That sinking feeling when you cannot find the words is real, and you are not alone. The honest truth is that some situations are fixable and some are not, and the difference comes down to what exactly you lost and what kind of wallet you were using. This page walks through both cases plainly, shows you the few legitimate tools that exist, and explains why most companies promising to get your coins back are running a scam. It is educational content, not financial advice. Read the whole thing before you pay anyone a single cent or download anything.
People mix up three different things, and the recovery path depends entirely on which one is missing. Sort this out before you do anything else.
The seed phrase (also called a recovery phrase or mnemonic) is the list of 12 or 24 plain English words your wallet gave you at setup. This is the master key. Anyone with these words can rebuild your wallet on any device and take everything. By default no company keeps a copy for you in a self custody wallet, so no support desk can look it up. The one exception is an opt in backup service you signed up for yourself, such as Ledger Recover by Coincover, which encrypts your phrase, splits it between three separate companies, and can restore it after an identity check.
The wallet password or PIN is the code you type to open the app on your phone or browser. It only protects that one installation on that one device. It is not the master key.
The hardware device itself (a Ledger or Trezor, for example) is just a secure calculator. The coins are not inside it. They live on the blockchain. The device holds the keys derived from your seed phrase.
So ask yourself: do I have the words but forgot the password? Do I have the password but lost the words? Or is everything gone? Each answer leads somewhere different. To understand why these words matter so much, our explainer on how crypto wallets work is worth a quick read.
This is the most recoverable situation, and many people do not realize it. If your wallet still opens on your device with your password, the seed phrase is usually still sitting inside the app, encrypted. You just need to display it again and write it down properly this time.
For most software wallets, the path is similar. Open the app, go to Settings, look for an item called Security, Privacy, or Backup, and choose something like Show Secret Recovery Phrase or Reveal Seed Phrase. You will be asked for your password and then warned to make sure nobody is watching your screen. Write the words down on paper. Do not screenshot them.
MetaMask example. In the MetaMask mobile app, open the menu, go to Settings, then Security and privacy, then Reveal Secret Recovery Phrase. In the browser extension, open the menu, go to Settings, then Security and password, then Manage wallet recovery. Both ask for your password first (MetaMask support guide).
If the app will not open but you still know the password, MetaMask has a free official tool called the Vault Decryptor at metamask.github.io/vault-decryptor. It was built by MetaMask co founder Dan Finlay. You load your browser's encrypted vault file into it, type your password, and it shows the phrase back to you. It runs locally and works offline. It is built for the desktop browser extension's vault file, so it does not recover the phrase from the mobile app this way.
This case is almost always fine, and it surprises people how simple it is. The seed phrase is the master key, so a forgotten app password or a lost, broken, or stolen hardware wallet does not lock you out. You restore from the words.
Here is the basic process for a software wallet:
1. Install a fresh copy of the same wallet app on a clean device.
2. On the welcome screen choose Import using Secret Recovery Phrase (not Create new wallet).
3. Type the 12 or 24 words in the exact order.
4. Set a brand new password. Your balances reappear once the wallet syncs.
For a hardware wallet, get a new device and choose Restore from recovery phrase during setup. Because Ledger, Trezor, and most others follow a shared standard called BIP39, the same 24 words can usually be entered into a different brand of device. So if your Ledger broke, a Trezor can often restore the same accounts from the same words, and the reverse works too.
One warning: never type your real seed phrase into a wallet you reached through a search ad, a pop up, or a link someone sent you. Download wallet software only from the official site or the official app store listing. Reading our note on basic crypto security habits first is a good idea.
If you have a partial seed phrase, a word in the wrong spot, or a misspelled word, there is a real, free, open source tool that can help: BTCRecover. It is licensed under GPL and the code is public at github.com/3rdIteration/btcrecover, with documentation at btcrecover.readthedocs.io. It supports BIP39 phrases across many coins.
Be clear about what it does and does not do. BTCRecover is for when you already know most of your phrase. It can try every valid combination for one or two missing or scrambled words, fix a transcription error, or test a password you have a reasonable guess about. A small example: if you have 11 of your 12 words and you know the missing one is somewhere in the list of valid words, the tool can test the possibilities against one of your own receiving addresses, which you have to supply, and tell you which candidate rebuilds your wallet. That is very doable.
What it cannot do is guess a phrase you have completely lost. The number of possible 12 word combinations is so large (the standard word list has 2,048 words) that brute forcing a fully unknown phrase is not realistically possible, even with the world's fastest computers. Anyone who tells you otherwise is selling something.
This is advanced. It involves the command line and some patience. If that is not for you, that is okay, but read the next two sections very carefully before hiring help, because that is exactly where people get robbed a second time.
If you bought crypto on an exchange like Coinbase, Kraken, or Binance and left it there, you may never have been given a seed phrase at all. These are custodial accounts. The company holds the keys, and you log in with an email and password like any normal website. That means you can reset a forgotten password.
Use the Forgot Password link on the official login page. The exchange emails you a reset link. If you also lost access to your two factor authentication (the 6 digit code app or text), exchanges have an identity verification process: you submit a government ID, sometimes a selfie, and answer account questions to prove it is you, after which they disable the old 2FA so you can set up a new one.
Two rules here. Start only from the exchange's real website or official app, never from a search ad. And know that custodial recovery only applies to coins actually held on that exchange. If you moved coins out to your own wallet, the exchange cannot help with those. The trade off between holding your own keys and letting a company hold them is covered in our piece on self custody and cold storage.
If you have a self custody wallet, no seed phrase, no password that opens it, and no encrypted vault file, then in almost every case the funds cannot be recovered. This is not a limitation that a clever expert or a special program can get around. It is the entire point of the design.
