The ‘free crypto’ seed-phrase gas-fee honeypot scam
A wallet showing a large token balance is not proof that you have been given free crypto. In this scam, someone publishes a recovery phrase that appears to open a funded wallet, then waits for a target to send ETH or another network fee asset so the tokens can be moved. A bot or the scammer can sweep the fee as soon as it arrives. The tokens may also be worthless, blocked from being transferred or designed only to make the story look convincing.[4]
Do not import a recovery phrase found online. Do not send gas to the address. Do not connect your wallet to a site or sign a transaction because a post promises a reward.
How the honeypot works
The bait usually follows a recognisable sequence:
- A post, video comment or message shares a recovery phrase and points to a wallet address.
- A block explorer or wallet interface appears to show a balance, often in an unfamiliar token.
- The wallet has little or none of the network’s native asset, so a token transfer appears to need a small gas payment.
- A curious person sends the missing gas.
- Software watching the account moves the newly arrived fee away, often before the person can do anything else.
The phrase is public by design. Anyone who imports it can see the same accounts, but that does not make the contents theirs. It means the secret has already been exposed, and anyone with the corresponding signing access may be able to spend assets held by those accounts. Ethereum says a recovery phrase is the master key to a wallet and warns that anyone who has it can access its accounts and drain assets.[1]
The scammer does not need to persuade the target to reveal their own seed phrase. The public phrase is bait. The target is meant to supply the missing native asset, while the party already monitoring the account takes it.
Why the balance can look real
A token balance on a block explorer is only one piece of information. It does not tell you that:
- the token has a reliable market or can be sold;
- the token contract allows a transfer or sale;
- the account owner is offering it to you;
- you control the private keys safely; or
- the value is greater than the gas needed to interact with it.
Some versions use a token with restrictions that prevent ordinary transfers or sales. Others use a balance that has no meaningful market value. Even when the token is technically transferable, a publicly shared phrase means another party may already control the same account.
A wallet app can display token data for an address without proving who owns that address. Ownership on a self-custody network is tied to the ability to authorise transactions with the relevant secret. That is why a phrase posted as bait should be treated as compromised, not as a gift.
What “missing gas” means
On Ethereum, gas measures the computational work needed for an operation. A gas fee is the gas used multiplied by the price per unit, and fees are paid in ETH, the network’s native currency.[2] Token balances and ETH balances are separate: an account can display tokens while holding too little ETH to pay for a transaction that moves them.
That distinction creates the hook. The post frames the ETH top-up as a small unlock payment, but it is not an unlock. It is a normal transaction fee paid to the network, and the person who controls the account can receive or spend the ETH that arrives. Ethereum’s documentation also warns that there is no legitimate source of free or discounted ETH and that no one needs access to your private keys.[1]
The same idea can appear on other EVM-compatible networks, where the native fee asset and fee rules differ. Check the specific network’s documentation rather than assuming that an Ethereum explanation applies unchanged everywhere.
Why the sweep can happen so quickly
The scam often relies on automation. Software can monitor a known public address and react when its native balance changes. It may submit a transaction that spends the new balance, leaving nothing available for the intended token transfer.[4] The exact timing and transaction design vary by network and account setup; readers do not need to reproduce them to recognise the danger.
The important point is simpler: the phrase is already public, and the account is being watched. Funding it does not give you priority over the person who created the bait. It can give the watcher exactly what they were waiting for.
A failed attempt can still cost money. Ethereum states that gas is paid whether a transaction succeeds or fails.[2] Sending more fee currency, changing the fee, or trying repeatedly does not turn a compromised account into a safe one.
Red flags
Treat the post as a scam when several of these appear together:
- a recovery phrase is pasted into a public comment, video description or message;
- the message promises free crypto or a large token balance;
- the account appears to need ETH or another native coin before the tokens can move;
- the sender urges speed, secrecy or a specific top-up amount;
- the token is unfamiliar, has no clear independent market information or cannot be verified through the project’s official documentation;
- the same phrase or address appears across multiple posts;
- a website asks you to connect a wallet, enter a recovery phrase or approve an unfamiliar transaction;
- someone claims that a top-up will “unlock”, “activate” or “release” funds.
NCSC describes phishing as using emails, texts or calls to trick people into visiting a malicious site or giving up personal or financial information. The same pressure and deception can appear in public crypto posts and messages, even when the bait is a wallet balance rather than a bank login.[3]
What to do instead
If you see the bait:
- Do not import the phrase, send gas, connect a wallet or sign a transaction.
- Do not test the token by sending a small amount. A small amount can still be swept, and interacting with an unknown contract can create a separate risk.
- Leave the page or post and use the platform’s reporting tools. Do not repost the phrase or address as a warning.
- If you already sent funds, stop adding more. Save the transaction hash and screenshots without sharing any private wallet secrets.
- If you connected your own wallet or approved a contract interaction, use the wallet provider’s official security guidance to review and revoke permissions where appropriate. Move remaining assets to a new, trusted wallet only if you can do so safely and without exposing its recovery phrase.
- If you entered a recovery phrase belonging to your own wallet into a website or shared it with anyone, treat that wallet as compromised and move assets using a clean device and a newly generated wallet. Never publish the new phrase.
Ethereum advises users never to share recovery phrases, private keys or passwords, to check transaction details before signing and to be wary of phishing links.[1] NCSC’s phishing guidance explains how to report suspicious websites and what to do if personal information has been shared.[3]
For a wider overview, see our guides to gas fees and network fees, crypto scams, rug pulls, phishing and fake support and wallets, private keys, addresses and seed phrases.
The short version
A public recovery phrase is not a free wallet. It is a warning that the account’s signing access has been exposed. A visible token balance may be illiquid, blocked or worthless, and the missing ETH is often the bait: once you fund the account, an automated sweep can take the fee. Do not interact with it.
Sources
[1] https://ethereum.org/security — Ethereum security and scam prevention
[2] https://ethereum.org/developers/docs/gas — Ethereum gas and fees
[3] https://www.ncsc.gov.uk/collection/phishing-scams — NCSC phishing scams: how to spot and report them
[4] https://support.metamask.io/stay-safe/protect-yourself/social-engineering/honeypot-scams — MetaMask Help Center: Honeypot scams