage practices. The extension therefore defaults to standard import, consistent with how most users interact with their seed phrases.

The consequence is that a user with hidden accounts on Trezor cannot fully restore their wallet by importing the seed phrase into Rabby. If the goal is to access hidden accounts through Rabby, the proper method is to keep the Trezor connected as a hardware wallet integration, connect to Trezor firmware through Rabby’s interface, and then use the hardware wallet to sign transactions. This maintains the security model: the Trezor holds the secret, Rabby facilitates the connection, and the user enters the passphrase on the device when needed.

Hardware wallet integration as an alternative to seed import

Rabby supports hardware wallet integrations including Ledger, Trezor, GridPlus, OneKey, Keystone, BitBox02, and CoolWallet. Connecting a Trezor through this method is different from importing its seed phrase. The hardware wallet remains the sole holder of the private keys. Rabby communicates with the device through a USB connection or the Trezor Bridge software and displays the accounts that the device generates, without ever seeing the seed phrase or passphrase.

When you connect a Trezor to Rabby via the hardware integration, the device can generate both standard and hidden accounts. If you have set up a passphrase on the Trezor, you enter it on the device itself when prompted. Rabby displays the resulting addresses but has no knowledge of the passphrase. This approach works well for frequent use: every time you want to access the hidden accounts, you connect the device, enter the passphrase, and sign transactions through Rabby’s interface. The passphrase is never transmitted to the browser extension or stored anywhere except in your memory or a secure offline record.

The downside is that this method requires the Trezor to be physically connected or accessible through Trezor Bridge each time you interact with those accounts. You cannot use Rabby to send funds from hidden accounts while the device is disconnected. You also cannot switch between the standard and hidden accounts on the same Trezor without physically accessing the device again and re-entering the passphrase, because Rabby can only display one account set at a time based on what the device currently generates.

Watch-only mode as a backup for hidden account monitoring

Some users maintain hidden accounts on a Trezor but want to monitor their balances or transaction history in Rabby without needing the device present. Watch-only mode allows adding an address to Rabby without any private key, seed phrase, or hardware wallet integration. You simply enter the public address directly.

For a hidden account, this means you must first discover the address on the Trezor itself, by connecting the device to Rabby or another interface, entering the passphrase on the device, and locating the generated account address. Once you have that address, you can add it to Rabby as a watch-only account. Rabby will then display the balance and transaction history for that address without any ability to spend funds or see private keys.

Watch-only access is useful for monitoring but does not replace the hardware wallet integration for actually sending transactions. If you later lose the Trezor or the passphrase, the watch-only account in Rabby will still display the balance and history, but you will have no way to move the funds. This is why watch-only mode should never be considered a backup strategy for hidden accounts. It is a supplementary tool for situations where you want convenience monitoring without active signing capability.

Creating a backup strategy that accounts for passphrases

A robust backup for hidden Trezor accounts must address both the seed phrase and the passphrase separately, with different risk models. The seed phrase—twelve or twenty-four words—should be stored in the same way you would back up any seed phrase: written on physical media, secured offline, kept in a safe place, and never photographed or stored digitally. This backup protects your standard accounts and is also necessary as a precondition for recovering hidden accounts if the passphrase is known.

The passphrase itself should be treated as a separate secret. Do not store it alongside the seed phrase. If an attacker discovers both together, the hidden accounts lose their protection. Instead, store the passphrase in a location physically or logically separate from the seed phrase. Some users keep the passphrase in memory, written in a non-obvious location, stored in a password manager, or distributed across trusted individuals with instructions for reconstruction. The method depends on your risk model and how accessible you need the passphrase to be if you become incapacitated or forgetful.

Test your backup strategy in a controlled way before relying on it. On a secondary device, attempt to access the hidden accounts using only your backed-up information. If you are using hardware wallet integration, confirm that you can enter the passphrase on the Trezor and sign a transaction through Rabby. If you are planning to import the seed phrase and passphrase into another software wallet in an emergency, verify that process works while you still have access to your Trezor. This testing should never involve entering the seed phrase or passphrase into a web interface or an unverified application; use only official wallets and documented recovery procedures.

