Seed phrases and private keys
A seed phrase commonly derives a set of wallet keys, while a private key directly controls signing for a specific account. Both are highly sensitive secrets, and exposure can put account control at risk. In practice, place “seed phrases and private keys” back into the context of the active account, network and intended target instead of judging the action from interface styling or button labels alone.
Backups should be offline and recoverable
A backup must avoid both disclosure and accidental loss. Use a reliable offline medium, verify order and readability, and consider real-world risks such as physical damage, accidental destruction and unauthorized access. This is rarely solved safely by clicking through again. A repeatable verification order for backups should be offline and recoverable is more reliable than trial and error.
Screenshots and cloud sync expand exposure
Screenshots, automatic photo sync, cloud notes and chat backups can copy recovery information across more devices or services. Keeping a seed phrase online for convenience increases the number of places where it can be exposed. Treating screenshots and cloud sync expand exposure as its own decision point helps prevent rapid click-through mistakes across multiple accounts, networks or DApp steps.
Restore only in a trusted environment
Restore a wallet only on a trusted device with the correct application. Do not use a website to “verify” a seed phrase and never enter recovery information while screen sharing or under remote control. The practical goal of restore only in a trusted environment is to separate on-chain facts from interface presentation; if the two disagree, verify public blockchain state first.
Support cannot recover private keys
In a self-custody wallet, keys remain with the user and legitimate support does not know or request private keys. Anyone claiming a seed phrase is needed to “unlock,” “verify” or “recover” assets should be treated as a serious risk. Because blockchain actions can create persistent or irreversible state, understanding support cannot recover private keys should come before signing, approving or submitting.
Rotate control after suspected exposure
If secret material may have been exposed, changing an interface password does not change the original blockchain key. Create a new wallet on a trusted device, verify the new address and network, migrate assets carefully and stop relying on the compromised key. Reviewing rotate control after suspected exposure never requires giving anyone a seed phrase or private key; public state can be checked with addresses, transaction hashes and contract information.
Use this list as a final review before you submit a transaction, signature or approval related to this topic.
- Keep an ordered offline backup
- Avoid automatic cloud sync of recovery material
- Never enter a seed phrase into chat or unrelated websites
- Avoid remote control during recovery
- Move to new keys after suspected exposure
Never share a seed phrase, private key or verification code. A wallet provider generally cannot reverse a confirmed on-chain transaction, and third-party DApps or smart contracts can carry independent risk.
