Scam Identification Guide

Crypto Wallet Recovery Phrase Scam Texts

Every crypto text scam is eventually reaching for the same twelve words. Here's what your recovery phrase actually is, why nobody legitimate will ever ask for it, and how the request gets dressed up.

EC
Digital Safety Editor
Published 10 min read

Nobody has a legitimate reason to ask for your recovery phrase. Ever.

Not support. Not a security team. Not a wallet provider, an exchange, a tax authority, or the police. Not to verify you, restore access, migrate your wallet or reverse a hack. If a person, a website or a message asks for your 12 or 24 words, that is the theft. There is no further step coming and no other explanation. Full stop.

What a recovery phrase actually is

Set up a self custody wallet, whether that is MetaMask, Trust Wallet, a Ledger or a Trezor, and it hands you a list of ordinary English words. Usually twelve, sometimes 24. It tells you to write them down and never share them. Most people do write them down. Rather fewer understand what they are holding.

Those words are not a password for your wallet. They are the wallet. The phrase mathematically generates every private key inside it, so anyone holding the words has complete control of the money, from any device, anywhere in the world, without needing your phone, your PIN or your permission. There is no account to lock, no provider to ring, no fraud team who can undo it. That is why the phrase is what nearly every crypto scam is working towards, and why the request always arrives disguised as something else.

12-24
Words that give complete, permanent control of a self custody wallet
272,000
Ledger customers whose names, phone numbers and home addresses were dumped online after the 2020 breach
Seconds
How long automated software takes to empty a wallet once a phrase is exposed

£4 million, eight victims, and one request

Three men were jailed at Southwark Crown Court on 16 July 2026 after taking more than £4 million in cryptocurrency from eight victims. They had impersonated police officers and built fake police websites to make the whole thing hold together.

The approach was the same each time. Somebody claiming to be a senior law enforcement officer made contact, explained that the victim's crypto was caught up in a criminal case, and asked for the wallet's recovery phrase so it could be secured. Nothing about it looked like theft while it was happening. It looked like assisting an investigation.

In one case the equivalent of £2.1 million was moved out of the wallet within minutes of the phrase being handed over. Not hours. Minutes. There was no window in which anybody realised, rang somebody and stopped it, because once the words are out there is nothing left to stop.

Eight people, none of whom set out to give a stranger their money. The lesson is not that they were careless. It is that the recovery phrase request works precisely when it arrives wrapped in authority, and that no badge, warrant card or case reference changes the rule. Nobody legitimate needs those words.

Why you specifically are getting these texts

Most crypto scam texts are fired out blindly. This one often is not, and that is what makes it unnerving. In June 2020 attackers took Ledger's e-commerce and marketing database. Ledger initially reported that around a million email addresses had been exposed but detailed records for only about 9,500 customers. When the data was dumped publicly that December, it turned out to be 272,000 records containing full names, telephone numbers, postal addresses and product order histories.

That list is still circulating. It is a directory of people known to own hardware wallets, complete with mobile numbers and home addresses. Customers have been targeted by text and email phishing for years since, and some received physical letters demanding Bitcoin under threat of being exposed or worse. Ledger is simply the best documented case rather than the only one, and crypto firms and their payment partners keep suffering breaches. So if a text seems to know that you hold crypto, and even greets you by name, that isn't insight into your wallet. It's a spreadsheet.

How the approach works

Nobody texts you asking for twelve words outright. It is always framed as a technical necessity, and the framing is where the craft goes.

1. A problem you cannot check

The text raises something technical enough that you cannot immediately judge it. A mandatory security migration, a firmware vulnerability, a wallet that will be deactivated unless it is synced again, a suspicious outgoing transaction. Every one of those is something you have no independent way of verifying, which is the whole design. The scam needs you dependent on them for the answer.

Why migration is the favourite story

Wallet software does get updated, networks do change, and people have genuinely had to move assets between standards before. A message about a required migration sits comfortably inside things a crypto holder already believes can happen. And a migration is the one context where entering a recovery phrase sounds almost reasonable, which is exactly why it was picked.

2. The validation page or the support line

The text sends you one of two ways. A link leads to a clone of the real wallet site with a grid of twelve or 24 input boxes, labelled something like validate wallet or restore session. Or a phone number connects you to a convincing support agent who walks you through it out loud, reading the words back to confirm them. The phone version does more damage, because a friendly human explaining why this is necessary defeats more people than a web form ever will.

Where the fake support numbers come from

Plenty of them are advertised. Criminals buy search ads and seed forum posts so that anyone googling "MetaMask support number" or "Ledger helpline" finds them first. Self custody wallet providers do not run inbound phone support at all, so a number claiming to be one is fake by definition. Finding the number yourself rather than being sent it is not a safety check.

