Slow down approval screens

Before approving anything, verify the website domain, connected address, network, asset, amount, contract, and the exact permission being requested. Reject requests that feel unclear or unexpected. A malicious approval can grant a contract ongoing access to your tokens, so read every field.

Treat urgency as a warning

Scams often pressure you to act quickly, paste secret words, claim fake tokens, install unknown profiles, or move assets to a new address to stay safe. Real security fixes never require your recovery phrase. When something feels urgent, that is exactly the moment to slow down and verify.

Recognize common scam patterns

Watch for fake support accounts in comments and direct messages, airdrop sites that ask you to connect and sign, lookalike domains with small spelling changes, and giveaways that promise to double your crypto. If an offer seems too good to be true, it is.

Use separate habits for experiments

When trying unfamiliar dapps, consider using smaller balances, a separate wallet address, and careful permission reviews. Disconnect sessions you no longer need and periodically review token approvals so old permissions cannot be abused later.