Skills

Recognize common wallet scams

Pause requests that exploit urgency, familiar branding or misunderstood permissions.

✨ Learn with AI

Copy this context and paste it into your preferred assistant. Check important claims against the sources.

Select the text to copy it manually.

Start with: wallet, approvals.

Before you start

No legitimate public-address check requires a seed phrase or private key. Keep this distinction clear before responding to an urgent message or unexpected token.

Request Authority or exposure to check
Seed phrase or private key Full key-controlled account access
Transaction The exact onchain state change
Signature Login, permit, order or another authorization
Token allowance Token, spender, amount and duration
Remote access Control of the device that prepares requests

Steps

  1. Identify the request. Is someone asking for a secret, a signature, an allowance, a payment or remote access? Each can transfer control in a different way.
  2. Check the origin independently. Open known official documentation rather than following a private-message or advertisement link. Familiar names and avatars can be copied.
  3. Inspect the promised benefit and claimed emergency. Guaranteed returns, surprise rewards and “act now to save your wallet” demands are reasons to pause and verify.
  4. Compare the actual wallet request with the claimed action. A login should not silently become an unlimited allowance. A free signature can still grant valuable authority.
  5. For receiving addresses, verify the full destination through a trusted channel. Ignore lookalike addresses inserted into history and unsolicited token links.

Verify the result

You can explain the source, purpose and authority of a request before accepting it. If you cannot, declining is a valid outcome. Use a separate trusted channel to confirm suspicious messages.

If something differs

If you already acted, save public identifiers and inspect what permission or transfer occurred. Do not pay an unsolicited recovery agent or share secrets. Key compromise, a token allowance and a mistaken transfer need different responses; avoid a rushed second transaction that compounds the loss.

note — The right response depends on what was exposed. Disconnecting a site, revoking an allowance and moving assets solve different problems.

Sources

💬 Discussion

One conversation for every language. Ask questions in any language. Comments appear after this page is shared in the updates channel.

Load Telegram comments

Updates channel ↗ · Community forum ↗