Private key compromise: what does it mean and what can you do about it?

Private key compromise: what does it mean and what can you do about it?

What is a compromised private key (private key compromise)?

A compromised private key means that someone else has your secret key, can use it, or that you’re no longer sure whether it’s still secret. With a private key, you can prove that you control a certain crypto address and sign transactions from that address. So whoever has the key can usually also move the crypto that can be spent through that address.

You can think of a private key as the key that proves control over your crypto wallet and addresses. Your wallet app password is something different: it often only protects the app or the encrypted wallet file on your device. The private key is ultimately the cryptographic key used to sign transactions on the blockchain.

Many wallets also use a seed phrase, sometimes called a Secret Recovery Phrase or SRP. That’s a set of recovery words from which a wallet can derive multiple private keys and addresses. If that recovery phrase leaks, not just one address could be at risk, but possibly all wallets and addresses derived from that seed phrase.

With self-custody, you manage the private keys yourself. That gives you full control, but also the responsibility to keep them safe. If you use a crypto exchange that manages the private keys for you, a hacked exchange account is something different from a stolen private key. Both are serious, but the risks and recovery steps are different.


Key Takeaways

  • A private key is the secret key used to sign transactions from a crypto address.
  • Whoever has your private key can usually move the crypto on the linked address.
  • A seed phrase can give access to multiple accounts within the same crypto wallet.
  • A wallet password is not the same as a private key.
  • With self-custody, you manage the keys yourself, while a crypto exchange normally manages them for you in a custodial account.

How can a private key be compromised?

A private key is usually compromised because someone tricks you, your device gets infected, or a backup falls into the wrong hands. Phishing is a well-known method. For example, you might end up on a fake wallet, exchange, or support page through a link and enter your seed phrase or private key there.

Note: Legitimate support will never ask for your seed phrase, private key, password, or 2FA code. Not even if someone pretends to be an employee of a crypto company, a crypto exchange, an influencer, or another trusted party.

Malware is another risk. Think of software that reads keystrokes, pulls data from your browser, checks your clipboard, or installs a fake extension. An infected browser extension or fake wallet can, for example, send seed phrases, private keys, or other sensitive data directly to an attacker.

An online backup can also cause problems. A screenshot of your recovery phrase may seem convenient, but it can automatically end up in cloud storage. The same goes for recovery words in email, chat messages, or unsecured files. Physical access to a visible note, unsecured device, or unprotected backup can also be enough to put your wallet at risk.

Important distinction: a harmful permission given to smart contracts is not automatically the same as a compromised private key. With such an approval, you give a dApp permission to move certain tokens on your behalf. That can cause a lot of damage, but your private key does not have to be stolen for that to happen.

With a harmful approval, revoking that permission may be enough to prevent further damage. With a leaked private key, it’s different: you should assume the attacker may have full control over that key and move your remaining crypto to a new wallet with new private keys as quickly as possible.

What signs point to a compromised private key?

Unknown outgoing transactions from a self-custody address are an important warning sign. Something happened that you did not intentionally do. That can point to a leaked private key or seed phrase, but a token may also have been moved through a previously granted approval.

So first check exactly what happened on the blockchain. Look at the wallet activity and the transaction details in a blockchain explorer. Pay attention to unknown transactions, approvals, and interactions with smart contracts.

A strong sign of a compromised private key is transactions signed directly from your address that you did not make yourself. In that case, an attacker may be using the key or seed phrase to send transactions on your behalf.

Another clear sign is a so-called “sweeper bot.” Say you send new crypto to an old address and the balance is removed again almost immediately. That can mean a bot is actively watching the address and automatically sending out new funds as soon as they arrive. That may indicate an attacker has control over the private key or seed phrase.

Other warning signs include:

  • You entered your seed phrase or private key on a website or shared it with someone else.
  • You find unknown token approvals or smart contract interactions.
  • Your device or wallet extension turns out to be infected or replaced by malware.
  • You see transactions from your wallet that you did not sign yourself.

So an unknown approval does not automatically mean your private key was stolen. An approval only gives a smart contract certain rights over specific tokens. If the approval is the only problem, revoking it may help limit further damage.

If you instead see unknown transactions signed directly with your account, or new deposits disappear automatically through a sweeper bot, then it’s more likely that the private key or seed phrase itself has been compromised.

With a crypto exchange, it works differently. An unknown login, changed security settings, or withdrawal can point to a hacked exchange account, but that does not automatically mean your private key was stolen. With a custodial exchange, the exchange manages those keys for you.

What are the consequences of a private key compromise?

With a private key compromise, an attacker can sign transactions on behalf of your address. That means they can, for example, move coins, tokens, and NFTs or carry out other actions tied to that address.

If your seed phrase leaked, the risk is often bigger. An attacker may be able to access multiple accounts and addresses derived from that same recovery phrase. Creating a new account within the same seed phrase does not help, because that account still depends on the same exposed secret.

Most transactions made on public blockchains cannot simply be reversed. A self-custody wallet cannot just roll back a sent transaction. Whether you get stolen crypto back depends, for example, on the recipient cooperating voluntarily or, in rare cases, on intervention by the platforms involved, token issuers, or the proper authorities.

Some assets need extra attention. You can often send a token directly to a new wallet, but a DeFi position, staking position, or role inside a smart contract does not always move automatically. So check per blockchain and protocol which assets and rights are still tied to the old address.

A less visible consequence is that an attacker may also be able to sign messages as if they came from you. Think of a signed login, governance action, or other cryptographic permission. Once a private key is compromised, you can no longer automatically trust new signatures made with that key.

