What is a seed phrase, in practice?
A seed phrase (also called a recovery phrase or secret recovery phrase) is a list of ordinary words generated when you create a self-custody wallet. Most beginner wallets use 12 or 24 words from a published word list. Those words can recreate the private keys that control your addresses. The phone is replaceable. The app is replaceable. The hardware device is replaceable. The phrase is the backup that brings the same wallet back.
This is why seed phrase safety feels different from a bank login. A bank can reset a password after identity checks. A public blockchain cannot identify you. It only checks that a transaction is signed with the matching keys. There is no “forgot phrase” button.
If keys and addresses still feel abstract, start with keys and wallet addresses. This lesson is the storage and phishing half of that story.
How do you protect a seed phrase?
People searching “how to protect your seed phrase” usually want a short list they can follow the same day they create a wallet. Official wallet makers give the same core rule: keep the words offline, and never type them into a computer or phone except during a restore you started.
MetaMask’s Secret Recovery Phrase guide is explicit: support will not ask for the phrase, and you should not enter it on a website. Ledger’s recovery-phrase article says the same for hardware wallets: a page that wants the words to “sync firmware” or “verify the device” is the attacker, not the product.
Practical beginner rules:
- Write the words on paper or stamp them into metal. Copy the order exactly. Number the lines if it helps you not skip a word.
- Store at least one copy somewhere dry, private, and boring — a home safe, a locked drawer, or another physical place only you (or a planned heir) can reach. Two separate physical locations beat one clever hiding spot that you later forget.
- Do not photograph the phrase. Do not paste it into Notes, WhatsApp, Telegram, email, Google Docs, iCloud, or a password manager that syncs to the cloud unless you fully accept that a compromised account can empty the wallet.
- Never type the words after a search ad, SMS, Discord/Telegram DM, or “wallet will be frozen” banner. Open the official app or device from a bookmark you saved on a calm day.
- Keep the backup away from people who should not be able to move your funds. A roommate, cleaner, or visitor who can photograph a sticky note has the same power as a remote hacker.
This lesson explains how self-custody backups work so you can avoid irreversible mistakes. It does not recommend coins, wallets as investments, or any product. A hardware wallet is a key-storage device, not a way to make money. If you already typed recovery words into a site, treat that wallet as compromised.
Why are screenshots and cloud backups dangerous?
A screenshot feels convenient until you remember how photos actually travel. Many phones upload new pictures to iCloud, Google Photos, or a laptop the next time you plug in. A “locked phone” does not stop a synced album, a shared family plan, or a stolen-device restore onto a new handset. If that account is phished later, the attacker may find the image months after you took it.
The same problem shows up in notes apps and email drafts. Cloud products are designed to be available on every device. That is useful for shopping lists. It is a poor model for a master key. Crypto theft is often quiet: the attacker waits until the balance is worth moving, then drains the wallet in one transaction.
For tiny learning amounts on an app wallet, you may still choose convenience. For anything you would hate to lose, treat the recovery phrase as a physical object, not a file.
What do seed-phrase traps look like in 2026?
These are patterns, not a claim that any one brand was “hacked.” The chain usually worked. The person typed secrets or signed a prompt.
Fake “firmware” or “sync” pages. You search for a hardware-wallet update, click an ad, and land on a lookalike site that asks you to enter 24 words to “re-pair” the device. A hardware wallet’s job is to keep those words off the internet. If a website wants them, close the tab.
Helpful support after you posted a problem. You ask in Discord why a transfer is pending. Minutes later, an account with a logo DMs a ticket link. The form asks for the seed phrase “so we can unlock the wallet.” Real support cannot restore self-custody from those words, and the U.S. FTC cryptocurrency scam briefing treats recovery-for-a-fee follow-ups as a known second trap.
Photo backup you forgot existed. You photographed the setup card “just for tonight,” then deleted the picture from the camera roll. The copy still sits in a recently deleted album, a laptop Photos library, or an old iCloud backup. Treat any phrase that has ever been a photo as weaker than a phrase that only existed on paper.
Clipboard and fake-app stealers. Malware on a phone or PC can copy what you paste. A fake wallet app from an ad can show a normal home screen and still exfiltrate the words you typed at setup. Install wallet software only from a URL you typed, then confirm the publisher name on the brand’s own help site.
