Wallet passphrase & private keys : NEVER share it with anyone

Chris Newman

BANNED
Joined
Oct 13, 2018
Messages
6,868
Reaction score
6,032
Never ever share your Secret Recovery Phrase (passphrase) or private keys of your crypto wallet with anyone. Sharing your Secret Recovery Phrase or private keys with someone would be like handing over the pin code to your bank card or the keys to your house. It would give that person the ability to access and transfer all of your funds.
Do not share your passphrase, private keys, even with any official support person of your crypto wallet, they would never need it for anything ever.
Before posting this, I searched in topics in this cryptocurrency section to ensure that my post (thread) is not a repeat.
And I am posting this because now more and more people are learning about crypto and using crypto wallets to store crypto and everyone must store their funds safely.
 
Last edited:
Cryptocurrency holders beware. There's a nasty malware bug crawling around that jeopardizes your cryptocurrency transactions by spying on your clipboard (the temporary storage that hosts your copy-and-paste data).
This malware will accessed the clipboard and switch a crypto's sending address with the hacker's own address.
And for those who use Trust Wallet, please enable "transaction signing". If you use trust wallet please go to your security settings and creat a “passcode” Once you do this you should have a new option under security settings to activate “Transaction Signing”. This is a security measure that requires you to enter your passcode before any transaction is made. It is a good additional safety measure.
More and more people are now embracing and using cryptocurrencies, so please always stay safe.
 
There was a site which collected wallet code. It just had a paste button to paste that code so that people can check their portfolio. A guy fell for it and lost $20000.
 
If you use trust wallet please go to your security settings and creat a “passcode” Once you do this you should have a new option under security settings to activate “Transaction Signing”. This is a security measure that requires you to enter your passcode before any transaction is made. It is a good additional safety measure.
This is completely useless if a scammer knows your passphrase.
The coins/tokens are saved on the blockchain, so if someone else knows your passphrase and imports your wallet into his wallet app, they will be able to transfer everything without you signing or noticing.
It's only useful to prevent thefts from someone who actually has your phone in his hands.
 
@R4v3nbl4ck The transaction signing is useful in case of the copy/paste malware only, as a user who is cautious, will be self consciously reminded to recheck the sending address. Incase of someone knowing pass phrase, this transaction signing security feature would not be helpful.
 
The transaction signing is useful in case of the copy/paste malware only, as a user who is cautious, will be self consciously reminded to recheck the sending address. Incase of someone knowing pass phrase, this transaction signing security feature would not be helpful.
Yes, or if you physically give your phone to someone and they try to steal your crypto.
 
Sharing your Secret Recovery Phrase or private keys with someone would be like handing over the pin code to your bank card or the keys to your house.
But but but, some people leave their key under the matt
 
Yes, or if you physically give your phone to someone and they try to steal your crypto.
That may be possible, especially if the phone is not well locked. There can be many scenarios : Read in the news that a person was mugged, the muggers took his phone, phone was locked and they then pointed a gun on his head and got him to unlock the phone. Muggers saw some crypto wallet (installed) on the phone and made him to login to the crypto wallet, and under gunpoint, made him to transfer all his crypto to the muggers (Real news story). So, crypto or any other assets in the world, are always prone to theft and the scammers or thieves are getting more advanced. But, some awareness and precautions in most (may be not all) cases, often saves people from getting scammed.
 
There was a site which collected wallet code. It just had a paste button to paste that code so that people can check their portfolio. A guy fell for it and lost $20000.
Crypto is still at it's nascency stage, but more and more people are starting to use crypto & some of them are not fully aware on taking precautions.
The scenario you've mentioned also happens, because some people are unaware that for linking crypto exchange to another website (such as a trading website), APIs are required and not pass phrases or private keys. And API access settings must NOT provide access to transfer or withdraw any funds (ONLY AND ONLY one exception is when giving API access to a very trusted & personally known trader).
 
Sometimes some websites are set up to resemble the original companies. If you do not see a small lock icon indicating security near the URL bar and no "https" in the site address think twice, please.

Such fake websites often do look identical to the one you think you're visiting, and you may find yourself directed to another platform for payment. For example, you click on a link that looks like a legitimate site, but attackers have created a fake URL with a zero in it instead of a letter ‘o’. That platform, of course, isn't taking you to the cryptocurrency investment that you've already researched. To avoid this, carefully type the exact URL into your browser and after landing on the website, once again check the URL bar of your browser to ensure you are at the legitimate website.
 
There are websites and platforms that claim they are doing crypto trading and they offer sometimes 2% to 5% daily returns, etc. Most (in my opinion all) such websites / platforms are ponzi scheme scams, which finally disappear with people's money. We often read the same in the news as well.
When it comes to crypto or infact any investments, always do your own research and stay safe always.
 
I like what this thread author has mentioned.
Please do not mind me saying 1 real my life thing. I was security guard for total 8 years of my life and how we are guarding our house, like that we must guard our assets also. Security is security.
So, I will like to add 1 more security related thing. If you are using Telegram and you receive any message from person you do not know, person you did not invite, then just DO NOT reply and delete that message, it can be scammer trying to do a scam with you.
 
Have you guys seen some of the ads on Facebook for "Trust Wallet" that advertises +input your 12 word seed phrase to receive Shib inu+? idk know how those ads get there...oh wait, its because most dont understand how crypto really works
 
Have you guys seen some of the ads on Facebook for "Trust Wallet" that advertises +input your 12 word seed phrase to receive Shib inu+? idk know how those ads get there...oh wait, its because most dont understand how crypto really works
That type of ads is happening by bad (scammer) people using cloaker & other techniques. If a person is knowing how crypto is working, that person will not enter pass phrase, will not enter private key.
Persons who using crypto, but do not know how crypto works only will do mistake of providing pass phrase, private keys.
I am not person highly educated. But I gain knowledge because I doing plenty reading and research.
 
That type of ads is happening by bad (scammer) people using cloaker & other techniques. If a person is knowing how crypto is working, that person will not enter pass phrase, will not enter private key.
Persons who using crypto, but do not know how crypto works only will do mistake of providing pass phrase, private keys.

thats correct. theres more than too many scam ads on social media platforms to be comfortable with. this is why theres KYC and all of that jazz which kinda defeats the purpose of encryption and anonymous transactions
 
Back
Top