Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If your crypto seed phrase was exposed, assume someone else may be able to reconstruct the wallet. Changing the wallet-app password, deleting a photo, clearing the clipboard, or buying a new hardware device does not make the old phrase secret again. Create a fresh wallet from newly generated recovery material in a trusted environment, then move remaining assets and authority away from the compromised accounts.
Key Takeaways
- Treat viewing, copying, photographing, uploading, or entering the phrase into an untrusted system as exposure.
- Do not reuse the old phrase on a new device; that recreates the same compromised keys.
- Inventory coins, tokens, NFTs, staking positions, approvals, multisignature roles, and contract ownership before migration.
- Prioritize actions by credible attacker access, asset value, transfer time, fees, and contract constraints.
- No recovery service needs the exposed phrase to “secure” it, and nobody can guarantee recovery of assets already transferred.
Exposure is broader than posting all words publicly. Treat the phrase as compromised if another person saw it, a camera recorded it, it was typed into an unfamiliar site or app, malware may have captured it, it entered a cloud note or photo backup, or a support agent asked you to send it.
A partial disclosure may also matter. The risk depends on how many words, their order, any additional passphrase, and the wallet's design. Do not assume missing words make a photographed or copied phrase harmless. Use the wallet provider's security guidance rather than trying to estimate how long an attacker would need.
The exposure may include more than one account. One recovery phrase can derive many addresses across networks. A wallet interface showing only one account does not define the full scope.
Stop typing or pasting the phrase. Disconnect from the suspicious conversation and do not install “cleanup,” “verification,” or “recovery” software. If the exposure happened on a potentially infected computer or phone, do not use that device to create the replacement wallet.
Preserve non-secret evidence: the URL, sender identity, message text, application name, time, transaction hashes, and permissions requested. Do not include the phrase itself in screenshots, reports, email, or support tickets. If a screenshot already contains it, do not upload that screenshot as evidence.
Check whether unauthorized transfers are already visible through a trusted block explorer or wallet view. Viewing public addresses from a separate device is generally safer than signing from the exposed wallet. Remember that a zero balance does not mean every token, NFT, position, or administrative role is gone.
Use a device you control and have reason to trust. If malware caused the exposure, clean or replace the affected system according to qualified guidance before using it for secrets again. Updating one application is not enough evidence that an infected environment is safe.
Obtain wallet software or hardware through the manufacturer's official path. Verify the domain, publisher, device authenticity, and current instructions independently. Do not follow a link sent by someone offering to help with the incident.
Decide whether the replacement should use a hardware wallet, software wallet, multisignature arrangement, or another supported design based on your actual recovery capability. This is not the moment to adopt an unfamiliar complex scheme without testing it.
Create new recovery material using the replacement wallet's documented process. The new seed must be generated independently; importing the old phrase into a new app, resetting a device and entering the old words, or changing a local password preserves the old keys.
Record the new backup offline and privately. Do not photograph it, copy it through a general clipboard, save it in an ordinary cloud drive, or send it to yourself. Confirm the words, shares, passphrase, or other required components exactly as the wallet instructs.
Verify a receiving address on the trusted device display. If the wallet supports multiple accounts or networks, identify the correct account type before sending funds. Keep the new and old addresses clearly labeled so urgency does not cause a transfer in the wrong direction.
The crypto wallet backup guide explains how to separate secret recovery material from non-secret instructions and records.
List what the old seed may control. MetaMask's account migration guidance calls out native assets, tokens, NFTs, and other account relationships that may require separate handling.[2] Your inventory may include:
Record public addresses and transaction identifiers, not recovery words. Check every network you actually used. A portfolio app can help discover items, but verify important positions against the relevant protocol or explorer.
There is no universal order. Consider whether an attacker is already active, which assets can move immediately, which positions require an unlock or withdrawal, whether the old account has enough fee asset, and whether a public transaction will reveal your response.
High-value, liquid assets may deserve early movement, but an attacker monitoring the address may compete for the same funds. Adding fee assets to a compromised account can be taken immediately by an automated sweeper. Do not repeatedly fund it without understanding the chain-specific risk.