What should you do if a private key is compromised?

Treat a suspected leaked private key or seed phrase as permanently unsafe right away. Simply changing your password, reinstalling the wallet, or creating a new account within the same seed phrase will not solve the problem. A copied key does not become secret again.

Be careful, but act quickly. These are the most important steps:

  1. Stop using the old address. Do not send any new crypto to the old wallet and do not create new accounts with the same seed phrase.

  2. Use a clean environment. Work from an updated device that you have checked for malware, or use a separate device or browser profile that was not exposed to the suspected attack.

  3. Create a completely new crypto wallet. Use a new seed phrase or new private keys that are not linked to the old recovery phrase in any way.

  4. Map everything out. Check which tokens, NFTs, DeFi positions, approvals, and any smart contract roles are still tied to the old address.

  5. Save evidence. Write down addresses, transaction hashes, amounts, date, and time. Also save screenshots and communication with the suspected scammer.

  6. Secure linked accounts. Check your device and also secure your email, phone, and accounts at a crypto exchange. Change relevant passwords and refresh 2FA if needed.

How do you move crypto to a safe wallet?

Move your remaining crypto only to a completely new wallet with a new seed phrase or new private keys. Do not import your old seed phrase or private key into the new wallet, because that just carries the problem over.

Take it step by step:

  1. Create a new wallet in a safe environment. The new seed phrase or private key must be completely separate from the old wallet.

  2. Check the receiving address. Make sure you are using the correct address for the new wallet and that you are on the right blockchain.

  3. Inventory your assets. With an EVM wallet, these can include native crypto, ERC-20 tokens, NFTs, liquidity positions, and roles in smart contracts.

  4. Send assets that can be transferred right away. Read all transaction details before signing and make sure you have enough network fees.

  5. Check special positions separately. Some staking, DeFi, or contract ownership positions require separate steps. Simply sending a token does not automatically move those rights.

  6. Do not use the old address afterward. Avoid all accounts and addresses linked to the compromised seed phrase.

Example: If you have ETH and a few tokens on an exposed address, send them to your new wallet on the same chain. If you also have a DeFi position, you need to check separately how to close or migrate that position.

Do you think a sweeper bot is active? Then do not just deposit extra ETH or other native crypto into the old address to pay gas fees. A sweeper bot can send that deposit away immediately before you get the chance to move other assets.

When should you warn an exchange or another party?

Warn a crypto exchange right away if your exchange account may have been taken over. Think of unknown logins, changed security settings, or withdrawal requests you did not make yourself. Use only the official support channel that you look up yourself, not a phone number or link from an unexpected message.

Warning an exchange or other custodial service can also make sense when you can see that stolen crypto was sent to a deposit address of that service. In that case, share as much useful information as possible:

  • the blockchain used;
  • the transaction hash;
  • the source and destination address;
  • the amount and type of crypto;
  • the date and time of the transaction.

Also report the theft to the proper police or national cybercrime or fraud agency in your country. Keep all details and communication safe. Reporting quickly can help with investigation and tracing, but it does not guarantee that a platform can freeze the assets or that your money will be recovered.

With a self-custody wallet, the wallet provider usually cannot reverse a completed transaction, because it does not manage your private key. Contacting them can still be useful to report phishing or get help using the wallet safely.

How do you prevent a private key compromise?

You mainly prevent a private key compromise by keeping your seed phrase and private keys secret and as offline as possible. Think of these details like the key to a safe: whoever gets them may be able to access your crypto.

A few habits make a big difference:

  • Never share your private key or seed phrase with anyone. No support agent, website, dApp, or chat contact needs this information.
  • Do not store recovery words as a screenshot, in email, chat, or an unsecured cloud file.
  • For larger amounts you want to keep for longer, use a hardware wallet or another form of offline signing. That way, the private key normally stays on the secured device.
  • Only download wallet software and browser extensions through verified official channels.
  • Read transactions before signing. Do not give smart contracts unlimited permission if a more limited approval is enough.
  • Keep only a limited amount in a hot wallet for everyday use.
  • Use unique, strong passwords and strong multi-factor authentication for your email, phone, and crypto exchange accounts.

A hardware wallet mainly reduces the risk of your private key being exposed to an online device. It does not protect you if you share your seed phrase yourself, sign a harmful transaction, or send crypto to the wrong address.

Offline backups also need attention. They reduce online risk, but they can still be lost, burned, stolen, or read by someone else. So make sure you use a backup method that limits both digital and physical risks.

Conclusion

A private key compromise is one of the most serious risks in self-custody. If your private key or seed phrase may have leaked, you should treat the old wallet as permanently unsafe. In a clean environment, create a completely new wallet and move the remaining assets to new addresses where possible.

Also always distinguish between a leaked private key, a harmful token approval, and a taken-over account at a crypto exchange. All three can lead to losses, but they require different recovery steps.

The main protection is still simple: keep your seed phrase and private keys secret, check what you sign, and be extra careful with unexpected links, messages, and software.

About Finst

Finst is a leading cryptocurrency platform in the Netherlands, providing ultra-low trading fees, institutional-grade security, and a comprehensive suite of crypto services such as trading, custody, staking, and fiat on/off-ramp. Finst, founded by DEGIRO's ex-core team, is authorized as a crypto-asset service provider under MiCAR by the Dutch Authority for Financial Markets (AFM) and serves both retail and institutional clients in 30 European countries.

The crypto platform for all investors

Whether you're an active trader or long-term investor, Finst enables you to grow your crypto wealth with confidence and peace of mind.

Sign up