Seed Phrase or Private Key Exposed

    Reviewed and updated September 14, 2026 by the SmartCryptoEarnings editorial team · editorial policy

    A recovery phrase is not a password. It cannot be changed, and it reproduces every key and address derived from it. Once anyone else has seen it, every account in that wallet must be treated as theirs.

    Work through the steps below in order. Speed matters, but so does not making the situation worse by creating the new wallet on a device that may be compromised.

    Do this first

    1. Assume the wallet is already drained-capable. Do not wait to see whether anything happens.
    2. Create a brand-new wallet with a completely new recovery phrase. Use a device you trust — ideally a different one from where the exposure happened, or a hardware wallet.
    3. Write the new phrase on paper, offline. Do not photograph it, type it into any app other than the wallet itself, or store it in a password manager screenshot, note, email or cloud drive.
    4. Move assets to the new wallet, highest value first. On account-based networks you need a small amount of the native coin in the compromised wallet to pay each transfer fee.
    5. Move native coins last, since they pay the fees for everything else.
    6. Revoke outstanding token approvals from the old wallet if any remain and you still control it.
    7. Retire the old wallet permanently. Never receive to it again, even for a small amount.

    If the old wallet holds staked, locked or vesting positions you cannot move immediately, a drainer bot may take them the moment they unlock. Plan for that rather than hoping.

    If the device itself may be compromised

    • Do not create the new wallet on the same device until it is cleaned or replaced.
    • A hardware wallet keeps the new key off the computer entirely, which is the strongest option available quickly.
    • Change the passwords for the email accounts tied to any exchange logins, and review active sessions there.
    • Run a full malware scan, and consider a clean reinstall of the operating system if a fake wallet app or a cracked program was involved.

    Common ways phrases get exposed

    • Typed into a website or pop-up that claimed to 'restore', 'validate', 'sync' or 'migrate' the wallet.
    • Photographed, screenshotted, or saved in cloud notes, email drafts or a messaging app.
    • Entered into a support chat with someone impersonating a wallet or exchange team.
    • Stored in a browser-based password manager on a device later infected by an info-stealer.
    • Shown on camera during a screen share or a video call.

    What not to do

    • Do not 'change' the phrase on the same wallet. Passwords and PINs can change; the underlying phrase cannot be rotated in place.
    • Do not send funds to any address that contacted you offering a 'secure vault' or 'safe holding' service.
    • Do not pay a recovery service. Nothing can un-expose a phrase.
    • Do not keep using the wallet because nothing has happened yet — automated sweepers often wait for a balance.

    If funds are already gone

    A confirmed transfer cannot be reversed. Record the transaction hashes, destination addresses, dates and amounts, then report it. US residents can file with the FBI's Internet Crime Complaint Center and the FTC. Reporting does not create an expectation of recovery, but it creates a record that investigators can link to other cases.

    Frequently Asked Questions

    Can I change my seed phrase?

    No. A recovery phrase is the source of the wallet's keys, not a credential layered on top. The only way to get a new phrase is to create a new wallet and move the funds to it.

    I typed my phrase into a site but nothing was taken. Am I fine?

    No. Treat the wallet as compromised regardless of what has happened so far. Stolen phrases are frequently collected and used later, often automatically when a balance appears.

    Does a passphrase (25th word) protect me?

    A separate passphrase creates a different wallet from the same phrase, so accounts behind an unexposed passphrase are not directly reachable. That is a reason to move carefully, not a reason to keep using the exposed setup.

    Sources

    Spotted something out of date? See our corrections policy and fact-checking policy.

    Continue reading

    Educational information only. Nothing here is financial, legal or tax advice.