Terenval Answers · P1 safety · Русская версия
What Should You Do If Your Seed Phrase Is Exposed?
If someone else may have seen your seed phrase, assume the wallet is compromised. The phrase itself cannot be made secret again, so the durable fix is a new recovery setup.
Last reviewed: 2026-10-05.
Published by Terenval
Technical review: Terenval Wallet team
Editorial policy
Key takeaways
- Seed exposure is a key-compromise event, not a password-reset problem.
- A new account derived from the same compromised seed can still be compromised.
- Use a clean device and verified wallet source for the replacement wallet.
- Prioritize assets by value and urgency while accounting for gas.
- If a sweeper bot is active, ordinary recovery attempts can become more complex; avoid sending fresh gas blindly.
1. Decide whether the phrase was actually exposed
Assume compromise if you entered the phrase into a phishing site, sent it to “support,” stored it where an attacker gained access, installed a fake wallet that received it or used it on a device you know is infected.
You do not need proof that funds have already moved. Recovery phrases are bearer-like secrets: once copied, another party can wait before using them.
2. Create a fresh recovery setup
Use a clean device or browser profile and install a wallet through its independently verified official source. Generate completely new recovery material and record the backup securely according to the wallet's documented process.
Do not “change a few words” in the old phrase. BIP39 mnemonics are structured backups; editing words manually is not key rotation.
3. Inventory and move assets
Use block explorers and the wallet to identify assets across networks. Move higher-value and liquid assets first when practical, while leaving enough native gas for subsequent transfers. NFTs, DeFi positions and token approvals can require separate actions.
If assets disappear immediately whenever gas arrives, a sweeper bot may be monitoring the compromised account. Do not repeatedly fund it without a deliberate recovery plan.
4. Revoke and retire
Where relevant, revoke old token approvals as part of the migration, but remember that revoking an allowance does not make compromised private keys safe. Once assets and positions are moved, discontinue use of all accounts derived from the exposed seed.
Also investigate how the phrase leaked: malware, fake wallet, phishing, cloud storage, screen sharing or social engineering. Otherwise the new wallet can be compromised in the same way.
Incident-response checklist
- Stop entering the old seed anywhere.
- Use a clean, verified environment.
- Create a fresh wallet and recovery phrase.
- Verify the new receive addresses.
- Inventory old-wallet assets and gas needs.
- Move assets carefully, prioritizing material balances.
- Review DeFi positions and approvals.
- Retire the old seed and fix the original compromise source.
How this works in Terenval Wallet
If recovery material used with Terenval Wallet is exposed, create a fresh wallet through the official Terenval create flow or another independently verified self-custody wallet, then move assets using normal transactions on the correct supported networks. Terenval support does not need your seed phrase to diagnose the incident.
Do not assume that reinstalling Terenval or changing a local password rotates blockchain keys. A genuinely fresh recovery source is required.
Official pages: Supported networks · Security
Open Terenval WalletFrequently asked questions
Can I change my seed phrase without moving funds?
Normally no. Key rotation means creating a new wallet or recovery source and moving assets to addresses controlled by it.
What if no funds have been stolen yet?
Treat the phrase as compromised anyway. An attacker can wait before acting.
Is a new account under the same seed safe?
No. The seed can derive multiple accounts, so knowledge of the seed can compromise newly derived accounts as well.
Related Terenval Answers
Primary and authoritative sources
- https://bips.dev/39/
- https://support.metamask.io/stay-safe/protect-yourself/ive-been-hacked-scammed-unauthorized-transactions-on-my-account
- https://support.metamask.io/stay-safe/protect-yourself/fighting-back-against-sweeper-bots/
- https://support.metamask.io/manage-crypto/move-crypto/transfer/account-migration-guide/
Terenval-specific statements are first-party; general technical claims are checked against primary or authoritative sources.