Quick answer: never enter your seed phrase into a website, never share it with anyone claiming to be support staff, and never store it anywhere digital. Nearly every major NFT theft traces back to one of these three rules being broken, not to the blockchain itself being hacked. The technology holds up. The scams target the person, not the system.
Why the seed phrase is the actual target
Attackers don’t need to break blockchain encryption to steal an NFT collection. They just need the owner to type their seed phrase somewhere it shouldn’t go. Once someone has that phrase, they can recreate the wallet on their own device and move everything out in seconds. There’s no fraud department to call and no transaction to reverse.
That’s why nearly every scam in this space, regardless of how it’s dressed up, has the same underlying goal: get you to reveal or enter your seed phrase.
The scams that actually work
Fake support messages. A message shows up, often in a Discord server for a real NFT project, claiming to be from the team and offering help with a wallet issue. It asks you to “verify” your wallet by entering your seed phrase into a linked site. No legitimate project or wallet provider will ever ask for this.
Phishing sites that copy real marketplaces. These sites look identical to OpenSea, Magic Eden, or your wallet’s own interface. They’re usually promoted through fake ads, compromised social accounts, or links sent directly to you. Connecting your wallet to a phishing site can trigger a prompt for your seed phrase, or a spending approval you didn’t intend to give. Always check the URL directly.
Fake mint pages. A new NFT drop is announced, and a link circulates claiming to be the official minting page. The fake version asks for wallet connection and then requests unusually broad permissions, sometimes disguised as a normal transaction confirmation. Verify mint links through a project’s official website or verified social account, not through direct messages.
“Wallet drainer” browser extensions. Malicious extensions, sometimes disguised as portfolio trackers or price alerts, request access to your browser and quietly monitor wallet activity. Only install extensions from sources you’ve verified, and periodically review what’s installed.
Airdrop and giveaway scams. An unexpected NFT or token shows up in your wallet for free. Interacting with it, including trying to sell it, can trigger a malicious contract. If you didn’t request it, leave it alone.
The rules that stop nearly all of this
- Never type your seed phrase into any website, ever, after the one time you write it down during initial wallet setup. There is no legitimate reason to enter it again.
- No one legitimate will ever ask for it. Not a project team, not a marketplace, not a wallet provider, not “customer support.” Anyone asking is running a scam.
- Type marketplace and wallet URLs directly, or use a saved bookmark. Don’t click links from Discord, X, or email to get there.
- Keep your seed phrase offline, written on paper or engraved on metal, never in a screenshot, notes app, cloud drive, or email.
- Use a hardware wallet for anything valuable. See our Wallets & Security guide for the difference between hardware and software wallets, and when each one makes sense.
Check Ledger Wallets →
If you think you’ve already been scammed
Move any remaining assets to a new wallet with a freshly generated seed phrase immediately; don’t wait to investigate first. If a hardware wallet was compromised at the software level (not the device itself), the same rule applies: assume the exposed seed phrase is permanently unsafe and start over with a new one.
There’s no recovery process for stolen crypto or NFTs. Prevention is the only real defense, which is exactly why the five rules above matter more than any technical safeguard on the blockchain side.
