Why You Should Never Share Your Seed Phrase — Even with “Customer Support”

One of the most common crypto scams does not involve hacking a wallet at all. Instead, attackers try to convince the owner to hand over access voluntarily. They may pretend to be customer support representatives, warn about suspicious activity, or offer to help restore access to a wallet. At some point, they ask for the seed phrase.

There is one simple rule every crypto user should remember: legitimate support staff do not need your seed phrase. If someone asks for it, you should never provide it, no matter how convincing the message may look.

What Is a Seed Phrase and Why Is It So Important?

A seed phrase, also known as a recovery phrase, usually consists of 12 or 24 words. It is created when many non-custodial crypto wallets are set up and can be used to restore access if a phone, computer, or hardware wallet is lost.

This is exactly why a seed phrase must be protected so carefully.

A password for an app can often be changed. The app itself can be reinstalled. A seed phrase works differently: anyone who obtains it may be able to restore the wallet on another device and gain control over the assets stored there.

The attacker does not necessarily need your phone password, access to your computer, or physical possession of your hardware wallet.

How Scammers Pretend to Be Customer Support

Many scams begin with a message about an alleged problem. The user may be told that someone tried to access the wallet, that the account needs verification, or that an urgent security update is required.

Another common scenario starts when users look for help themselves. For example, someone may post about a transaction problem on a forum or social network. Soon afterwards, an account that appears to belong to official customer support contacts them.

Scammers often use company logos, similar usernames, professional-looking messages, and technical language. Sometimes they start with harmless questions to gain the user’s trust before asking for the seed phrase later in the conversation.

They may claim that it is needed to “synchronize the wallet,” “verify a transaction,” “fix an error,” “confirm ownership,” or “unlock funds.”

The wording may sound technical, but the rule remains the same: customer support does not need a seed phrase to solve these problems.

When Is a Seed Phrase Actually Needed?

A seed phrase is primarily intended for the wallet owner. It may be required when restoring a wallet on a new device or regaining access after a reset.

However, there is a major difference between restoring your wallet yourself and entering a seed phrase on a website sent to you by someone else.

Millpay specialists recommend checking exactly where recovery data is being entered before proceeding. Links received by email, messenger, social media, or in comments may lead to fake copies of legitimate websites designed specifically to steal recovery phrases.

A genuine support team may ask for information such as the wallet app version, a transaction ID, or a public wallet address. None of these requires access to the secret recovery phrase.

What Messages Should Raise Suspicion?

Messages that create a strong sense of urgency should always be treated carefully. Scammers may claim that the wallet will be blocked within a few hours or that funds will be lost unless the user completes an immediate “verification.”

Other warning signs include requests to:

  • provide the 12 or 24 words from a seed phrase;
  • send a photo or screenshot of the recovery phrase;
  • enter the phrase on a website opened from a received link;
  • install an unknown application for “wallet verification”;
  • give someone remote access to a computer.

Millpay experts also recommend avoiding contact details provided by the person who approached you. If there is any doubt, open the wallet provider’s official website yourself and use the support contacts published there.

What to Do If Someone Already Has Your Seed Phrase

If a seed phrase has been sent to another person or entered on a suspicious website, it should no longer be considered secure.

Changing the wallet app password is not enough. The safer approach is to create a new wallet with a new seed phrase and move the remaining assets there as quickly as possible. The compromised phrase should no longer be used.

It is also worth checking the device for malware and trying to understand how the attacker first contacted you. This can help prevent a similar incident in the future.

The Most Important Rule

A seed phrase is intended for the wallet owner, not for customer support. It is not required to verify identity, cancel a transaction, or diagnose a technical problem.

For that reason, any request for a seed phrase should be treated as a serious warning sign. Even if the message looks professional, uses the logo of a well-known company, or includes some of your personal information, the recovery phrase should never be shared.

In crypto, users are largely responsible for protecting their own keys. One of the simplest security rules is also one of the most important: never share your seed phrase with anyone.

Leave a Comment