§ Guide · Foundation

Is your seed phrase compromised? How to know — and act

Seed phrase leaked, photographed, or typed into a website? How to judge real compromise, when to move coins immediately, and how to set a tripwire alarm.

By dont-trust-verify Published July 17, 2026

There’s a specific 3 a.m. thought every self-custodian eventually has: did anyone ever see my words? Maybe you found an old phone photo of the seed card. Maybe you vaguely remember typing the phrase into some site in 2021. Maybe the safe was open during renovations. And now you’re staring at the ceiling doing forensic reconstruction of five years of your own carelessness.

This guide is for that night. Not to reassure you — sometimes the right answer is “move everything, today” — but to replace vague dread with an actual decision: know what compromise looks like, sort your situation into one of three buckets, and act on the bucket. I’ve ordered it the way I’d triage it myself.

TL;DR. You usually cannot prove a seed is safe — a copied seed makes no sound and leaves no trace until the sweep transaction. So work the other direction: if the words were ever typed into any website or app, photographed onto a cloud-synced device, or stored in any online note or vault, treat the seed as compromised — move the coins to a fresh seed now. If exposure is merely possible (paper someone might have seen), put the addresses on a movement alarm today and schedule the move calmly. If the seed was born on a hardware wallet and never existed anywhere else, you’re clean — upgrade to steel and consider a passphrase. When in doubt, the move costs one transaction fee; being wrong costs everything.

Who could have seen it — the honest threat model

Start with an inventory, not a feeling. A seed phrase is compromised the moment a copy exists somewhere you don’t control. The places copies actually come from, roughly in order of real-world frequency:

Two structural facts make this inventory unforgiving. First, exposure is permanent: a seed seen once is a seed known forever — there’s no rotation, no reset, no expiry. Second, one seed is every address: an HD wallet derives all its addresses, past and future, from those words. There is no “they only saw part of my wallet”.

The brutal truth: you can’t watch for what makes no sound

Here’s the asymmetry that makes this threat uniquely nasty: a copied seed is perfectly invisible. The thief doesn’t log in. Nothing shows “last accessed”. The wallet balance looks normal for weeks, months, years — attackers routinely sit on harvested seeds, waiting for balances to grow or simply working through a backlog. The first and only signal you will ever get is the sweep transaction itself, and by then it’s over: seed-holders don’t need to crack anything, they just spend.

So the question “how do I check if my seed is compromised?” has a disappointing literal answer: you can’t check. There is no scanner, no lookup, no service that can tell you whether a copy of your words exists on someone’s disk. (Anyone selling that check is selling the drain itself — never type a live seed into anything to “verify its safety”. The BIP-39 validator on this site exists for practice and recovery-test checksum verification and runs entirely in your browser; a seed guarding real money shouldn’t be typed even there, or anywhere.)

What you can do is classify honestly. These signals mean compromised — full stop, no further debate:

And these put you in the uncertain bucket: the paper was findable during a renovation; a relative might have photographed it; you split the phrase in a way you no longer fully remember; you moved houses and the chain of custody has gaps. Not proof of leak — but you can no longer say “no copy exists” with a straight face.

The decision table

Your situationVerdictAction
Words touched any website/app/cloud, ever · pre-seeded device · unexplained transactionCompromisedMove everything to a fresh seed today
Physical exposure possible but no digital copy: findable paper, unaccounted boxes, house guestsUncertainPut every address on a movement alarm today; do the move deliberately, soon
Seed generated on a hardware wallet, exists only on paper/steel, never photographed, never typedCleanKeep it that way: steel backup, consider a passphrase

Bucket 1 — definite compromise: move now

Don’t research for three more days; the move itself is one afternoon. The steps, compressed (each is expanded in the safe-move section below): generate a new seed on a hardware wallet, verify the new receive address on the device screen, send a small test amount, confirm it arrives, then sweep the rest at a fee that confirms quickly. The one non-negotiable: the new seed must be fresh — generated on hardware the old setup never touched — not a reshuffle of coins between wallets that share the tainted words.

