Wallet Security ManualWALLET SECURITY MANUAL
The key IS the key · Never share it

Wallet Security Manual · FILE WH-2026-002

Your wallet has
only one key.

Your seed phrase IS that key. The moment it leaves your hands — photographed, pasted into a website, sent to "support" — your wallet no longer belongs to you. This manual covers three things: how keys get lost, how to keep them, and what to do if they're gone.

Demo prop · The thing scammers want most

SEED PHRASE
Unsealed 0 / 12
Demo complete. You just demonstrated one of the most dangerous ways to leak your seed:exposing words one by one on screen. Remember — a real seed phrase should only ever exist on paper, never on any screen, never typed into any website.

* Above are demo words, not a real seed phrase. Click cells to peel the seal.

The Threat Ledger

There are only three ways your wallet gets emptied.

No elite hacker required. No device breach needed. Most thefts travel these three most ordinary paths. Know the enemy first, then know what to defend.

SEV-1 · Most Common

Phishing Sites & Fake Airdrops

Fake official sites, forged airdrops, "official" DMs — all using pages that look completely legitimate to trick you into entering your seed phrase or signing malicious transactions. The FBI reported over $5.6 billion in crypto-related fraud losses in 2023 alone.

Method: weaponized trust · Target: anyone

SEV-1 · Most Fatal

Seed Phrase Leakage

Screenshots, cloud sync, typing into "verification" sites, sending to "customer support." The seed phrase is the only key to your wallet. Once it leaves your hands — even once — treat it as compromised. No exceptions.

Method: stealing the key · Outcome: irretrievable

SEV-2 · Most Hidden

Unlimited Approval

Under the "mint""claim""stake" approval popup may hide an unlimited allowance. Scammers don't need you to send funds — they can drain everything within that limit yourself. You may not notice a thing.

Method: signature trap · Outcome: silent drain

The Defense Manual

Six iron rules. Follow them in order.

This isn't a wish list — it's a sequence. Start at rule one. Follow each step.

01FIRST

Seed only on paper

Write it by hand on paper. Lock it in a drawer or safe. Never screenshot it, never type it into any website, never send it to anyone. A digital seed phrase is already compromised.

02SPLIT

Hot/cold separation

Store large holdings in a hardware wallet (cold). Use a separate hot wallet for daily small transactions. The two wallets must have different seed phrases — if the hot wallet is compromised, the principal stays safe in cold storage.

03VERIFY

Verify full address before sending

After pasting, verify character by character. Focus on the first and last 8 characters. Save addresses to a contacts list. Compare every time — don't just glance at the first few.

04SCOPE

Control approval limits

Check the scope of approvals on unfamiliar contracts. Revoke unused ones at revoke.cash. Beware of clone domains — verify the tool's own URL before confirming anything.

05LOCK

Lock large amounts

Large transactions should require hardware confirmation and second-factor auth. For team or family funds, use a multi-sig wallet — no single person can move everything.

06PLAN

Prepare emergency plans

Write down in advance: what to do if your device is lost, if you suspect a leak, if you send to the wrong address. List the steps now, follow them later — don't decide in a panic.

Seed Vault

How should you store your seed phrase to truly keep it safe?

"Write it on paper" is only half the story. Writing it down is just the beginning — how you store it determines whether it survives 30 years, and whether it ever passes near a network.

Medium
01MEDIUM

From Paper to Metal

Paper can be flooded, burned, eaten by insects. For long-term large holdings, metal backup (engraved stainless steel plates like Cryptosteel or Billfodl) is recommended, or at minimum waterproof paper cards with lamination. Any "digital seed phrase" in screenshots, documents, or cloud storage should be treated as compromised.

Shards
02SHARD

Split the Key

Use Shamir Secret Sharing to split your seed phrase into multiple parts stored separately (e.g. 2-of-3, 3-of-5): losing any single shard isn't fatal, leaking any single shard isn't fatal either. Best for large long-term holdings — but the shard rules themselves must be stored as securely as the seed phrase.

Copies
03COPIES

Three Locations Rule

Main copy + backup copy + emergency copy (at a trusted person's place), stored in different physical locations. Each copy must guard against being "seen" — a roommate, a security camera, a repair worker could all become witnesses.

Edge Case
04EDGE CASE

What About Password Managers?

Generally no. Password managers live on internet-connected devices — one malware infection and your seed phrase is gone. The only truly safe "digital seed phrase" exists on a fully offline device, and even then there's still the risk of being photographed or cloud-backed up. Beginners should skip this route.

Verification
05RECOVERY TEST

The Cost of a Wrong Word

One wrong word in your seed phrase and recovery will fail. After writing it down, practice recovery right away: delete your wallet, recover using only the paper words, confirm it works — this is the only way to verify your backup is actually good.

