The four rules for a mobile wallet
Mobile wallets fail in predictable ways. These four habits prevent nearly all of
it, and none of them takes more than a minute.
Install only from a link on the maker's own website. Fake wallet
apps appear on both stores regularly, and paid search results for "Trust Wallet
download" have been used to distribute them. Go to trustwallet.com, follow their
link to the store listing. It is one extra step and it removes an entire class
of loss.
Write the recovery phrase on paper before you fund it. Not a
screenshot — screenshots go to iCloud or Google Photos, and those accounts get
compromised. Not a password manager, for the same reason at one remove. A pen
and the back of an envelope beats every digital option.
Treat every "connect wallet" prompt as a decision. The most
common drain mechanism is not a stolen key, it is an approval you granted to a
contract you did not read. Revoke old approvals periodically, and if an app you
do not remember has spending permission over a token, remove it.
Keep the balance proportionate. A phone wallet is a wallet in
the literal sense — the amount of cash you carry, not the amount in your savings
account. When the number gets uncomfortable, that is the signal to buy a
hardware wallet.
▲ Nobody legitimate ever asks for your phrase
Not support, not a "wallet validation" page, not a migration notice, not a
Discord moderator, not an airdrop claim form. There is no circumstance in
which a genuine service needs your twelve or twenty-four words. If something
is asking, it is stealing. Full detail in the
scams and drains guide.