Wallet security, scam prevention, and the everyday habits that keep your assets and your peace of mind intact onchain.
Web3 hands you something traditional finance never could: full, direct control over your own assets. No bank to call when something goes wrong, no customer support ticket that gets you your funds back, no "are you sure?" pop-up before a transaction drains your wallet. That freedom is the whole point and it's also exactly why Web3 has become a playground for scammers.
The good news is that staying safe onchain isn't about being a security expert. It's about building a handful of habits and asking the right questions before you click, connect, or sign anything. This guide walks through those habits in plain language, with practical steps you can start using today.
The one mindset that matters most If you remember nothing else from this post, remember this: verify, don't trust . Not the DM that looks official. Not the link in a comment with thousands of likes. Not the "support agent" who slid into your messages first. Every single time, you check for yourself.
How to Stay Safe on the Internet in Web3
Web3 safety starts long before you ever open a wallet popup. Most attacks succeed not because someone "hacked" a wallet, but because a person was tricked into approving something themselves. Your wallet did exactly what it was told the problem was what it was told to do.
- Separate identities Don't use the same wallet for everything. Keep your "savings" wallet separate from the one you use to explore new dApps, mint NFTs, or test airdrops.
- Slow down Scammers rely on urgency. If something feels rushed "only 10 minutes left!" that pressure is the scam, not a bonus.
- Bookmark, don't search Save the official URLs of dApps you use regularly. Search engine ads and fake links are one of the most common entry points for phishing.
Think of your online behavior in Web3 the same way you'd think about handing someone your house keys. You wouldn't hand a stranger your keys just because they said "trust me, I'm with building maintenance." Wallet connections and signature requests deserve the same scrutiny.
Before You Connect or Sign: What to Actually Check
Connecting your wallet to a site, and signing a message or transaction, are two very different levels of risk and a lot of people don't realize that.
Connecting a wallet This usually just lets a site see your public address and balances. On its own, it doesn't move funds. Still, only connect to sites you've verified, since a malicious site can use the connection to immediately prompt a harmful signature request.
Signing a message or transaction This is where the real risk lives. A signature can authorize a token transfer, grant an approval for a contract to spend your tokens, or even transfer an NFT sometimes without a clear "you are about to send X" warning in the wallet popup.
Before connecting or signing anything, run through this quick checklist:
- Check the URL character by character Scam sites often use lookalike domains extra letters, swapped characters, or a different domain extension (.io vs .com vs .app). Compare it against a bookmarked official link.
- Read the wallet popup, don't just click "Confirm" Look at what contract you're interacting with, what permission is being requested, and whether the amount or token matches what you expected.
- Ask "why does this need this permission?" A simple NFT mint shouldn't need "unlimited approval" over your entire token balance. If the permission requested is bigger than the action makes sense for, stop.
- Use a wallet that isn't your main one For new or unfamiliar dApps, connect with a burner wallet first (more on this below) so that even a worst-case scenario only affects a small, expendable amount.
Burner Wallets: What They Are, Why People Use Them, and How to Make One
A burner wallet is a secondary, low-value wallet you use specifically for risky or unfamiliar interactions minting from a new project, testing an unaudited dApp, claiming a questionable airdrop, or connecting to a site you're not 100% sure about yet.
The idea is simple: if that wallet gets drained because of a malicious contract or a bad signature, the damage is limited to whatever small amount you put in it not your life savings.
- Damage control: Worst case, you lose a small, pre-decided amount instead of your main holdings.
- Privacy: Your main wallet's activity and balances stay separate from experimental interactions.
- Freedom to explore: You can try new projects, mints, and airdrops without the anxiety of risking significant funds.
How to create a burner wallet, step by step
- Install a fresh wallet (or create a new account) Most wallet apps (e.g. MetaMask, Rabby, Backpack) let you create multiple accounts/profiles within the same app. Use "Create new account" rather than reusing your main seed phrase's address.
- Generate a brand-new seed phrase For maximum separation, create an entirely new wallet with its own unique seed phrase rather than just a new address derived from your main one. Write it down and store it separately from your main wallet's seed.
- Fund it with a small, "I'm okay losing this" amount Send only what you'd be comfortable losing entirely enough to cover gas fees plus whatever small amount you want to use for the interaction.
- Use it for unfamiliar interactions only Connect this wallet not your main one when minting from a new project, trying an unaudited dApp, or claiming an airdrop you haven't fully vetted.
- Top it up as needed, and retire it if compromised If a burner wallet ever gets drained or you suspect it's compromised, simply stop using it and create a new one. Nothing important was tied to it.
How to Check If a Site or Project Is Legit
Before connecting your wallet anywhere, take a few minutes to verify the project itself. This single habit filters out a huge percentage of scams.
- Find the official link from the source, not from a search or DM Go to the project's verified social account (look for verification badges and an established posting history), and get the website link from their pinned post or bio not from a reply, comment, or message someone sent you.
- Cross-check across multiple official channels Does the link match what's listed on their official X/Twitter, their Discord announcement channel, and their documentation site? If one channel shows a different domain, that's a red flag.
- Look at the team and history Is the team identifiable, with a track record? Has the project existed for a while with consistent communication, or did it appear overnight with no history?
- Check community sentiment but skeptically A flood of generic positive comments ("amazing project!! ππ") on every post can be a sign of bot activity. Look for genuine discussion, questions, and even criticism.
- Check the contract, if applicable For tokens or NFTs, look up the contract address on a block explorer. Check whether it's verified, whether ownership has been renounced or is held by a recognizable entity, and how the token distribution looks.
Common Red Flags of Scam Projects
Watch out for these patterns
- Anonymous teams with no track record anonymity alone isn't always a red flag in crypto, but combined with big promises and no verifiable history, it's a serious warning sign.
