A seed phrase is a list of 12 or 24 ordinary words that regenerates every private key in your wallet. Anyone holding those words holds the money. There is no password on top, no support line, and no undo.

That is the definition. Most guides stop there and tell you to store it safely.

This one covers what to do when that has already gone wrong, because the order of your next few actions decides how much you keep.

What it is, briefly

Your wallet does not store coins. It stores keys, and those keys are derived mathematically from the seed phrase.

Type the same words into any compatible wallet, anywhere, and the same accounts appear. That portability is the feature and the danger in one.

The words come from a fixed list of 2,048, which is why they are always ordinary and always lowercase. Full definition in the glossary, and how to store one covers the storage side properly.

How exposure usually happens

Not by someone guessing. By you entering it somewhere:

  • A fake wallet-support page asking you to “validate” or “sync”.
  • A phishing site cloned from a real wallet’s domain.
  • A photo of the phrase in a cloud-synced camera roll.
  • A password manager or notes app that got breached.
  • A “wallet recovery” service that asks for the phrase to help you.

Nothing legitimate ever asks for your seed phrase. Nothing. There is no exception, and the exception you are thinking of is the attack.

If it has leaked: the first 10 minutes

Assume the attacker already has an automated script watching the address. They usually do.

1. Do not move funds to a wallet you made from the same phrase

This is the most common fatal mistake. Every account in that wallet — every coin, every chain, every “account 2” — comes from the same phrase. Moving assets between them moves nothing out of reach.

2. Create a brand-new wallet on a clean device first

New phrase, written down offline, before you touch the compromised one. If the device itself may be infected, use a different one.

3. Move the highest-value asset first, not the easiest

People instinctively move the small, simple balance to “test”. That wastes the window. Send the largest holding first.

4. Watch out for the gas trap

Attackers often run bots that sweep the native token the instant it arrives, so you can never fund a transaction to rescue the tokens.

If that is happening, moving assets out normally will not work. This is the situation where a specialist recovery service using private transaction relays is a legitimate option — but only ones you found yourself, never one that contacted you.

5. Revoke approvals only after the assets are out

Revoking approvals costs gas and time. It matters, but not before the balances are safe.

What you cannot save

Being straight about this:

  • Staked or locked assets with an unbonding period. If unlocking takes days, the attacker will be there when it completes.
  • NFTs, if the bot sweeps gas faster than you can transfer.
  • Anything already gone. Transactions do not reverse.

What to do after: document the addresses and transaction hashes, report it, and expect a second wave of “recovery” offers targeting you specifically. The first 24 hours covers the reporting side.

The habit that makes all of this survivable

Use more than one wallet, generated from different phrases.

One for holding, rarely connected to anything. One for interacting with apps, holding only what you are willing to lose that week.

A compromise then costs you the second wallet instead of everything. Setting up a wallet safely walks through it.

What to do next

If nothing has gone wrong yet, check one thing right now: is a photo or a text copy of your phrase anywhere on a device that syncs to the internet? Camera roll, notes app, email drafts, password manager.

If yes, that is your afternoon. Move the funds to a fresh wallet and delete the copy — in that order.

Educational content only, not financial or security advice. Wallet recovery outcomes depend on circumstances no article can assess. Disclaimer