Advertisement
If someone gets your crypto wallet’s recovery phrase, they may be able to take control of the wallet and move its assets. If you lose the phrase, the wallet provider may not be able to restore access for you.
This makes the recovery phrase one of the most important security responsibilities in cryptocurrency. It is not a password you can reset through email, and it is not information you should send to customer support, friends or anyone claiming to offer technical help.
Advertisement
This guide explains what a recovery phrase is, where to keep it, how to recognise scams and what to do if you think it has been exposed.
Table of Contents
What is a recovery phrase?
A recovery phrase, also called a seed phrase or secret recovery phrase, is a group of words generated when you create a self-custody crypto wallet. The phrase is used to recreate access to the wallet and the accounts associated with it.
The exact number and arrangement of words matter. Changing one word, leaving out a word or writing the words in the wrong order can prevent recovery.
Anyone who has the complete phrase may be able to access the wallet, even if they do not have your phone, wallet app or device. For this reason, treat the phrase like the master key to your digital assets.
First decision: exchange account or self-custody wallet?
Not every crypto account uses a recovery phrase in the same way. A custodial exchange account is managed by a service provider. You normally sign in with an email address, password and additional security controls. A self-custody wallet gives you control of the wallet keys, but also makes you responsible for protecting them.
Before following instructions, identify which type of account you are using:
- Exchange account: secure the account with a strong, unique password, multi-factor authentication and protection for your email account.
- Self-custody wallet: protect the recovery phrase and private keys. The wallet provider generally cannot reset the phrase for you.
- Hardware wallet: the recovery phrase is created during setup and should be recorded offline. The device PIN protects the device, but it does not replace the recovery phrase.
Never enter a recovery phrase into an exchange website, online form or ordinary website simply because a message tells you to do so.
How to store your recovery phrase safely
1. Record it privately during setup
When a trusted wallet application or hardware wallet generates the phrase, write it down carefully in the correct order. Check every word and spelling before continuing. Set up the wallet in a private place where nobody can see your screen or paper.
Do not photograph the phrase. Avoid saving it in your phone’s notes, email, cloud storage, messaging apps or password manager unless you fully understand the security risks and the wallet manufacturer specifically recommends a suitable approach. A phone, computer or cloud account can be hacked, lost or accessed by another person.
2. Keep an offline backup
Paper can work if it is kept dry, protected from fire and stored where unauthorised people cannot find it. For longer-term storage, some users choose a suitable metal backup designed to withstand physical damage. The important principle is that the backup should remain offline and private.
Do not store the phrase in an obvious location labelled “crypto recovery phrase”. Avoid hiding it where visitors, workers or other household members can easily discover it. At the same time, do not hide it so cleverly that you may forget the location.
3. Consider more than one secure location
A single backup can be destroyed, lost or stolen. A second backup may reduce the risk of permanent loss, but every additional copy creates another opportunity for exposure.
If you create more than one copy, place them in separate, secure locations. Do not give a complete copy to an untrusted person. If you are planning for inheritance, use a carefully considered legal and family arrangement without revealing the phrase casually or storing it in an accessible document.
Never share the phrase with “support”
One of the most common crypto scams begins with an urgent message. A person may claim that your wallet is frozen, your transaction has failed or your account requires verification. They then ask for your recovery phrase, private key or a screen recording.
That request is a major warning sign. Legitimate wallet support should not need your recovery phrase to inspect a transaction or solve an ordinary app problem. A real support representative should not ask you to transfer funds to a “secure” wallet either.
Be cautious with:
- Direct messages on social media offering wallet support.
- Search advertisements or websites that imitate a wallet brand.
- Giveaways that ask you to send crypto first.
- Messages claiming your wallet will be closed unless you act immediately.
- Fake browser extensions, mobile applications or links sent through messaging apps.
- People offering to recover lost funds in exchange for an upfront payment and your wallet details.
Use the wallet provider’s official website or application store listing to find support instructions. Do not rely on a link sent by a stranger.
Protect the devices around your wallet
Recovery-phrase security is only one part of wallet safety. Update your phone, computer, browser and wallet application through trusted channels. Use a screen lock and avoid installing unknown applications or browser extensions.
For exchange accounts, use a password that is unique to that account and enable multi-factor authentication where available. Protect the email address connected to the account because control of your email can help an attacker reset other accounts.
Be careful when using public Wi-Fi, shared computers and internet cafés. Never paste a crypto address from an unknown source without checking it. Malware can sometimes replace a copied wallet address with an attacker’s address.
A safer transaction workflow
Before sending a large amount, slow down and check each important detail:
- Open the wallet or exchange using the genuine application or website.
- Confirm the recipient’s address through a trusted channel.
- Compare the beginning and end of the address, and check as much of the full address as practical.
- Confirm the network. Sending an asset through the wrong network can create serious recovery problems.
- Review the amount and transaction fee before approving.
- For a new recipient or a large transfer, consider sending a small test amount first.
- Keep your transaction confirmation, but do not share private wallet information publicly.
A familiar-looking address is not proof that it belongs to the intended recipient. Confirm it independently, especially when payment instructions arrive by WhatsApp, Telegram or email.
What if your recovery phrase has been exposed?
Act quickly, but do not panic or respond to people offering instant recovery. If the phrase was photographed, typed into a website, sent to someone or stored in a compromised account, assume the wallet may no longer be safe.
Using a trusted device, create a new wallet with a new recovery phrase. Write down the new phrase offline and verify it carefully. Move remaining assets to the new wallet, checking the network and destination address before approving each transaction. Do not reuse the exposed phrase.
If the wallet is connected to decentralised applications, review and remove connections you do not recognise. Depending on the asset and network, you may also need to consider token approvals or permissions. If you are unsure, consult the wallet’s official documentation or a reputable security professional without disclosing the phrase.
If funds have already been stolen, preserve transaction IDs, wallet addresses, screenshots and messages. Report the incident to the relevant platform and appropriate authorities, but be realistic: no person can guarantee that stolen cryptocurrency will be recovered.
A simple security check
- Is the recovery phrase written offline and kept private?
- Have you avoided photographing or uploading it?
- Do you know whether your account is custodial or self-custody?
- Is your email account protected with a unique password and multi-factor authentication?
- Do you verify wallet addresses and networks before sending?
- Would you recognise a fake support message asking for secret information?
- Do you know where your backup is without making its location obvious?
The safest rule is straightforward: your recovery phrase should remain secret, offline and under your control. No promised profit, urgent warning or supposed support request is a good reason to reveal it. In cryptocurrency, protecting the phrase is not an extra technical task; it is the foundation of protecting the wallet itself.
Advertisement

