Trust Wallet
Security

No seed phrase requests. Ever.

Your recovery phrase is the wallet. Anyone who holds it is you. No legitimate app, website, support agent or support process will ever ask for it — which makes the rule simple and absolute.

Download on the App Store Get it on Google Play

The rule

If any screen, form, chat, email, phone call or pop-up asks you for your recovery phrase — twelve or twenty-four words in order — it is not Trust Wallet. Close it and do not continue.

There is no verification process, no support escalation and no recovery service that needs it. Signing a transaction does not require it. Proving you own a wallet does not require it. Restoring access to your own device does not require it either — that is the entire purpose of it, and it belongs to you alone.

Warning: the most common way people lose a wallet

Not phishing for a password — phishing for a recovery phrase. Sites imitating a wallet interface are extremely convincing, and they are the only places that ever ask for these words. A real wallet login is a password or a biometric. It is never a list of words.

How the scam works

Attackers do not need to break any encryption. They attack the moment you are most likely to trust a screen:

  1. They get your attention. A direct message, a sponsored search result, a fake airdrop, a “support” reply, or an email that looks like a security alert.
  2. They send you somewhere convincing. A pixel-perfect imitation of a real wallet, asking you to connect, verify, sync or restore.
  3. They ask for the phrase to “restore” it. This is the trap. Restoring a wallet needs the phrase and nothing else — not your address, not your balance, not an order number.
  4. They take everything. The moment the words are entered the funds are swept. The page then usually shows a loading spinner, and recovery is effectively impossible.

Step 3 is the tell. A genuine restoration flow asks for one thing: the phrase. Anything that also requests an email, a wallet ID or an account number is trying to sound more legitimate than it is.

How to spot it in the wild

  • Manufactured urgency. “Your wallet will be deactivated”, “verify within 24 hours”, “suspended pending verification” — pressure designed to stop you thinking.
  • An unexpected incoming asset. A token you did not ask for appears in your wallet, and claiming it is the only way to see it. Real airdrops do not need your phrase to view.
  • A shortened or misspelled domain. Read the address bar, not just the logo.
  • A request for a single word. “Just confirm the fourth word of your wallet” is a cheap probe for a response. The answer is always no.
  • Contact that did not come from you. Anyone who reached out first, unsolicited, is not support.

What real support looks like

Genuine help never needs your secret. A legitimate request can be answered entirely with information that is already visible on your screen, and none of it gives anyone control of your funds.

They may ask for
Your public wallet address, a transaction hash, the app version, the device and OS version, or a screenshot with balances covered.
They will never ask for
Your recovery phrase, a private key, a screen-share that shows your backup screen, or for you to install a remote-access tool so they can “check” your device.
Recovery after a loss
If you lose access to a device, your own backup phrase is the way back in. No support agent and no third party can restore it for you.

If you already entered your phrase

Act immediately and treat the funds as gone:

  1. Do not return to the site. If the wallet is still open on your device, note your own public address from a trusted screen.
  2. Assume the funds are being swept. Every second counts, and a broadcast transaction cannot be reversed.
  3. Move any remaining balance in the affected wallet to a new address generated on a clean device, immediately.
  4. Assume the device is compromised. If you typed the phrase into a web page, treat the device as hostile and rebuild from a clean install using your backup.
  5. Report the address on-chain to the relevant exchanges so it can be flagged.

Recovery is rarely possible, but moving quickly limits the damage to what was not yet swept.

The rule, restated

If a screen asks for your recovery phrase, it is not Trust Wallet. Nothing else needs checking — not the branding, not the domain, not who sent you there. That single test is enough, and it is the whole reason this page exists.

Ready to put your USDT to work?

Open Trust Wallet, pick a term and start earning from 10 USDT. Your assets stay in your wallet the entire time.

Download on the App Store Get it on Google Play