Fake wallets and the seed-phrase trap: why one line of words empties the whole wallet
Fake MetaMask apps, fake extensions, fake "sync and verify" pages — the tricks vary, but they all stare at the same thing: your seed phrase. Once you grasp why this string is the highest level of access to the entire wallet, you'll see why there is no "exception" that ever requires typing it into a web page.
A lot of people lose their assets stuck in the confusion of "but I didn't click anything dodgy, how did I get robbed". The cause is usually not some high technical wizardry, but being led into handing over the seed phrase with their own hands. To avoid this kind of trap you first have to be clear on two things: which kind of wallet you're using, and what access that string of backup words actually represents.
Self-custody vs exchange wallets
This distinction decides who holds your keys, and it also decides that the things you have to guard against are different.
An exchange wallet (your balance inside an account on a platform like Binance) has its private keys held by the platform. You log in with a username, password, and 2FA — there's no seed phrase involved. Its risk is mainly the account being stolen, so what you guard against is fake support, phishing logins, and being tricked into handing over a verification code.
A self-custody wallet (MetaMask, Trust Wallet, imToken, and the like) keeps the private keys with you, and behind them is the seed phrase. There's no support team to recover it for you and no "forgot password" to reset. The upside is that it's truly yours and no one can freeze it; the price is that once the seed phrase leaks, no one can save you and nothing can be undone.
In one line: an exchange wallet is like a bank account — if something goes wrong you can still go to the bank; a self-custody wallet is like a stack of cash in your hand — lose it and it's gone. The traps in this entry mainly target self-custody users.
This isn't to say self-custody is bad; its "no one can freeze you" is exactly the upside for some people. The point is that you have to be clear: choosing self-custody means taking on the full responsibility of holding the keys yourself, with no do-over and no support rescue. Most people new to it overrate their own discipline at keeping a seed phrase, and underrate how everyday the situations are where you're lured into giving it up. Recognise the weight of that responsibility first, and only then will you take every trap below seriously.
What a seed phrase actually is
A seed phrase (also called a recovery phrase) is usually 12 or 24 English words in a fixed order. It isn't a "password" — it is the root of the entire wallet: every private key and every address in your wallet is derived from this string.
So here's the key point: whoever gets your seed phrase can fully rebuild your wallet on any device and move out every asset in it. Unlike an exchange password, it can't be changed and there's no 2FA layer behind it. The seed phrase is the end of the line — no second layer of protection, and no "freeze to stop the bleeding" mechanism.
In normal use, you only see and write it down once, when you first create the wallet and back it up. After that, day-to-day transfers, signatures, and connecting to DApps rely on the password or biometric unlock inside the wallet app, and you almost never need to type the seed phrase again. Remembering this "normal use doesn't need it" is the baseline for every judgement that follows. For the concepts of private keys and recovery phrases, the ethereum.org security page has a plain explainer.
The three faces of a fake wallet
The scammer gets you to install or use something that "looks like a wallet" for one of two ends: to take your seed phrase directly, or to have you type it into their interface so it can be uploaded.
1. Fake apps
A counterfeit wallet app, with a name and icon made almost identical to the real one, showing up on unofficial download sites, ad-driven pages, sometimes even slipped into the lower results of an app store search. You install it, go through "create wallet" or "import wallet", and the seed phrase you enter is sent straight back. Some fake apps generate an address whose private key they already hold, and sweep it as soon as you deposit.
2. Fake browser extensions
Wallets like MetaMask have browser-extension versions. Scammers publish fake extensions with similar names and icons, or lure you to install one via search ads. Once installed, it either steals your seed phrase when you import, or swaps things out when you sign a transaction, changing the recipient to the scammer's address. A different trick that needs no extension and targets your transfers directly is address poisoning — planting a look-alike address, matching the ends of one you use, into your transaction history so you paste the wrong one next time.
3. Fake sync pages / fake verification pages
This one doesn't even need you to install anything. The other party (often fake support) gives you a web page that says it will "sync your wallet", "verify your assets", or "resolve a stuck transaction", with a 12- or 24-cell input box waiting for you to fill in your seed phrase. Fill it in and you've photographed your key ring and handed it over.
Of these three, fake apps and fake extensions depend on a bad "source", while fake sync pages depend on a "script" to talk you up to the input box. The first two can be blocked by managing where you download from (covered below); the third has no technical defence at all — it needs nothing installed, only your belief that "this time you really do need to enter your seed phrase". That's why the last line of defence is always the same: however reasonable the page sounds, the seed phrase simply does not go into any web page. Hold that line and the most convincing fake sync page is wasted effort.
