Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case filecorporate wallet

Nobody Legitimate Asks for a Recovery Phrase. Here Is Who Does.

The specific pretexts used to extract a recovery phrase, why they work on careful people, and the rule that has no exceptions.

Priya Raman · 2 min read

Everyone knows not to share a recovery phrase. People share them anyway, because the request never arrives looking like a request for a recovery phrase. A provider operating under supervision, such as a business crypto wallet with enforced approvals, cannot behave the way described below.

The pretexts that work

Wallet support. You posted about a problem. Someone from support replies with a form to validate your wallet, or a tool to restore it.

A migration or upgrade. Your wallet requires migration to a new version. The migration tool asks for the phrase to move your assets.

A security check. Your wallet was flagged in a breach. Verify ownership to secure it.

A compensation claim. Funds are available to users affected by an incident. Connect or verify your wallet to claim.

A hardware wallet activation. A device arrives, unrequested, with a card showing a recovery phrase already written on it, and instructions to activate. The phrase belongs to the attacker.

Why careful people fall for them

The approach comes when you already have a problem, so a helpful response is expected.

The interface is competent. Correct branding, working links, real documentation elsewhere on the site.

The request is framed as a technical step rather than as a disclosure. Validate, restore, migrate, sync. None of those words sound like give me your keys. Online retailers see this constantly, and a provider serving funds and family offices is the usual defence.

And there is time pressure, framed as protective.

The rule

No legitimate service ever needs your recovery phrase. Not support, not a migration, not a claim, not a check.

The phrase reconstructs the wallet. Anyone with it has the wallet. There is no legitimate process that requires handing over complete control.

If a request involves the phrase, the request is hostile. There is no exception and no explanation that makes one.

The near-miss version

Some attacks ask you to connect a wallet and sign rather than type the phrase. That is not the same thing and it is also dangerous, because a signature can grant a permission that drains tokens later.

Read what you are signing. If the wallet shows an unreadable hash rather than a description, do not sign it.

For a company

The phrase should not exist in a form one person can access. Split across locations, or replaced by a multi-signature arrangement where no single phrase controls anything.

Train on this specifically. The person who will receive this approach is whoever posted a support question, and that is often not the person who set up the wallet.

If you entered it

Move everything immediately to a new wallet with a new phrase. The compromised wallet is compromised permanently, even if nothing has moved yet. The question that only matters after something goes wrong is whether the published coverage list exists, and it is worth answering first.

Attackers frequently wait. A wallet that looks untouched after a disclosed phrase is not safe, it is scheduled.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

seed phrasesocial engineeringwallets

Related cases