The street cats I feed took months to trust me. Not days — months. The first few weeks I put food down and walked away, and they ate only once I was out of sight. The bold one came first. The careful one still keeps a hedge between us, five years in, and I have come to think she has the healthier instinct.
A stranger offering food is the oldest trap there is. Every cat born outside knows it. Every human who has just learned what a seed phrase is appears to have forgotten it entirely.
This article will not make you money. It might stop you losing all of it, which is the same thing arriving in a less exciting shape.
1. Nobody Is Going to Ask For Your Seed Phrase Except a Thief
Start here, because it covers a majority of losses on its own.
There is no legitimate reason for anyone to ever see your recovery phrase. Not support. Not a wallet developer. Not a "validation" website. Not a migration tool. Not an exchange. Not a friendly person in a Telegram group who is trying to help you fix an error message.
If a human being, a website, or a form asks for those words, you have already found the thief. There is no second interpretation. The request itself is the entire diagnosis.
Same for entering them into anything that isn't your hardware wallet's own screen. A phishing site that perfectly clones your wallet's interface costs about twenty euros to build and drains you in under a second.
2. How They Actually Reach You
The technique is almost never technical. It's social, and it's aimed at the two moments you're most vulnerable: when you're confused, and when you're desperate.
- Fake support. You post a problem publicly — on X, Reddit, Discord, a Telegram group. Within minutes, a DM arrives from "support". Real support never DMs first. Ever. The speed of the reply is the tell.
- Address poisoning. A scammer sends you a tiny transaction from an address that looks almost identical to one you use — same first four characters, same last four. Later you copy an address from your transaction history and grab theirs instead. Always verify the middle of the address, not just the ends.
- Clipboard malware. Software on your machine watches for a copied bitcoin address and silently replaces it with the attacker's. Check the address on your hardware wallet's own screen before confirming — that screen is the last thing they cannot forge.
- Fake airdrops and "claim your" anything. A page that asks you to connect a wallet or sign a message to claim free tokens. The signature is the theft.
- Slow-burn investment relationships. The one that takes the most money per victim. Weeks of friendly conversation — sometimes romantic, sometimes just a helpful acquaintance — leading to a "platform" that shows growing profits and permits one small successful withdrawal to build trust. Then a large deposit and a wall of fees to get anything out. There is no platform. There never was.
- Recovery services. These target people who have already been robbed. Nobody can reverse a bitcoin transaction. The service is a second theft aimed at people too hurt to be careful.
3. The Feelings That Precede Losses
Scams don't defeat your intelligence. They defeat your state of mind, and they are engineered to produce a specific one.
Urgency. A deadline, a closing window, a limited allocation. Every legitimate opportunity in bitcoin will still be there tomorrow. Manufactured hurry exists to prevent the pause where you'd notice.
Flattery and specialness. Early access. A private group. Selected for something. It is very hard to check a claim while feeling chosen.
Shame. The one that keeps the money moving. Victims don't ask a friend to sanity-check the platform because they're embarrassed not to already know. Scammers rely on that silence completely.
If you feel hurried, chosen, or embarrassed — stop. Those three feelings are the actual alarm system. Not a checklist.
4. The Habits That Actually Protect You
- A separate browser for money. No extensions, no random sites, bookmark-only navigation. Never reach your exchange or wallet through a search result — sponsored search ads for fake wallet sites are a standing industry.
- Verify on the device screen. The whole reason a hardware wallet has a display is so that malware on your computer cannot lie about where the money is going. Read it. Every time.
- Small test transaction. For any new address or large transfer, send a small amount first. The fee is cheap insurance.
- A trusted second opinion. Name one person you'll run anything unusual past, in advance. The mere act of describing a scam out loud kills most of them.
- Assume every DM is hostile. This is unfriendly and correct.
5. If It Already Happened
Say it out loud to someone. That's the first step, and shame is what stops it.
Then: move any remaining funds to a completely new wallet with a newly generated seed — assume the old one is fully compromised, including any accounts sharing that phrase. Report it to your local police and to the exchange involved; recovery odds are low, but patterns matter and reports occasionally connect. And ignore, absolutely, every single person who appears afterwards offering to get it back.
Being scammed is not stupidity. These operations are professional, funded, and run at industrial scale against millions of people. The only genuine mistake is staying quiet afterwards.
The Point
The careful cat behind the hedge is not paranoid. She has correctly identified that the cost of being wrong about a stranger is very high and the cost of waiting is a slightly later dinner.
Self-custody hands you a bearer asset with no undo button. That's the power and the whole liability in one sentence. Act like the cat who keeps a hedge between herself and anything new.
Nobody legitimate will ever need your seed phrase. Keep the hedge. 🐾⚡
Not financial advice — I feed cats and write about Bitcoin, which qualifies me for neither profession. If you have been targeted, report it to your local authorities.