Crypto Safety
Verify, don't trust. That is the Polkadot way and the $WUD way. Too many people lose their savings to scams in this space, and almost every loss follows the same few patterns. Here is everything we wish someone had told us on day one. It applies to every website, app and person in crypto, including us.
UpdatedThe one rule that matters most
Your recovery phrase (also called a seed phrase or secret phrase) is the master key to your wallet. Anyone who has it can take everything, from anywhere, at any time, and nobody can reverse it.
- Never type it into a website, a form, a chat or an email. It only ever belongs in your wallet app, or written on paper kept offline.
- Never share it with anyone. Not support, not a team, not a wallet company, not a friend, not someone offering an airdrop or help.
- If anyone asks for it, they are trying to steal from you. There are no exceptions. Real teams, real wallets and real support never need it.
Connecting, signing and approving
Websites can ask your wallet for three very different things. Knowing which is which is most of staying safe.
| Request | What it does | What to check |
|---|---|---|
| Connect | Shares your public address so the site can show balances. It cannot move anything. | That you are on the real address of the site you meant to visit. |
| Sign a message | Proves you own the address, for example to sign in. On Polkadot wallets it is free and cannot move funds. | The text makes sense. On Ethereum wallets, be careful with anything called a permit, which can allow spending. |
| Approve a transaction | Actually does something: sends, swaps, buys, burns or changes a setting. This is the one that can move your funds. | What is being sent, how much, and where to. If it doesn't match what you clicked, reject it. |
| Approve spending (Ethereum) | Lets a contract take your tokens later, often an unlimited amount. This is the favourite trick of wallet drainers. | Only for apps you trust, only the amount you need. Remove old ones at revoke.cash. |
Rejecting a request is always free and always safe. When in doubt, reject and ask in an official community channel.
How wallet drainers work
A drainer can't break into your wallet. It has to get you to open the door yourself. The usual ways in:
- Lookalike websites with one letter changed, or a different ending, found through ads, search results or links in replies.
- Fake airdrops and giveaways that ask you to connect and "claim", then present a transaction that sends your tokens away.
- Fake support that messages you first after you ask a question in public, then asks you to "verify", "sync" or "validate" your wallet.
- Fake apps and extensions copied from real wallets, uploaded to app stores or promoted in ads.
- Hacked accounts and sites, where a real project's social account or website is taken over and starts posting a trap.
Every one of these ends the same way: you approve something you didn't read, or you type your recovery phrase where it doesn't belong. Read every request, and keep the phrase offline, and almost all of them fail.
Check links with VirusTotal
Before opening a link you weren't expecting, or connecting to a site for the first time, you can check it for free at virustotal.com. It asks dozens of security companies whether they know the address as dangerous.
- Copy the link. Don't open it yet.
- Go to virustotal.com, choose URL, paste the link and press search.
- Look at the result. Any red flags mean don't open it. Click Reanalyze to get a fresh check if the result is old.
Here is what a live report looks like, for this website: gavunwud.com on VirusTotal. Click Reanalyze and you get a fresh result from every vendor, whenever you like.
A clean result helps, but it is not a guarantee. Brand-new scam sites often show clean for the first hours or days. Use it as one check among several, and make it a habit for any site you connect a wallet to.
Your checklist before you approve anything
- Is the address exactly right? Use a bookmark for sites you use with your wallet instead of links from messages or ads.
- Did you start this action yourself? If a request appears that you didn't expect, reject it.
- Does the wallet show what you meant to do? Same token, same amount, same destination.
- Is anyone rushing you? "Only 10 minutes left" and "your wallet will be locked" are pressure tactics. Real projects let you take your time.
- Is anyone asking for your recovery phrase? Stop. That is a scam, every time.
Set yourself up safely
- Use two wallets. A spending wallet with a small balance for websites, games and new apps, and a savings wallet that never connects anywhere.
- Consider a hardware wallet. A Ledger keeps your keys on the device and shows each transaction on its own screen, so a bad website can't sign anything without you seeing it. You can use one on Polkadot through Talisman, SubWallet, Nova Wallet or Polkadot.js.
- Download wallets only from their official sites or app stores. Check the publisher name before installing.
- Protect your email and exchange accounts with an authenticator app or a security key, not text messages.
If something goes wrong
- If your recovery phrase was exposed: create a brand-new wallet with a new phrase right away and move everything that is left into it. The old wallet can never be trusted again.
- If you approved spending on Ethereum: remove the approval at revoke.cash as soon as you can.
- Beware of "recovery" services. People who promise to get stolen crypto back for a fee are almost always running a second scam.
- Tell the community. Reporting a scam link or a fake account quickly protects the next person.
How gavunwud.com works
We hold ourselves to the same rules. gavunwud.com never asks for your recovery phrase or keys, and never asks for open-ended permission to spend your tokens. Message signatures are only used to prove you own an address. Transactions only happen when you choose an action, and your wallet shows each one before you approve it. The live site is checked automatically around the clock, and if anything ever changes that we didn't publish, a warning goes out in our official channels. Even so, don't take our word for it: verify. The details are in our terms.
Our official links are gavunwud.com, x.com/gavunwud, t.me/gavunwud and our Discord. If something claims to be us and isn't on that list, treat it as fake.
Questions people ask
Is it safe to connect my wallet to a website?
Connecting only shares your public address, so on its own it can't move your funds. The risk comes afterwards, if you approve a transaction or spending permission you didn't read. Connect only to sites you trust, check the address, and read every request before approving it.
Can someone steal my crypto with just my address?
No. Your address is public by design, like an account number. To move your funds, someone needs your recovery phrase or private key, or needs you to approve a transaction yourself.
What should I do if I shared my recovery phrase?
Act immediately. Create a new wallet with a new recovery phrase and move everything that is left into it. Treat the old wallet as compromised forever, and don't pay anyone who offers to recover stolen funds.
Does a clean VirusTotal result mean a site is safe?
It means none of the security companies it asks have flagged the address yet. That is useful, but new scam sites can look clean at first. Combine it with checking the address, reading every wallet request and never sharing your recovery phrase.