Transaction ID or hash
A public reference used to locate a blockchain transfer. Sharing it does not grant control of the wallet.

A request for recovery words is not account verification—it is an attempt to take control of the wallet.
A withdrawal stalls, then a “support agent” appears with a solution: provide the 12 or 24 recovery words before the account is frozen, funds vanish, or a limited refund expires. STOP. End the chat or call immediately. Do not send even part of the phrase, enter it into a linked form, or share a screenshot.
A seed phrase can restore a wallet on another device, giving whoever holds it control of the assets. Legitimate sportsbook staff may request an account ID, transaction hash, or ordinary identity checks, but they do not need wallet recovery words. The safe response is to close the conversation, avoid any supplied links, and contact the operator through the address or app opened independently. If any words were already disclosed, the wallet should be treated as compromised and remaining assets moved promptly to a newly created wallet.
Transaction ID or hash
A public reference used to locate a blockchain transfer. Sharing it does not grant control of the wallet.
Wallet address
A public destination for sending or receiving funds. It may reveal transaction history, but it cannot authorize spending.
Account and KYC evidence
Legitimate support may request an account ID, screenshots, payment receipts, or identity documents. Sensitive evidence belongs only in the sportsbook’s verified app or website.
Recovery phrase
The 12, 18, or 24 words that can restore a wallet and move its funds. No sportsbook, wallet provider, or support agent needs them.
Private key
The secret that authorizes transactions from an address. Anyone who obtains it can control the associated funds.
A request to “verify,” “synchronize,” or “unlock” a wallet by entering a recovery phrase or private key is an attempt to take control. Close the conversation, avoid linked forms, and contact support through the operator’s independently verified website or app.
Impersonators rarely rely on one message. A sponsored search ad may lead to a cloned sportsbook page, followed by a convincing live chat, a social-media account with copied branding, or a call from someone quoting details submitted moments earlier. Each channel appears to confirm the others, but the entire chain may belong to the same scammer.
Common explanations are technical-sounding distractions:
The wording changes; the objective does not. Legitimate staff do not need a seed phrase, private key, wallet import, or remote-control session to inspect a betting account. Guidance on spotting fraudulent support requests helps separate normal account checks from attempts to seize funds.
When contact begins through an ad, direct message, or unsolicited call, the safer move is to stop and open the sportsbook through a previously saved address or official app. Support should then be contacted through that independently reached channel—not through links or numbers supplied by the stranger.
Do not argue, explain, or test the supposed agent. Block the account or number; further conversation only creates more opportunities for pressure.
Do not open chat links, QR codes, attachments, wallet prompts, or “verification” pages—even if they appear to use the sportsbook’s branding.
Capture the message, sender handle, phone number, website address, and time. Never reconnect merely to collect more proof.
Type the known official address manually or use a trusted bookmark. These steps for checking whether a sportsbook site is genuine can help distinguish real support from a clone.
Contact the operator through the independently verified site and provide the saved screenshots. If a wallet was connected or a secret was entered, treat that as a separate wallet-security incident.
Closing a request, reversing a withdrawal, or ending a support case never requires a payment, deposit, recovery phrase, private key, or wallet signature. Any such condition is a reason to stop immediately.
Any recovery phrase that has been typed, pasted, photographed, spoken, or shown during screen-sharing should be treated as copied. Screenshots, cloud clipboards, call recordings, browser extensions, and remote-access tools can preserve it without leaving an obvious sign. Waiting for unauthorized activity only gives an attacker more time.
On a clean device, install wallet software from its verified official source or initialize a trusted hardware wallet. Create an entirely new wallet with a newly generated recovery phrase; never import the exposed phrase into it. Record the new phrase offline and verify the receiving address on the wallet’s own screen when possible.
Transfer assets from every account and network tied to the old phrase. Include tokens, collectibles, and enough native currency to pay transaction fees. A small test transfer can confirm the destination address, but speed matters if suspicious transactions have already appeared.
A hardware wallet cannot protect a phrase after disclosure. The device may still hold keys securely, but anyone with the phrase can recreate those same keys in another wallet and sign transactions independently. Ownership of the physical device does not provide exclusive control.
Deleting screenshots, reinstalling an app, changing a password, or resetting a hardware wallet does not reverse exposure. Restoring the same phrase recreates the same compromised keys. Only a wholly new recovery phrase establishes a separate wallet.
Is connecting a wallet the same as exposing its seed?
No. A connection usually reveals the public address and lets a site request actions; disconnecting ends that session but does not cancel approvals already granted.
What if a token approval was granted?
Use a trusted explorer or wallet tool for revoking risky wallet permissions, then cancel the spender’s allowance. Revocation can block future token transfers, though anything already stolen remains gone.
What if a suspicious transaction or message was signed?
Reject any pending request and inspect the wallet’s recent activity. A submitted transaction may be irreversible; a signature can also authorize later abuse, so related approvals or permits should be revoked and valuable assets moved if the risk remains unclear.
Can revoking permissions make an exposed recovery phrase safe?
No. Revocation limits specific contracts, while the phrase controls every account derived from it; a fresh wallet with a new phrase is required. The compromised phrase should never be reused, even after all visible permissions are removed.
Replace the sportsbook password with a unique one, then secure the linked email account. Any other service sharing that password also needs an immediate change.
Use the account’s security page to sign out all devices and remove unfamiliar remembered devices, API keys, or connected apps.
Enable a passkey, security key, or authenticator-app code where available. Save recovery codes offline; SMS is a weaker fallback.
Keep screenshots, chat transcripts, email headers, phone numbers, profile links, deposit addresses, and transaction hashes. Record dates and times before messages or profiles disappear.
Contact the sportsbook using its official site or app, not the original conversation. Report impersonating profiles to the hosting platform and, where appropriate, notify local cybercrime authorities or the relevant gambling regulator.
Reports may remove fraudulent accounts, flag addresses, or help connect related cases. They rarely recover funds after a confirmed blockchain transfer, and anyone promising guaranteed recovery for an upfront fee may be running a second scam.
Legitimate sportsbook support can investigate deposits, withdrawals, and account issues using transaction hashes, public addresses, and account records. It never needs control of a customer’s wallet.
That boundary is central to efforts to protect a wallet when betting with crypto. Branding, urgency, or a convincing support agent does not change it: phrase request means leave, phrase exposure means migrate, and permission risk means inspect and revoke.