Start with the core concepts
For Phishing & Scams, seed phrases and private keys should remain under the user’s control. Anyone asking you to reveal, validate or send them should be treated with extreme caution; legitimate support should not require those secrets or verification codes.
For phishing sites, fake support, fake airdrops, clipboard risks and social engineering, a reliable approach is to separate what the interface shows, what you are asking the wallet to do, and what will actually change on-chain. Labels are only an entry point; the network, address, contract, signature and transaction determine the result. Keeping those layers distinct makes it easier to notice a wrong network, a mismatched asset, an excessive approval or an unexpected request source.
Key checks
- Relate Phishing & Scams to the address, network, asset or contract involved.
- When information conflicts, prefer verifiable on-chain data and the explicit rules of the receiving service.
- Do not treat a successful-looking interface state as a substitute for checking the network and transaction hash.
Use a clear decision sequence
Screenshots, cloud storage, chat tools and email can increase the exposure of recovery data. An offline record that is not routinely kept on an internet-connected device reduces that exposure.
For phishing sites, fake support, fake airdrops, clipboard risks and social engineering, a reliable approach is to separate what the interface shows, what you are asking the wallet to do, and what will actually change on-chain. Labels are only an entry point; the network, address, contract, signature and transaction determine the result. Keeping those layers distinct makes it easier to notice a wrong network, a mismatched asset, an excessive approval or an unexpected request source.
Practical review points
- Confirm the active network and target before reviewing amount, permissions or fees.
- Before signing, make sure the request matches the action you intended to perform.
- For unfamiliar functions, break the task into smaller steps and leave time to verify each one.
Watch for common risk patterns
Phishing often relies on urgency, fake support, fake airdrops or lookalike domains. Claims that require immediate action are a reason to slow down and independently verify the source.
For phishing sites, fake support, fake airdrops, clipboard risks and social engineering, a reliable approach is to separate what the interface shows, what you are asking the wallet to do, and what will actually change on-chain. Labels are only an entry point; the network, address, contract, signature and transaction determine the result. Keeping those layers distinct makes it easier to notice a wrong network, a mismatched asset, an excessive approval or an unexpected request source.
Risk reminders
- Do not use a similar name, icon or address format as proof that two assets or networks are identical.
- When using Phishing & Scams, never send a seed phrase, private key or verification code to anyone.
- Third-party DApps, smart contracts and external services can each introduce their own risks.
Build a repeatable review routine
Security also depends on the device and network environment. Shared computers, public Wi-Fi and remote-control sessions are poor settings for sensitive wallet operations, and the final transfer address should be checked again before signing.
For phishing sites, fake support, fake airdrops, clipboard risks and social engineering, a reliable approach is to separate what the interface shows, what you are asking the wallet to do, and what will actually change on-chain. Labels are only an entry point; the network, address, contract, signature and transaction determine the result. Keeping those layers distinct makes it easier to notice a wrong network, a mismatched asset, an excessive approval or an unexpected request source.
Routine checklist
- Check address, network and amount before a transfer.
- Check request source, target and permission scope before signing or approving.
- Periodically review connections and approvals you no longer use.
Go one level deeper
Scammers may reach users through search ads, social messages, lookalike domains or fake support pages. A polished appearance is not proof of legitimacy; useful checks include the domain, exact request, contract information and resulting on-chain data.
As your usage changes, adjust the checks to the networks, assets and DApps you actually use. Caution with unfamiliar requests and a consistent review sequence for familiar tasks both reduce the chance of approving something by habit.
Principles to keep
- For actions related to Phishing & Scams, remember that blockchain transactions generally cannot be unilaterally reversed by a wallet.
- A wallet can display request details but cannot guarantee the behavior of every third-party contract.
- Clear, verifiable information is more useful than speed when the consequences are on-chain.
