A user receives a direct message on Discord or Telegram claiming to be from Solflare support. The message says there is a problem with their account, references a recent transaction, and asks for their recovery phrase to “verify ownership” or “restore access.” The request appears legitimate because it mentions specific details about their wallet activity. Within minutes, the user has typed twelve or twenty-four words into a text box, hit send, and lost complete control of every token and NFT stored in that wallet. Recovery is impossible. The funds are gone.
This scenario repeats constantly across blockchain communities, and the outcome is always the same: total loss. A recovery phrase is not a password that can be reset. It is not a secret tied to a specific device or service. It is the master key to every asset in a wallet, and sharing it with anyone—even someone claiming to represent Solflare support—is mathematically equivalent to handing over all the private keys at once. The Solflare wallet extension provides robust security features, built-in phishing protection, and local encryption to keep your keys safe, but no amount of technical hardening can defend against a user who voluntarily gives away the seed phrase.
What a recovery phrase actually is and why it cannot be recovered
A recovery phrase, also called a seed phrase or mnemonic seed, is a sequence of words generated by your wallet during setup. In the Solflare wallet extension, this phrase is created when you first install the extension or import an existing wallet. The phrase is not stored on Solflare’s servers. It is not backed up to the cloud by default. It exists only where you wrote it down, took a screenshot, or stored it manually.
That phrase is mathematically derived from a master private key, which generates every private key associated with every account and asset in your wallet. Someone with access to the phrase can regenerate every private key. They can import your wallet into their own Solflare wallet extension, any other Solana wallet, or any wallet software that supports Solana. They can then move, sell, or destroy every token and NFT you own. The process takes minutes.
Critically, the recovery phrase cannot be changed. Passwords can be reset. Email addresses can be updated. Two-factor authentication can be reconfigured. But a recovery phrase is the underlying cryptographic secret. Once someone else has it, there is no password reset that will lock them out. There is no technical support team that can revoke it. There is no blockchain transaction that can undo the theft. The Solflare wallet extension uses local encryption to store private keys on your device, but that encryption is only as strong as the seed phrase you protect.
This is not a flaw in Solflare. It is a property of how blockchain wallets work. Any wallet that allows you to recover your funds after a device loss—and recovery is essential—must use a system where the recovery phrase is the master secret. The consequence is that the recovery phrase must be protected with perfect secrecy. No exceptions.
Why Solflare support will never ask for your seed phrase
Official Solflare support channels do not request recovery phrases, private keys, or any secret that could unlock your wallet. This is not a suggestion or a best practice. It is a rule. If someone claiming to represent Solflare asks for your recovery phrase, they are not a representative of Solflare. They are a scammer.
The reason is both simple and absolute: Solflare has no capability and no need to use your recovery phrase. The wallet is non-custodial, meaning Solflare does not hold your private keys or manage your funds. Your keys are stored locally on your device, encrypted with local encryption. Support staff cannot log into your account, move your tokens, reset your wallet, or verify your ownership by any method that requires your seed phrase.
If you forget your password to the Solflare extension itself, there is a password reset procedure—but it does not require contacting support. The password is separate from the recovery phrase. You can reset it using your recovery phrase in a local, offline recovery process on your own device. That process happens entirely within the extension, with no external communication and no manual entry of the seed phrase into any website, form, or chat message.
If you have a technical problem—the extension crashes, a transaction fails, tokens do not appear after a transfer—legitimate support can help troubleshoot. They may ask you what you see on screen, what steps you took, what transaction ID appears in your browser history, or details about your Solana RPC node settings. They will never ask for anything that would let them access your wallet. If someone claims otherwise, you are talking to a scammer.
How attackers impersonate Solflare and exploit trust
Scammers do not build fake Solflare websites because they want to run a competing wallet. They build fake sites and create fake support accounts because they want to trick you into believing you are talking to Solflare when you are not. Common impersonation tactics include creating Discord bots that mimic Solflare’s official account, sending direct messages after you follow a malicious link, or registering email addresses that look almost identical to official support addresses—solflare-support@gmail.com instead of the actual support channel, for example.
