In simple terms — A seed phrase is the recovery phrase from which a wallet can recreate its keys. Someone who obtains a copy may rebuild the derived accounts on another device and authorise transfers.
It is not the password used to open an app and is not the same as one private key. A password protects local access to the wallet app or vault on that installation; the recovery phrase controls the accounts derived from it. Changing the password or PIN therefore does not secure a seed that another person has seen, photographed, or received.
How the phrase is stolen
A fraudster may impersonate support, offer an airdrop, or display a “sync” page that asks for the words. They may also induce someone to store the phrase in a form, chat, or compromised online archive. Follow the maker's instructions: a seed is used only in a verified wallet setup or recovery flow; with a hardware wallet, enter it on the device and never into a generic website or app. No support agent should request it through a message, email, or call.
Losing the phrase without another person acquiring it is an access problem, not theft. Signing a malicious approval is instead a possible wallet drainer: it may affect specific assets without exposing the seed. When the whole phrase is compromised, every derived account should be treated as exposed while it still holds funds or continues to be used.
Response to suspected exposure
On a trusted device, create a completely new wallet with a new seed and transfer any remaining assets. Check the address, network, and token before sending, then act with urgency proportionate to the risk without trusting supposed technicians who approached through chat. After migration, do not reuse the old wallet to receive new funds.
Preserve URLs, messages, addresses, and transaction hashes, and report the incident to the wallet provider and relevant authorities. Revoking allowances on the old address may reduce a separate risk, but it does not neutralise the seed: the phrase cannot be changed while keeping the same derived wallet. If only a password or permission was exposed, the response may differ; identify which secret or authorisation actually left your control before acting.
Sources
- MetaMask — Secret Recovery Phrase — Distinguishes recovery phrases, passwords, and keys and explains control over derived accounts.
- FBI IC3 — Fraudulent NFT airdrops — Documents fake airdrops and dApps that induce users to disclose a seed phrase.
- ESMA — Crypto frauds and scams — Notes that legitimate firms do not request seeds or private keys through unexpected contacts.
Related entries
Anti-scam · Red flags · Phishing · Wallet drainer · Recovery scam