Build key-protection principles

Key idea

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. For Device Security, start by identifying the object you are actually interacting with. Interface labels and icons are not enough; addresses, network names, contract addresses and transaction hashes should be cross-checked against verifiable on-chain information when appropriate. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. Before submitting a transfer, signature or approval, perform a final review of the destination, network, asset, amount, gas terms, contract and permission scope. On-chain transactions generally cannot be reversed by the wallet alone, so prevention is more reliable than recovery. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Recognize common risk scenarios

Key idea

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. Before submitting a transfer, signature or approval, perform a final review of the destination, network, asset, amount, gas terms, contract and permission scope. On-chain transactions generally cannot be reversed by the wallet alone, so prevention is more reliable than recovery. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. If information conflicts, stop the action and verify the source again. Urgency, countdowns or claims from supposed support staff should not reduce your checking standards. If a DApp or contract is unfamiliar, cancel the request and verify its public documentation and contract address first. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

What to do when something looks wrong

Key idea

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. If information conflicts, stop the action and verify the source again. Urgency, countdowns or claims from supposed support staff should not reduce your checking standards. If a DApp or contract is unfamiliar, cancel the request and verify its public documentation and contract address first. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. For long-term use, turn security checks into routine: keep recovery material offline, maintain device hygiene, avoid entering secrets on public computers, use public networks cautiously, review old approvals and retain transaction hashes for later verification. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Everyday security checklist

Key idea

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. For long-term use, turn security checks into routine: keep recovery material offline, maintain device hygiene, avoid entering secrets on public computers, use public networks cautiously, review old approvals and retain transaction hashes for later verification. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page. For Device Security, start by identifying the object you are actually interacting with. Interface labels and icons are not enough; addresses, network names, contract addresses and transaction hashes should be cross-checked against verifiable on-chain information when appropriate. Seed phrases and private keys should remain under the user’s control. No legitimate support process should require users to disclose a seed phrase, private key or verification code. If exposure is suspected, evaluate key and approval risk rather than entering more information into an untrusted page.

Action checklist

  • Never send a seed phrase, private key or verification code to anyone.
  • Check the address, network and amount before transfers.
  • Review the domain, contract and permissions before signing for a DApp.
  • Consider revoking approvals that are no longer needed.
Risk notice

On-chain transactions generally cannot be reversed by the wallet alone. Third-party DApps, smart contracts and network services may involve technical or operational risk.