Skip to content

Nobody Legitimate Will Ever Ask for Your Seed Phrase

7 min read · Verified September 2026

A seed phrase mathematically generates every private key in your wallet, so whoever holds it owns the funds. No legitimate app, exchange or support agent ever needs it, because none of them can do anything useful with it that you cannot do yourself. Any request for it is an attack, without exception.

Most security advice in crypto is a matter of degree. This one is not. There is no legitimate circumstance in which another person or another piece of software needs your recovery phrase, which means the request itself is complete evidence of an attack, before you assess anything else about who is asking.

That absolute is worth understanding rather than memorising, because attackers are very good at constructing the one scenario that seems to be the exception.

What is a seed phrase, exactly?

Twelve or twenty-four ordinary English words, drawn from a fixed list of 2,048 defined in the BIP-39 standard. They look harmless. They encode a large random number.

From that number, your wallet software derives a master key, and from the master key it derives every private key for every account you will ever create in that wallet, across every chain it supports, in a fixed and reproducible order. This is why you can lose the phone, buy a new one, type twelve words, and watch every balance reappear. The wallet was never on the phone. It was in the words.

Which means the phrase is not a password protecting the wallet. It is the wallet. Possession is ownership, entirely and instantly, with no account holder to verify and no institution able to distinguish you from anyone else who can type the same words. There is no reset. There is no fraud department. A transaction signed by a key derived from your phrase is, by every technical definition available, a transaction you made.

A tracker only ever needs a public address. Nothing you paste into one can move funds.

Why does no real service ever need it?

Work through who might plausibly ask.

A portfolio tracker needs to read balances. Reading a blockchain balance requires only the public address, which is already published on a permanent ledger anybody can query. Reading an exchange balance requires a read-only API key issued by the exchange. Neither of those touches a private key, which is the whole reason connecting an exchange read-only is a defensible thing to do at all.

A wallet app you already installed derives keys locally on your device. It asked for the phrase once, during restore, inside software you downloaded and verified, and it does not need to ask again. A wallet that asks a second time, mid-session, through a popup or a web page, is not your wallet.

A support agent, at an exchange or a wallet company or a hardware manufacturer, can do precisely nothing with your phrase except steal from you. They cannot unstick a stuck transaction with it. They cannot restore a lost account with it. They cannot validate, verify, synchronise, migrate or unlock anything with it, because none of those operations exist as described. The vocabulary is invented for the scam.

A hardware wallet manufacturer will never contact you about your phrase, and will never ship you a device with a pre-filled recovery card. If a card arrives with words already on it, someone else generated that wallet and is waiting for you to fund it.

What do the scripts actually look like?

Four patterns cover almost everything, and they are all built around the same trick: creating a moment where handing over the phrase feels procedural rather than catastrophic.

The fast support DM. You post in a project's Discord, a Telegram group or a reply thread describing a wallet problem. Within minutes an account with the right avatar and a near-identical username messages you privately, sympathetic and technically fluent. It walks you toward a "recovery form" or a support portal. Real support does not open direct messages, and the speed is the tell: the accounts monitoring those channels are bots waiting for keywords like "stuck", "lost" or "help".

Wallet validation and migration. A message or a page announcing that your wallet requires validation after a network upgrade, a security incident or a chain migration, with a deadline attached. It presents itself as routine maintenance, which is why it works on careful people. No blockchain has ever required users to submit a recovery phrase for any reason.

The airdrop claim page. You are eligible for tokens. The page asks you to connect your wallet, which is normal enough, then reports an error and offers to "import" or "restore" the wallet manually instead. The manual path is a text box for twelve words. A variant skips the phrase and requests a token approval that grants unlimited spending on your assets, which drains you just as thoroughly with nothing that looks like a seed phrase involved.

Counterfeit apps. A wallet app in an app store that presents a restore screen on first launch and transmits what you type. This is a live and industrialised threat rather than a theoretical one: Kaspersky documented 26 such apps on Apple's App Store in 2026, impersonating Ledger, MetaMask, Trust Wallet and others, several using deliberate misspellings such as "LeddgerNew". Fake crypto apps covers how they reach the stores and how to identify one before you type anything.

Underneath all four sits a fifth vector that never speaks to you at all. Malware on your device that reads the photo library, running text recognition over screenshots looking for word sequences that match the BIP-39 list. A photographed seed phrase in a cloud-synced camera roll is a seed phrase you have published.

I already shared it. What do I do?

Move fast, in a specific order, and accept that some of it may already be gone.

  1. Create a brand new wallet on a clean device. New seed phrase, generated offline where possible, never touching the compromised machine or the compromised phrase. If the exposure came from a device rather than a website, do not trust that device for this step.
  2. Move the highest-value liquid assets first. Native coins, major tokens, stablecoins. Attackers run automated sweeper bots that empty an address the instant anything spendable lands in it, so you are racing software, not a person.
  3. Do not simply send gas to a drained address. If the wallet has no native token left to pay fees, a plain transfer of gas will be swept before your rescue transaction confirms. This is the single most common way people lose the remaining assets while trying to save them. Private transaction bundling exists for exactly this case and is worth researching before you try.
  4. Deal with staked, locked and vesting positions honestly. Anything with an unbonding period cannot be rescued today. Note the unlock date, set a reminder, and expect the attacker to have set one too.
  5. Revoke outstanding token approvals from the compromised address, and treat every address derived from that phrase as compromised, not just the one you used.
  6. Update every tracker and watchlist. Remove the dead address, add the new one, and re-enter anything that was recorded manually. Multi-wallet setup covers keeping the new structure legible rather than accumulating dead addresses.

Then stop and work out how it happened, because the same route is usually still open.

How do I make this a settled question?

Write the phrase on paper or stamp it into metal, store it somewhere fire and flood will not reach, and never let it exist as a photograph, a note, a password manager entry, a cloud document or a message to yourself. Buy a hardware wallet for anything you would be genuinely upset to lose, so that signing requires a physical button press on a device that never exposes the key. Tracking a hardware wallet covers watching those balances by public address without the device ever coming out of the drawer.

Then adopt the one rule that survives every new variant of the scam: you never type the phrase anywhere except into your own wallet software, on your own device, when you are the one who decided to restore it. Everything else is somebody asking.

Common questions

Not quite, and the difference makes it worse. A private key controls one address. A seed phrase deterministically generates every private key for every account in that wallet, across every chain it supports. Giving up one key loses one address; giving up the phrase loses all of them.

That is a legitimate reason to duplicate it, but treat it as duplicating the wallet rather than sharing a password. Anyone holding a copy can spend the funds at any moment without your involvement. Split-secret schemes and sealed instructions with a solicitor exist precisely because a plain copy has no safeguards.

No. Real support responds inside an official ticket or a channel you initiated. Unsolicited direct messages from accounts claiming to be support are the single most common opening move of a seed phrase theft, and they arrive within minutes of any public post describing a wallet problem.

Assume you are not. Malicious pages capture keystrokes as you type, so the submit button is decoration. Treat the phrase as compromised and move the funds.

Yes, and a growing one. Malware families now scan photo libraries with optical character recognition specifically looking for recovery phrases, and cloud photo backups extend that exposure to your cloud account. Write it on paper or metal and delete the image.

Never, under any circumstance. Reading a wallet balance requires only the public address, which is why watching a wallet in a tracker involves pasting a string that is already published on the blockchain.

Watch 15+ blockchains by public address, with no private key or seed phrase involved at any point.

Keep reading

← All guides