A self custody wallet is protected by strong cryptography precisely so that no one, including the wallet maker, can reach your coins without the keys. The same wall that stops a thief stops you. There is no master reset, no support line that can override it, and no court order that can force the math to give up. The coins still exist on the blockchain forever, visible to everyone, but unspendable without the key.
It is painful to read, and we are not going to pretend otherwise. Accepting this early protects you from the scammers in the next section, who specifically prey on people who refuse to accept it.
Once your wallet is genuinely lost, a second wave of predators appears. They find you in comment sections, by direct message, through ads, and sometimes by cold call, promising they can get your money back. The pattern is so common that the FBI has issued repeated public warnings about it.
In a 2025 alert, the FBI's Internet Crime Complaint Center described fake law firms that impersonate real attorneys, forge official looking documents, and claim partnership with government agencies or invented bodies like an "International Financial Trading Commission" to seem legitimate. They target people who already lost money once, including many elderly victims. The advice is blunt: use a "Zero Trust" approach and verify everything independently. The alert states plainly that the U.S. Government does not request payment for law enforcement services (FBI IC3 alert PSA250813).
The scale is large. In its 2025 annual report, the IC3 counted 181,565 complaints mentioning cryptocurrency with reported losses of about 11.4 billion dollars, and people aged 60 and over filed 44,555 of those complaints and lost about 4.4 billion (IC3 2025 Internet Crime Report).
The red flags are consistent. Walk away if you see any of them:
- An upfront fee, a "tax," or a "bank fee" before any work is done.
- A request for payment in crypto or gift cards.
- A guarantee of success. No honest recovery is ever guaranteed.
- A claim of a secret method to brute force a lost seed phrase. The math makes this impossible.
- Anyone asking for your seed phrase or remote access to your computer. Handing those over is handing over your wallet.
- Pressure to act fast and secrecy demands.
Our broader guide to spotting crypto scams covers more of these tactics.
Legitimate help does not cold call you and does not charge an upfront fee. If you lost funds to theft or to a recovery scam, report it through official channels. In the United States, file a report with the FBI's Internet Crime Complaint Center at ic3.gov. Provide every detail you have: wallet addresses, transaction IDs, the website or phone number used, and copies of messages. Law enforcement occasionally seizes and returns scam funds, but only through official processes, never for a fee paid to a private "recovery" firm.
Outside the US, report to your national police cybercrime unit and your financial regulator. Keep expectations realistic: tracing is hard and most stolen crypto is never returned, but a report still helps investigators and protects others.
Whether or not you recovered this time, set things up so a lost phrase can never lock you out again. The goal is a backup that survives a fire, a flood, and a burglar, all at once.
1. Write the words on paper at setup, by hand. Check the spelling and the order twice.
2. Never store the phrase as a digital file. No photos, no screenshots, no notes app, no cloud drive, no email to yourself. Taking a photo during setup is one of the most common ways people get drained later.
3. Make at least two copies and keep them in two different places. One at home in a safe, one somewhere else like a trusted relative's house or a bank deposit box. If one is destroyed, the other survives.
4. Consider a metal backup for the long term. Paper burns and dissolves. Stamped or engraved steel plates (Cryptosteel, Billfodl, and similar) survive heat, water, and time. Engrave the plate yourself and never photograph it.
5. Store the password separately from the phrase, and remember the password is only a convenience. The phrase is what truly matters.
6. Test your backup once. Wipe a spare device and restore from your written words to confirm they work, then reset it. A backup you have never tested is a guess.
Some wallets support newer recovery designs, like social recovery (you nominate trusted contacts who can help you regain access) or splitting a key into shares. These reduce single point of failure risk but add complexity. Our overview of cold storage methods goes deeper on safe long term setups.
No. If the phrase is completely lost and you have no password and no encrypted vault file, the cryptography that protects your wallet also blocks you, and there is no tool or expert that can break it. A standard 12 word phrase has so many possible combinations that brute forcing a fully unknown one is not realistic even with the fastest computers. Tools like BTCRecover only help when you already know most of the phrase. Anyone who guarantees recovery of a lost phrase is lying.
No, you are fine. The seed phrase is the master key. Install a fresh copy of the wallet, choose the import or restore option, type your 12 or 24 words in order, and set a new password. Your balances come back after it syncs. The forgotten password only protected that one installation, not your coins.
The seed phrase is the master key to everything in a self custody wallet and can rebuild it on any device. It cannot be reset or replaced. The password or PIN only opens the app on one device and can be changed if you still have the phrase. On a custodial exchange account you usually have only a password, and that one can be reset by email or identity check because the company holds the keys.
Treat it as a scam. The FBI has warned repeatedly about fake recovery services and fake law firms that target people who already lost money. Real law enforcement never charges you to recover funds, and no honest service guarantees results or demands an upfront fee, crypto, or gift cards. Never share your seed phrase or give anyone remote access to your computer. Report the approach at ic3.gov.
Not if you have your recovery phrase. The coins live on the blockchain, not inside the device. Buy a new hardware wallet and choose Restore from recovery phrase, then enter your words. Because most devices follow the shared BIP39 standard, you can usually even restore onto a different brand. The only true loss is if both the device and the phrase are gone.
No. A photo is the single most common way people get robbed. It can sync to cloud backups, sit in your camera roll, and be exposed if your phone, account, or computer is ever compromised. Anyone who sees those words can take everything, no device needed. Keep the phrase on paper or stamped metal, store two copies in two physical locations, and never store it as any kind of digital file.