Web3 Safety
Check what you are being asked to sign
Phishing can expose recovery phrases or persuade a user to sign a transfer, approval, or message they did not intend. Review the requested action, not only the website's appearance.
The scammers are good at their job. They create perfect copies of real websites, impersonate project founders on Discord, and engineer urgency ("claim your airdrop in the next 10 minutes or it expires").
Check the domain and contract address against an independently obtained source before signing.
Common attack types
The token approval problem
When you use a DeFi protocol, it asks permission to spend your tokens. This is called a token approval. Legitimate protocols need this to execute swaps, deposits, and withdrawals.
The danger: many approvals are set to "unlimited" by default. This means the contract can spend as many of your tokens as it wants, forever. If that contract gets hacked, or if it was malicious from the start, it can drain your entire balance.
How to protect yourself:
- Set custom approval amounts instead of unlimited (most wallets allow this)
- Regularly check and revoke old approvals at revoke.cash
- Never approve tokens on a site you do not fully trust
The wallet separation strategy
Use at least two wallets:
| Wallet | Purpose | Type | What goes here |
|---|---|---|---|
| Daily wallet | Browsing DeFi, minting NFTs, trying new protocols | Hot (MetaMask) | Small amounts you can afford to lose |
| Savings wallet | Long-term holdings | Cold (Ledger/Trezor) | Main portfolio - never connects to risky sites |
Separate keys and limited balances can reduce the amount exposed to one compromised account. Two addresses derived from the same exposed recovery phrase do not provide that separation.
Red flags checklist
If you see any of these, stop immediately:
- A website URL that is slightly different from the real one (uniiswap.com instead of uniswap.org)
- Anyone asking for your seed phrase, for any reason
- "Send 1 ETH, get 2 ETH back" - this is always a scam
- Urgency pressure ("Claim in the next 5 minutes")
- Unsolicited DMs about airdrops, investment opportunities, or "support"
- A token that appeared in your wallet that you did not buy (airdrop scam - interacting with it can drain your wallet)
- Anonymous team with no public track record
- No audit, no GitHub, no documentation
Key takeaways
- Most losses come from social engineering, not blockchain hacking. Slow down and verify.
- Phishing (fake sites and DMs) is the most common attack. Bookmark real URLs.
- Token approvals are a hidden risk. Use limited approvals and check revoke.cash regularly.
- Use separate wallets: a hot wallet for daily use, a cold wallet for savings.
- Treat unexpected offers and pressure to sign quickly as reasons to stop and check the source.
Further lessons
The other courses cover DeFi applications, contract development, and career preparation in more detail.
Next paths to explore:
- Decentralized Finance - learn how DEXs, lending, and yield strategies work
- Smart Contract Development - learn to write and deploy your own contracts
- Web3 Careers - how to get hired at a Web3 company
Quiz: Web3 Safety
1 / 5Which example describes phishing?