If another person may have the complete seed phrase, the old wallet is no longer a recovery system. It is a race between two copies of the same authority.
The fix is not a new PIN, a factory reset or a new device loaded with the same words. The fix is new keys.
This is an incident runbook. The first job is to work out what leaked; the second is to create an independent destination; the third is to move value without stranding assets or reusing the compromised environment.
Minute zero: identify the scope before you touch anything
| What may be exposed | What it can affect | Immediate direction |
|---|---|---|
| Complete seed phrase | All accounts derived from that seed, subject to any independent passphrase | Create a new wallet with new recovery material and migrate |
| One private key | The address controlled by that key, depending on wallet design | Move affected assets and investigate derivation scope |
| Token approval | Approved token or NFT permission on that chain | Revoke the approval; do not assume seed compromise without evidence |
| Exchange password | The exchange account | Lock or secure the account; this is not automatically a self-custody seed incident |
| Stolen hardware signer | Physical device risk | Assess device/PIN threat and recovery route; migrate if the residual risk is unacceptable |
If the complete seed was entered into a website, photographed, stored in cloud notes, shown to another person or generated by someone else, assume it can be copied. Trezor’s current guidance is similarly conservative: if a wallet backup may be compromised, assume it is and move funds elsewhere.
Before moving value, build a destination the old environment does not know
The most dangerous emergency mistake is creating the “new” wallet through the same phishing page, infected computer or compromised backup process that caused the incident.
- Use verified wallet software and, where appropriate, a trusted hardware signer.
- Generate genuinely new recovery material. Do not modify or reuse the old words.
- Record the new backup offline.
- Verify the backup using the wallet’s documented recovery-check process.
- Generate the receiving address and confirm it on the trusted signer where possible.
- Send a small test if there is enough time and no active drain is occurring.
Do not put the new seed into a browser form just because the situation feels urgent.
If funds are already moving, preserve gas and rescue the highest-consequence assets first
An emergency migration is constrained by the network. Tokens on Ethereum and other EVM chains need native gas. Staked, lent or bridged assets may have to be unwound before they can leave. NFTs may require separate transfers.
A practical sequence is:
- Move immediately transferable high-value native assets.
- Move liquid tokens while preserving enough native gas for the remaining transactions.
- Move NFTs and other assets requiring separate contract calls.
- Unwind staking, lending, LP or bridge positions through verified official interfaces.
- Sweep residual balances only after the valuable positions are safe.
Do not send away the last ETH, SOL, BNB or other native fee asset while valuable tokens remain stranded behind it.
Bitcoin has a different emergency shape
For Bitcoin and other UTXO-based assets, verify the new destination on the signer and choose a transaction fee appropriate to current network conditions. Several UTXOs can be moved in one transaction, but consolidation can increase transaction size and reveal address relationships.
The important point is the same: the compromised seed can still be used through an isolated hardware signer during migration. You do not need to expose it to an ordinary software wallet merely because the keys are being retired.
A malicious approval is not the same incident as a leaked seed
This distinction saves people from both underreacting and overreacting.
If a malicious contract has token-spending permission but the seed remains private, revoking the approval can remove that specific authority. Ethereum.org’s current guidance also distinguishes disconnecting a wallet from actually revoking token access: an approval can persist after the website is disconnected.
If the seed itself is exposed, revocation is only cleanup. An attacker with the seed can recreate the signing keys elsewhere. The root authority has to be replaced.
Do not waste time on repairs that cannot invalidate the attacker’s copy
- Changing the hardware-wallet PIN protects that device, not a copied seed.
- Factory-resetting the signer does not revoke keys derived from the old words.
- Restoring the same seed on a new device creates the same wallet again.
- Deleting a photo does not prove cloud backups, caches or another viewer did not retain it.
- Creating another account under the same seed still derives authority from the compromised root.
- Revoking approvals only does not repair seed exposure.
Key rotation is the containment action. Everything else is secondary.
After the main value is safe, investigate the entry point
A new wallet is not safe if the original compromise path remains active.
Review the device and accounts that touched the old seed:
- browser extensions and wallet software;
- cloud photo, note and document backups;
- email and messaging accounts;
- phishing URLs and fake support conversations;
- malware or clipboard-replacement indicators;
- exchange passwords and reused credentials;
- token approvals on operational wallets.
Reinstall or replace a device when malware cannot be confidently removed. Change related account credentials from a trusted environment and enable strong MFA where available.
Preserve evidence without preserving the secret
Keep transaction hashes, destination addresses, timestamps, legitimate screenshots, phishing URLs and communications. Do not include the new seed phrase in an incident document.
If funds have already been stolen, blockchain transactions generally cannot simply be reversed. Ethereum.org also warns that “recovery experts” who promise guaranteed reversal for an upfront payment are a common second scam. Contact relevant exchanges or law-enforcement channels when identifiable services or material losses are involved, but do not confuse reporting with guaranteed recovery.
When the incident is over
The old seed should be treated as retired permanently.
Update watch-only wallets, exchange withdrawal allowlists, portfolio trackers and inheritance records to point at the new system. Store the new recovery material using a design that fixes the original failure rather than reproducing it.
For the replacement backup, use How to Store a Seed Phrase. For contract permissions, use the token approval guide.
Primary sources
- Trezor: move crypto to a wallet with a new wallet backup
- Ethereum.org: revoke token access
- Ethereum.org: scam response and recovery-scam guidance
- BIP-39 mnemonic specification
No affiliate link is used in this article.








