What a recovery phrase actually is
Set up a self custody wallet, whether that is MetaMask, Trust Wallet, a Ledger or a Trezor, and it hands you a list of ordinary English words. Usually twelve, sometimes 24. It tells you to write them down and never share them. Most people do write them down. Rather fewer understand what they are holding.
Those words are not a password for your wallet. They are the wallet. The phrase mathematically generates every private key inside it, so anyone holding the words has complete control of the money, from any device, anywhere in the world, without needing your phone, your PIN or your permission. There is no account to lock, no provider to ring, no fraud team who can undo it. That is why the phrase is what nearly every crypto scam is working towards, and why the request always arrives disguised as something else.
£4 million, eight victims, and one request
Three men were jailed at Southwark Crown Court on 16 July 2026 after taking more than £4 million in cryptocurrency from eight victims. They had impersonated police officers and built fake police websites to make the whole thing hold together.
The approach was the same each time. Somebody claiming to be a senior law enforcement officer made contact, explained that the victim's crypto was caught up in a criminal case, and asked for the wallet's recovery phrase so it could be secured. Nothing about it looked like theft while it was happening. It looked like assisting an investigation.
In one case the equivalent of £2.1 million was moved out of the wallet within minutes of the phrase being handed over. Not hours. Minutes. There was no window in which anybody realised, rang somebody and stopped it, because once the words are out there is nothing left to stop.
Eight people, none of whom set out to give a stranger their money. The lesson is not that they were careless. It is that the recovery phrase request works precisely when it arrives wrapped in authority, and that no badge, warrant card or case reference changes the rule. Nobody legitimate needs those words.
Why you specifically are getting these texts
Most crypto scam texts are fired out blindly. This one often is not, and that is what makes it unnerving. In June 2020 attackers took Ledger's e-commerce and marketing database. Ledger initially reported that around a million email addresses had been exposed but detailed records for only about 9,500 customers. When the data was dumped publicly that December, it turned out to be 272,000 records containing full names, telephone numbers, postal addresses and product order histories.
That list is still circulating. It is a directory of people known to own hardware wallets, complete with mobile numbers and home addresses. Customers have been targeted by text and email phishing for years since, and some received physical letters demanding Bitcoin under threat of being exposed or worse. Ledger is simply the best documented case rather than the only one, and crypto firms and their payment partners keep suffering breaches. So if a text seems to know that you hold crypto, and even greets you by name, that isn't insight into your wallet. It's a spreadsheet.
How the approach works
Nobody texts you asking for twelve words outright. It is always framed as a technical necessity, and the framing is where the craft goes.
1. A problem you cannot check
The text raises something technical enough that you cannot immediately judge it. A mandatory security migration, a firmware vulnerability, a wallet that will be deactivated unless it is synced again, a suspicious outgoing transaction. Every one of those is something you have no independent way of verifying, which is the whole design. The scam needs you dependent on them for the answer.
Why migration is the favourite story
Wallet software does get updated, networks do change, and people have genuinely had to move assets between standards before. A message about a required migration sits comfortably inside things a crypto holder already believes can happen. And a migration is the one context where entering a recovery phrase sounds almost reasonable, which is exactly why it was picked.
2. The validation page or the support line
The text sends you one of two ways. A link leads to a clone of the real wallet site with a grid of twelve or 24 input boxes, labelled something like validate wallet or restore session. Or a phone number connects you to a convincing support agent who walks you through it out loud, reading the words back to confirm them. The phone version does more damage, because a friendly human explaining why this is necessary defeats more people than a web form ever will.
Where the fake support numbers come from
Plenty of them are advertised. Criminals buy search ads and seed forum posts so that anyone googling "MetaMask support number" or "Ledger helpline" finds them first. Self custody wallet providers do not run inbound phone support at all, so a number claiming to be one is fake by definition. Finding the number yourself rather than being sent it is not a safety check.
3. The wallet empties before you close the tab
No person does this part. The moment a valid phrase is submitted, automated software imports it, scans every address it generates across multiple blockchains and sweeps whatever it finds to addresses the criminals control. Seconds, at any hour, and it does not care whether you realised your mistake straight away. People routinely describe watching their balance drop to zero while still looking at the page.
Changing your PIN does nothing
A device PIN or a wallet password only protects that one installation. The recovery phrase works independently of both, because it can be typed into any wallet app on earth to rebuild your wallet from scratch. Once the words are out, the only real defence is moving the money to a brand new wallet with a brand new phrase, and doing it before the software gets there.
What these texts look like
These are examples based on messages reported across the UK. Four framings, one destination. Each gives you a reason why this time is the exception to the rule you already know.
