A recovery phrase or private key is not a password reset token. Anyone who receives it can usually reconstruct signing authority. Legitimate support workflows should never require it, and security processes should assume any disclosed recovery material is permanently compromised.
This concept matters because Never type a seed phrase into a website presented as support.
Seed phrases deterministically reconstruct signing authority and therefore cannot be scoped like a password reset token.