The short version

A wallet password may unlock one device. A private key or recovery phrase can recreate control elsewhere.

01

Four different things people call “the wallet”

An address is a public identifier. It is where value is sent, it is safe to share for that purpose, and it reveals your activity to anyone who looks. A public key participates in verifying that a signature is genuine. A private key authorizes actions: it produces the signature the network checks. A recovery phrase—usually twelve or twenty-four ordinary words—is a compact encoding from which one or many private keys can be derived.

These sit in a hierarchy. The recovery phrase can regenerate the private keys; the private keys produce signatures; the signatures move value. Anyone holding a level can reconstruct everything below it. This is why the phrase is the most dangerous secret in the system, more dangerous than a bank password, because it is the account rather than access to the account.

The wallet application itself is a viewer and a signing tool. It reads network data to display balances and constructs transactions for you to approve. Deleting the app destroys nothing; the record lives on the network and the authority lives in the phrase.

02

Local lock versus underlying authority

A PIN, a fingerprint, or an app password protects access on one device. It is a genuine and worthwhile protection against someone picking up your unlocked phone. It is not a protection against a copied recovery phrase.

Changing that password does not revoke anything. If someone photographed your phrase last month, they can enter it into any compatible wallet on any device and sign transactions immediately. There is no session to terminate, no device list to review, and no support desk that can invalidate it. The only remedy is to generate a completely new wallet and move everything to it before the holder acts.

This asymmetry is the single most important operational fact in self-custody, and it is worth stating plainly: exposure is permanent, and the response is migration, not damage control.

03

Where phrases actually leak

Most losses do not involve breaking cryptography. They involve the phrase being somewhere it should not be. The recurring places are a photo in a synced camera roll, a note in a cloud-backed notes app, a password manager entry that was later shared, a screenshot taken during setup, a text message “just to have a copy,” and a support chat with someone impersonating a wallet provider.

A second cluster involves entering the phrase into a website. Legitimate wallet recovery happens inside the wallet application you deliberately installed. A web page asking you to “validate,” “sync,” “migrate,” or “claim” with a recovery phrase is a theft mechanism in every case, without exception, regardless of how convincing the branding is.

04

The non-negotiable boundary

No support agent, giveaway, airdrop claim, wallet migration, security check, tax tool, or verification form needs your private key or recovery phrase. There is no scenario in which a legitimate party requires it, because nothing legitimate needs the ability to sign on your behalf.

This makes the rule unusually easy to apply. You do not have to judge whether a particular request is plausible, evaluate the quality of a website, or assess whether the person is really from support. The request itself is the answer.

  • Share addresses only when the privacy implications are acceptable.
  • Never type or paste recovery material into a website or chat.
  • Never photograph or store the phrase on a device that syncs.
  • Enter the phrase only in a wallet app you installed deliberately and verified.
  • If a phrase is ever exposed, move funds to a new wallet rather than hoping.

Sources and review

Primary and official sources anchor consequential claims. The review date changes only after the lesson and its references are checked again.

Written by
Crypto Academy Editorial Desk
Reviewed by
Crypto Academy Research Desk
Next review
Dec 2, 2026
Finished this lesson?Stored only in this browser.