Bucket 2 — uncertain: this is what a tripwire is for

The uncertain bucket is the uncomfortable one. Moving coins has real costs — fees, planning, the risk of fumbling a rushed migration — and maybe nobody ever saw the paper. But doing nothing means betting your stack on “probably fine”, when the one fact you know for sure is that a sweep would be silent.

Split the difference deliberately: put the watched addresses on a movement alarm today, then do the move on your schedule instead of never. Our Watchtower is built for exactly this seat: it’s watch-only (it never sees keys or seed, so it can’t touch coins), the free tier watches an address with no signup, and it emails you the minute anything moves — plus a weekly “still untouched” heartbeat, so silence becomes a signal instead of a hope. If the worst is true and the thief sweeps, you know in minutes, not months — while reporting to exchanges is still worth something and whatever else shares that setup can still be rescued. An alarm is not a shield; nothing can block a seed-holder from spending. What it buys is the thing this whole threat model denies you: time and knowledge. Then schedule the move for the next quiet weekend, alarm still armed while you prepare.

Bucket 3 — clean: make it stay clean

If the seed was generated on a hardware wallet and has only ever existed on paper or steel in places you control — good. That’s the ceiling; there’s no “extra clean”. Spend the nervous energy on upgrades that raise the floor instead: get the backup off paper and onto steel (fire and water beat paper constantly, and a destroyed backup with a live wallet is its own emergency), and consider a BIP-39 passphrase — it turns a future leak of the bare words into an attacker holding a decoy wallet instead of your stack. Read the failure modes first: a forgotten passphrase loses coins exactly as thoroughly as a thief does. Then run the self-custody score — eight questions, two minutes — to see which layer of your setup is actually weakest; it’s rarely the one people worry about at 3 a.m.

Doing the move safely

A rushed migration is where careful people get hurt — sending real money while adrenaline is high. The discipline:

  1. Set up the destination completely first. New hardware wallet, fresh seed generated on the device, backup written (steel later, paper now is fine), and run a recovery drill before funding it if your nerves allow — better to discover a mis-copied word while the wallet is empty.
  2. Verify the receive address on the device screen, character groups at start and end, not just in the companion app. If the computer is part of why you’re worried, its screen doesn’t count. Sanity-check formats with the address validator if anything looks odd.
  3. Test send first. A small amount, wait for one confirmation, see it arrive on the new device. This costs one extra fee and removes the catastrophic failure modes (wrong address, wrong wallet, clipboard malware).
  4. Choose the fee by threat level. Definite compromise: pay the next-block rate from mempool.space — you may literally be racing another key-holder, and RBF-bumping later wastes exactly the minutes you don’t have. Uncertain-but-alarmed: a few-blocks rate is fine.
  5. Sweep the rest — all of it. Every address, every scrap of change; the old seed’s balance should be zero. A leaked seed with “just a little” left on it is a standing invitation.
  6. Retire the old seed. Physically destroy the old backups so nobody — including future-you — ever reuses those words. The old wallet gets deleted, not repurposed.

Related walkthrough if your coins are on an exchange rather than a suspect seed: moving Bitcoin off an exchange to a hardware wallet.

FAQ

Is my seed phrase safe in a password manager?

No — treat it as compromised and move the funds. Vaults sync to servers, sit behind one phishable master password, and are harvested wholesale by infostealer malware. Seeds belong on paper or steel, offline, only.

There’s a photo of my seed on my phone — compromised?

If it ever synced to any cloud, assume yes and move. Provably offline-only photo: lower risk, same conclusion — new seed, and never photograph the words again.

Can someone with 11 of 12 words steal my coins?

Yes, realistically. The checksum narrows the last word to ~128 valid candidates — minutes of work. Partial exposure is exposure.

Is a passphrase a second factor for my seed?

Functionally yes, and it’s the best pre-emptive defense here: leaked words alone then open a decoy, not your stack. It must exist before the leak, be strong, and be stored separately — and it doesn’t rescue coins already sitting on the non-passphrase wallet.

I typed my seed into a site years ago and nothing happened. Safe?

No. Harvested seeds get warehoused, sold, and drained on a delay — often when the balance finally justifies it. Quiet ≠ safe. That seed is burned.