A user discovers that their recovery phrase may have been exposed: a screenshot was taken by someone else, an email account containing the backup was breached, or a family member with access to their notes saw it during an unguarded moment. The immediate question is not whether the wallet software is secure. The question is how quickly funds can be moved out of an account whose private keys are no longer private. Every minute an exposed seed phrase remains active is a minute during which an attacker with access to it could drain the account across multiple chains.
Rabby Wallet’s self-custody model means that account security rests entirely on the secrecy of the recovery phrase and any imported private keys. No centralized service can freeze the account, recover a lost password, or block transactions. That autonomy is the benefit of self-custody; it is also the reason that compromise requires immediate action. This guide walks through the practical steps to migrate funds to safety, create a fresh account, and understand where the attack surface actually lies in the seconds and minutes after exposure is discovered.
Assess the actual exposure within the first hour
Before executing transfers, determine how long the phrase has been exposed and to whom. If you took a screenshot and immediately deleted it, the exposure window is narrower than if the phrase was visible in an email for three days. If only you and a trusted partner know it, the threat differs from a public repository or breached service. This assessment determines urgency but should not delay action if there is any doubt. An exposed recovery phrase is a compromised account in principle, even if no theft has occurred yet.
Check the account’s transaction history on a block explorer such as Etherscan or a chain-specific equivalent. Look for any outgoing transactions you did not authorize, unusual token approvals, or contract interactions. If the account has already been drained or is actively under attack, your priority shifts from migration to documentation for tax and insurance purposes. If the account is still intact, proceed immediately to fund extraction.
Do not delay to change passwords, enable notifications, or adjust wallet settings on a compromised account. Those actions may alert an attacker or provide false confidence. Instead, treat the compromised account as live bait that must be evacuated. The only setting that matters now is confirming that you can see all assets and can initiate outgoing transactions.
Create a fresh Rabby Wallet account on a different device or browser profile
If possible, install Rabby Wallet on a separate device that has not accessed the compromised account. If that is not practical, create a new browser profile in Chrome, Brave, or Microsoft Edge and install the extension there. This isolation prevents the new account from sharing any stored data with the compromised installation. Do not import the old recovery phrase into this new environment under any circumstances.
During installation, select “Create a new wallet” rather than “Import.” When prompted to create a recovery phrase, Rabby will display a 12-word sequence. Write this phrase on paper offline and store it in a physically secure location such as a safe deposit box or home safe. Do not photograph it or type it into any digital device except during this account creation process. This new phrase is the only record you will make, and you must verify it by re-entering the words in the order displayed during the confirmation step.
Once the new account is created, you will see a primary Ethereum address. This is your destination for the migration. Write down this address in plaintext; you will need it in the next few minutes. Verify it twice by copying and pasting it into a text editor rather than relying on clipboard contents, which can be modified by malware. The address should begin with “0x” and contain 42 characters total.
Identify all assets across all supported chains in the compromised account
Return to the compromised Rabby Wallet installation and navigate to the Assets or Balance view. Rabby displays assets across multiple EVM-compatible chains including Ethereum, Polygon, Arbitrum, Optimism, Avalanche, Binance Smart Chain, and others. Expand each chain’s view to see native assets and any ERC-20 tokens held in the account. Note the balance of each asset type and the chain on which it resides.
For tokens with small balances, check whether the gas cost to transfer the token will exceed the token’s value. A token worth $5 with a $15 gas fee is a loss to move. In emergency scenarios, you may choose to leave dust balances on the compromised account, migrate the significant holdings, and return later if that makes sense. Write down a prioritized list: Ethereum mainnet assets first, then Polygon, Arbitrum, and other chains in order of total value.
Do not attempt to swap or bridge tokens on the compromised account. Execute straight transfers only. An attacker monitoring the account may see swaps as an opportunity to frontrun or steal the transaction. Keep the compromised account’s actions as simple and transparent as possible so that you can complete them before interference occurs.
Execute rapid transfers from the compromised account to the new address
Open the compromised Rabby Wallet and initiate a transfer of the largest-value asset first. In the Send dialog, paste the new address you created on the fresh installation. Verify that the destination address matches exactly before clicking send. Rabby provides a pre-transaction risk scan that checks for common threats such as suspicious contracts or known scams, but this scan cannot detect a legitimate address that belongs to you. The responsibility for verifying the destination is yours.
After confirming the transaction, do not wait for it to be mined. Move immediately to the next asset. Parallel transfers on the same chain or across different chains can be initiated in sequence, which speeds up the process. On Ethereum mainnet, gas prices fluctuate constantly, so expect to pay whatever the current rate is. Avoid setting a custom gas price lower than Rabby’s recommendation; you need these transfers to confirm quickly, not cheaply.
As each transfer is confirmed, watch the receiving address on a block explorer to confirm that funds have arrived. Do not assume a transaction succeeded based only on the wallet’s display. Open Etherscan, enter the receiving address, and verify that the incoming transaction shows the correct amount and asset type. If any transaction appears stuck or fails, retry it immediately or escalate the gas price if the interface offers that option.
If the account is actively under attack and transactions are being reversed or stolen mid-transfer, stop and document what is happening. Contact the Ethereum community through security-focused channels such as ethersecurity.org, but do not expect external recovery. The funds that remain on the compromised account are effectively lost; focus on preventing further damage and securing the remainder.
