Hardware-wallet seed-phrase / recovery-phrase reveal phish — "Enter your 24-word seed phrase to verify your Ledger / Trezor / Tangem wallet" via lookalike domain harvests the master key for every coin held by the device. Categorically illegitimate phrase set: NO canonical wallet vendor (Ledger, Trezor, Tangem, GridPlus, Keystone, BitBox, Coldcard, Foundation, Cypherock) ever asks the user to enter / verify / validate / restore / migrate / reveal a seed phrase via email — the entire hardware-wallet trust model depends on the seed never leaving the device. New SACRED-tier near-absolute-trash class (parallel to "never delete starred" but inverse polarity — "always trash seed-phrase reveal"). Distinct from `fake-hardware-wallet-firmware-update-lure` (firmware-update pretext, not direct seed-phrase harvest). Multi-locale: matches Swedish "ange din återställningsfras" / "bekräfta din återställningsfras" alongside English. Source: Red-Team R9 multi-agent council S4 (hardware-wallet-firmware specialist), Lead consensus C2.
hw-wallet-seed-phrase-reveal-phish
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Hardware-wallet seed-phrase / recovery-phrase reveal phish targeting hardware-wallet owners (Ledger, Trezor, Tangem, GridPlus, Keystone, BitBox, Coldcard, Foundation, Cypherock). The phish narrative arrives as: "Your Ledger Nano X requires re-validation. Please enter your 24-word recovery phrase below to verify ownership and migrate your wallet to the new firmware. Without verification your device will be locked," or "To restore access to your Trezor wallet please validate your 12-word secret recovery phrase via the BIP39 verification form below." Categorically illegitimate phrase set: NO canonical wallet vendor ever asks the user to enter / verify / validate / restore / migrate / reveal a seed phrase via email — the entire hardware-wallet trust model depends on the seed never leaving the device, and every legitimate vendor ships the device with a printed warning to that effect. New SACRED-tier near-absolute-trash class (parallel to "never delete starred" but inverse polarity — "always trash seed-phrase reveal"). Distinct from `fake-hardware-wallet-firmware-update-lure` (firmware-update pretext, not direct seed-phrase harvest); these two signals can co-fire on a single email that combines both pretexts. Multi-locale: matches Swedish "ange din återställningsfras" / "bekräfta din återställningsfras" alongside English "enter / verify / validate / restore / migrate / confirm / submit / reveal / provide / input" + "seed phrase / recovery phrase / 24-word / 12-word / secret recovery phrase / SRP / BIP39." Wallet-context co-predicate (Ledger / Trezor / Tangem / GridPlus / Keystone / BitBox / Coldcard / Cypherock / hardware wallet / wallet / krypto / crypto) prevents firing on generic password-recovery flows. Sender allowlist is intentionally narrow — even canonical Ledger / Trezor newsletters never use the ENTER / REVEAL / VALIDATE prompt vocabulary, so the only practical bypass for canonical senders is to keep the language educational ("Ledger will never ask you to reveal it"). Auto-classified as danger via the `-phish` suffix. Source: Red-Team R9 multi-agent council S4 (hardware-wallet-firmware specialist), Lead consensus C2.
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started