For the wider pause-and-compare list (drainers, address poisoning, claim buttons), use wallet scam red flags. For the industry catalog, see crypto scams and phishing.
How should a beginner test a backup?
Honest limit: a perfect backup still cannot undo a malicious signature. If you approve a send or a token permission you do not understand, the phrase will not save those coins. Read wallet approvals before you experiment with new apps.
Do this with an empty wallet or a tiny test amount you can afford to lose:
- Create the wallet on a device you control. Write the words as they appear. Do not type them into anything else.
- Confirm you can still read your own handwriting. If a word is ambiguous, check it against the wallet’s word list while the device still shows the phrase (many wallets let you verify word by word).
- Put the paper away. Then restore: delete the app, or use a second device, and enter the phrase only inside the official restore flow you opened yourself.
- Check that the receive address matches the one you noted before the restore. If it matches, you have a working backup. If it does not, you copied a word wrong — fix the paper before you deposit more.
- Only then move funds you care about. Keep a small experiment wallet separate from long-term storage. Wallet types are explained in hot wallets vs cold wallets.
Advanced extras such as a BIP-39 passphrase (sometimes called a “25th word”) or split backups can hide a second wallet behind the same 24 words. They also create a second secret you can lose forever. Beginners usually add risk, not safety, by stacking extra schemes before the paper backup is boring and reliable.
What if the phrase might already be exposed?
Assume the wallet is burned if the words were typed into a website, sent in chat, photographed and synced, or shown on a video call. Closing the tab does not unsay the secret.
- Do not send more funds to “unlock,” “tax,” or “whitelist” addresses. That is a second scam.
- On a clean device, create a new wallet. Write a new phrase. Never reuse the old words.
- Move what you still control to an address from the new wallet. Start with a tiny test if the amount is large and time allows.
- If you also signed a contract, review approvals on a revoke tool you navigated to yourself — not a link from the scammer. See wallet approvals and token permissions.
- If you are in the United States and lost funds to a scam, you can file a complaint with the FBI Internet Crime Complaint Center (IC3). Filing does not reverse a confirmed transfer.
Live prices on this site do not tell you whether a page is safe. You can open live rates without connecting a wallet. Bookmark the Security pillar and /education instead of search ads.
What should you do when a prompt appears?
| What you saw | Safer next step | Unsafe next step |
|---|---|---|
| A site or chat asks for the 12 or 24 words | Close it. If you already typed the words, create a new wallet and move remaining funds from a device you still control. | Finish “verification,” screenshot the card, or send the list to anyone claiming to be support. |
| You need a backup tonight | Write the words on paper now. Store the paper before you deposit more than a test amount. | Email the phrase to yourself or drop it in a synced notes app “temporarily.” |
| You are restoring a wallet you own | Open the official app or hardware device yourself. Enter words only in that restore screen. | Follow a link from a DM, ad, or email that “starts restore for you.” |
| A hardware wallet screen is asking you to confirm a send | Read the address and amount on the device. Reject if it does not match what you intended. | Approve because the computer window looks official. The device is the last check. |
FAQ
How do I protect my seed phrase?
Keep it offline on paper or metal, in a private place you can still find. Never type it into a website, chat, or cloud note. Only enter it during a restore you started in the official wallet or device.
Can customer support ask for my seed phrase?
No. Real wallet support should never need your seed phrase. Anyone asking for it can move your funds. Compare that pattern with wallet scam red flags.
Should I split my seed phrase into pieces?
Advanced users sometimes split backups, but beginners often lose a piece or make recovery too complex. Keep one complete, readable copy you tested, then add complexity only after that habit is solid.
What happens if I lose my seed phrase?
If the wallet is still open on a device, move funds to a new wallet whose phrase you have already written down. If the device is gone and the phrase is gone, recovery is usually impossible.
Is a screenshot safe if I lock my phone?
A screenshot can still sync to cloud backups, shared albums, and other devices. Prefer an offline copy that never becomes a picture.
Does a hardware wallet mean I can skip this lesson?
No. The device still generates a recovery phrase at setup. If those words leak, the attacker does not need your device. You also still have to read what you approve on the screen.
How do I avoid crypto phishing scams that target recovery words?
Type official URLs yourself. Ignore DMs. Treat any page that wants the phrase as hostile. Connecting a wallet is not the same as spending; spending needs a signature you understand. See crypto scams and phishing.