Seed-Phrase and Private-Key Phishing: Why No One Legitimate Ever Asks
Your seed phrase is the master key to your crypto. Anyone who asks for it is trying to rob you. Here is how the phishing works and how to stay safe.
Your seed phrase, sometimes called a recovery phrase, is a short list of words that can restore your entire wallet on any device. Your private key does the same job in a different format. Whoever holds either one controls your funds completely. That is why seed-phrase and private-key phishing is so devastating: it skips every lock and simply asks you to hand over the master key.
What this scam is
Seed-phrase phishing is any attempt to trick you into typing, pasting, photographing, or reciting your recovery words or private key. There is no legitimate reason for a website, app, support agent, or person to ever need them. The entire design of self-custody wallets assumes that only you will ever see those words.
How it works, step by step
1. A believable pretext
The scammer invents a reason that sounds helpful or urgent. Common scripts include “we need to verify your wallet,” “sync your wallet to fix an error,” “validate your account to receive your reward,” or “our security team detected a problem and needs to migrate your funds.”
2. The delivery
The pretext reaches you through a fake support chat, a DM from an account posing as an official helper, a phishing email, a pop-up, or a counterfeit wallet website that appears when you search for help.
3. The input trap
You are shown a form, a chat box, or a fake “wallet restore” screen asking for your twelve or twenty-four words, often one word per box to look technical and legitimate. Some versions ask you to “import” your wallet into a tool by pasting the phrase.
4. Instant theft
The moment you submit those words, the attacker loads your wallet on their own device and empties it. There is no delay, no negotiation, and no undo.
The exact red flags
- Any request for your seed phrase or private key, in any form. This is the one rule that never has an exception.
- “Verify,” “validate,” “sync,” “restore,” or “migrate” your wallet. These words are used to make handing over the phrase sound routine.
- A support agent who messages you first. Real support does not slide into your DMs asking for recovery words.
- A form that accepts each word in its own box. Legitimate wallets restore locally on your device, never through a website.
- Pressure to act before your funds are “lost.” Fear is the tool that makes people paste the phrase.
How to avoid it
Adopt a single, unbreakable habit: your seed phrase never leaves the physical place you stored it. You do not type it into websites, you do not paste it into chats, you do not send it in messages, and you do not read it aloud on calls. The only time you ever enter it is directly into your own wallet app when restoring, and even then only if you started that process yourself.
Store the words offline, on paper or metal, somewhere private. Never save them in a screenshot, a notes app, an email draft, or cloud storage, because malware and account breaches routinely harvest exactly those places. Treat anyone who brings up your recovery phrase as a scammer until proven otherwise, and that proof essentially never comes.
Why this scam is so effective
Seed-phrase phishing works because it hides inside moments when you already feel worried or hopeful. A message warning that your funds are at risk triggers panic, and a message promising a reward triggers excitement, and both emotions make people act before they reason. Scammers also lean on authority, dressing their request in the language of security teams and official procedures so that handing over the phrase feels like following instructions rather than breaking the one rule that matters. Knowing this in advance helps you catch yourself the moment those feelings rise, because the emotion itself is often the first sign that someone is steering you toward the phrase.
What to do if you have shared it
If you have already entered your seed phrase somewhere you should not have, assume that wallet is compromised right now.
- Move funds immediately to a brand-new wallet created with a fresh seed phrase, ideally on a clean device.
- Abandon the exposed wallet. Never reuse it, because the attacker can restore it at any time.
- Scan for malware if you entered the phrase on a device that may be infected.
- Report it to your wallet provider’s official support channel and to your local police and national cybercrime or fraud reporting service.
A promise from us: TokenSpin will never ask for your seed phrase or private key, not to claim a reward, not to verify your identity, not for any reason. If you ever see a message using our name to request it, that message is fraudulent.
Frequently asked questions
Why would a wallet or exchange never ask for my seed phrase?
Self-custody wallets are built so that your recovery phrase stays on your device and is never transmitted anywhere. The provider does not have it and does not need it to help you. Exchanges use accounts and passwords, not your personal wallet seed. Because the phrase grants total control of your funds, any legitimate service treats it as something only you should ever see, which is why a request for it is always a scam.
Is it safe to store my seed phrase in a password manager or photo?
It is far safer to keep it offline on paper or engraved metal. Screenshots, notes apps, cloud drives, and email drafts are common targets for malware and account breaches, and a single compromise there can expose your whole wallet. If you must keep a digital record, understand you are accepting real risk. Most security-minded holders keep the phrase entirely offline and stored privately in more than one physical location.
I typed my seed phrase into a site by mistake. What now?
Treat the wallet as compromised immediately. Create a brand-new wallet with a fresh seed phrase on a device you trust, and move any remaining funds there right away. Do not keep using the exposed wallet, since the attacker can restore it whenever they choose. Scan your device for malware, then report the incident to your wallet provider's official support and to your local authorities.