The framing that causes the damage is treating a seed phrase like a password. Passwords have a reset link and someone to appeal to. This has neither, and once it is out it stays out.
It is not a password — it is the asset
A seed phrase deterministically produces the private keys that control your wallet. Whoever holds it holds the wallet, and there is no account, no provider, and no reset.
The standard behind the familiar twelve or twenty-four word format is public — BIP-39 describes it. The useful consequence to internalise is that the words are not a reference to your wallet held somewhere. They are the wallet, written down.
Leak paths, described as things you actually do
Nobody decides to publish their seed phrase. It leaks through actions that feel like sensible record-keeping.
Every one of these has happened to someone
- Photographing it. Phone galleries sync to cloud storage by default. The photo is now in a service protected by a password and, if you are lucky, two-factor.
- Screenshotting it during setup. Same destination, and screenshots are frequently the first thing shared by accident.
- Typing it anywhere with a keyboard that syncs. Predictive keyboards and clipboard history can retain what you type, and some sync to a vendor account.
- Messaging it to yourself. Saved-messages features feel private and are stored on someone else's servers.
- Putting it in a notes app. Notes sync. That is what they are for.
- Emailing it, even as a draft. Drafts sync too, and mailboxes are a standard target.
- Storing it in a password manager without thinking about it. Better than the above, but it moves the risk to that one master password.
The pattern connecting all of these: anything convenient enough to reach from a second device is convenient enough for someone else to reach. Convenience and exposure are the same property viewed from two directions.
Changing wallet app is not changing wallet
The wallet app is an interface. The wallet is the seed phrase. Delete the app and nothing happens to your assets; import the same phrase into a different app and it is the same wallet.
The consequence that matters: if the phrase has leaked, reinstalling the app changes nothing. New device, new app, new passcode — none of it alters the fact that someone else has the words. The only response is a new phrase and moving assets to it.
A normal thing that looks alarming
Importing the same phrase into two different wallets can show different addresses and a zero balance. Usually the assets are fine — the two apps default to different derivation paths, and the same phrase legitimately produces different sets of addresses.
Do not react by entering the phrase into any site offering to help you find your funds. That is the situation described in the absolute rule below. Switch derivation path in the wallet's advanced settings, or go back to the app you originally used.
Worth separating from all of this: assets on an exchange are not controlled by any seed phrase. Those are governed by an account — password, two-factor, withdrawal settings — and belong to a different set of habits, covered in SMS, authenticator app, hardware key. People who use both should not blend the two mental models.
A hardware wallet does not remove this problem
The common assumption is that buying a hardware wallet retires the seed phrase question. It does not — it changes which half of the question you are exposed to.
What the device genuinely does: it keeps the private key off your general-purpose computer, so malware on that computer cannot extract it, and it makes you confirm transactions on a screen the computer does not control. Those are real protections against a real class of attack.
What it does not do: the device is still initialised from a seed phrase, and you are still told to write that phrase down. That written copy has exactly the same properties as any other — photograph it and it is in cloud storage; type it into a page and it is gone. The hardware protects the key in use. The backup risk is unchanged.
The specific way this goes wrong
A message or page claims your device needs "re-verification", a firmware fix, or a migration, and asks for the recovery phrase. A hardware wallet never needs its recovery phrase entered anywhere except into a wallet during a deliberate restore that you initiated. Not into a website, not into a companion app prompted by a notification, not to support.
People who bought the device specifically to be careful are a valuable target, and the pretext is built around the device itself.
There is one genuine addition hardware brings to this page's subject: many devices support the optional passphrase covered below, and enter it on the device rather than on a computer. That is a real improvement over typing it into software, and it comes with the same permanent, unrecoverable downside if it is forgotten.
Storing it offline, in practice
Write it by hand, on something durable, and keep it somewhere that is not obviously a place where valuables live. That is the whole of the basic method.
Practical details that matter more than they sound. Write legibly and check the word order twice as you go — the error you cannot see is the one that surfaces years later. Record which wallet and which derivation it belongs to on a separate note, not on the same sheet. And keep it away from heat, damp and anything that gets thrown out during a move.
One placement rule that gets overlooked: do not store the written phrase with the device it belongs to. A hardware wallet and its recovery sheet in the same drawer is a single object as far as theft or fire is concerned, and it removes the protection the device was bought for.
The other half of the risk: losing it yourself
There are two ways to lose a wallet, and defending against one usually worsens the other. A single handwritten copy in a drawer has near-zero exposure, and is vulnerable to fire, water, and being mistaken for scrap paper.
More copies means lower chance of loss and higher chance of exposure. There is no optimum, only a trade-off you choose deliberately.
| Approach | Solves | Costs |
|---|---|---|
| One paper copy | Cheap, never online | Single point of failure |
| Stamped or etched metal | Survives fire and water | Costs money; mistakes are hard to correct |
| Two copies, two locations | One loss is not fatal | Two places to secure |
| Split into parts, stored apart | One part found is not enough | Harder to reassemble; one missing part is total loss |
And the step almost everyone skips: verifying the backup. Until you have restored from what you wrote down, you do not know that you wrote it down correctly, and you will find out at the exact moment there is no alternative.
Do it safely: on a clean device, restore using your written copy, confirm the address matches, then remove it. Do not submit the words to anything online, and do not use a "seed phrase checker" tool. That is the next section.
If a hardware wallet offers an official on-device recovery check, prefer that route: the words stay inside the device. Otherwise use wallet software obtained and verified through the wallet's official channel on a reset spare device. Never type the phrase into a website, chat window or unfamiliar app for testing, and do not move assets merely to prove the backup works.
About the optional 25th word
Some wallets support an additional passphrase on top of the seed phrase. Both together are required to derive your wallet.
What it buys: someone who finds the written words alone still cannot open the wallet. Against the "the paper was seen" risk, that is real protection.
What it costs, and this is not a small footnote: there is no recovery for the passphrase. Forget it and the assets are gone exactly as if you had lost the seed phrase. It has no fixed word list to check against either, so a typo produces no error — it silently derives a different, empty wallet.
Should you use one
If self-custody is new to you, not yet. Get the seed phrase handling right first; that step has a better return and a smaller downside. Consider the extra layer once you have a backup routine you actually follow.
If you do use one, treat it as a second seed phrase: offline, redundant, never typed into a web page. Storing it beside the seed phrase means you have added nothing.
The one absolute rule
Other than you personally restoring a wallet in a wallet application, anything that asks for your seed phrase is a scam. There is no exception to check for.
No support desk needs it. No verification process needs it. No airdrop, migration, security upgrade, synchronisation or compensation process needs it. Because the phrase is the wallet, a request for it is a request for the wallet — regardless of how the request is worded.
This rule is valuable precisely because it requires no judgement. You do not evaluate the story, the branding, or how plausible the person sounds. The request itself is the answer.
If you think it may already be exposed
Act on suspicion, not on confirmation
- Create a new wallet with a new phrase, on a device you trust, and move everything of value to it now. Do not wait to establish whether the old phrase actually leaked.
- Treat the old wallet as permanently compromised. Do not send anything to it again, ever.
- Check other wallets derived from the same phrase. They are compromised too, on every network.
- Review approvals on the old address before you stop using it, since an attacker may hold allowances as well — see what that button actually signed.
There is no way to revoke a seed phrase, which is why the response is replacement rather than repair. The cost of moving assets unnecessarily is a transaction fee. The cost of not moving them is everything.