SaveSaveSaveSave
← All guides

Guide · Wallet risk · September 2026

The Twelve Words

The single most expensive message in crypto, taken apart line by line.

The message arrives polite.

The logo matches.

The link opens a page that looks exactly like the wallet you already use—the same colours, the same typeface, the same quiet illustration in the corner.

It asks you, calmly, to confirm your recovery phrase so that access can be restored.

There is no situation in which that request is legitimate.

Not support. Not a migration. Not an airdrop. Not a security check. Not a refund. Not a validation.

Not once. Not ever. By anyone.

That is the entire article, really. Everything that follows simply explains why the request still works so often.

1. What the twelve words actually are

Most people treat their recovery phrase as a password. That single category error is the root of almost every subsequent disaster.

A password guards an account that someone else already holds. Lose the password and you reset it. The account survives.

A recovery phrase is different.

It is the master number from which every one of your private keys is generated. Your wallet takes those twelve (or twenty-four) words, converts them into an extremely large integer, and derives every address you will ever control on every chain the wallet supports—including chains you have not yet used.

The phrase is not a key to a door.

It is the material from which the doors themselves are made.

What the recovery phrase controls Twelve words at the top derive every address the wallet holds, on every supported chain, including addresses not yet created. Anyone holding the words holds all of it. your recovery phrase 1 ····· 2 ····· 3 ····· 4 ····· 5 ····· 6 ····· 7 ····· 8 ····· 9 ····· 10 ····· 11 ····· 12 ····· derives every address you have · on every chain the wallet supports · including accounts you have not created yet · every token, every NFT, every balance · now, and everything you add to it later A password guards an account. This is what accounts are made from.
There is no “small” leak of a recovery phrase. There is no partial version of holding it.

2. Why nobody legitimate ever asks

Support cannot use it. A wallet provider never holds your funds and therefore cannot move them on your behalf; that is the design. Handing a support agent your phrase would hand them complete control of your money. No competent company permits that request.

A migration cannot require it. Moving to a new contract or a new app version happens on-chain, or by you re-importing the wallet yourself, on a device you control.

An airdrop cannot require it. Sending tokens needs only your public address—the one you paste into forms. Receiving never demands proof that you can spend.

A security check cannot require it. Proving ownership is done by signing a message; the signature confirms control without ever revealing the keys.

A refund cannot require it—least of all a refund for a previous scam.

Every one of those products exists. None of them has ever needed your recovery phrase, because the phrase does not authenticate you. It replaces you.

This is not only our claim. MetaMask's own support documentation states the rule plainly: “if anyone asks for your Secret Recovery Phrase, they are trying to scam you” — a wallet vendor saying, about its own support team, that the request itself is the proof.

3. Five costumes, one request

The stories change. The final sentence does not.

Five stories, one request Support, migration, airdrop, security alert and scam compensation are five different framings that all end in the same request for a recovery phrase. Support "let us help you restore access" Migration "re-validate for the new contract" Airdrop "verify to claim your allocation" Security alert "suspicious login, confirm it's you" Compensation "we refund scam victims" "enter your 12-word recovery phrase" Five different reasons to be reading. One sentence at the end of all of them. The story is decoration. The request is the attack.
Learning the five common stories is useful. Learning that the last line is always identical is what actually protects you—including against a sixth story that has not been written yet.

4. Here is one

Read it the way you would at half past eleven at night, on a phone, after being told something is wrong with your money.

Wallet Security Notice We detected an unrecognised sign-in attempt on your wallet from a new device earlier today. As a precaution your account has been placed in limited mode. To restore full access, please confirm ownership by entering your 12-word recovery phrase at the secure link below: https://wallet-support.verify-restore.example.com/unlock Accounts not confirmed within 24 hours may be permanently locked and any remaining balance moved to protective custody. Thank you for helping us keep your assets safe. Wallet Security Team

This is representative of real campaigns documented by security researchers and wallet vendors. The wording, urgency, invented restrictions, and recovery-phrase request appear repeatedly in phishing messages targeting MetaMask, Trust Wallet, hardware-wallet users, and generic “crypto wallet” recipients. Live versions use different brand names and domains; the underlying request does not change.

Show me what is wrong with it

The request itself is the entire answer. Everything else is secondary. Still, it is worth noticing how carefully the packaging is constructed:

  • “Limited mode” and “protective custody” are invented states. Real wallets do not have them. They sound like banking language because banking is where people have learned to expect such language.
  • “Within 24 hours” is the clock—placed there specifically to stop you asking anyone else.
  • The address reads left-to-right as trustworthy. wallet-support is only a subdomain and carries no authority. The part that actually decides where you land is verify-restore.example.com. Always read a URL from the right.
  • The spelling is perfect. The grammar is correct. There is nothing left to catch by surface inspection.

