Why will nobody legitimate ever ask for your seed phrase?
A seed phrase (also recovery phrase or mnemonic) is a list of ordinary words — usually 12 or 24, though the standard also allows 15, 18 and 21 — that a wallet shows you once, at setup. Unit 3 explains what it mathematically contains. For safety purposes you need one sentence now:
Whoever has those words has the money — immediately, completely, from anywhere on earth, with no further check.
It is not a password protecting an account. There is no account. The words are the wallet. This is why seed-phrase theft is the single highest-yield attack in the entire space, and why it has been industrialised into a set of repeatable scripts.
The documented patterns
Fake support. You post a problem in a public forum, a Discord server, a Telegram group or a social feed. Within minutes, direct messages arrive from accounts using the project's logo and a name like "Support Desk". They are helpful, patient, and eventually need your recovery phrase — or ask you to enter it on a "validation" page — to fix the issue. Real support teams do not initiate direct messages, and no support process on earth requires the phrase.
Wallet-validation and "sync" pages. A site claims your wallet must be verified, synced, migrated or unlocked, and presents twelve input boxes. The form is the entire attack; there is no product behind it.
Fake apps and extensions. Counterfeit wallet apps have repeatedly appeared in mainstream app stores and browser extension stores, sometimes with fabricated reviews. They function normally, and transmit the phrase at setup.
Airdrop and migration lures. "Claim your allocation" or "your tokens must be migrated to the new contract" — followed by a wallet-import screen. Urgency and a deadline are always part of the script, because urgency suppresses checking.
Pre-seeded hardware devices. Devices bought second-hand, from marketplace resellers, or arriving unsolicited, sometimes ship with a recovery phrase already printed on the card. A genuine device generates the phrase itself, on the device, in front of you, on first use. A phrase you did not watch being generated is a phrase somebody else already has.
Your own backups. A photo of the words in your phone gallery is in whatever cloud backs that gallery up. Typed into a notes app, it is on that provider's servers. Emailed to yourself, it is in an inbox protected by a password that has probably appeared in a breach.
The single rule
A seed phrase is typed exactly once: into the wallet software you are deliberately restoring, on a device you control, at a moment you initiated.
Every other prompt — every one, without exception, regardless of how official the logo looks — is an attack. There is no legitimate second reason to enter it. This rule needs no judgement calls, which is precisely why it works under pressure.
The custodial equivalent
If your assets sit on an exchange, the equivalent target is your login. The documented pattern there is the SIM swap: an attacker persuades a mobile carrier to move your number to their device, then resets your password and intercepts SMS codes. This is why SMS is the weakest second factor available, and why app-based or hardware security keys exist.
Try it now
- Say the rule aloud once: "I will never enter my recovery phrase anywhere that asked me to." The phrasing matters — the attacker is always the one who initiated.
- Audit your own storage. Make a list of every place any recovery words exist: paper, metal, photo, password manager, notes app, email. If you cannot complete the list, you do not know how many copies are out there.
- On a public block explorer, search for an address the explorer itself has tagged with a phishing or scam label — Etherscan publishes such tags — and read its inbound transfers. Every one of them was authorised by a person who believed the screen in front of them, and every one is permanent.