Disclaimer: Independent informational blog. Not affiliated with Guarda Wallet.
Official site: https://guarda.com

Home / Blog / Seed Phrase Rules: What Never to Do

Security

Seed Phrase Rules: What Never to Do

2026-01-13 • 8 min • Keywords: seed phrase rules, recovery phrase, backup rules, never share seed

Cover illustration
Important: Independent blog. No wallet access, no downloads, and we never ask for restore phrases or private keys.

Restore is the highest‑risk moment for phishing. A safe restore happens only inside official wallet software on a clean device. Never enter a recovery phrase on any website, and never share it with “support”.

Step-by-step checklist

  1. Pause and assume scammers target restore steps; do not rush.
  2. Get the software only from the official website (guarda.com) or official app stores.
  3. Update OS/browser and security patches before restoring.
  4. Disable/remove unknown browser extensions and suspicious apps.
  5. Avoid screen sharing or remote access while restoring.
  6. Start the restore flow inside the official app/extension/desktop software.
  7. Enter the recovery phrase only in the official restore screen (not in a website form).
  8. Verify word order and spelling carefully; do not autocorrect.
  9. After restore, confirm balances using public info (addresses/tx hashes).
  10. If you suspect exposure, create a new wallet and move funds when safe.
  11. Create a fresh backup plan (two offline copies stored separately).
  12. Keep notes on backup locations and physical access.
  13. Ignore “restore pages” in ads/search; use bookmarks.

Common mistakes

  • Typing the seed phrase into a website that claims to restore wallets.
  • Following “support” links from chats or ads.
  • Restoring on a compromised/shared device or under remote assistance.
  • Copy/pasting the phrase via clipboard managers.
  • Storing the phrase as photos/screenshots or cloud notes.
  • Mixing up word order or using autocorrected words.
  • Keeping only one backup copy in a single place.

Risk level table

Risk levelWhat to doWhat not to do
HighRestore only inside official software on a clean device.Enter the phrase on any website or share it with anyone.
MediumUpdate the device and disable unknown extensions before restoring.Restore under urgency, ads, or remote “help”.
LowUse public info (addresses/tx hashes) to verify outcomes.Share sensitive screenshots or device data publicly.

Mini-cases

  • If you see: A page asks you to “restore” by entering 12/24 words.
    Do: Close it immediately; that is a phishing pattern.
  • If you see: You see “Guarda wallet restore” in sponsored ads.
    Do: Ignore ads; type the official domain manually or use a bookmark.
  • If you see: Someone says they can “recover funds” if you share your phrase.
    Do: Stop. Legitimate support will never request it.
  • If you see: You restored and something looks different.
    Do: Pause, verify sources, and consider migrating to a new wallet.
  • If you see: You are not sure the device is clean.
    Do: Do not restore yet; switch to a trusted, updated device.

FAQ

Is “restore” the same as “login”?

No. Restore involves secret key material and is much higher risk.

Should I ever enter my recovery phrase on a website?

No. Treat that as a scam indicator.

What does “restore” usually mean?

Recreating access using your recovery phrase inside official wallet software.

What does “replace” mean in practice?

Usually replacing a device/app and restoring, or creating a new wallet and migrating assets.

Can official support ask for my phrase?

No. Never.

Is it safe to screenshot the phrase?

No; screenshots often sync to cloud storage.

What if I already entered the phrase somewhere?

Assume compromise and migrate assets to a new wallet as soon as safely possible.

How many backup copies should I keep?

At least two offline copies stored in separate locations.

Can I verify balances without secrets?

Yes, via public addresses and transaction hashes.

Why do scammers target “restore” keywords?

Because users are stressed and more likely to ignore domain checks.

What is the safest next step if unsure?

Stop and verify using official channels and official software only.


Official link

For any real wallet action (access, downloads, support), use the official website:

Open official Guarda website

Related