3. The wallet empties before you close the tab

No person does this part. The moment a valid phrase is submitted, automated software imports it, scans every address it generates across multiple blockchains and sweeps whatever it finds to addresses the criminals control. Seconds, at any hour, and it does not care whether you realised your mistake straight away. People routinely describe watching their balance drop to zero while still looking at the page.

Changing your PIN does nothing

A device PIN or a wallet password only protects that one installation. The recovery phrase works independently of both, because it can be typed into any wallet app on earth to rebuild your wallet from scratch. Once the words are out, the only real defence is moving the money to a brand new wallet with a brand new phrase, and doing it before the software gets there.

What these texts look like

These are examples based on messages reported across the UK. Four framings, one destination. Each gives you a reason why this time is the exception to the rule you already know.

"Mandatory migration"

Deadline plus consequence. The threat of losing access permanently is what stops people pausing to check, and calling it a migration makes entering a phrase sound procedural rather than reckless.

"Action required: wallets not migrated to the new security standard by 14/12 will be permanently deactivated. Migrate now: [link]"

"Firmware vulnerability"

Aimed squarely at hardware wallet owners, often the ones on the leaked customer lists. Real firmware updates exist, which is what gives it cover. Real ones never involve typing your phrase into anything.

"Ledger Security: a critical vulnerability affects your device. Verify your recovery phrase to apply the patch: [link]"

"Unauthorised transaction"

Borrows the bank fraud script wholesale. The number leads to a wallet security team who will help you protect your money, and protecting it turns out to require your phrase.

"Alert: an outgoing transfer of 1.84 ETH is pending from your wallet. If unauthorised, call our recovery team on 0203 XXX XXXX."

"Airdrop claim"

The one that uses greed rather than fear. Free tokens are waiting, and claiming them means connecting or verifying your wallet. People drop their guard for something that appears to cost nothing.

"You have an unclaimed airdrop worth £2,140 expiring in 24h. Connect your wallet to claim: [link]"

The rules that keep your phrase safe

You do not need to recognise every variant. You need a handful of rules that hold no matter how convincing the story is.

Always

  • Keep the phrase on paper or metal, offline, out of sight
  • Type it only into your own wallet app, only when restoring
  • Update hardware wallets through the official desktop app only
  • Assume any message about your wallet is fake until proven otherwise
  • Check balances in your own app, never through a link

Never

  • Photograph it, or store it in notes, email or the cloud
  • Type it into a page you reached from a message or an advert
  • Read it aloud to anyone, for any reason, on any call
  • Ring a wallet support number, because they do not exist
  • Believe a deadline that demands you act tonight

If you get one of these texts

1

Do not tap the link or ring the number

There is no version of a genuine wallet problem that gets solved through a link in an unexpected text. Curiosity is the risk, because some of these pages try to trigger a wallet connection prompt the moment they load.

2

Check in your own wallet app

Open the app you already have installed, or the official desktop software for a hardware device. Genuine firmware updates and genuine balances both appear there. If the app is calm, nothing is happening.

3

Forward it to 7726 and block the sender

Free on every UK network, and it lets your provider trace the sender and shut the route down. Blocking the individual number will not stop the campaign, but it stops that one.

Wallet providers also take phishing reports through their official websites, which helps get the cloned site taken offline.

4

Report the number on CallerCheck

Fake support numbers get reused across campaigns far more than sender IDs do, so reporting one is unusually valuable. Somebody about to ring that helpline is exactly who a search result protects.

Already entered your phrase?

Treat the wallet as lost and act on that basis. Don't spend time trying to make the old wallet safe, because it cannot be made safe.

  1. 1

    Create a new wallet on a clean device and move everything now

    A brand new wallet with a brand new recovery phrase, set up on a device you are confident is not compromised. Move every asset across immediately. If anything is staked or locked, move it the moment it frees up, because the software watching those addresses waits for exactly that.

  2. 2

    Never reuse that phrase or that wallet again

    Retire it completely. Do not send funds back to it later, even small amounts, and do not restore it just to check. Anyone holding the words will be watching those addresses indefinitely.

  3. 3

    Secure everything connected to it

    Change passwords on any exchange linked to that wallet, switch two step verification to an authenticator app rather than SMS, and revoke token approvals the wallet has granted to third party sites. If you installed anything during the process, treat the device as compromised too.

  4. 4

    Report to Action Fraud and keep the evidence

    Ring 0300 123 2040 or report at actionfraud.police.uk, or Police Scotland on 101. Record the transaction hashes and destination addresses, because those stay traceable on the blockchain even when the people behind them are not, and they matter to investigators building a case. The Southwark convictions came out of exactly this kind of evidence.

  5. 5

    Expect the recovery scam and ignore it

    Within weeks you will probably hear from somebody offering to trace and return your money for an upfront fee. It is a second scam aimed at the same victim, often run by the same people. Nobody can reverse a blockchain transaction, whatever they claim.

