Seed phrase safety: who asks for it
Published: September 30, 2026
Also available in:Русский
A seed phrase is the set of words — usually twelve or twenty-four — from which your wallet derives every private key it will ever hold. It is not a password to the wallet. A password can be changed; the phrase cannot, because it is not protecting the money, it is the money, written down in words. Recovery phrase, mnemonic phrase and seed phrase all mean the same thing.
What follows from that is the part the definition pages leave out: there is no operation that checks a seed phrase. Every check requires typing it somewhere, and typing it somewhere is the transfer of everything, to whoever asked. We run notrace.exchange, a mixing service, and from behind this counter it is unusually clear how the phrases are actually taken.
What it is, briefly
The words come from a fixed list of 2,048, defined by BIP-39. The standard is direct about why words exist at all: "A mnemonic code or sentence is superior for human interaction compared to the handling of raw binary or hexadecimal representations of a wallet seed."
That sentence says what the words are not. They are not something you chose; they are a human-readable encoding of a number your wallet generated, and turning them back into that number is mechanical: "To create a binary seed from the mnemonic, we use the PBKDF2 function with a mnemonic sentence (in UTF-8 NFKD) used as the password and the string "mnemonic" + passphrase (again in UTF-8 NFKD) used as the salt."
From that number comes a master key, from it children, from them the rest. Which is why a wallet asks for words rather than a list of keys when you restore it — from the words it rebuilds the whole tree, including branches that were empty when you wrote them down.
How the phrase differs from a single private key, and what the extended public key does that neither of them does, is a separate subject we covered in seed phrase vs private key. This article is about the phrase leaving your hands.
Why "verify your phrase" is never a real request
There is no action in which a seed phrase reaches someone else and the money stays with you. No intermediate step exists: not "verify ownership", not "sync", not "validate your wallet", not "activate withdrawals", not "restore access". Each of them means exactly one thing in practice — the recipient restores your wallet on their machine and can sign a transfer anywhere. Immediately, and permanently.
This makes the usual advice — check whether the support agent is genuine, check whether the site is real — beside the point. No genuine service and no genuine support agent has any use for the phrase, under any circumstance. No exchange, no wallet vendor, no mixing service performs a single operation that needs it. The one place the words are ever typed is your own wallet's recovery screen, on your device, because you decided to restore it.
That is a rare kind of rule: it needs no judgement calls. The request itself is the answer, whoever is making it.
The market for other people's phrases, in numbers
Writing about "scammers" in general terms is easy and weightless. Here are figures instead — from Ahrefs, US market, measured on 29 September 2026 while researching a different article:
seed phrase generator— 200 searches a month;12 word seed phrase generator with balance— 100 searches a month.
Read the second one twice. A generator "with balance" is not a tool for making your own wallet. It is what someone looks for when they want to run through phrases and keep the ones with money behind them. A hundred people a month, in one country, searching for it in the open.
We do not know how many of them found anything, and we are not going to invent a number. But the demand itself is measurable: hunting for seed phrases is a market with a visible search footprint, not an abstract warning from a security checklist. None of the pages explaining what a seed phrase is mentions this.
There is arithmetic behind why such a search is worth running at all. Twelve words drawn from a list of 2,048 produce a number nobody will ever brute-force. But nobody tries to. What gets searched is the predictable subset: phrases produced by a weak source of randomness, phrases a person composed from words that meant something to them, phrases lifted from documentation examples, screenshots, videos and photographs of a piece of paper sitting in cloud storage. The attack is not against the standard. It is against the people who stepped around it.
Where the request comes from
The wrapping varies; the demand does not. The dangerous version is the one that looks familiar.
A dead brand's domain eventually leaves the registry and anyone can take it. The name is right, the bookmark works, the page loads and looks the way it always did. That is what happened with the Tornado Cash domain: a user arrived through an old bookmark, entered their data into the interface they recognised, and the chain shows 1,010 ETH leaving across two addresses. How to tell a live service from an address that merely answers is in what is at the addresses of the seized mixers — the short version is to read the domain's registry record rather than judging the page.
The rule that generalises it: a correct name, a working link and a familiar appearance are not evidence. A convincing fake has all three by construction.
What actually protects it
A short list, because the list is short:
- The words live off the network. Paper, metal, a safe — anything that is not on a device with an internet connection. A photo in your phone's gallery, a note in cloud storage and a message to yourself in a chat app are all the network.
- They get typed exactly once, on your own wallet's recovery screen, and nowhere else ever.
- More than one copy, in more than one place. Fire and flood destroy money as reliably as theft does.
- A passphrase on top — the extra string from the formula above, stored apart from the words. It turns a stolen piece of paper into a useless one.
And the thing not to do: look for a service that will check, insure or recover the phrase for you. No such service exists. Only things calling themselves that.
Where we stand
notrace.exchange never asks for a seed phrase, a private key or an extended public key, and there is nothing here that could use one. An order needs two addresses for the payout to go to.
- There is no registration, no email, no documents and no identity check. What is kept is the order — addresses, amounts and times. An order created on the clearnet site also records the connecting IP, which on 30 September 2026 was erased after 30 days; an order created over Tor has no IP at all. The current wording is on the FAQ page.
- While your chosen delays run, the service holds the funds — section 8 of the terms says exactly that, and what it does and does not change is in custodial vs non-custodial.
- Each order carries a letter signed with our PGP key, naming what you send, the least you will receive, both payout addresses and both delays. It is checkable before you pay, which is the entire reason it exists.
- The payout leaves as two transfers with independent delays, each settable from zero to 6 hours on 30 September 2026; our fee that day was 0.5% and was the only thing added to the quote.
The limit is the usual one: nothing removes what is already in the chain, and no service can. What changes is whether coins leaving a known address can be followed forward.
Where to start
If you came for the definition: the phrase is your keys written as words, and there is no version of showing it to someone in which you keep the money.
If someone has already asked you for it, that is the end of the conversation with them, however convincing the form looks. And if you are choosing a service, the checks in how to choose a bitcoin mixer are the ones we would run, against us included; the bitcoin mixer page opens the form with its current minimum.