And one line stranger than it first appears: “confirm ownership.” Your recovery phrase does not confirm ownership to anyone. It transfers it.

5. Why the spelling test stopped working

For two decades people were taught to spot fraud by its seams—broken English, a mismatched logo, a greeting that begins “Dear Customer.”

That advice made sense when producing a convincing page was expensive.

It is now free. Fluent text in any language can be generated in seconds. Copying a website’s exact appearance has never been difficult; the design is public by definition.

A message that looks professional therefore tells you nothing about its legitimacy. It only tells you that someone spent a few minutes.

What has not changed—and cannot change—is what the attacker needs. They need the words. Whatever else they invent, they must eventually ask for them.

Stop grading the presentation. Read the request.

6. Why there is always a clock

Every version of this message contains a deadline: twenty-four hours, end of day, before the account is suspended.

The clock is not there to hurry you. It is there to prevent the single action that reliably collapses the attack: telling another person. Spoken aloud to almost anyone—a friend, a forum, a search engine—the request evaporates. A deadline forces the decision to be made alone.

The deadline is therefore not a detail of the story. It is load-bearing. When you notice one attached to a request for secrets, that observation is itself the finding.

7. Where the phrase should live

Briefly, because the rule is simple.

You type your recovery phrase in exactly one situation: restoring a wallet into software you installed yourself, on a device you control.

Never into a web page.

Never into a form that arrived in a message.

Never into a chat, a support ticket, a spreadsheet, a photograph, a password-manager note, or an AI assistant.

If you use a hardware wallet, the phrase should never be typed into a computer at all after the day you first wrote it down.

8. If you already entered it

Then this section is the only part that matters, and speed matters more than neatness.

Assume that wallet is gone and act on the assumption immediately. Do not wait for confirmation. Do not test with a small transaction. Do not try to change a password—there is no password to change.

What to do in the first ten minutes Create a new wallet with a new phrase on a clean device, move the most valuable liquid assets first, then the rest, and treat the old wallet as permanently compromised. Automated sweeper bots may take incoming funds instantly. 01 New wallet, new phrase, clean device Not a new account inside the same wallet — that shares the same phrase. 02 Move the most valuable liquid assets first Stablecoins and major tokens. Biggest number first, not easiest first. 03 Then NFTs, then anything staked or locked These take longer. Do them after the liquid value is out. 04 Expect a race, and expect the gas problem Automated bots watch stolen wallets and take gas the moment it arrives. 05 Retire the old wallet permanently Never reuse it. Never receive to it again. Update anywhere you published it. Revoking approvals does not help here — whoever has the phrase is the wallet.
The ordering is deliberate. Value first, convenience never.

On the gas problem, because it catches people at the worst possible moment: moving a token requires the chain’s native coin to pay the fee. If the compromised wallet holds none, you must send some in—and automated sweepers watching the address will often take it within a single block. People try three times, lose the gas three times, and conclude nothing can be done.

Workarounds exist, including bundling the funding and the rescue into one atomic transaction that cannot be interrupted. They are fiddly and chain-specific. If a meaningful amount is at stake, ask someone experienced before burning further attempts.

And the cruellest sequel: people who have just been robbed are often approached within hours by “recovery specialists” who promise to trace and return the funds. They ask for the phrase again, or for an upfront fee. It is the same attack, aimed at the same person, on their worst day. Nobody can reverse a blockchain transaction. Anyone claiming otherwise is selling the second robbery.

9. What a scan can and cannot tell you

Paste a message like the one above into our scanner and it will return FAIL, flagging the seed-phrase request as critical and noting the suspicious link structure.

Here is what it does not do.

For this particular attack a scanner is a useful backstop, not the primary defence. The defence is one sentence long, and you already have it.

The rule

Nobody needs your recovery phrase. Not ever. Not for any reason. No matter who they claim to be.

Any message that asks for it is a theft attempt. That is not a heuristic with exceptions; it is the complete rule, and one of the rare security rules that truly has no edge cases.

If you are ever unsure, distrust the deadline first. Then ask someone. That single step ends the attack.


Related: instructions written for an AI rather than for you, and text that renders as nothing. This article is for educational purposes only and is not financial advice. The example message is representative of real campaigns, uses a reserved example domain, and targets no real company.