Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileself-custody failures

Why Screenshotting Your Seed Phrase Is a Terrible Idea

The screenshot leaves your device within seconds. Here is the specific chain of events that turns a convenient backup into a total loss.

Priya Raman · 3 min read

It is the obvious thing to do. The words are on the screen, you have a camera, and writing twelve words by hand feels needlessly primitive.

Here is what actually happens next.

The chain of events

Second one. The screenshot is saved to your camera roll.

Second two to thirty. It syncs to cloud storage. On default settings this happens automatically on every major phone operating system.

From that point. The image exists on at least two devices and one set of servers. It is included in backups. It may be scanned by the photo application’s text recognition, which on most modern phones runs automatically and makes the words searchable.

Later. It is included in any future device migration, appears in shared albums if you use them, and persists after you delete the original, because cloud services keep deleted items for a period.

Your recovery phrase is now in more places than you can enumerate, and each of those places is protected by a password rather than by cryptography.

Why this is different from other passwords

A leaked password can be changed. A leaked recovery phrase cannot.

There is no reset, no revocation, no support line. Anyone who obtains the phrase can reconstruct the wallet and empty it, from anywhere, and you will have no indication that this has happened until it does.

The phrase is also self-contained. Unlike a password, it needs no username, no device, no second factor. Twelve words are the entire security model.

The specific ways this leads to loss

Cloud account compromise. A reused password, a phishing email, a SIM swap defeating SMS-based recovery. The attacker gains access to storage and searches the photo library for text resembling a seed phrase. This is automated.

Malware with photo library access. Several documented families of mobile malware specifically scan images for recovery phrases using text recognition.

Device resale or repair. Insufficiently wiped devices, and repair shops with access to unlocked phones.

Shared devices and accounts. Family plans, shared tablets, a laptop signed into the same account.

Backup exposure. A phone backup restored to a device someone else controls.

None of these requires anyone to target you specifically. Most are automated and opportunistic.

The same applies to

  • Password managers. Better than a camera roll, and still an internet-connected device holding the thing that was meant to stay off internet-connected devices.
  • Notes applications, which sync.
  • Email to yourself, which sits on a provider’s servers indefinitely.
  • Cloud documents of any kind.
  • Photographs of a paper backup, which is the same problem with extra steps.

What to do instead

Write it by hand on paper. Legibly. Check each word against the screen before moving on.

Consider steel for anything substantial. Stamped metal plates cost roughly $30 to $100 and survive fire and water.

Store it away from the device. A fire that destroys your hardware wallet should not also destroy the only backup.

Consider splitting locations. Home and a relative’s safe, so one event does not take both.

Test the backup before funding. Wipe the device, restore from what you wrote, confirm the address matches. This catches transcription errors while they are still fixable.

If you have already screenshotted it

Treat the wallet as compromised, even if nothing has happened.

Create a new wallet with a newly generated phrase, written on paper. Move everything to it. Then delete the screenshot from the device, the cloud, the deleted items folder and any backups.

The order matters. Move the funds first, because deleting the image does not undo the exposure and the old wallet must be considered permanently readable.

For the working balance you use regularly, holding it at a regulated venue such as Collect & Exchange removes the phrase problem entirely for that portion, which is a legitimate trade-off for money you are actively using.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

seed-phrasebackupsecurity

Related cases