Phishing
Look-alike domains and fake support can redirect users to malicious requests.
Learn wallet control, secret material, offline backup and recovery with practical security checks and on-chain verification guidance.
Private keys authorize blockchain actions, while seed phrases commonly restore a set of derived keys. Anyone who obtains this secret material may gain control of the corresponding assets.
Look-alike domains and fake support can redirect users to malicious requests.
A persistent token permission can remain active after a DApp session ends.
Screenshots, remote control and public devices can reveal sensitive material.
Wrong network, address or amount can lead to irreversible outcomes.
Official support should never ask for a seed phrase or private key. Requests to verify, synchronize, unlock or recover a wallet by entering secret material into a website should be treated as high risk.
Recovery should be performed only in a trusted wallet on a controlled device, not during remote-control or screen-sharing sessions.
For wallet control, secret material, offline backup and recovery, use a deliberate sequence: verify the entry point, confirm the network, check the address or contract, review the exact request, then submit. For asset movement, also verify the amount, fee and transaction hash. For DApps, distinguish connection, message signatures, transaction signatures and token approvals because they create different permissions.