What to do when a seed phrase may be exposed
If another person may have copied the complete seed phrase, treat the wallet as compromised. Preserve current access, create a new wallet with a new verified seed, move the Bitcoin away from the exposed wallet, and retire every old copy.
A device PIN, new hiding place, safe, lock, or replacement metal backup does not revoke a seed that may already have been copied.
Immediate action order
- Preserve control of the current wallet. Do not reset the only functioning device.
- Stop further exposure. Do not enter the seed into any additional tool or conversation.
- Determine whether the complete seed, a passphrase, or only one partial component may be exposed.
- Create a new wallet with a new seed through a legitimate wallet workflow.
- Record and verify the new recovery backup offline.
- Confirm the new destination wallet.
- Move funds away from every wallet controlled by the exposed seed.
- Retire old copies and correct the storage failure.
Classify the exposure
| Exposure | Default response |
|---|---|
| Confirmed complete copy | Migrate to a new seed. |
| Credible opportunity to copy | Migrate when a faithful copy cannot be confidently excluded and the consequence is unacceptable. |
| Brief accidental view | Correct the storage failure immediately. Evaluate whether recording or faithful memorization was realistically possible. |
| Digital exposure | Assume copying may be permanent and unbounded. Migrate to a new seed. |
| One component of a documented threshold system | Evaluate the actual standard, threshold, other exposed shares, labels, and metadata. Do not apply complete-seed assumptions blindly. |
| One half of a DIY split | Treat the visible fragment as sensitive and assess the whole custom design. DIY splits can leak useful information and create recovery ambiguity. |
What an attacker does not need
A person with the complete seed may not need:
- the original hardware wallet;
- the device PIN;
- physical access to your safe again;
- your permission;
- an immediate reason to move the funds.
No suspicious transaction today does not prove that no copy exists.
The passphrase branch
Seed exposed, passphrase remains separate and private
The intended passphrase-protected wallet may not be reachable from the seed alone. However, the seed remains a compromised recovery component and the system should be rebuilt with a new seed and a new verified passphrase path.
Seed and passphrase exposed together
Treat the intended wallet as directly compromised and follow the migration sequence immediately.
Changing only the passphrase
A new passphrase creates another wallet branch, but it does not revoke the exposed seed. A complete rebuild with a new seed is the clean recovery boundary.
The replacement sequence
- Generate a new seed through the legitimate new-wallet process.
- Record it offline in the exact format produced by the wallet.
- Verify the backup through a trusted wallet-level check.
- Verify the exact new passphrase when one is used.
- Confirm a receiving address or wallet fingerprint on the trusted interface.
- Move funds from the old wallet to the new wallet.
- Confirm the migration and review every relevant account controlled by the old seed.
- Retire old paper, metal, digital residue, temporary notes, and obsolete family instructions.
What does not fix exposure
- changing the device PIN;
- moving the same backup to a better hiding place;
- putting the exposed seed into metal;
- replacing a tamper seal;
- buying another hardware wallet and restoring the same exposed seed;
- waiting for suspicious activity;
- asking support whether the seed was used.
Preserve evidence without preserving risk
Record non-secret incident facts such as date, location, who had access, whether a photograph or digital entry occurred, which components were involved, and what corrective actions were completed.
Do not copy the seed into the incident log.
Resolution checklist
- [ ] Current wallet access was preserved during the response.
- [ ] A new wallet generated a new seed.
- [ ] The new backup and exact passphrase branch were verified.
- [ ] The new destination wallet was confirmed.
- [ ] Funds no longer depend on the exposed seed.
- [ ] Old recovery material and setup residue were retired.
- [ ] Family and emergency instructions now identify the new active wallet.
- [ ] The original exposure path was corrected.
Product selection begins only after the exposed wallet has been replaced and the new recovery path has passed verification.
Move the bitcoin first, then rebuild the backup
Buying metal does not neutralize an exposed seed. The urgent work is to preserve current control, create a new wallet with a new verified seed, migrate away from the exposed wallet, and retire every old copy. Product selection belongs only after that migration path is complete.
For the replacement seed, Trezor Keep Metal is our overall permanent winner. Choose the exact variant generated by the new wallet, not the format used by the compromised wallet unless they happen to match.
Official Trezor store affiliate link. We may earn a commission at no extra cost to you.
Complete the incident response first. Then read the Trezor Keep Metal review or compare other replacement formats in Best metal seed phrase backups.
Frequently asked questions
Can someone steal Bitcoin with only the seed phrase?
A complete seed can recreate wallets derived from it. A separate passphrase may protect a specific wallet branch, but the exposed seed remains compromised.
Does changing the hardware-wallet PIN protect me?
No. The PIN protects that particular device. It does not revoke a copied seed.
Can I move the same seed to a better hiding place?
A better location reduces future access to the physical object, but it cannot erase a copy that may already exist.
What if the tamper seal is broken?
A broken seal is evidence that access may have occurred, not proof of copying. Evaluate the exposure and migrate when a faithful copy cannot be confidently excluded.
What if someone saw only one part of a multi-part backup?
Evaluate the actual recovery standard, threshold, other exposed components, labels, and metadata. One share is not automatically equivalent to a complete seed, but it remains sensitive.
Should I wait to see whether funds move?
No. A copied seed can be used later. Credible complete-seed exposure should be resolved through a new verified wallet and migration.