Updates and device locking
Keeping the operating system, browser and wallet application updated reduces exposure to known vulnerabilities. Use a reliable device lock and automatic locking so brief physical access does not immediately expose the wallet interface. Treating updates and device locking as its own decision point helps prevent rapid click-through mistakes across multiple accounts, networks or DApp steps.
Be cautious with apps and extensions
Unknown browser extensions, installation packages or utility apps can read web content, clipboard data or input. A device used for wallets should minimize unnecessary software and install updates only from trusted sources. The practical goal of be cautious with apps and extensions is to separate on-chain facts from interface presentation; if the two disagree, verify public blockchain state first.
Avoid recovery on public computers
The security state of a public computer cannot be verified and may include key logging, screen capture or malicious extensions. Do not enter seed phrases or private keys or perform high-value signing on such devices. Because blockchain actions can create persistent or irreversible state, understanding avoid recovery on public computers should come before signing, approving or submitting.
Public networks still require domain checks
On public Wi-Fi, do not ignore certificate warnings or unexpected redirects. A working network connection does not make a website trustworthy; DApp domains and request details still require full verification. Reviewing public networks still require domain checks never requires giving anyone a seed phrase or private key; public state can be checked with addresses, transaction hashes and contract information.
Remote control and screen sharing
Wallet unlocking, recovery and signing carry extra risk while another person can control or watch the screen. End remote sessions before handling the wallet and confirm that no unexpected screen-sharing tools are running. Before moving on, make sure the fields related to remote control and screen sharing match the intended task. If an important field cannot be explained, stop and verify the source.
Separate backups from the device
A seed phrase backup should not exist only on the same phone or computer as the wallet, because device loss, damage or malware could affect both the wallet and its backup. Keep reliable recovery material appropriately separated from everyday connected devices. If the interface does not match expectations, record the network, address or transaction hash and troubleshoot separate backups from the device one variable at a time.
Use this list as a final review before you submit a transaction, signature or approval related to this topic.
- Keep the system and wallet app updated
- Minimize unnecessary extensions and software
- Never enter recovery material on public computers
- End remote-control sessions before wallet use
- Keep backups separate from everyday connected devices
Never share a seed phrase, private key or verification code. A wallet provider generally cannot reverse a confirmed on-chain transaction, and third-party DApps or smart contracts can carry independent risk.
