Stay safe from scams
Most losses happen when someone is tricked into revealing a recovery phrase or approving a malicious request. These habits protect you more than any single feature.
Never share your secrets
Section titled “Never share your secrets”- Nobody from M5wallet will ever ask for your recovery phrase, private key, PIN or passcode: not support staff, not a moderator, not an “admin” in a chat.
- Never type your recovery phrase into a website. M5wallet only asks for it inside the app, when you import a wallet.
Check what you connect to and sign
Section titled “Check what you connect to and sign”- Before you connect to a website, check its address carefully. Scam sites copy real ones with small spelling changes.
- Read every request before you approve it. For request types that are often abused, M5wallet adds a warning:
- For
eth_signrequests: “This type of signature request can sometimes be used for malicious purposes. Only sign it if you fully trust the website.” - For permit and order signatures: “Malicious signatures may result in asset loss. Ensure the dApp is trustworthy to avoid asset loss.” You must tick a box before you can sign.
- For
- Don’t treat the absence of a warning as a guarantee. A website, token or address with no warning is not proof that it is safe.
Double-check recipients
Section titled “Double-check recipients”- Compare the whole address, not only the first and last few characters. Scammers create lookalike addresses.
- If a recipient closely resembles an address in your address book but is different, M5wallet warns you: “This address resembles a previously used address but it is different. Verify carefully before sending.”
- When you send to a new address, send a small test amount first.
Review token approvals
Section titled “Review token approvals”Contracts you’ve approved can keep spending a token until you revoke them. Check the list regularly: see Token approvals.
If something looks wrong
Section titled “If something looks wrong”If you think your recovery phrase or private key has been exposed, create a new wallet on a device you trust and move your funds to it straight away. Revoking token approvals doesn’t help once a key is exposed.