BLOG |
How-tos
Here's how phishing scam works, and the one rule that keeps you safe.
Phishing for wallet credentials isn't new. What's new is fake websites now asking Bitcoin users to type in their backup phrase, the one thing that can actually empty a wallet. Here's how the scam works, and the one rule that keeps you safe.
There is exactly one piece of information that can empty your wallet without your permission: your backup phrase, also called a seed phrase. Everything else, your email, your phone number, even your PIN, a scammer can work around. Your backup phrase, they cannot. So that's the one thing they're going to come after.
A backup phrase (also called a seed phrase) is a set of words generated when you set up a non-custodial wallet, usually 12 or 24, depending on the wallet. Blink uses 12.
Phishing itself is not new. It's one of the oldest tricks used against self-custodial Bitcoin wallets, and it's not unique to Blink. What is new is the target. Fake websites asking you to "verify," "restore," or "sync" your wallet by typing in your backup phrase.
If you're not fully sure why those twelve words matter so much in the first place, start here: Not Your Keys, Not Your Coins — What Does It Mean?. Everything below assumes you already understand that your backup phrase is your Bitcoin, which is exactly why it's the only thing worth stealing.
Fair warning: this article won't teach you how phishing sites are built, and I won't be linking to any real examples. The goal here is one rule, repeated until it's boring: nobody, ever, under any circumstance, needs your backup phrase typed into a website. Not Blink. Not "Blink support." Not a wallet you've never heard of that suddenly needs to "verify" you.
For years, the biggest threat to Blink users wasn't technical, it was social. Someone messaging first, pretending to be Blink support, asking for account details, PINs, or verification codes. We've talked about this a lot, and it worked: most people in this community now know, instinctively, that Blink support never messages you first. That single piece of awareness has saved a lot of people a lot of money.
Now there's a second habit worth building alongside it.
Backup phrase phishing has targeted self-custodial Bitcoin wallet users for over a decade. It's not a new tactic, and it's not unique to Blink, any wallet with a recovery phrase has been a target for as long as recovery phrases have existed. What's changed is who, on Blink, now has one.
For most of Blink's history, the majority of users were custodial. There was no backup phrase to steal, because there was no backup phrase, full stop. The worst a scammer could do was trick you into revealing login details or a 2FA code.
That changed the moment non-custodial accounts became real. Now a growing number of people are holding twelve words that are the entire wallet: no password reset, no support ticket, no undo button. That's the whole point of non-custodial ownership, and it's a genuine trade-off we've been upfront about since day one: true ownership means true responsibility.
It also means a category of scam that's old news across other Bitcoin wallets is, for the first time, worth running against Blink users specifically. A fake login screen asking for your email is worth very little to a criminal. A fake screen asking for your backup phrase is worth however much Bitcoin you own. That incentive did not exist for most of Blink's history. It exists now.
This is specifically relevant to Blink users because Blink now has a non-custodial account option. If you've made the switch, or you're thinking about it, you're holding a backup phrase for the first time, which makes you a first-time target too, even though this style of attack is well-worn ground on other Bitcoin wallets. Learn more about non-custodial accounts on Blink Wallet.
I can't predict the exact disguise it'll wear: a fake app update, a cloned website with a URL one character off, a "wallet recovery tool," a QR code at a meetup that leads somewhere it shouldn't. The costume changes. The ask never does.
The tell is always the same: somewhere, at some point, you'll be asked to type your twelve words into a text box. That's the entire scam. Everything before that moment, the urgency, the official-looking logo, the countdown timer, the "your funds are at risk" message, exists purely to get you to that text box.
A backup phrase goes into a wallet you opened yourself. Never into a website.
Say it however you need to remember it. Your backup phrase unlocks your wallet on your device, in an app you deliberately installed. It does not get typed into a browser, a chat window, a support form, or a "verification portal." If something is asking you to do that, close it. It does not matter how convincing it looks.
What a legitimate recovery actually looks like: you open a wallet app, the real one, downloaded from the real App Store or Play Store listing, or built from source if you're that kind of user, and you type your words directly into that app, offline, with nothing sent anywhere. That's it. There is no legitimate version of this that happens on a webpage.
What Blink will never do: we will never ask for your backup phrase, over chat, email, phone, or web form. Not to "verify" your account, not to help you recover funds, not for any reason. If we ever needed your backup phrase to help you, that would mean we could already access your funds, and the entire design of non-custodial accounts is that we can't.
Bookmark the real site, don't search for it. A search ad or a lookalike domain is one typo away from the real thing. Type blink.sv once, bookmark it, use the bookmark.
Treat urgency as a red flag, not a reason to hurry. "Your account will be suspended," "verify within 24 hours," "your funds are at risk," these phrases exist to shut down the part of your brain that would otherwise stop and check. Real recovery has no clock running.
Back up your backup phrase somewhere only you control. Steel plate, password manager, encrypted cloud backup, pick the one you'll actually maintain. The safest backup in the world does you no good if a fake site convinces you to hand a copy to someone else six months later.
Assume any unsolicited contact is hostile until proven otherwise. Not "unlikely to be legitimate," assume hostile. The people running these scams are patient, and they only need to be right once.
Non-custodial control is the right direction. It's also not free. Custodial wallets had a support team standing between you and a lost password. Non-custodial wallets have you, your twelve words, and nothing else. I'm not going to pretend that trade-off doesn't exist, and I'm not going to let a single hype paragraph paper over the fact that self-custody means you are now the target, the same way self-custodial Bitcoin holders using other wallets already have been for years.
That's not a reason to avoid non-custodial ownership. It's a reason to take the one rule seriously: your backup phrase goes into your wallet, on your device, and nowhere else. Ever.
Will Blink support ever ask me for my backup phrase to help recover my account?
No. Never. If we could recover your funds with your backup phrase, it would mean we had access to them, and the entire point of non-custodial accounts is that we don't. Anyone asking for your backup phrase "to help" is not Blink.
What if a website looks exactly like blink.sv?
Check the URL character by character before you check anything else. Lookalike domains rely on you trusting the logo and skipping the address bar. Bookmark the real domain and never reach it through a search result or a link in a message.
I already typed my backup phrase into a site that looked official. What do I do?
Move your funds to a brand-new wallet with a freshly generated backup phrase immediately, before doing anything else. Assume the old phrase is compromised the second it left your device, even if nothing has been taken yet.
Is this only a Blink problem?
No. This is a Bitcoin-wide risk, not a Blink-specific one. Any non-custodial wallet, Blink, Phoenix, or otherwise, has this exact same single point of failure: the backup phrase. Blink users are simply newer to being a target than most.
Does using a hardware wallet make this risk go away?
It reduces it, because your backup phrase never has to touch an internet-connected device to sign transactions. It doesn't remove the risk entirely, you can still be tricked into typing your words into a fake "restore" flow on a screen. The rule stays the same regardless of what wallet you use.
Your twelve words are worth exactly as much as your Bitcoin, and no more. Treat any request for them, however official it looks, the same way you'd treat a stranger asking to hold your cash "just for a second." You wouldn't, don't start now.
Start receiving and sending bitcoin now