Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case filescams and phishing

Screen Sharing Attacks

A support session where the helpful person asks you to share your screen. Everything they need is visible without them ever touching your machine.

Priya Raman · 2 min read

A variant of the fake support scam that does not require the victim to type anything sensitive.

The sequence

The victim has a problem and posts about it, or is contacted after being identified. A helpful person offers to walk them through the fix.

Rather than asking for a phrase, they suggest a screen sharing session so they can see what is happening.

During the session they ask the victim to open their wallet, navigate to settings, and display the recovery phrase “so we can verify the wallet is correctly configured”.

The victim never sends the phrase. They simply display it, on a screen that is being recorded.

Why it is more effective than asking directly

It bypasses the rule. Most people have absorbed “never share your seed phrase” as never sending it to anyone. Displaying it on a screen does not feel like sharing.

It has a plausible framing. Verification, configuration checking, and confirming the wallet type are all things that sound like legitimate diagnostic steps.

The victim performs the action. There is no request to send anything, which removes the moment where suspicion usually arrives.

The variants

Remote control software. Beyond viewing, the attacker asks for control to fix it faster. This grants full access to everything on the machine.

Reading a hardware wallet screen. The victim is asked to display the recovery phrase on the device during setup, which is a stage where a phrase is legitimately displayed.

Screenshot requests. Asked to send a screenshot of a settings page that happens to include sensitive data.

The rules

Never share a screen with anyone who contacted you. Support you initiated through a verified channel is different from support that arrived.

Never display a recovery phrase on a screen during any session, for any reason. There is no diagnostic that requires it.

Never install remote control software at someone’s request during a support interaction you did not initiate through an official channel.

Legitimate support does not need to see your screen to resolve a transaction issue. They need a transaction hash, which is public.

What legitimate support actually asks for

A transaction hash. An account identifier. Timestamps. A description of what you did.

All of that is either public or specific to an account they already have access to. None of it compromises anything.

If a support interaction moves toward seeing your screen or your phrase, it has stopped being support.

The structural defence

Use venues where support is a ticket system rather than a conversation with an individual who found you.

A ticket raised through an account at an exchange you can actually contact is authenticated by the account itself, which means the support agent already knows who you are and has no reason to ask for anything.

The moment anyone needs you to prove ownership by revealing a secret, you are not talking to support.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

social-engineeringremote-accesssupport

Related cases