Home / Learn / Wallet & funds security

Wallet and funds security: seven ground rules

Crypto is rarely stolen by breaking a wallet’s cryptography. It is stolen through leaked seed phrases, approval phishing, counterfeit wallet apps and clipboard malware. These seven rules block almost all of it.

The seven rules

#RuleWhat to do
1Deposit addresses stay out of mobile walletsOur deposit addresses are generated offline and their keys never touch a server. To check a balance, paste the address into a block explorer: bscscan.com for BSC, tronscan.org for TRON, solscan.io for Solana.
2Your seed phrase is the whole balanceNever screenshot it, never sync it to a cloud drive, never send it to anyone, never type it into a web page or app. Write it on paper and store it offline, or keep it in a hardware wallet.
3Install wallets only from the official site or app storeSearch-ad placements, group-chat files and installers sent by strangers are a common source of counterfeit builds. After installing, verify the official package name.
4Do not sign or approve blindlyApproval phishing is the most common way funds are drained. Only interact with dApps you trust, and periodically revoke approvals you no longer use.
5Verify the address before you sendAfter pasting, check the first and last four to six characters. For large amounts, send a small test transfer first.
6Split your holdingsKeep only spending money in a mobile wallet. Store larger balances in a hardware or cold wallet rather than behind one address.
7We never ask for secretsAt no point in any flow do we ask for your seed phrase, private key or SMS/email verification code. Anything that does is a scam.

Stop immediately if you see this

Someone messaging you in a group or DM claiming to be “support” and asking to see your wallet or seed phrase; a link promising an upgrade, airdrop or unfreeze that asks you to connect a wallet and sign; a request to move funds to a “safe address” to verify something. Those three scripts cover almost every incident.

Our only support channel is the Telegram account listed in the site footer and documentation. Any other account is not us.

Frequently asked

Do I need to import the deposit address into a mobile wallet?

No. It is generated offline, its key is not on any server, and it is only used to receive. Any block explorer will show the balance.

Will the platform ever ask for my seed phrase or private key?

Never. Not at any step, and not for any reason — nor for SMS or email codes.

What if a wallet is compromised?

Move the remaining funds to a brand-new address with a freshly generated offline seed phrase, revoke approvals granted by the old address, and check your devices for malware or remote access tools.