The seed phrase rule
Never enter your seed phrase into a website, form, direct message, support chat, or app prompt unless you are intentionally restoring a wallet in software you already trust.
No legitimate support agent needs your seed phrase.
No airdrop needs your seed phrase.
No exchange withdrawal needs your seed phrase.
Watch for fake support
Scammers often impersonate:
- exchange support
- wallet support
- project founders
- moderators
- recovery services
- airdrop teams
Real support will not rush you into revealing private keys, seed phrases, or remote access.
Slow down before signing
Wallet signatures can grant permissions.
Before signing, ask:
- Do I recognize this site?
- Is the URL correct?
- What permission is being requested?
- Is the wallet holding more funds than needed?
- Can I use a smaller separate wallet?
When in doubt, reject the request and verify from official sources.
Be careful with approvals
Token approvals can let a contract spend tokens from your wallet.
Avoid unlimited approvals when possible. Revoke approvals you no longer need, especially after using unfamiliar apps, bridges, or mint pages.
Airdrop and mint traps
Be suspicious of:
- surprise airdrop links
- claim pages sent by direct message
- urgent countdowns
- wallet-draining approvals
- fake verification pages
- impersonated project accounts
If the opportunity disappears because you took ten minutes to verify it, that is usually fine.
Separate wallets by risk
Use different wallets for different jobs:
- cold storage for long-term funds
- daily wallet for normal app use
- burner wallet for new or risky interactions
This keeps one bad approval from touching everything.
The practical takeaway
The safest crypto habit is not paranoia. It is friction.
Pause, verify the URL, use the right wallet, keep the seed phrase offline, and never let urgency make the security decision for you.