The settings where seed-phrase phishing happens
Phishing doesn't only happen inside a "fake wallet"; more often it's dressed up in various reasons to lead you to the step of entering your seed phrase:
- Fake support "helping out": your transaction is stuck or a withdrawal failed, and "support" says they need your seed phrase to "check the wallet". Further reading: the fake support entry.
- Fake airdrop claim pages: claiming tokens, but before claiming they want you to "verify wallet ownership" by entering your seed phrase or signing in a window you don't understand. A real claim never needs a seed phrase.
- A "wallet anomaly, recovery needed" pop-up: disguised as a wallet system prompt saying an anomaly was detected and you need to re-enter your recovery phrase. A genuine wallet does not pop up asking you to re-type your seed phrase like this.
- Support / a group asking you to "screenshot the seed-phrase backup page": a different phrasing to trick it out of you; the substance is the same.
- Fake wallet upgrade / migration notices: saying the old version is being retired and asking you to "import your old wallet to migrate" on some page — the input box is still waiting for your seed phrase.
The common thread is identical: manufacturing a reason that makes you feel "this time you need to enter your seed phrase". As long as you remember that normal use never needs it, all these reasons collapse.
Why one entry is the end
Many victims ask: "I only filled it in once, I didn't hit transfer — how did the money vanish?" The answer is in the nature of the seed phrase:
First, once it leaves your device it can't be recalled. The instant you type the 12 words into a web page, that string has reached the other side's server — you've handed over a copy of the wallet. Logging out or closing the page afterwards changes nothing; the key is already in someone else's hands.
Second, it has no second line of defence. An exchange account with a stolen password still has 2FA to slow things down and can be frozen; once a seed phrase leaks, the other side rebuilds the wallet directly — no password needed, no verification, and no freeze mechanism to intercept.
Third, on-chain transfers are irreversible. Once assets are moved out, no support team, no bank, no centralised institution can undo it or recover them. That's why losses of this kind are almost always total and permanent.
So there's no room here for "let me just try it". In the moment you hesitate over "should I enter this", the right answer is always no.
Setting an exchange password against a seed phrase makes the difference clearer. An exchange password is like your front-door key — lose it and you can change the lock (change the password), there's still a door chain (2FA) for one more layer, and if things go wrong the bank side has risk controls that can freeze. A seed phrase is more like the title deed and a master key fused together: whoever holds it is the owner, and you can't even report to the police that "the house is mine", because the chain only recognises the key, not the person. That's exactly why stealing the seed phrase is the most-wanted goal of this kind of scam: get it and there are no further gates to pass.
The official download rules
Managing the source blocks the two big categories — fake apps and fake extensions. A few rules:
- Reach the download page from the link the wallet's official website gives you, rather than searching the name in a store or search engine and installing — the ad slot above the search results is a hotspot for counterfeits.
- Verify the official URL. First confirm you're on the real official site (use the look-alike domain checker for a character-by-character comparison), then click through to the store or download link from there.
- Check the developer name and reviews. Before installing, confirm the developer is the official entity, and watch for a very recent listing date, an abnormally low download count, and hollow review text — all signs of a fake app.
- Install extensions only from the store page the wallet's official site points to, and after installing, check that the extension's identifying details match the official ones.
A clean source, plus the rule "never enter a seed phrase into a web page", already blocks the overwhelming majority of wallet scams.
There's a step that's easy to overlook: a lot of people search "MetaMask download" or "Trust Wallet official site" and click the top result — and that top spot is often a paid ad pointing to a counterfeit download page. The right order is to remember or bookmark the official domain first, go in through the bookmark when downloading, then click through to the store or download link from the official site — don't treat a search result as the official entrance. Desktop extensions especially deserve care: after installing, you can check the extension's identifier against the one the official side publishes in your browser's extensions management page.
Seed-phrase leak vs approval leak: don't confuse them
Both lose money, but the mechanism and the fix are completely different, so it matters to tell them apart:
- Seed-phrase leak: you handed over the recovery phrase, the whole wallet is breached, and every asset and address is under the other side's control. It can't be fixed by "revoking an approval" — revoking is useless against someone who already has the seed phrase, because they can act as the wallet's owner directly. The only thing to do is move your assets to a brand-new wallet fast.