The short version

Red flags

  • • Any request for your 12 or 24 words
  • • Validate, migrate, sync or restore your wallet
  • • A wallet support phone number
  • • A deadline before your wallet is deactivated
  • • An airdrop you must connect a wallet to claim

What to do

  • • Keep the phrase offline and never share it
  • • Check your own wallet app instead
  • • Forward the text to 7726
  • • If exposed, move funds to a new wallet immediately
  • • Report the number on CallerCheck

Your recovery phrase isn't a password for your wallet. It is your wallet.

Frequently Asked Questions

Is there ever a legitimate reason to enter my recovery phrase?
Exactly one. Restoring your own wallet into wallet software you installed yourself, on your own device, because you decided to. That is the entire list. If the prompt came from a link, a message, an advert, a phone call or anyone else's suggestion, it is a theft in progress. The test is not which app is on screen, it is who started it. If it was not you, from scratch, do not type a word.
Would the police ever ask for my recovery phrase?
No, and this is worth being absolutely clear about, because impersonating the police is now one of the most effective versions of the scam. The three men jailed at Southwark Crown Court in July 2026 took more than £4 million from eight victims doing precisely this, complete with fake police websites. UK police forces have repeatedly warned that officers will never ask for your seed phrase, your private keys, your codes, or for you to move assets to a police safe account. If somebody claiming to be an officer asks, hang up and ring 101 to check.
How did they know I own a hardware wallet?
Almost certainly from a breached customer list rather than anything to do with your wallet. The 2020 Ledger breach put 272,000 records into public circulation, containing names, phone numbers, postal addresses and order histories, and that data has fuelled targeted phishing ever since. Other crypto firms and their payment partners have had breaches too. The reassuring part is that it tells them who to text, not what is in your wallet. Your money is only reachable if you hand over the phrase.
I only typed in a few of the words, then stopped. Am I safe?
Treat the wallet as compromised and move the money anyway. These pages usually capture every keystroke as you type rather than waiting for you to press submit, so stopping partway through does not mean nothing was sent. A partial phrase also narrows the search enormously for anyone trying to work out the rest. Moving to a fresh wallet costs you a transaction fee and an hour. Being wrong about this costs you everything in it.
Do MetaMask, Trust Wallet or Ledger have phone support?
No. Self custody wallet providers do not run inbound telephone support, which makes this one of the cleanest tests available. Any phone number presented as a wallet helpline is fraudulent, without exception. That holds whether the number arrived in a text, appeared in a search advert, or was posted in a forum thread by somebody being helpful. Support for these products happens in writing, through channels you reach from the provider's real website, which you should navigate to yourself.
Where should I actually keep my recovery phrase?
Offline and physical. Written on paper, or stamped into a metal backup plate if the amount justifies it, stored somewhere secure and ideally in more than one place so a fire or a flood does not take your only copy. Keep it well away from anything digital. No photographs, no notes app, no password manager entry, no email to yourself, no cloud backup. Anything touching a connected device can eventually be reached by somebody else, and a phrase only has to leak once.

About the Author

Digital Safety Editor

Cybersecurity Specialist

Emma is a digital safety expert focused on social engineering and phone-based fraud. She analyses scam report submissions to identify new fraud tactics and updates our scam guides with real-world examples. Emma follows threat intelligence from the National Cyber Security Centre, Action Fraud, and banking industry reports to ensure our scam identification advice helps readers stay protected.

Cybersecurity Social Engineering Scam Identification Online Safety
Updated Published 5th August 2026 Fact-checked by CallerCheck Editorial Team

Had a text or a support number asking about your wallet?

Report it on CallerCheck so the next person sees the warning before they ring.

We value your privacy

We use cookies to enhance your browsing experience, analyse site traffic, and show personalised ads. You can choose which cookies to accept below. Read more about cookies on CallerCheck.co.uk

Cookie Settings

Manage your cookie preferences

Essential Cookies

Always Active

Required for the website to function. These cannot be disabled as they are necessary for security and basic functionality.

callercheck_sessionSession management
XSRF-TOKENSecurity (CSRF protection)
cookie_consentStores your preferences

Analytics Cookies

Help us understand how visitors interact with our website by collecting anonymous information.

Google Analytics
_gaVisitor identification (2 years)
_ga_*Session state (2 years)
_gidUser distinction (24 hours)

Advertising Cookies

Used to show you relevant ads and support our free service. Disabling won't remove ads, but they'll be less relevant.

Google AdSense
Contextual and personalised advertising

Functional Cookies

Enable enhanced functionality like social sharing buttons and embedded content from third-party services.

YouTubeEmbedded videos
Google MapsEmbedded maps
View full Cookie Policy