Security
Wallet security depends on protecting the recovery phrase, verifying every destination, and understanding every approval before signing.
Protect the recovery phrase
- Keep it offline and private.
- Never share it with support, a dApp, or another person.
- Do not store it in screenshots, cloud notes, email, chats, or the clipboard.
- Enter it only in the official Wavel desktop app when restoring a wallet.
Verify transactions
- Read the full destination address.
- Confirm the exact network and asset identifier.
- Review the amount, fee, memo, and tag.
- Use a small test transfer for a new destination when practical.
- Assume submitted transactions are irreversible.
Limit approvals
Approvals can permit a contract to spend tokens later. Verify the spender, token, amount, network, and expiration. Prefer limited approvals and revoke permissions you no longer use.
Use dApps carefully
- Verify the exact domain before connecting.
- Connect only the intended account and network.
- Reject unexplained signatures and network switches.
- Disconnect inactive sessions and separately revoke on-chain permissions.
If you suspect compromise
- 1Stop interacting with suspicious apps or links.
- 2Disconnect suspicious sessions.
- 3Review and revoke on-chain approvals where possible.
- 4From a trusted environment, create a new wallet with a new recovery phrase.
- 5Move remaining assets after carefully verifying the destination and network.