Seed phrase phishing
Definition
Seed phrase phishing is a scam that tricks you into entering your recovery phrase into a fake site or form, handing over full wallet control.
Seed phrase phishing is a specific, high-impact form of phishing aimed at one prize: your seed phrase. Because the phrase can regenerate every private key in a wallet, an attacker who obtains it can rebuild the wallet on their own device and take everything, with no further trick required. The scam simply persuades you to type the words somewhere the attacker can capture them.
Why it matters
The tactics are varied but share a pattern of manufactured urgency or false legitimacy: a fake “wallet validation” or “sync” page, a counterfeit support agent asking you to “verify” your phrase, a bogus migration or airdrop that demands the words, a malicious browser extension, or a pop-up warning that your wallet is compromised. Some fake wallet apps exist only to record any phrase entered during “import.” Once the phrase is captured, the loss is total and irreversible.
Common misunderstanding
The core misconception is that there is ever a legitimate reason to type your phrase into a website, chat, form, or support tool. There is not. A genuine seed phrase is used only to set up or restore a wallet within the wallet software itself, on your own device, and it should never be entered online, photographed, stored in the cloud, or shared with anyone. Any request to “enter,” “verify,” “validate,” or “sync” your phrase is, by definition, an attack. Treat the phrase as the one secret that never leaves offline storage. If a message pressures you to enter it urgently, that pressure itself is the clearest sign of a scam.
Related terms
Frequently asked questions
Is there any safe reason to type my seed phrase into a website?
Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.