Skip to main content

What to Do If Your Secret Phrase Is Exposed

Treat an Exposed Secret Phrase as Compromised​

Anyone who knows your Secret Phrase can import the wallet on another device and control its assets. They do not need your phone, password, or biometric authentication.

Treat the phrase as exposed if it was:

  • Shared with another person, including someone claiming to be support.
  • Entered into a website, form, chatbot, or unfamiliar app.
  • Saved in email, cloud storage, notes, or an online password field.
  • Included in a screenshot, photo, screen recording, or livestream.
  • Seen by another person or security camera.
  • Stored on a device you believe is infected or remotely controlled.
danger

An exposed Secret Phrase cannot be changed, reset, or made private again. Create a new wallet with a new phrase and move any remaining assets. Do not continue using the exposed wallet.

Do Not Reproduce the Exposure​

You do not need to re-enter or share the phrase to confirm the problem. Do not open the suspicious website or app again, and do not send the phrase to Gem Wallet support.

Use public information to assess the wallet instead:

  1. Open each affected asset in Gem Wallet.
  2. Review its activity for transactions you do not recognize.
  3. Select a transaction and use View on explorer name to verify its public status.
  4. Record public transaction IDs and addresses needed for reporting.

If unauthorized transactions have already occurred, also follow What to Do If Your Crypto Wallet Is Compromised.

Create a New Wallet​

Use a trusted device. If the original device may contain malware or remote-access software, use a different clean device.

  1. Open the wallet selector in Gem Wallet.
  2. Select Create a New Wallet.
  3. Complete the setup to generate a new wallet and Secret Phrase.
  4. Give the new wallet a recognizable name so it is not confused with the exposed wallet.

Do not select Import an Existing Wallet and do not enter the exposed phrase. Importing it creates access to the same compromised wallet rather than a safe replacement.

important

Gem Wallet is self-custodial. It cannot rotate a phrase, freeze a wallet, reverse a blockchain transaction, or block another person who already knows the phrase.

Back Up the New Secret Phrase Safely​

Follow Backup Gem Wallet and write the new phrase down in the correct order. Store it offline somewhere only you control.

Do not:

  • Take a screenshot or photo.
  • Save it in a notes app, email, chat, or cloud drive.
  • Copy it into an online form.
  • Store it beside the exposed phrase without clearly distinguishing them.

Gem Wallet displays a warning when a screenshot of the Secret Phrase is detected because screenshots may be accessible to other apps or cloud backups.

Move Remaining Assets​

For every asset still controlled by the exposed wallet:

  1. Open the asset in the new wallet and select Receive.
  2. Confirm the asset and blockchain network.
  3. Copy the complete new receive address.
  4. Return to the exposed wallet and select the matching asset.
  5. Select Send, enter the new address, and verify the network.
  6. Review the amount, recipient, and network fee before confirming.
  7. Wait for the transaction to become Successful and verify the new balance.

Move assets network by network. Tokens normally require the old wallet to have the correct native coin for network fees.

caution

If an automated thief is monitoring the exposed wallet, newly deposited fee funds may also be stolen. Do not keep adding funds or repeatedly retrying transactions. There is no guaranteed race against an attacker who has the same signing authority.

Prioritize assets according to their value, transfer requirements, staking or lock state, and available network-fee balance. Confirm each destination before submitting because blockchain transactions are generally irreversible.

Check Staked, Locked, and Connected Assets​

Some assets may not be immediately available because they are staked, locked, reserved, or held through a smart contract. Review the asset's Balances, staking screen, and transaction activity.

Unstaking and withdrawals can require time and additional transactions. Continue monitoring the exposed wallet until all recoverable assets have reached the new wallet.

Revoking token approvals or disconnecting dApps can limit some smart-contract access, but it does not protect a wallet when the Secret Phrase itself is exposed. Anyone with the phrase can still sign new transactions.

Stop Using the Exposed Wallet​

After all recoverable assets have moved:

  • Stop receiving funds at every address derived from the exposed phrase.
  • Update saved withdrawal addresses and contacts that point to the old wallet.
  • Remove the exposed wallet from connected dApps and services.
  • Delete the wallet from Gem Wallet only after confirming that nothing else needs to be moved or monitored.

Deleting the wallet removes it from that device. It does not invalidate the phrase, erase blockchain history, or prevent someone else from importing it.

Report Theft or Fraud​

Save public evidence such as transaction IDs, wallet addresses, dates, amounts, website addresses, and messages. Report scams to the relevant platform and local cybercrime or law-enforcement authority.

Open Settings > Support in Gem Wallet for guidance. Support can help explain app behavior and public transactions, but it cannot recover stolen funds or require a blockchain to reverse them.

caution

Gem Wallet support never needs your Secret Phrase or private key. Anyone asking for either one is trying to take control of your wallet.

Exposure Response Checklist​

  • Stop using the suspicious app, website, or device.
  • Create a new wallet with a new Secret Phrase on a trusted device.
  • Back up the new phrase offline.
  • Verify new receiving addresses and networks.
  • Move remaining available assets and confirm each transaction.
  • Continue monitoring staked or locked assets.
  • Update saved addresses and connected services.
  • Abandon the exposed phrase permanently.
  • Save public evidence and report unauthorized activity.