Some protocols let you change an owner or withdrawal address instead of closing a position. Others require waiting, unstaking, bridging, or claiming. Follow the official protocol procedure from an independently verified source. If substantial value or active attacker automation is involved, seek qualified incident-response help that never asks for the seed.
Copy the new receiving address from the trusted wallet and verify it on the device display. Compare the beginning and end, the full address when practical, and the network. Clipboard malware can replace addresses, so do not trust a pasted value without device confirmation.
Use a low-value test when time and fees allow, then confirm it on the destination before moving more. A test does not prove every later paste is safe; verify each transaction. Read amount, asset, destination, fee, network, and contract action on the signing device.
MetaMask's incident guidance recommends creating a new wallet on another browser, profile, or device and moving remaining funds, then stopping use of the compromised recovery phrase.[1] Treat this as a security migration, not a transfer to a temporary address that will later import the old seed.
Moving visible tokens may leave control elsewhere. Change multisignature signers, contract ownership, validator withdrawal credentials, protocol delegates, domain or name-service controllers, and recovery roles where the relevant system supports it.
Review token approvals and signature permissions associated with the old address. Revocation can reduce a spender's authority but cannot change the private keys derived from the seed. If the seed itself was exposed, revocation is supplementary; the old wallet is still not a trusted home for assets.
Ethereum.org notes that transactions are generally irreversible and advises users to move assets from compromised wallets, revoke approvals where appropriate, and report scams through relevant channels.[3] Exact tools and consequences vary by network, so verify the contract and spender before authorizing a revocation transaction.
After the inventory is complete, mark the old wallet and seed as compromised. Remove it from routine wallet views where doing so will not destroy evidence, and never use it to receive new funds. Update saved withdrawal addresses, payment instructions, mining or staking payouts, and contacts that might send to the old address.
Do not destroy the only incident record prematurely. Public addresses and transaction history may be needed for tax, legal, insurance, exchange, or law-enforcement reporting. Store those non-secret records separately from the new backup.
Tell trusted senders only what they need: the old receiving address is retired and the new address must be verified through an agreed channel. Never send the new seed as proof.
Report unauthorized activity to the relevant wallet provider, exchange, protocol, or law-enforcement channel as appropriate. Reach each organization independently. Blockchain transfers may be irreversible, but prompt reporting can help an exchange flag deposits or preserve records; it is not a guarantee of recovery.
Beware of follow-up recovery scams. Public posts about lost crypto attract impersonators who promise tracing, hacking, unlocking, or guaranteed recovery for an advance fee. The recovery scam guide explains why private “agents” and secret payment requests are warning signs.
If the phrase entered a clipboard or unknown application, review the clipboard hijacking guide and investigate the device separately. Device cleanup and wallet migration solve different parts of the incident.
No local app password changes the cryptographic keys derived from the old phrase. Create new recovery material and move control to the new wallet.
Do not guess at the remaining security. Phrase length, word position, additional passphrases, and attacker knowledge matter. Follow the provider's incident guidance and migrate if the backup can no longer be treated as private.
No. Copies may remain in backups, trash, synchronization history, caches, notifications, or another person's possession. Deletion reduces further exposure but cannot prove the secret was never copied.
They may require separate transactions, networks, fees, or protocol actions. Include every asset and role in the inventory and verify the destination for each one.
No. Revocation limits specified contract permissions. It does not prevent someone with the seed-derived private keys from signing new transactions.
Do not trust unsolicited help, guaranteed recovery, advance fees, or requests for the seed. Verify any professional independently and define a scope that never transfers secret control.
No. Encryption in transit cannot erase a copied secret, rotate wallet keys, reverse a transaction, or remove an attacker's local copy.
Disclaimer: This article provides general security information, not financial, investment, legal, tax, forensic, or wallet-specific advice. Transactions and migrations may be irreversible; seek qualified help for high-value or active incidents.
[1]MetaMask Help Center, I've been hacked or scammed: https://support.metamask.io/stay-safe/protect-yourself/ive-been-hacked-scammed-unauthorized-transactions-on-my-account/
[2]MetaMask Help Center, Account migration guide: https://support.metamask.io/manage-crypto/move-crypto/transfer/account-migration-guide/
[3]Ethereum.org, Scams and incident support: https://ethereum.org/community/support/scams/
Sources checked 8 September 2026.
Related articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.