BTC:
ETH:
SOL:
BNB:
XRP:
Wallet safety

Seed phrase and private key hygiene

Your seed phrase (or exported private key) is the single credential that recreates full control of a wallet on any device, anywhere. Anyone who has it has everything—instantly, silently, and irreversibly.

6 min readReviewed July 13, 2026Wallet safety

The short answer

A seed phrase (usually 12 or 24 words) is generated once and mathematically produces every key pair your wallet ever uses. It should be written down on something physical, stored in at least one location no one else can access, and never typed into anything except your own wallet app's official recovery screen—never a website, a bot, a support chat, or a form.

There is exactly one legitimate reason to enter a seed phrase into a device: restoring an existing wallet you own into a wallet app you just installed. If anything else is asking for it, the answer is no.

Storage that actually holds up

  • Write it physically. Paper or a metal backup plate, not a photo, screenshot, cloud note, password manager note field synced online, or email draft to yourself.
  • Split knowledge, if you want redundancy. Some traders store partial phrase segments in separate physical locations so no single location leak is a full compromise—at the cost of more complex recovery.
  • Never enter it on a device connected to the internet unless you are actively restoring the wallet in that moment, in your own wallet app's own recovery flow.
  • Assume clipboard and screenshot risk. Malware that watches the clipboard or screen is common enough that copy-pasting a seed phrase, even briefly, carries real risk.

Exported private keys carry the same risk

Some Solana wallets let you export a single account's private key separately from the full seed phrase. That key controls only that one account rather than every account derived from your seed—useful for limiting blast radius—but it is still a full-control credential for whatever it protects, and the same rules apply: never paste it into a website, bot, or chat under any pretext.

Signals a request is fraudulent

  • Urgency: "verify now or lose access," countdown timers, limited windows.
  • A pop-up or form asking you to "reconnect," "sync," or "validate" your wallet by entering the phrase—legitimate wallets never surface this flow.
  • Support contacting you first in a DM, especially with an admin-looking badge or profile picture—see Telegram and Discord scams.
  • Any browser extension or bot asking you to "import" your wallet by phrase.

Sources

Turn the lesson into evidence

Check a wallet without ever exposing a key.

Preflight only ever needs a public address—never a phrase or private key.

Open wallet preflight