- Approval leak: you didn't give the seed phrase, but on some wallet connection you signed an "approve" that lets a contract move one of your tokens. This kind can be stopped by revoking the approval — take that approval back and the other side can no longer touch your coins.
Remember it simply: seed-phrase leak = you gave away the whole key ring, only moving house helps; approval leak = you opened one door, just close it. For what an approval is and how to check and revoke one, see the wallet approval review and revoke guide; the most common source of malicious approvals is in the fake airdrop entry. As for how that approval got signed in the first place — often it isn't an "approve" pop-up at all, but a harmless-looking, gas-free signature request. For the underlying concepts of approvals and signatures, see the ethereum.org security page.
We downloaded and installed a few of the major self-custody wallets from their official sites, wanting to settle one thing: whether normal use ever pops up a "please re-enter your seed phrase". From actually using them, a genuine wallet only touches the seed phrase at the moment you create or import a wallet, and otherwise unlocks with a local password or fingerprint/face — so anything that asks you to re-type the seed phrase mid-use is almost always a problem. The page and button names of each wallet change with versions, so this page does not hard-code paths — go by the interface you see after entering from the official site.
What you should keep your eyes on are these three columns: one, was the download link clicked through from the official URL — if the source is wrong, don't install; two, is any page or pop-up asking you to enter your seed phrase — if so, stop immediately; three, the transfer recipient and approval target in the signing window — if you don't understand it, don't sign. These three are what decide your wallet's safety.
If it has already leaked: emergency steps
Work out which kind you're in, then handle it accordingly — get this wrong and you'll limit the loss too slowly:
Seed phrase already leaked
- Treat that wallet as compromised and stop depositing into it.
- Immediately move whatever assets still move from the old wallet into a brand-new wallet whose seed phrase has never leaked. Move fast, racing the other side.
- If assets are staked, locked, or in some protocol, unlock and move as much as you can, and limit the loss on whatever can't be unlocked.
- Permanently retire the old wallet and that seed phrase; never use them again.
Only an approval was tricked out of you
- No need to move house; the point is to revoke that malicious approval.
- Use an approval-checking tool to see which approvals the wallet carries and revoke any you don't recognise. For the steps, see the approval revoke guide.
- Revoking is itself an on-chain transaction and needs a small fee (gas); that's normal.
Either way, afterwards it's worth preserving evidence and notifying the relevant platforms. The full flow is in the first 4 things to do after a scam.
There are two more details easy to trip over when moving house. First, the new wallet's seed phrase must be freshly generated — not reusing any string that ever appeared on an old device or old backup, otherwise you're moving assets into another lock that's already known. Second, when moving assets, don't rush to do it all at once — send a small test amount first, confirm the new address receives it and works normally, then move the rest, to avoid sending coins to the wrong place in a panic. While your wallet is being watched, the other side may have an auto-sweep program running, so be decisive — but read every address carefully at each step. If the amount is large, or it spans several chains and tokens, move the most valuable, most-likely-to-be-swept items out first and handle the rest one by one; don't slow down the most critical bleed-stopping move just because you want to empty everything in one go.
FAQ
Is it convenient and safe to store my seed phrase in my phone's photo album or notes app?
It's not safe. Photos, cloud notes, and chat logs can all be reached by malware, leaks, or other people. The standard practice for a seed phrase is to write it on paper and keep it offline: no photos, no uploads, never typed into any connected device. For something important, keep separate copies, protected from fire and damp.
Does a hardware wallet make it impossible to be tricked out of my seed phrase?
A hardware wallet does greatly reduce the risk of a private-key leak, because signing happens inside the device and the seed phrase never reaches the computer. But it can't stop you from being tricked into typing your seed phrase on some page, and it can't stop you from signing a malicious approval on the hardware wallet itself. The device is a tool; the judgement is still on you.
When a wallet app updates, will it ask me to re-enter my seed phrase?
A normal update won't. An update just refreshes the app version; your wallet data is still on the device and unlocks with your existing password. Anything claiming an "upgrade / migration" that asks you to re-enter your seed phrase should be treated as phishing.
I only "pasted" my seed phrase in and deleted it right away without confirming. Am I in trouble?
Yes. The moment that string entered a page or input box you don't control, treat it as leaked and move your assets out per the emergency steps above immediately. Don't bet on having deleted it fast enough.