Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › If your seed phrase is exposed

Your seed phrase may be exposed: what to do now

By Golan Ben Moshe · Co-founder, Chain Pursuit · 8 min · Last updated 1 October 2026

If there is any reasonable chance someone else has seen your recovery phrase, treat the wallet as permanently compromised and move everything to a new one now. Do not wait for proof. Attackers routinely automate sweeping a known-compromised address, so anything arriving there afterwards is likely gone within seconds. Changing a PIN or password does nothing, because the phrase is the wallet.

Do this now

Read the rest afterwards.

1. Create a new wallet. On a device you trust, with a phrase that has never existed anywhere before. If the device you used might have malware, use a different one.

2. Move everything to it. Every token, every chain, starting with the largest holdings. Do not wait to work out what happened.

3. Do not send anything back to the old address. Not a test amount, not gas to pay for a transaction. Sweeping is automated.

4. Do not bother revoking approvals. Someone with your phrase controls the wallet outright. Revocation is irrelevant here.

5. Treat the old phrase as burned. Do not reuse it, do not fund that wallet again, do not keep it "just in case".

Why certainty is the wrong threshold

People wait because they are not sure. That instinct is backwards here, because the two outcomes are wildly asymmetric.

If you move funds and the phrase was never exposed, you have spent an hour and some transaction fees.

If you wait and it was exposed, you lose everything in the wallet, and probably at a moment you are not watching.

There is no partial compromise. A recovery phrase either is known to someone else or is not, and you usually cannot establish which. Act on the possibility.

What counts as exposure

Any of these means treat it as compromised:

The middle group is where most people fall, and the point that catches them is that a temporary measure outlives the intention. A photo taken to get through a setup step sits in a cloud backup for years.

Moving funds safely

Start with the largest holdings. If you are interrupted, you want the big balances moved first.

Each chain separately. One phrase generates accounts across many blockchains. Check every one you have used, not only the chain where you noticed the problem.

Watch for balances you have forgotten. Staked positions, liquidity provided to a protocol, tokens on a chain you used once, NFTs. Unstaking takes time on some protocols, and it is worth starting that process early.

Keep some gas in the old wallet only long enough to move things. Do not top it up beyond what a transaction needs, and expect anything extra to disappear.

If a token cannot be moved, because it is locked, vesting or staked with a delay, note it and accept you may lose it. Do not delay moving everything else while you solve that one.

What does not help

Changing your wallet password. The password protects the local application. It is not what an attacker would use.

Uninstalling and reinstalling the wallet. Your keys are derived from the phrase, not stored in the app.

Adding a passphrase now. A passphrase creates a different wallet. It does not protect the one already derived from the exposed phrase.

Revoking approvals. Covered above, and worth repeating because people reach for it instinctively. Our guide to revoking approvals explains what it is for.

Contacting your wallet provider. There is no support process, because there is nothing support can do.

After the funds are safe

Work out how it happened, because the same route may still be open. If you entered the phrase on a site, that site may also have installed something. If the exposure was a device, treat the device as compromised until you have dealt with it.

Secure your email, then exchanges. Email controls password resets for everything, and if the same compromise reached your email the problem is larger than one wallet. Check for forwarding rules you did not create.

Set up the new wallet properly this time. Our seed phrase guide covers backup without creating a new exposure, and the cold wallet guide covers hardware setup.

If funds were taken, preserve what you have. Our evidence checklist covers what matters, and the country guides explain which reporting channel can lead to an investigation.

Expect someone to offer to help

Anyone who loses crypto is approached afterwards, usually within weeks. In this category the offer is often specific: a service claiming it can recover a wallet from the address, or restore a compromised phrase.

Neither is possible. A private key cannot be derived from a public address. That is the cryptographic property the entire system depends on, and no amount of computing power changes it.

Read how to spot a crypto recovery scam before replying to anyone.

Red flags in the hours afterwards

Checklist

Immediately

Within the day

What this guide cannot do

Acting fast improves the odds of saving what remains. It cannot recover anything already taken, and in many cases an exposed phrase is discovered only after the wallet is empty. Nothing here guarantees an outcome.

This is general information, not legal or financial advice.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Frequently asked questions

I think I entered my seed phrase on a fake site but nothing has happened. Am I safe?

No. Attackers often wait, either to accumulate victims or until a wallet holds more. The absence of an immediate theft is not evidence the phrase is safe. Move everything to a new wallet now.

Can I just change my wallet password instead?

No. The password protects the local application on your device. Your funds are controlled by the recovery phrase, which anyone holding can use on any device, anywhere, without your password.

Will adding a passphrase protect my existing wallet?

No. A passphrase produces a different wallet entirely. It does not secure the one already derived from the exposed phrase. Use one when you set up the new wallet, if you have a dependable way to remember and back it up.

Should I revoke token approvals as well?

It will not help in this situation. Someone with your recovery phrase controls the wallet directly and does not need an approval. Revocation matters when a malicious contract was granted permission, not when the phrase itself is compromised.

I have tokens staked with a long unlock period. What do I do?

Start the unstaking process straight away, then move everything else without waiting. Note what is locked and when it releases, and set a reminder. You may lose it, and delaying the rest of the move risks losing more.

Can anyone recover my wallet from the address if I tell them the phrase was stolen?

No, and anyone claiming otherwise is running a scam. A private key cannot be derived from a public address. Services promising this are among the most common forms of recovery fraud.

How do I know which chains to check?

Any you have ever used with that address. A block explorer for each chain will show a balance, and some portfolio tools scan multiple chains at once. Check the obvious ones first and work outwards; a forgotten balance on a chain you used once is easy to miss.

Is it worth reporting if nothing has been taken yet?

There is nothing to report until a loss occurs, and preserving evidence is the priority if it does. Focus on moving funds first. If something is taken, report it through the channel in your country that can open an investigation.

Once your funds are safe

Eleven questions showing which documentation and reporting routes are available in your case.

Check my case

Keep reading