Wallet safety · International; wallet-specific instructions apply
Seed phrase compromised: why changing your password is not enough
What exposed recovery words mean, how to think about a clean replacement wallet and why rescue offers can be dangerous.
By Stonebridge Resolution · Published 4 October 2026 · Updated 4 October 2026
AI-generated illustration; not a depiction of a real case.
The short answer
Anyone with a wallet's recovery phrase may be able to recreate its signing keys. Changing the app password does not invalidate those words. Treat the affected wallet and accounts derived from the phrase as compromised.
Recognise exposure even without an immediate loss
Exposure includes entering the phrase into an unfamiliar website, sending it to support, storing it where an intruder has access, or allowing someone to view it through remote-control software. An attacker may wait rather than empty the wallet immediately.
A lack of suspicious transactions does not restore secrecy. Do not test safety by adding money. Preserve evidence of how the phrase was exposed without copying the phrase into your report or screenshots intended for others.
A wallet password protects a different layer
The password or PIN used to unlock a wallet application can protect that installation. The recovery phrase can recreate the wallet elsewhere. An attacker with the phrase does not need your current app password.
Creating another account inside the same wallet may still derive keys from the same phrase. For a clean replacement, the important distinction is genuinely new secret material generated through trusted software or hardware—not a new account label.
Use a clean environment for replacement keys
If the exposure involved malware or remote access, stop using that device for financial actions until it has been assessed and secured. Generate the replacement wallet through authentic software or hardware obtained from verified sources.
Keep the new phrase offline and private according to the wallet provider's guidance. Do not photograph it for a recovery agent, store it in the compromised email account, or paste it into a browser form to prove that the replacement works.
Moving remaining assets can carry risk
An attacker may run software that transfers incoming funds immediately. Depositing fee tokens into a compromised wallet can simply increase the loss. Complex holdings, staking positions and pending withdrawals can require careful wallet-specific decisions.
Avoid improvising with scripts supplied by strangers. If specialist help is necessary, independently verify the provider and insist on an explanation of the proposed actions. No adviser needs permanent access to your new recovery phrase.
Review the wider compromise
Secure the email account used for exchanges, revoke unfamiliar sessions and review recovery settings from a safe device. Check whether the same incident exposed identity documents, passwords or other wallets.
Record outgoing transaction hashes and report through official channels. Recovery remains uncertain, but documenting the access method helps distinguish key compromise from a disputed purchase or a malicious allowance.
Checklist
- Treat the old phrase as permanently exposed.
- Use new keys generated on a clean device.
- Do not repeatedly top up a wallet under active theft.
- Review email, exchange access and other affected accounts.
Common questions
Can I change the words for the same wallet?
Ordinarily a new recovery phrase creates a different wallet rather than changing the old wallet's keys in place. Follow the specific provider's instructions.
Should I send the phrase to police as evidence?
Do not include spending credentials in routine reports. Describe the exposure and provide transaction records instead.