What Is a Seed Phrase Phishing Scam? Never Do This
Seed phrase phishing scams explained: how fake prompts trick users into entering their recovery phrase, and why no legitimate service ever asks for it.
A seed phrase phishing scam is any attempt to trick a crypto user into typing their wallet's recovery phrase into a website, app, form, or message, giving the scammer complete and irreversible control over every asset secured by that phrase.
A seed phrase — typically 12 or 24 words — is the master key to a crypto wallet. Anyone who has it can recreate the wallet and move its funds anywhere, at any time, with no further verification needed. This makes it the single highest-value target for scammers, and protecting it is more important than almost any other security practice in crypto.
How seed phrase phishing typically presents itself
Fake wallet "sync" or "restore" prompts. A fraudulent site or pop-up claims your wallet needs to be "reconnected," "verified," or "restored" and provides a form asking for your recovery phrase to complete the process. Legitimate wallets never need your seed phrase to reconnect a device that's already set up — restoring a wallet on a new device is the only scenario where you'd ever type it in, and only directly into the official wallet app itself.
Fake customer support requests. As covered in our fake support scam guide, impersonated support staff may ask for your seed phrase to "verify your wallet" or resolve a fabricated issue. No legitimate support interaction, from any exchange or wallet provider, ever requires this.
Fake airdrop or claim forms. Some scam sites disguise a seed phrase input field as part of a token "claim" or "eligibility check" process, sometimes labeling the field ambiguously to obscure what's actually being requested. See our guide on fake airdrop scams for related tactics.
Fake wallet apps. Counterfeit mobile or desktop wallet applications, sometimes distributed outside official app stores, may prompt users to "import" their existing wallet by typing in their seed phrase directly into the fake app's interface, transmitting it straight to the scammer. Our guide on fake mobile wallet app scams covers this in more detail.
Phishing emails and fake security alerts. Emails warning of a supposed security breach or suspicious login, urging the recipient to "verify" their wallet by entering their recovery phrase on a linked page, remain a persistently common tactic.
Why this scam is so damaging
Unlike a token approval exploit, which can sometimes be stopped by revoking access before further funds are drained, a stolen seed phrase gives the attacker permanent, complete control — there is no way to "revoke" a seed phrase or lock the scammer out once they have it. The only real response is to move any remaining funds to an entirely new wallet immediately, since the compromised wallet can never be considered safe again. Our guide on recovering from a hacked wallet covers these steps.
The one rule that stops nearly all seed phrase phishing
No legitimate wallet provider, exchange, support team, or protocol will ever ask you to type your seed phrase into any website, app, form, or message, under any circumstance. The only appropriate place to ever enter a seed phrase is directly into your own wallet's official interface, during your own deliberate restore process on a device you trust — never in response to an unsolicited prompt, warning, or request from someone else.
Legitimate scenarios vs. phishing attempts
| Scenario | Legitimate? | Why |
|---|---|---|
| Typing your seed phrase into your own wallet app to restore it on a new device | Yes | You initiated it, directly into official software |
| Entering seed phrase into a site after clicking a "verify wallet" link | No | No legitimate verification process requires this |
| Support agent asks for seed phrase to "check" your account | No | Support never needs the seed phrase to help |
| A form requests seed phrase to "check airdrop eligibility" | No | Eligibility checks never require wallet control |
| Seed phrase requested to "reverse" or "cancel" a pending transaction | No | Blockchain transactions can't be reversed this way, and no phrase is needed to try |
Bottom line
A seed phrase phishing scam only needs one moment of trust to cause permanent, total loss of a wallet's funds, because the phrase itself is the entire key — there's no password reset, no fraud reversal, and no partial protection once it's been typed somewhere it shouldn't have been. The defense is a single, absolute rule: never enter your seed phrase anywhere except your own wallet's official restore process, initiated by you, and never in response to any unsolicited request, warning, or "verification" prompt. For broader wallet protection habits, see our DeFi wallet security guide.
Related articles
This article is for educational purposes only and is not financial advice. DeFi involves significant risk, including total loss of funds. Always do your own research.