TL;DR
It’s always a scam. No real support team, wallet maker, exchange or app ever needs your seed words. The only place you ever type them is on the hardware wallet itself, in a recovery you started.
How it usually looks
- An email or text “from Ledger, Trezor or BitBox” saying your wallet is compromised and needs validating.
- A helpful stranger on social media or a forum who offers to fix a problem you posted about.
- A fake support chat or phone number found through a search ad.
- A website or app that asks you to “sync” or “restore” by entering your words.
- A letter or package with a replacement device and instructions to enter your words.
Why they target hardware wallet owners
Customer lists have leaked before. Ledger’s database leak in 2020 put many names and addresses in scammers’ hands. Assume they know you own a hardware wallet and act accordingly.
What to do
- Don’t reply, click or call back
- Go to the maker’s site by typing the address yourself if you want to check something
- Tell family members who might one day handle your coins, and put this rule in your inheritance letter
Already entered them?
Treat that seed as exposed and move to a new multisig right away: a seed backup was seen or taken. In a 2-of-3 one leaked seed isn’t enough for a thief, which gives you time, but not much.