Crypto safety starts before you sign
How to recognize impersonators, phishing links, malicious approvals, fake support, and suspicious wallet requests.
Most scams start before the transaction
A scam usually begins with pressure: a surprise giveaway, an account warning, a fake support message, or a limited-time opportunity that demands immediate action. The goal is to make you connect, sign, approve, or reveal something before you stop to verify it.
Slow down. Open official websites from your own saved bookmarks. Confirm announcements through verified community channels instead of trusting a screenshot or a direct message.
Know what the wallet is asking
A connection request, a message signature, a token approval, and an asset transfer are not interchangeable. Some signatures can authorize powerful actions even when they are presented as harmless verification.
Read the request carefully. Check the website address, the network, the account involved, and any spending permissions. Reject requests that do not match what you intended to do.
Approvals can outlive the moment
A token approval may allow another address or contract to spend an asset later. Large or unlimited approvals increase the damage a compromised or malicious application can cause.
Review active permissions periodically using a trusted block explorer or a reputable approval-management tool such as Revoke.cash. Navigate to the service yourself; never rely on a link sent by somebody claiming to help.
Build safer habits
- Keep recovery phrases and private keys offline.
- Treat unsolicited support messages as suspicious.
- Use a separate wallet for unfamiliar applications.
- Verify account names and website domains carefully.
- Start with a small test transaction when trying something new.
- Disconnect unused applications and review old approvals.
- Ask for a second opinion before signing an unfamiliar request.
Security is not about never making a mistake. It is about reducing the number of ways one mistake can become irreversible.