Documentation matters more for hidden accounts than standard ones. A paper note stating “hidden account passphrase stored in [location]” or “hidden account accessible only through Trezor hardware integration” ensures that whoever is managing your recovery—yourself in the future, or a designated heir—knows that these accounts exist and understands the recovery method. Without this note, someone with your seed phrase might assume they have recovered your entire wallet, never suspecting that hidden accounts exist.

Common mistakes that expose hidden account security

The most dangerous error is writing the passphrase next to the seed phrase. This completely defeats the security advantage of the passphrase. An attacker or finder of your backup now has both secrets and can access the hidden accounts. The passphrase is meant to be a second secret, unknown to anyone with physical access to your seed phrase backup.

A second common mistake is relying on a single method to access hidden accounts. If you back up only the seed phrase and assume you will eventually import it into another wallet with the passphrase, you are betting on recovering an accurate passphrase after years of storage. Passphrases are case-sensitive and do not follow word lists; even a single character error makes them useless. Testing your recovery procedure while you are healthy and your memory is clear is the only way to verify that you have recorded the passphrase correctly. Many users discover too late that they recorded a typo or misremembered a character.

A third mistake is failing to document that hidden accounts exist. If you set up hidden accounts on Trezor and then store the Trezor in a safe place, future you—or your family—may not know that hidden accounts exist at all. The seed phrase alone will import only standard accounts, appearing to be a complete backup when it is actually incomplete. A simple document stating “this Trezor contains hidden accounts; recovery requires the passphrase stored [separately]” can prevent funds from being lost forever.

Using the same passphrase across multiple Trezor devices is also inadvisable, though sometimes done for convenience. Each device with the same seed phrase and passphrase will generate identical accounts. That means a compromised Trezor exposes not just the current device’s secrets but also any other devices using the same combination. Better practice is to use unique passphrases for each device, or to accept that one Trezor is the primary keeper of hidden accounts and the others serve different purposes.

Reconciling hidden accounts with Rabby’s account management

Rabby allows users to add addresses and manage multiple accounts in a single interface. This flexibility is useful for consolidating assets across several wallets and devices. But hidden accounts complicate this workflow because they cannot be seamlessly integrated like regular imported or connected accounts. A hidden account must either be maintained on the Trezor device itself (accessed through hardware integration) or monitored as a watch-only address (for balance checking only).

If you use Rabby to manage a large portfolio of accounts, separating hidden accounts mentally is important. Mark them distinctly in your account notes so you remember which accounts are hidden and therefore require Trezor device access for transactions. Some users create a naming convention, such as prefixing hidden accounts with “Trezor Hidden:” to ensure they do not accidentally attempt to move funds from a watch-only version in Rabby, where the transaction would fail because there is no private key available.

The inability to import hidden accounts through seed phrase also affects long-term wallet migration. If you decide to move away from Trezor entirely in the future, migrating hidden accounts is manual and deliberate. You must connect the Trezor, access the hidden account, move the funds to a new wallet or address, and then update your records. This is actually a feature, not a limitation: it forces a careful, audited migration rather than a one-click import that could accidentally misconfigure the hidden accounts or lose track of them.

Frequently asked questions

Can I import my Trezor’s hidden accounts by entering just the seed phrase into Rabby?

No. Rabby’s seed phrase import does not include a field for a passphrase. Importing the seed phrase will only recover the standard accounts. Hidden accounts require either a passphrase entry at import time (not supported by Rabby) or connection to the Trezor device itself through hardware wallet integration, where you enter the passphrase on the device when prompted.

How do I access hidden Trezor accounts if I want to use Rabby?

Connect your Trezor to Rabby through the hardware wallet integration. When the device is connected, Rabby will prompt you to enter the passphrase on the Trezor itself. The device will then generate the hidden accounts, which Rabby can display and use for transactions. Alternatively, add the hidden account addresses to Rabby as watch-only accounts for balance monitoring without signing capability.

What is the safest way to back up hidden Trezor accounts?

Store the seed phrase and passphrase separately in offline locations. The seed phrase should be written on physical media and secured in a safe place, just like any seed phrase backup. The passphrase should be stored in a different location, using a method that prevents an attacker who finds the seed phrase from also discovering the passphrase. Test your recovery procedure on a secondary device to ensure both secrets are recorded accurately before relying on them.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *