Hashtag Web3 Logo

Web3 Safety

9 min
beginner

Check what you are being asked to sign

Phishing can expose recovery phrases or persuade a user to sign a transfer, approval, or message they did not intend. Review the requested action, not only the website's appearance.

The scammers are good at their job. They create perfect copies of real websites, impersonate project founders on Discord, and engineer urgency ("claim your airdrop in the next 10 minutes or it expires").

Check the domain and contract address against an independently obtained source before signing.

Common attack types

Phishing Fake websites and DMs that trick you into signing malicious transactions Most common attack Rug Pull Developer launches a project, attracts deposits, then drains all the funds Check for audits + lock-ups Bad Approvals Approving a contract to spend unlimited tokens, which it later drains Use revoke.cash regularly Defense checklist ✓ Bookmark real sites - ✓ Never click DM links - ✓ Verify contract addresses ✓ Use hardware wallet for savings - ✓ Separate wallets for daily/savings - ✓ Revoke old approvals ✓ Start with small amounts - ✓ Read what you sign - ✓ If it sounds too good, it is

The token approval problem

When you use a DeFi protocol, it asks permission to spend your tokens. This is called a token approval. Legitimate protocols need this to execute swaps, deposits, and withdrawals.

The danger: many approvals are set to "unlimited" by default. This means the contract can spend as many of your tokens as it wants, forever. If that contract gets hacked, or if it was malicious from the start, it can drain your entire balance.

How to protect yourself:

  1. Set custom approval amounts instead of unlimited (most wallets allow this)
  2. Regularly check and revoke old approvals at revoke.cash
  3. Never approve tokens on a site you do not fully trust

The wallet separation strategy

Use at least two wallets:

Wallet Purpose Type What goes here
Daily wallet Browsing DeFi, minting NFTs, trying new protocols Hot (MetaMask) Small amounts you can afford to lose
Savings wallet Long-term holdings Cold (Ledger/Trezor) Main portfolio - never connects to risky sites

Separate keys and limited balances can reduce the amount exposed to one compromised account. Two addresses derived from the same exposed recovery phrase do not provide that separation.

Red flags checklist

If you see any of these, stop immediately:

  • A website URL that is slightly different from the real one (uniiswap.com instead of uniswap.org)
  • Anyone asking for your seed phrase, for any reason
  • "Send 1 ETH, get 2 ETH back" - this is always a scam
  • Urgency pressure ("Claim in the next 5 minutes")
  • Unsolicited DMs about airdrops, investment opportunities, or "support"
  • A token that appeared in your wallet that you did not buy (airdrop scam - interacting with it can drain your wallet)
  • Anonymous team with no public track record
  • No audit, no GitHub, no documentation

Key takeaways

  • Most losses come from social engineering, not blockchain hacking. Slow down and verify.
  • Phishing (fake sites and DMs) is the most common attack. Bookmark real URLs.
  • Token approvals are a hidden risk. Use limited approvals and check revoke.cash regularly.
  • Use separate wallets: a hot wallet for daily use, a cold wallet for savings.
  • Treat unexpected offers and pressure to sign quickly as reasons to stop and check the source.

Further lessons

The other courses cover DeFi applications, contract development, and career preparation in more detail.

Next paths to explore:

  • Decentralized Finance - learn how DEXs, lending, and yield strategies work
  • Smart Contract Development - learn to write and deploy your own contracts
  • Web3 Careers - how to get hired at a Web3 company

Quiz: Web3 Safety

1 / 5

Which example describes phishing?