- Copied or near-identical websites same layout, same wording, just a different name or slightly different domain as a legitimate project.
- Unsolicited DMs about support, refunds, or "special" opportunities real support teams don't message you first.
- Manufactured urgency countdown timers, "last chance," "only X spots left." Legitimate projects rarely need to pressure you into acting in the next five minutes.
Common Scam Types You Should Recognize
Phishing links Fake versions of real sites designed to capture your seed phrase or trick you into signing a malicious transaction. Often spread through search ads, comments, or compromised accounts.
Fake airdrops "You're eligible for a free token claim!" links that lead to draining contracts. Often timed around real, hyped airdrop announcements to blend in.
Address poisoning Scammers send tiny transactions from an address that looks almost identical to one you've used before, hoping you'll copy the wrong address from your transaction history later.
Drainer sites Sites built specifically to request broad token approvals or signatures that, once granted, allow the attacker to sweep funds from your wallet.
Fake support DMs Someone posing as "official support" reaches out first, usually after you post a question publicly, offering to "help" and then asking for your seed phrase or remote access.
Impersonation accounts Social accounts with names and profile pictures nearly identical to real projects or team members, often with a slightly altered handle.
Reading What a Transaction Is Actually Asking You to Sign
Wallet popups can look intimidating, but a few key details tell you most of what you need to know:
- What contract are you interacting with? Does the address match the official contract for the project (check it on a block explorer if unsure)?
- What function is being called? Things like approve, setApprovalForAll, or permit are permission grants they don't move funds immediately, but they give a contract future access to your tokens or NFTs.
- What's the spending limit? An "unlimited" approval means the contract can move any amount of that token, at any time, until you revoke it. A reasonable, capped amount is generally safer than "unlimited" when given a choice.
- Does the action match your expectation? If you clicked "mint NFT" but the popup is asking for approval over your stablecoins, something is very wrong.
Tools that can help Transaction simulators (built into many modern wallets and some browser extensions) show you a preview of what a transaction will actually do which tokens move, to where, and how much before you confirm. Approval-checking tools let you view and revoke active approvals for any address. Using these regularly turns "blind signing" into "informed signing."
Revoking Old Wallet Approvals and Why You Should Do It Regularly
Every time you approve a contract to spend your tokens, that permission stays active until you manually revoke it even if you never use that dApp again. Over months or years, most active wallets accumulate dozens of old approvals, many to contracts from projects that no longer exist, were never audited, or have since been compromised.
An old, forgotten approval to a contract that later gets exploited can let an attacker drain tokens from your wallet even though you didn't sign anything new at the time of the exploit. The approval was already sitting there.
- Open an approval-checker tool Most major block explorers have a "token approvals" section for any address, where you can view all active approvals.
- Connect the wallet you want to review The tool will display a list of contracts with active spending permissions, the tokens involved, and the approved amounts.
- Review each approval For each one, ask: do I still use this dApp? Do I recognize this contract? Is the approved amount unlimited?
- Revoke anything you don't actively need Click "revoke" on outdated, unrecognized, or unlimited approvals you no longer use. This requires a small transaction (gas fee) but is well worth it.
- Make it a routine Set a recurring reminder monthly or quarterly to review and clean up approvals, especially after trying new dApps.
Seed Phrase Safety: The Foundation of Everything
Your seed phrase (recovery phrase) is the master key to your wallet. Anyone who has it has full, permanent control over everything in that wallet no password, 2FA, or "account recovery" can undo that.
Where to store it Written on paper (or engraved on metal) and kept in a secure physical location a safe, a locked drawer, or split across multiple secure locations. Some people use a hardware wallet's built-in backup features.
Where to NEVER store it Never in a text file, note app, email, cloud storage, password manager note (unless you fully understand the risks), photo, or messaging app. Anything connected to the internet is a target.
Who never needs it No legitimate project, exchange, wallet provider, or "support agent" will ever ask for your seed phrase not for verification, not to "fix an issue," not for any reason. Ever.
If you remember one rule about seed phrases: typing it into a website, app, or chat for any reason is the action that loses your funds. The phrase itself sitting on paper in a drawer is harmless.
What to Do If You Think Your Wallet Is Compromised
If you suspect your wallet has been compromised whether from a malicious approval, a leaked seed phrase, or a suspicious transaction
- Move remaining funds immediately If you still have access and assets remain, transfer them to a brand-new wallet (new seed phrase, generated on a clean device) as quickly as possible.
- Revoke all approvals from the compromised wallet Even after moving funds, revoke active approvals so the attacker can't act on any tokens you receive later or any remaining dust.
- Stop using the compromised wallet entirely Treat its seed phrase as permanently burned. Don't reuse it, don't try to "clean" it just retire it.
- Review how it happened Think back through recent connections, signatures, and downloads. Identifying the cause helps you avoid repeating it and helps you warn others if it was a specific scam site.
- Report it Reporting the malicious site, contract, or account to relevant platforms and communities can help protect others from the same scam.
Security Is a Habit, Not a One-Time Setup
Nothing in this guide requires special technical skills just a slight shift in how you approach each click, connection, and signature. Use a burner wallet for anything new. Keep your valuable assets cold and untouched by random sites. Take thirty seconds to actually read what a transaction is asking before confirming. Revisit your approvals every so often. And above all, verify everything yourself instead of trusting a link, a DM, or a sense of urgency someone else created for you.
Web3 gives you control most financial systems never will. The flip side is that the responsibility for protecting that control sits entirely with you and the habits above are how you carry that responsibility without it being a burden. Stay curious, stay skeptical, and stay safe out there.






Latest comments
0