Skip to content

Seed phrase theft

Anyone who obtains a seed phrase may recreate the wallet's derived keys and authorise transfers; it is not the app password.

In simple terms — A seed phrase is the recovery phrase from which a wallet can recreate its keys. Someone who obtains a copy may rebuild the derived accounts on another device and authorise transfers.

It is not the password used to open an app and is not the same as one private key. A password protects local access to the wallet app or vault on that installation; the recovery phrase controls the accounts derived from it. Changing the password or PIN therefore does not secure a seed that another person has seen, photographed, or received.

How the phrase is stolen

A fraudster may impersonate support, offer an airdrop, or display a “sync” page that asks for the words. They may also induce someone to store the phrase in a form, chat, or compromised online archive. Follow the maker's instructions: a seed is used only in a verified wallet setup or recovery flow; with a hardware wallet, enter it on the device and never into a generic website or app. No support agent should request it through a message, email, or call.

Seed phrase: one copy exposes derived keys Follow the flow, identify the decisive action, verify through a known channel. False request, Phrase exposed, Accounts at risk, New keys. OPERATIONAL MAP Seed phrase: one copy exposes derived keys Follow the flow, identify the decisive action, verify through a known channel False request: A fraudster invents an urgent or technical reason to make you type the phrase outside the verified wallet. 1 False request Support, airdrop, or recovery page Phrase exposed: A readable copy reveals the recovery secret even when the local application password remains unknown. 2 Phrase exposed Photo, chat, form, or breached storage Accounts at risk: Someone with the seed can recreate derived accounts and sign transfers without using your device. 3 Accounts at risk Keys reconstructed on another device New keys: Changing a password does not repair the seed; remaining assets must move to a securely generated wallet. 4 New keys New wallet and seed, then move the assets Tab or tap: explore the four stages Cyclepedia diagram · Emiciclo
An exposed seed is not repaired by changing the password: remaining assets must move to new keys.
Select the highlighted points to explore the detail

Losing the phrase without another person acquiring it is an access problem, not theft. Signing a malicious approval is instead a possible wallet drainer: it may affect specific assets without exposing the seed. When the whole phrase is compromised, every derived account should be treated as exposed while it still holds funds or continues to be used.

Response to suspected exposure

On a trusted device, create a completely new wallet with a new seed and transfer any remaining assets. Check the address, network, and token before sending, then act with urgency proportionate to the risk without trusting supposed technicians who approached through chat. After migration, do not reuse the old wallet to receive new funds.

Preserve URLs, messages, addresses, and transaction hashes, and report the incident to the wallet provider and relevant authorities. Revoking allowances on the old address may reduce a separate risk, but it does not neutralise the seed: the phrase cannot be changed while keeping the same derived wallet. If only a password or permission was exposed, the response may differ; identify which secret or authorisation actually left your control before acting.

Sources

Anti-scam · Red flags · Phishing · Wallet drainer · Recovery scam