Close or abandon the compromised installation entirely
Once the major assets have been transferred, uninstall Rabby Wallet from the compromised browser or device entirely. Do not leave the extension in place with the intention of “cleaning it up later.” A compromised recovery phrase means the account is accessible to anyone with that seed, regardless of whether you still have the extension open. Uninstalling the extension removes one potential attack surface but does not invalidate the private keys themselves.
If you used a secondary browser profile for the new account, you can delete the profile containing the old installation, which removes all cached data, cookies, and local storage associated with it. This is not strictly necessary for security but eliminates clutter and reduces confusion about which installation is active.
Do not attempt to move the compromised account to a hardware wallet, import it into a different software wallet, or use it in any other context. The recovery phrase is compromised, and any action involving it increases the window for theft. The only exception is if you are documenting the account’s history for forensic or insurance purposes, in which case you should verify and record the final balance and any suspicious transactions through a read-only block explorer view, not by connecting any wallet.
Verify the new account and secure the recovery phrase with extreme care
The fresh Rabby Wallet you created is your safety zone, but only if the recovery phrase remains secret. Open the new installation and verify that the primary address matches the one you have written down. Check that all transferred funds have arrived and are displayed in the Assets view. The balance should match what you migrated out of the compromised account (minus gas fees).
For the recovery phrase, follow these strict rules: store it in a single physical location such as a safe deposit box, home safe, or secure vault. Do not take photographs. Do not type it into your phone or computer again after the initial account creation. Do not share it with anyone, including family members, unless you have prepared them for account recovery in the event of your death, in which case provide written instructions on where the phrase is stored and how to use it, sealed and updated only when absolutely necessary.
Consider a multi-backup strategy for the recovery phrase if the account will hold significant value. One backup in a home safe and another in a safe deposit box reduces the risk of losing access through fire, theft, or natural disaster. Ensure that your will or estate planning documents make clear to your heirs where the backups are and how to access them, without actually revealing the phrase to anyone prematurely.
Understand what enabled the compromise and prevent recurrence
Recovery phrases must be treated as the ultimate secret: equivalent to the combination to a safe that holds all your funds. They are not passwords that can be reset. They are not recovery codes that support teams can issue. They are cryptographic material that directly unlocks accounts across every chain Rabby Wallet supports. Exposure is not something that can be “fixed” through support; it requires immediate account abandonment and migration.
The most common sources of exposure are screenshots stored in cloud accounts, recovery phrase written in password managers without encryption, notes saved in shared documents or collaborative apps, and physical notes left in unsecured locations. Less common but still relevant are malware that reads browser memory or clipboard contents, shoulder surfing, and social engineering attacks that trick users into revealing the phrase.
Rabby Wallet’s security model is strong—the application itself is open-source with code available on GitHub—but it depends entirely on users maintaining phrase secrecy. The wallet cannot protect an account from a compromised recovery phrase because the phrase is the account. Your responsibility as a self-custody user is to treat that phrase as a physical asset under armed guard. Download Rabby Wallet only from official sources: verify that you are installing from sites.google.com/rabby-wallet-extension.com/rabby-extension or from verified app stores such as Chrome Web Store for the browser extension, rather than from third-party repositories that may have inserted malware.
Recover if you cannot access the new account or funds don’t arrive
If you lose the new recovery phrase or cannot access the new Rabby Wallet account, the funds are gone. There is no recovery mechanism, no support team, and no recourse. Write the phrase down carefully the first time; do not assume you will remember it or that a digital backup will be accessible later.
If funds are transferred to the new address but do not appear in the new wallet after 15-20 minutes on Ethereum mainnet or the appropriate block time on other chains, verify the transaction on Etherscan first. If the transaction is confirmed on-chain but not showing in Rabby, try refreshing the wallet or restarting the browser. If the issue persists, verify that you are viewing the correct chain in the wallet settings. Funds sent to a Polygon address will not display if the wallet is set to Ethereum mainnet.
If a transaction fails or is reversed, try again immediately with a higher gas price if you are on mainnet. If the transaction remains stuck, the gas fee was likely insufficient. Do not send additional transactions to the same address until you understand why the original one is pending; parallel transactions can interact in unexpected ways.
Frequently asked questions
How quickly can an attacker drain an account if they have the recovery phrase?
If the attacker has technical knowledge and is monitoring the account, they can initiate transfers or approve token swaps within seconds of gaining access. Gas fees and network confirmation times are the only delays; there is no built-in rate limit or transaction approval delay for self-custody wallets. This is why immediate migration is critical—every minute the compromised phrase remains active is a window for theft.
Should I send a small test transaction to verify the new address before migrating everything?
Yes, if you have time. Send a small amount to the new address and confirm it arrives in the new wallet. This verifies that the address is correct and that you can see incoming transactions. However, if the compromised account is under active attack, skip the test and migrate everything immediately. A small delay testing the address is not worth leaving large balances exposed.
What should I do if my recovery phrase was exposed but I have not migrated yet and do not have time right now?
Migrate immediately. This is not a task to schedule for later. If you absolutely cannot act within the hour, move the account to a hardware wallet that you control locally as a temporary measure, then complete the full migration to the new Rabby account when you can. The longer an exposed recovery phrase remains active on any account, the higher the risk of total loss.