Iron Rule
06NEVER

Four NEVERs

NEVER screenshot it. NEVER type it into any website. NEVER send it to anyone — including those claiming to be official, security experts, or customer support. NEVER put it on any internet-connected device.

Remember: The seed phrase is the only key to your wallet. Every screen it appears on, every input field it's typed into, every chat window it shows up in — that is your wallet having been opened once. Make "digital form = compromised" your default assumption.

Red Flags

Spot them at a glance: when these signals appear, walk away.

Scams evolve constantly, but their flaws never change. Any one of these alone is enough to make you stop, verify, and leave.

Fabricated urgency

"Last 2 hours""Account will be frozen if you don't act." Official channels never manufacture urgency. Pressure is scam's first hallmark.

Asking for your seed phrase

No legitimate project will ever ask for your seed phrase or private key. If they ask, it's a scam. No exceptions. No "verification."

Domain cloning

wallet-connect-verify.com, or one or two characters off from the official spelling. Check the address bar. Don't check the page content — the page itself is fake.

Unsolicited "support" DM

Official support never DMs you first, and they never pull you into a "recovery group." "Official" contacts that come to you are, by default, fake.

Airdrop that requires payment

An "airdrop" that asks you to send funds first is a pay-to-receive phishing trap. Real airdrops never require you to pay anything.

Unreadable signature

Can't understand the English in the approval popup? It says "unlimited"? If you don't understand it, don't sign. Close the page and come back later.

Case File

Dissecting a scam: from DM to drained wallet.

Run through SHEET 04's red flags in a realistic sequence. On each step, the left side shows the scammer's move, the right side shows what you should do right now.

01CONTACT
Scam · What they do

You receive a DM (Telegram / Discord / X): "Hello, we're the official XX team. Congratulations — you qualify for an airdrop. Claim here: xxx-claim.com."

Action · What you do

Don't click. Links in DMs are phishing by default. Verify through official channels — cross-reference SHEET 06, or search the official announcement directly.

02BAIT
Scam · What they do

The fake site (domain xxx-claim.com) looks identical to the real one — even sporting a fake "official site" badge, with a giant claim button on the homepage.

Action · What you do

Check the address bar domain against the official entrances table, character by character. Page content can be faked. A domain cannot — you just have to look.

03ENTRY
Scam · What they do

The page asks you to "connect wallet," or directly asks you to "enter your seed phrase to verify identity." They claim this is a required step for the airdrop.

Action · What you do

A seed phrase must never be entered into any website. Connecting your wallet is fine — but watch the next approval popup carefully. That's the real battlefield.

04SIGN
Scam · What they do

The signing popup reads "Approve unlimited amount of TOKEN," with a countdown timer designed to rush you.

Action · What you do

If you don't understand it, don't sign. See unlimited? See a countdown? See any pressure? Click "Reject," close the page, and come back later.

05IF YOU SIGNED
Outcome A · You entered your seed

Assets are drained in bulk within minutes. Once a chain transfer is confirmed, it cannot be reversed.

Action · What you do

Immediately execute SHEET 07 Emergency Checklist Step 1: move remaining assets to a brand-new wallet (new seed phrase). Isolate first, investigate later.

06AFTERMATH
Outcome B · You signed approval

The scammer doesn't rush — they slowly drain within the approved limit. You may not notice for days or weeks.

Action · What you do

Immediately revoke that contract approval (revoke.cash — verify the domain first), then monitor your balance closely.

Why this matters: A scam isn't a single move — it's a four-step chain: contact, bait, entry, signature. Every step has a flaw, all documented in SHEET 04. You don't need to memorize every scam. You just need to pause one second at each step: Is this a DM? Is the domain right? Are they asking for my seed? Do I understand this popup?

Official Entrances

Trust only the official sites: enter through this table only.

Most phishing starts from advertised positions in search results or links in DMs. Give yourself a fixed entry point: only access wallet sites through this table, and always verify the address bar domain.