"Mandatory migration"
Deadline plus consequence. The threat of losing access permanently is what stops people pausing to check, and calling it a migration makes entering a phrase sound procedural rather than reckless.
"Action required: wallets not migrated to the new security standard by 14/12 will be permanently deactivated. Migrate now: [link]"
"Firmware vulnerability"
Aimed squarely at hardware wallet owners, often the ones on the leaked customer lists. Real firmware updates exist, which is what gives it cover. Real ones never involve typing your phrase into anything.
"Ledger Security: a critical vulnerability affects your device. Verify your recovery phrase to apply the patch: [link]"
"Unauthorised transaction"
Borrows the bank fraud script wholesale. The number leads to a wallet security team who will help you protect your money, and protecting it turns out to require your phrase.
"Alert: an outgoing transfer of 1.84 ETH is pending from your wallet. If unauthorised, call our recovery team on 0203 XXX XXXX."
"Airdrop claim"
The one that uses greed rather than fear. Free tokens are waiting, and claiming them means connecting or verifying your wallet. People drop their guard for something that appears to cost nothing.
"You have an unclaimed airdrop worth £2,140 expiring in 24h. Connect your wallet to claim: [link]"
The rules that keep your phrase safe
You do not need to recognise every variant. You need a handful of rules that hold no matter how convincing the story is.
Always
- Keep the phrase on paper or metal, offline, out of sight
- Type it only into your own wallet app, only when restoring
- Update hardware wallets through the official desktop app only
- Assume any message about your wallet is fake until proven otherwise
- Check balances in your own app, never through a link
Never
- Photograph it, or store it in notes, email or the cloud
- Type it into a page you reached from a message or an advert
- Read it aloud to anyone, for any reason, on any call
- Ring a wallet support number, because they do not exist
- Believe a deadline that demands you act tonight
If you get one of these texts
Do not tap the link or ring the number
There is no version of a genuine wallet problem that gets solved through a link in an unexpected text. Curiosity is the risk, because some of these pages try to trigger a wallet connection prompt the moment they load.
Check in your own wallet app
Open the app you already have installed, or the official desktop software for a hardware device. Genuine firmware updates and genuine balances both appear there. If the app is calm, nothing is happening.
Forward it to 7726 and block the sender
Free on every UK network, and it lets your provider trace the sender and shut the route down. Blocking the individual number will not stop the campaign, but it stops that one.
Wallet providers also take phishing reports through their official websites, which helps get the cloned site taken offline.
Report the number on CallerCheck
Fake support numbers get reused across campaigns far more than sender IDs do, so reporting one is unusually valuable. Somebody about to ring that helpline is exactly who a search result protects.
Already entered your phrase?
Treat the wallet as lost and act on that basis. Don't spend time trying to make the old wallet safe, because it cannot be made safe.
-
1
Create a new wallet on a clean device and move everything now
A brand new wallet with a brand new recovery phrase, set up on a device you are confident is not compromised. Move every asset across immediately. If anything is staked or locked, move it the moment it frees up, because the software watching those addresses waits for exactly that.
-
2
Never reuse that phrase or that wallet again
Retire it completely. Do not send funds back to it later, even small amounts, and do not restore it just to check. Anyone holding the words will be watching those addresses indefinitely.
-
3
Secure everything connected to it
Change passwords on any exchange linked to that wallet, switch two step verification to an authenticator app rather than SMS, and revoke token approvals the wallet has granted to third party sites. If you installed anything during the process, treat the device as compromised too.
-
4
Report to Action Fraud and keep the evidence
Ring 0300 123 2040 or report at actionfraud.police.uk, or Police Scotland on 101. Record the transaction hashes and destination addresses, because those stay traceable on the blockchain even when the people behind them are not, and they matter to investigators building a case. The Southwark convictions came out of exactly this kind of evidence.
-
5
Expect the recovery scam and ignore it
Within weeks you will probably hear from somebody offering to trace and return your money for an upfront fee. It is a second scam aimed at the same victim, often run by the same people. Nobody can reverse a blockchain transaction, whatever they claim.
The short version
Red flags
- • Any request for your 12 or 24 words
- • Validate, migrate, sync or restore your wallet
- • A wallet support phone number
- • A deadline before your wallet is deactivated
- • An airdrop you must connect a wallet to claim
What to do
- • Keep the phrase offline and never share it
- • Check your own wallet app instead
- • Forward the text to 7726
- • If exposed, move funds to a new wallet immediately
- • Report the number on CallerCheck
Your recovery phrase isn't a password for your wallet. It is your wallet.