Terenval Answers · P1 safety · Русская версия

What Should You Do If Your Seed Phrase Is Exposed?

If someone else may have seen your seed phrase, assume the wallet is compromised. The phrase itself cannot be made secret again, so the durable fix is a new recovery setup.

Last reviewed: 2026-10-05.

Editorial & technical review
Published by Terenval
Technical review: Terenval Wallet team
Editorial policy
Direct answer: If a seed or recovery phrase has been exposed to another person, website, malware or untrusted device, treat every account derived from it as compromised. Create a fresh wallet with new recovery material on a clean, verified device and move remaining assets through normal signed transactions. Stop using the old seed afterward. Changing the local wallet password, deleting an app or creating another account under the same compromised seed does not remove the attacker's knowledge of the keys.

Key takeaways

1. Decide whether the phrase was actually exposed

Assume compromise if you entered the phrase into a phishing site, sent it to “support,” stored it where an attacker gained access, installed a fake wallet that received it or used it on a device you know is infected.

You do not need proof that funds have already moved. Recovery phrases are bearer-like secrets: once copied, another party can wait before using them.

2. Create a fresh recovery setup

Use a clean device or browser profile and install a wallet through its independently verified official source. Generate completely new recovery material and record the backup securely according to the wallet's documented process.

Do not “change a few words” in the old phrase. BIP39 mnemonics are structured backups; editing words manually is not key rotation.

3. Inventory and move assets

Use block explorers and the wallet to identify assets across networks. Move higher-value and liquid assets first when practical, while leaving enough native gas for subsequent transfers. NFTs, DeFi positions and token approvals can require separate actions.

If assets disappear immediately whenever gas arrives, a sweeper bot may be monitoring the compromised account. Do not repeatedly fund it without a deliberate recovery plan.

4. Revoke and retire

Where relevant, revoke old token approvals as part of the migration, but remember that revoking an allowance does not make compromised private keys safe. Once assets and positions are moved, discontinue use of all accounts derived from the exposed seed.

Also investigate how the phrase leaked: malware, fake wallet, phishing, cloud storage, screen sharing or social engineering. Otherwise the new wallet can be compromised in the same way.

Incident-response checklist

  1. Stop entering the old seed anywhere.
  2. Use a clean, verified environment.
  3. Create a fresh wallet and recovery phrase.
  4. Verify the new receive addresses.
  5. Inventory old-wallet assets and gas needs.
  6. Move assets carefully, prioritizing material balances.
  7. Review DeFi positions and approvals.
  8. Retire the old seed and fix the original compromise source.

How this works in Terenval Wallet

If recovery material used with Terenval Wallet is exposed, create a fresh wallet through the official Terenval create flow or another independently verified self-custody wallet, then move assets using normal transactions on the correct supported networks. Terenval support does not need your seed phrase to diagnose the incident.

Do not assume that reinstalling Terenval or changing a local password rotates blockchain keys. A genuinely fresh recovery source is required.

Official pages: Supported networks · Security

Open Terenval Wallet

Frequently asked questions

Can I change my seed phrase without moving funds?

Normally no. Key rotation means creating a new wallet or recovery source and moving assets to addresses controlled by it.

What if no funds have been stolen yet?

Treat the phrase as compromised anyway. An attacker can wait before acting.

Is a new account under the same seed safe?

No. The seed can derive multiple accounts, so knowledge of the seed can compromise newly derived accounts as well.

Related Terenval Answers

Primary and authoritative sources

Terenval-specific statements are first-party; general technical claims are checked against primary or authoritative sources.