Public blockchain data only — we never ask for seed phrases, private keys or upfront fees.
No wallet data stored Runs in your browser
All prevention tutorials
Prevention Tutorial 02 2026-09-21 · 8 min read
Wallet Security Seed Phrase Safety: The 7 Rules That Make Wallet Draining Impossible

He Asked for 12 Words. Three Minutes Later My Wallet Was Empty

Your seed phrase is the whole wallet. These seven rules make it unstealable.

Safety note: we never guarantee recovery and never ask for seed phrases, private keys, crypto payments or upfront unlocking fees. Anyone who does is running a second scam.
The short version

What this tutorial says in five lines

  • The seed phrase IS the wallet — whoever has it owns everything, forever.
  • No legitimate service ever needs it: not support, not recovery, not verification.
  • Typing it into any website, even a real one, is a permanent handover.
  • A photo of it in your gallery is a copy of your entire net worth.
  • Hardware wallets keep the seed offline; that is their entire value.

Why this matters

Wallet draining does not usually involve breaking encryption. It involves asking, and being given. The twelve or twenty-four words behind your wallet are not a password — they are the private key itself, expressed in a form a human can write down. Understanding that one sentence removes almost all of the risk, because it tells you when a request is legitimate (never) and when it is theft in progress (always).

What a seed phrase actually is

A wallet does not store your coins. The coins live on the blockchain, assigned to addresses. What the wallet stores is the key material that proves those addresses are yours — and the seed phrase is that key material in plain language.

This has a consequence people find hard to internalise: there is no "reset password", no account recovery, no support line that can restore access. Whoever holds the words holds the wallet. That is true for you, and equally true for anyone you give them to.

Blockchain data cannot identify a thief. Once funds leave your address, the ledger records the movement, not the person. Prevention is the only reliable defence.

The seven rules

Treat these as absolute. Every rule exists because a real category of victim lost money by breaking it.

The seven rules, and the specific attack each one defeats
RuleWhat it saysAttack it defeats
1Never type your seed phrase into any website, app, form or chatPhishing pages and fake "wallet restore" screens
2No support agent, anywhere, ever needs itImpersonation of exchanges, wallets and "recovery" services
3Never photograph it or store it in cloud notes, email or messagesDevice compromise, cloud breach, shared-album leaks
4Write it on paper or metal, offline, in one place you controlDigital copies are copies; copies leak
5Never split it "for safety" across people or places you do not fully controlSocial engineering of a partial holder who then collects the rest
6Use a hardware wallet for meaningful amounts — the seed never touches the internetMalware, clipboard hijackers, malicious browser extensions
7Create a fresh wallet if the phrase was ever exposed, even brieflyAny exposure is permanent exposure; there is no "probably fine"
The seven rules, and the specific attack each one defeats

Who asks for it, and why the script always sounds reasonable

The request is always framed as a technical necessity or a safety measure, because a direct request would be refused instantly. These are the recurring framings, taken from published victim reports and consumer warnings. Note that the required response is identical in every row.

Common seed-phrase requests and the honest response
The requestThe framing usedWhat is actually happeningYour response
"Validate your wallet to fix the sync error"Technical supportA cloned wallet interface is harvesting the phraseHang up. No legitimate sync fix needs your seed.
"We need it to verify ownership of the funds"ComplianceOwnership on-chain is proven by signing, never by revealingRefuse. Ownership needs a signature, not words.
"Enter it to claim your airdrop"Free moneyA drainer contract or phishing page takes everythingIgnore. Real airdrops never ask for a seed.
"Type it into this migration portal"UrgencyA fake portal under your real wallet's nameCheck the domain. Then do not proceed anyway.
"I will help you recover — just share it"RescueA second scam targeting the same victimRefuse. A recovery agent with your seed takes the rest.
"Enter it to unlock staking rewards"YieldA drainer with a staking coat of paintRefuse. Staking needs a signature.
Common seed-phrase requests and the honest response

How much of your exposure is digital right now

Most people who believe their seed phrase is "written down somewhere safe" have at least one digital copy they have forgotten about. This is the audit that matters most, and it takes about four minutes. The figures below are the relative contribution of each storage method to reported wallet-drain incidents in public victim disclosures where the exposure route was identified.

Data

Where exposed seed phrases were stored when funds were drained

Share of identified exposure routes in public victim disclosures

Typed into a website or form 46
Screenshot or photo in gallery 19
Cloud notes, email or chat to self 15
Given to a "support agent" 12
Password manager or clipboard 5
Paper only, never digitised 3

Reading: The last row is the point of this chart. Paper that was never photographed is the only storage method that produced almost no identified drain incidents.

If you think your phrase is exposed, act in this order

Do not tidy up first. The correct sequence is short and time-critical, because a copy in someone else's hands is usually spent within hours.

  • 01Create a brand-new wallet from a brand-new seed phrase, generated offline on a device you trust.
  • 02Move every asset to the new address immediately — native coins first, then tokens, then anything staked or locked that you can unstake.
  • 03Revoke token approvals on the old address from a block explorer, so no contract can pull remaining balances later.
  • 04Abandon the old address permanently. Do not reuse it even if the balance reads zero — the phrase is public to whoever saw it.
  • 05If funds were already taken, stop treating it as a wallet problem and start treating it as an evidence problem: record the outgoing transaction hashes and report them.

This is the one prevention tutorial with an emergency step. Do it in the order above: new wallet, move, revoke, abandon, then document.

Setting up so this cannot happen again

Once recovery matters less than the rules, the setup becomes simple.

  • 01Use a hardware wallet for anything you would be upset to lose, and keep the seed offline from the moment it is generated.
  • 02Keep a small "hot" wallet with pocket change for new sites, and never let a large balance touch a page you have not verified.
  • 03Write the phrase on metal if the amount justifies it — paper survives a drawer, not a flood or a fire.
  • 04Never let a site or a person walk you through "restoring" a wallet. Restoring is something you do alone, offline, from your own written copy.

The visual summary

Everything above, reduced to the four stages that matter for this topic. If you only look at one thing on this page, look at this.

Infographic supporting Seed Phrase Safety: The 7 Rules That Make Wallet Draining Impossible
Seed Phrase Safety: The 7 Rules That Make Wallet Draining Impossible — supporting infographic
Stage map

Where this fits in the pattern

01

Before contact

Nothing has happened yet. This is when every tutorial here is most useful and costs you nothing but reading.

02

During the approach

The script is running. The verification tests in this tutorial are designed to be run here, neutrally, without confrontation.

03

At the money request

The decisive moment. Any request for funds, fees, taxes or unlock deposits is the end of the script, not a stage of it.

04

After a loss

Prevention is over; evidence work begins. Preserve, report, and never pay a second fee to recover the first.

Common questions

No. A seed phrase is generated with the wallet and cannot be rotated. The only safe response to exposure is to create a new wallet with a new phrase and move your assets.
It is better than a screenshot or a note in your email, but it is still an online copy. For meaningful amounts, offline written storage plus a hardware wallet is the stronger arrangement.
Partial disclosure is still disclosure. Treat it as fully exposed, because the remaining words can be guessed or obtained from the same person later.
Next step

Check whether a stolen address can be traced

If funds have already moved, paste the destination address into the tracer and build the evidence bundle for your report.

Primary sources and further reading

External links open in a new tab so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.

Share this tutorial

Prevention only works if it reaches people before the contact does.

Disclaimer: this tutorial is general information, not legal, financial or recovery advice, and is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.