Skip to content

Stay safe from scams

Most losses happen when someone is tricked into revealing a recovery phrase or approving a malicious request. These habits protect you more than any single feature.

  • Nobody from M5wallet will ever ask for your recovery phrase, private key, PIN or passcode: not support staff, not a moderator, not an “admin” in a chat.
  • Never type your recovery phrase into a website. M5wallet only asks for it inside the app, when you import a wallet.
  • Before you connect to a website, check its address carefully. Scam sites copy real ones with small spelling changes.
  • Read every request before you approve it. For request types that are often abused, M5wallet adds a warning:
    • For eth_sign requests: “This type of signature request can sometimes be used for malicious purposes. Only sign it if you fully trust the website.”
    • For permit and order signatures: “Malicious signatures may result in asset loss. Ensure the dApp is trustworthy to avoid asset loss.” You must tick a box before you can sign.
  • Don’t treat the absence of a warning as a guarantee. A website, token or address with no warning is not proof that it is safe.
  • Compare the whole address, not only the first and last few characters. Scammers create lookalike addresses.
  • If a recipient closely resembles an address in your address book but is different, M5wallet warns you: “This address resembles a previously used address but it is different. Verify carefully before sending.”
  • When you send to a new address, send a small test amount first.

Contracts you’ve approved can keep spending a token until you revoke them. Check the list regularly: see Token approvals.

If you think your recovery phrase or private key has been exposed, create a new wallet on a device you trust and move your funds to it straight away. Revoking token approvals doesn’t help once a key is exposed.