The emotional hook is always the same: a sense of urgency and authority. The message might say your account has suspicious activity, your assets are at risk, a transaction is pending, or a wallet update requires verification. Because you recently used the Solflare wallet extension or visited a Solana dApp, the message feels credible. You are concerned. You want to fix the problem. The attacker gives you a link, a chat window, or instructions to reply with your recovery phrase, and the urgency overcomes your caution.
A particularly deceptive variation involves directing you to a fake website that looks visually identical to the legitimate Solflare wallet extension download page. You might see correct logos, official-looking documentation, and even a functioning browser extension—one that simply steals your seed phrase when you import a wallet or create a new account. Users who find this fake extension in their browser store before the platform removes it report losing funds within hours.
Another tactic involves creating a fake support ticket system. You submit a problem through what looks like an official Solflare support portal, receive a response from what appears to be a support agent, and are asked to export your wallet or provide your recovery phrase for “verification.” The entire interaction is designed to look professional and official. The attacker may even know small details about your transaction history if they have monitored your public wallet address.
Red flags that reveal a scammer, no matter how convincing the story
The first and most absolute red flag is any request for your recovery phrase, private key, or the seed phrase itself. Stop reading immediately. Block the person or account. Do not respond. If someone asks for the seed phrase, they are trying to steal your funds. No official wallet, support service, blockchain platform, or legitimate third party will ever ask for this information. There are no exceptions.
The second red flag is urgency without context. “Verify your account immediately,” “Your funds are at risk,” or “Update required before midnight” are pressure tactics. Legitimate issues can be addressed through documented, public support channels, not through private messages or time-limited ultimatums. If you are concerned about a real problem, you can independently open your Solflare wallet extension, check your transactions, and contact official support through the Solflare website directly—not through a link provided by the person messaging you.
The third red flag is any request to click a link in a message. If someone contacts you about an account problem, do not use their link. Instead, navigate to the official Solflare website independently using a bookmark or a fresh browser search, then look for support resources there. A legitimate support team can provide troubleshooting steps that work through your own device and wallet, without redirecting you through external links.
The fourth red flag is a request to export your wallet, provide a JSON file, share a keystore, or upload any file that contains your keys. Scammers often reframe this as “verifying ownership” or “backing up your wallet.” Your wallet backup is your recovery phrase, and it should only ever be written down on paper—not sent to anyone, not uploaded anywhere, not exported from your device unless you are doing it yourself for your own recovery purposes.
How to verify you are talking to real Solflare support
If you have a legitimate problem and need help, the safest approach is to navigate directly to the official Solflare website and look for the official support channel. The Solflare wallet extension is available through the official website and major browser stores, and the official site will have clear contact information. Real Solflare support will be reachable through documented channels only.
Legitimate support will ask clarifying questions about your specific situation, but they will not ask for secrets. If you had a transaction problem, they might ask for the transaction ID, your RPC node settings, or details about what you saw on screen. They might ask if your Ledger hardware wallet is connected if you use hardware wallet support. They will never ask for anything that begins with “What is your” when the answer is something you alone should know.
Official Solflare accounts on social platforms are verified by the platform itself. Discord shows a checkmark next to verified accounts. Twitter shows an official badge. These are not foolproof—scammers sometimes impersonate unverified accounts that appear to belong to Solflare—but verified badges are a basic filter. If you are unsure whether an account is official, do not take their word for it. Instead, go to the official Solflare website directly and find the link to their social accounts there.
Documentation is another good test. Official support will direct you to public documentation, guides on the Solflare website, or steps that you can independently verify. They will not ask you to keep the conversation secret or tell you not to discuss the issue with anyone else. Legitimate support is transparent because they have nothing to hide.
What to do if you have already shared your recovery phrase
If you have shared your recovery phrase with anyone—even if it was someone you believed to be Solflare support—you must treat your wallet as completely compromised. The person who has your recovery phrase has full access to all your funds and NFTs. They can move everything immediately, or they can wait weeks or months, watching your wallet to see if you deposit new assets.
The immediate action is to move all remaining funds and NFTs to a new wallet. Create a new Solflare wallet extension in a fresh browser profile, or use a different wallet software entirely. Generate a completely new recovery phrase. Do not reuse any part of the old phrase. Move every asset—every SPL token, every SOL, every NFT—to the new wallet’s address. This must be done before the attacker moves the funds themselves.