01The domain must match the table below exactly — not a single character off
02Official channels will never DM you links or ask for your seed phrase
03Search result ad slots and "official site" badges can also be faked
Total 18
Wallet
Type
Official Domain
MetaMaskBrowser Extension / Mobile · Ethereum Ecosystem
Hot Wallet
Trust WalletMobile · Multi-chain
Hot Wallet
PhantomBrowser Extension / Mobile · Solana Ecosystem
Hot Wallet
RabbyBrowser Extension / Desktop · Approval Risk Detection
Hot Wallet
imTokenMobile · Established Multi-chain Wallet
Hot Wallet
TokenPocketMobile / Extension · Multi-chain Cross-chain
Hot Wallet
Bitget WalletMobile / Extension · Web3 Wallet
Hot Wallet
OKX Web3 WalletExchange-integrated · Web3 Wallet
Hot Wallet
ExodusDesktop / Mobile · Multi-currency
Hot Wallet
RainbowMobile / Extension · Ethereum
Hot Wallet
ZengoMobile · No Seed Phrase (MPC)
Hot Wallet
LedgerHardware wallet · Cold storage
Hardware
TrezorHardware wallet · Open-source pioneer
Hardware
TangemHardware Wallet · Card-shaped
Hardware
KeystoneHardware Wallet · QR Air-gap
Hardware
OneKeyHardware / Software · Multi-chain (Chinese)
Hardware
SafeMulti-sig · Smart Account Standard
Multi-sig
ElectrumDesktop · Bitcoin Legacy Open Source
Open Source

Domains verified August 2025. If you ever receive a "new URL," return to this table first, or double-check via the wallet's official social accounts — clone domains often differ by only one or two characters. Download apps only through links on the official website, or search the developer's full name directly in the official app store.
SSL Note: Legitimate wallet sites all use HTTPS, but note that an SSL certificate only means the connection is encrypted — it does not mean the website itself is trustworthy. Verifying the domain and address bar remains the most reliable check.

Emergency Runbook

If you suspect you've been targeted.

There is only one sequence: isolate first, investigate second. Asset safety always comes before understanding what happened. Execute each step:

1

Potential seed leak → Migrate immediately

Move assets to a brand-new wallet (new seed phrase) right now — don't wait a moment. The new seed phrase goes only on paper. Treat the old one as compromised; never use it again.

2

Approval may be abused → Revoke immediately

Revoke suspicious contract approvals at revoke.cash (verify the domain first), then watch your balance closely. Not sure which approvals are suspicious? Revoke them all. Re-authorize only what you actually need.

3

Funds already moved → Race the time window

Contact the project team and exchanges immediately to attempt freezing (the window is short). Preserve all evidence (transaction hashes, chat logs, links), then report to authorities. On-chain transfers are usually irreversible — that's why the first two steps always come first.

4

Under any circumstances → Refuse "recovery" services

Never pay anyone to "unlock funds" or "recover lost assets." Those claiming they can help you recover are the second wave of scammers, targeting people who just got burned.

Common Myths

What you think may not be true.

Four of the most common rationalizations — each one opens another door to your wallet.

I have a small balance — scammers won't target me

Bulk-scanning scripts don't discriminate. They scan for assets and exposures on-chain. Small accounts are on the same list.

Hardware wallets are completely safe

They protect against remote theft — they can't stop you from typing your seed phrase into a phishing page. A hardware wallet is only as safe as the hands holding its seed phrase.

In the official group, support won't scam me

Groups are public. Anyone can rename themselves "support." Impersonating official staff is the most common starting point for scams in crypto.

I only need to check the first few characters

Checksum addresses distinguish case. Imposters construct visually similar addresses. Verify completely — at least the first and last 8 characters, and cross-reference with your address book.

Glossary

Understand the words before talking about security.

All the sections above assume you know these terms. If you get stuck while reading, come back to this table. This is the manual's appendix — and also its starting point.

Seed Phrase
A "key backup" made of 12 or 24 words. Whoever holds the seed phrase owns the wallet — which is why it is the ultimate target of every scam.
Private Key
The ultimate key derived from the seed phrase, used to sign transactions. Just as confidential as the seed phrase — never share it either.
Hot / Cold Wallet
A hot wallet lives on internet-connected devices — convenient but high exposure. A cold wallet lives on offline devices (hardware wallets) — safer but less convenient. Keep large amounts cold, small amounts hot.
Approval
Allowing a contract to spend your tokens. The limit can be set to unlimited. Every approval is worth three seconds of scrutiny.
Signing
The act of confirming a transaction with your private key. Signing = authorizing a payment. If you don't understand the signing request, don't sign it.
Chain ID
The number that distinguishes different chains (Ethereum = 1, BNB = 56, etc.). Cross-chain phishing often tampers here. Confirm the chain in the popup is correct before signing.
Checksum Address
The mixed-case convention for Ethereum addresses. Fake addresses can mimic the appearance of real ones. Verify at least the first and last 8 characters when checking.
Multi-sig
A wallet that requires multiple parties (or keys) to co-sign before transferring funds. One person's compromise doesn't mean all assets are lost.
Airdrop
Free token distribution by a project team. A real airdrop never asks you to pay any fee or provide your seed phrase — anything that does is a scam.
MPC Wallet
Splits the private key into fragments held by multiple parties, no seed phrase exists (e.g., Zengo). Losing a phone doesn't mean losing your wallet.