Loading WURK...
cjiw0o
cjiw0o
Bagwork Enthusiast

Web3 Safety Guide for everyone and wurkers

Everything you need to protect your wallet from burner wallets and scam red flags to revoking approvals and reading what you're actually signing.

Published on June 11, 20266 min read

The first time I heard about someone losing their entire crypto portfolio to a phishing link, I thought: "That would never happen to me." Six months later, I nearly clicked a fake Uniswap airdrop link at the top of a Google search. The URL had a tiny "i" replaced with "l." I caught it at the last second.

Web3 is one of the most exciting frontiers in technology but it's also one of the most unforgiving. There are no chargebacks. No customer support hotlines. No bank to call. When funds leave your wallet to a scammer, they are gone. Forever. This guide is here to make sure that doesn't happen to you.


The Core Mindset: Verify, Don't Trust

In traditional finance, institutions verify things for you. In Web3, you are the institution. No one else is checking whether that contract is safe, whether that site is real, or whether that signature drains your wallet.

Before every onchain interaction, ask three questions:

  • Do I know exactly what this transaction will do?
  • Did I find this site from an official, verified source?
  • Am I being rushed or pressured to act fast?

If you can't answer "yes" to all three stop.

What you're actually signing

When a dApp asks you to "sign" something, it's not always a simple login. There are two very different types:

  1. Message signatures (off-chain): Free, no gas. Prove you own a wallet. Generally safe but malicious actors use them to authorize token transfers via EIP-712 permit functions. Read carefully.
  2. Transaction signatures (on-chain): These write to the blockchain. They can move funds, grant approvals, or interact with smart contracts. Never approve a transaction you don't understand.

Pro tip: Tools like Rabby Wallet show a human-readable preview of exactly what a transaction will do before you sign it. Use them.


Before you connect your wallet to any site

Never connect your main wallet impulsively. Run through this checklist before every new interaction:

  • Verify the URL manually. Type it yourself or use a bookmark. Never click links from Twitter replies, Discord DMs, or Telegram. Watch for lookalike characters: uniswap.org vs uniswаp.org (that "а" is Cyrillic).
  • Find official links from verified accounts. Go to the project's official Twitter/X. Cross-reference with their docs or GitHub. Check CoinGecko or CoinMarketCap for official links.
  • Check the domain's age. Use whois.domaintools.com. A "new DeFi protocol" with a 3-day-old domain is a massive red flag.

Burner wallets your best friend in Web3

A burner wallet is a separate, disposable crypto wallet you use for risky or experimental onchain activities. Minting NFTs from new projects, testing new DeFi protocols, claiming airdrops anything you're not 100% sure about.

Even if the site is malicious and drains the wallet, your main holdings are completely untouched. Think of it like carrying a separate card with only $20 when traveling somewhere unfamiliar.

  • Burner wallet For risky interactions, minting, and testing. Fund only what you need.
  • Hot wallet MetaMask / Rabby For daily use and smaller amounts. Always connected to internet.
  • Cold wallet Ledger / Trezor For long-term storage and large holdings. Never connected to internet.

How to create a burner wallet step by step

  1. Open Wallet app (Phantom) and click the account icon in the top-right corner.
  2. Select Add account or hardware walletAdd a new Solana account.
  3. Name it clearly call it Burner or Mint Wallet so you never confuse it with your main wallet.
  4. Fund it with only what you need for the specific interaction, plus a little extra for gas. No more.
  5. After using it, move any trusted assets to your main wallet promptly. Don't let valuable assets sit in a burner.

Create a new burner for every major new protocol you interact with. Wallets are free. Your peace of mind is priceless.

Red flags of scam projects

Anonymous teams with no track record Pseudonymity is fine but no verifiable history, no GitHub, no conference presence? That's a problem.

Copied or plagiarized websites Scammers clone legitimate projects' sites and swap the contract address. Google key phrases from their About section.

Fake urgency and artificial scarcity Only 2 hours left! Urgency bypasses rational thinking. Legitimate projects don't evaporate if you take 30 minutes to research.

Too-good-to-be-true rewards 3000% APY. Guaranteed returns. In DeFi, yield comes from somewhere if you can't figure out where, you might be the source.

Excessive DM outreach No legitimate project will DM you first. Ever. Set your DMs to closed in any crypto Discord.


Seed phrase safety

Your seed phrase (12 or 24 words) is the master key to your entire wallet. Whoever has it, owns everything in it. Permanently.

  • Written on paper, stored in a fireproof safe
  • Never in a notes app (Apple Notes, Notion, Telegram Saved Messages)
  • Never typed anywhere online, ever
  • Don't forget and lose it
  • Don't give it to anyone

The #1 rule: No legitimate project, dApp, support team, or human being will ever ask for your seed phrase. Not once. Not ever. If someone asks it's a scam. Full stop.


Revoking old wallet approvals

Every time you approve a dApp to spend your tokens, that permission often stays active indefinitely even if you never use the dApp again. If that protocol gets hacked later, the approval can drain your wallet.

How to revoke step by step (using Revoke.cash)

  1. Go to revoke.cash and enter your wallet address (you don't need to connect safer).
  2. You'll see all active approvals listed by network. Review each one: do you still use this dApp? Is the allowance unlimited?
  3. Click Revoke on anything you don't recognize or no longer use.
  4. Confirm the transaction in your wallet. A small gas fee is required per revocation.

Do this every 1–3 months as routine hygiene, immediately after any suspicious interaction, and before moving assets to a new wallet.


Tools

  • Revoke.cash Manage and revoke token approvals
  • Rabby Wallet Transaction preview before signing
  • Tenderly Simulate transactions before executing
  • Pocket Universe Flags dangerous transactions
  • ScamSniffer Blocklist for phishing sites
  • DeBank Portfolio + approval checker

If you think your wallet is compromised

Act fast. Every second counts.

  1. Don't panic-click anything. Panicked actions make things worse.
  2. Go to Revoke.cash immediately and revoke all approvals on the affected wallet.
  3. Transfer remaining assets to a brand new wallet one that has never been exposed. Don't send to another existing hot wallet.
  4. Document everything screenshots, transaction hashes, addresses. Useful for reporting.
  5. Report the scam to the platform where you found it and to the real project team if it was an impersonator.

What you cannot do: recover funds already sent. The blockchain is immutable. The best response to a compromise is learning from it.

Security is a practice, not a setting. Web3 security isn't a one-time setup. It's an ongoing mindset you carry into every click, every signature, every new protocol you try.

The people who thrive in this space long-term aren't necessarily the ones who found the best alpha. They're the ones who didn't get rekt when everyone else did because they verified before trusting, used burner wallets, revoked old approvals, and never shared their seed phrase.

You don't need to be a smart contract auditor to stay safe. Slow down, ask the right questions, and use the tools available to you. Stay skeptical. Stay curious. And stay safe out there.

Found this helpful? Share it with someone new to Web3 they'll thank you later.

Engagement

Join the conversation

Likes and comments are stored per blog so readers can react without heavy reloads.

Comments0
Connect your wallet to like this blog and leave a comment.

Latest comments

0
No comments yet. The first response can set the tone for the conversation.