The old wallet must then be treated as permanently compromised. Do not use it. Do not deposit anything into it. Do not assume that moving funds out once is enough. Monitor the old wallet’s public address to see if the attacker eventually sweeps the remaining balance, and report that activity to law enforcement if you want a record. But understand that reporting will not recover the funds. The only recovery is the transfer to a new wallet before the attacker acts.
The broader lesson is that the moment you realize you may have shared your phrase, assume the theft will happen and act first. Do not wait for the attacker to contact you. Do not assume they are “just testing” if they move a small amount. Move everything immediately to a new wallet address, then treat the old one as a loss. Speed matters because the attacker can act at any time.
Protecting your recovery phrase after you download Solflare
The moment you create or import a wallet using the Solflare wallet extension, you will see your recovery phrase on screen. This is the most dangerous moment. Write it down on paper immediately. Use a pen. Use paper that will not fade. Consider writing it twice on separate sheets and storing them in different physical locations.
Do not take a screenshot. Do not store it in your phone’s notes app, even encrypted. Do not save it to cloud storage, even password-protected. Do not send it to yourself in an email or a message. Do not type it into a document on your computer. Every digital copy creates a second place where your keys can be stolen—by malware, by cloud breach, by app permission abuse, or by the operating system itself.
The only format is paper, stored privately. If you do not have a good place to store paper safely, that is a sign you should use a hardware wallet, which allows you to store the recovery phrase offline and sign transactions through a separate device. The Solflare wallet extension supports Ledger hardware wallet integration, which means you can use the extension as an interface while keeping the recovery phrase and actual signing on a hardware device that never goes online.
After you have written down and stored the recovery phrase, you can safely use the Solflare wallet extension on a regular basis. The extension uses local encryption for the keys you store locally, and the phishing protection features help defend against malicious websites. But those defenses are all secondary. The recovery phrase is the primary secret, and losing it means losing everything.
Why this matters even if you have never been targeted
If you have used the Solflare wallet extension to interact with Solana dApps, hold SPL tokens, or manage NFTs, scammers already have your public wallet address. The address itself is not secret—it is how people send you funds—but it is a trail. Attackers can monitor your address, see when you receive tokens, and target you when you appear to have valuable holdings. They know you are a Solflare user because you interacted with a Solana application. They will craft a message tailored to you, claim to be Solflare support, and ask for the phrase.
Understanding why recovery phrases are irreversible is not just about avoiding one conversation with a scammer. It is about building the mental model that will keep you safe for years of wallet use. A recovery phrase is not like a password that a company can reset for you. It is not like a credit card that a bank can cancel and reissue. It is the permanent, irreversible master key to your funds. Once someone else has it, there is no recovery, no reversal, and no support team that can help.
The corollary is that protecting the recovery phrase is more important than any wallet feature, any software update, or any security setting. Phishing protection helps. Hardware wallet support helps. Local encryption helps. But none of those features matter if you voluntarily give away the seed phrase. The first line of defense is knowing what the recovery phrase actually is and why it can never be shared—not with support, not with friends, not for any reason whatsoever.
Frequently asked questions
Will Solflare support ever ask for my recovery phrase?
No, never. If anyone claiming to represent Solflare support asks for your recovery phrase, private key, or seed phrase, they are a scammer. Official support cannot and will not request secrets that would unlock your wallet. The Solflare wallet extension is non-custodial, meaning support staff have no access to your keys or funds and no legitimate reason to ask for them.
I shared my recovery phrase with someone who claimed to be from Solflare. What should I do?
Treat your wallet as completely compromised immediately. Create a new Solflare wallet extension or use a different wallet software, generate a completely new recovery phrase, and move all your SOL and SPL tokens to the new wallet’s address as quickly as possible. Do not wait. The attacker can move your funds at any time. After the transfer, the old wallet should be abandoned permanently.
How should I store my recovery phrase after I download and set up the Solflare wallet?
Write your recovery phrase on paper with a pen and store it in a safe, private place. Do not take screenshots, save it to notes apps, store it in cloud services, or create digital copies. Paper is the only secure format. If you prefer stronger isolation, the Solflare wallet extension supports Ledger hardware wallet integration, which lets you keep the recovery phrase offline while using the extension as an interface.