# Web3 safety 101: How to protect your wallet, avoid scams and stay safe on chain. (The do's and the don'ts)

- Author: Stqr_lonerr (https://wurk.fun/user/Stqr_lonerr)
- Published: 2026-06-11
- Canonical (HTML): https://wurk.fun/blog/the-perks-the-do-s-and-the-don-ts-of-web-3
- Cover image: https://ik.imagekit.io/wurk/213629_YMZToMsSP.jpg

---

Web3 is exciting. You own your assets, you control your identity, and no bank can freeze your account. But there’s a flip side: no customer support line either. If you lose your crypto or get scammed, it’s gone for good. 
The good news? 90% of Web3 losses come from 3 preventable mistakes. Here’s how to avoid them.
 Wallet Security: Your Keys = Your Money

In Web3, your wallet is your bank account. If someone gets your “keys”, they own your funds.
*Do this:*
1. Guard your seed phrase: That 12-24 word phrase is the master key. Write it on paper, store it offline. Never screenshot it, never type it into a website, never send it to “support”. No legit project will ever ask for it.
2. Use a hardware wallet for big amounts: Ledger, Trezor, etc. They keep keys offline. For daily trading, a hot wallet like MetaMask/Rabby is fine, but keep most funds in cold storage.
3. Separate wallets: Have 1 “vault” wallet for long-term holds. Use a separate “burner” wallet for airdrops, new dApps, minting. If the burner gets drained, your vault is safe.
A burner wallet is a throwaway wallet you use for testing new dApps, minting NFTs, or anything risky. You only keep small amounts there.
here's how to create a burner wallet: 
*On MetaMask mobile/desktop:*
1. Open MetaMask> Tap your account name at top
2. Add account > Create new account
3. Name it "Burner" so you don’t mix it up with your main vault wallet
4. That’s it - new address is ready. No seed phrase needed since it’s derived from your main one
*On Phantom/Solana:*
1. Open Phantom> Tap gear icon >Add/Connect Wallet
2. Create new wallet> Name it "Burner"
3. Done - new address generated instantly
4. Lock + backup: Set a strong password + enable biometrics on your wallet app. Back up the seed phrase in 2 physical locations.

![213637](https://ik.imagekit.io/wurk/213637_i1u7Iytjo.jpg)
*Don’t do this:*
1. Store seed phrase in Notes, Google Drive, Telegram, email
2. Click “Import wallet” links from DMs, Twitter replies, or random sites
*******************************************
2. Scam Prevention: If It Feels Off, It Is.
Scammers thrive in Web3 because transactions are irreversible. Watch for these top 5 scams right now and don't fall for it like i did:
1. Fake “support” DMs: “Hey, I’m from MetaMask support. Send your seed phrase to fix your wallet.” Real support never DMs you first. it's a scam
2. Token approval phishing: You click “Approve” on a malicious dApp. It gets unlimited access to drain your wallet. Always check what permissions you’re approving.
3. Fake airdrops/NFT mints: “Free 5 ETH airdrop! Connect wallet here.” If it’s too good to be true, it is. Never connect your vault wallet to random sites.
4. Address poisoning: Scammer sends you tiny amounts of tokens from an address that looks like yours. You copy the wrong address and send funds to them.
5. Rug pulls + fake tokens: Coin has 1000x hype, no audits, anonymous team. If you can’t find a real audit + doxxed team, assume high risk.
********************************************
3. Protect Yourself Onchain: Think Before You Click
Onchain = permanent. No “undo” button. Build these habits:
1. Audit before you ape: Before using a new protocol, check: Is it audited by Certik/Halborn/OpenZeppelin? Is the code public on Github? How long has it been live?
2. Start small: Test new dApps with $5-10 first. If it works, then move more.
3. Understand gas + slippage: Set slippage manually on DEXs. 99% slippage = bot will drain you. 
4. Watch for “infinite approval”: When a dApp asks for token approval, choose “Custom spend limit” instead of “Unlimited” if possible.
5. Use block explorers: Paste any token contract into Etherscan/Basescan before buying. Check: Is it verified? Are top holders locked? Is “mint” function disabled?

![213633](https://ik.imagekit.io/wurk/213633_4uw0HKvhT.jpg)

Here are some golden rules:
- Verify the URL: Bookmark official sites. Scammers use `metamαsk.io` with a Greek alpha instead of “a”.
- Revoke permissions monthly: Use http://revoke.cash or Etherscan Token Approvals to cancel old dApp access.
- Double-check addresses: Send a $1 test transaction first. Copy/paste errors cost millions.
********************************************
Web3 gives you freedom, but freedom = responsibility. You don’t need to be a developer to stay safe. You just need paranoia + good habits. 

Start with 3 things today: 1) Move seed phrase offline, 2) Revoke old token approvals, 3) Create a separate burner wallet and always keep in mind
The safest degens are the boring ones.
