Mnemonic phrases leaked: what it means and what to do
Risk level: critical. Can you change it: yes. Found in 1 breaches in this directory.
What this data is
The list of 12 or 24 words, also called a seed or recovery phrase, that recreates a cryptocurrency wallet on any device. It leaks when people keep it in notes apps, cloud documents, email drafts or a wallet service that stored a copy.
The risk on its own
This is as bad as a leak gets for the assets involved. The phrase is not a login that can be reset, it is the wallet itself, so anyone who types it into wallet software has exactly the control you have. There is no bank to reverse a transfer and no password change that locks them out.
The risk combined with other data
With your name or email address attached, attackers also know who to chase for other wallets and exchange accounts. It marks you as a crypto holder, which puts you on target lists for recovery scams and phishing. Criminals run automated tools that check leaked phrases for balances, so every hour of delay works in their favour.
How criminals use it
A script imports the phrase and sweeps every coin and token to an attacker address before the owner has even read the breach notice.
The attacker leaves a small balance alone and waits, draining the wallet only after you deposit something larger.
Coins on other blockchains derived from the same phrase, which many owners forget exist, are emptied as well.
A fake recovery service contacts you after the theft, claims it can trace the funds, and charges an upfront fee.
Your email address on the leaked list brings targeted phishing for your exchange login and your new wallet.
What to do now
Create a brand new wallet on a device you trust, ideally a hardware wallet, and write the new phrase on paper only.
Move every asset from the exposed wallet to the new one now, including tokens and coins on other networks that use the same phrase.
Stop using the old address completely and update any exchange withdrawal whitelist, invoice or payment link that still points to it.
Delete every digital copy of the phrase: screenshots, notes apps, cloud documents, email drafts and chat messages to yourself.
Change the password and switch on authenticator app two-factor authentication for the email address and any exchange account linked to the wallet.
If funds are already gone, report it to your national cybercrime reporting service and to the exchange that received them, and ignore anyone offering paid recovery.
Frequently asked questions
Can I change my seed phrase like a password?
No. A recovery phrase cannot be edited. The only fix is to create a new wallet with a new phrase and move everything across to it.
My coins are still there. Does that mean nobody used the phrase?
No. Some attackers wait for a larger deposit before draining a wallet. Move the funds now rather than reading an untouched balance as reassurance.
Can stolen crypto be recovered?
Rarely. Blockchain transfers cannot be reversed, and services that promise recovery for a fee are almost always a second scam. Reporting to police and the receiving exchange is still worth doing.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.