Practices

Protecting yourself from scams

The attacks that actually work against wallet users, and the small number of rules that stop all of them.

3 min readUpdated 16 Aug 2026
On this page

The cryptography is not what fails. People are persuaded, and the persuasion is better than most people expect.

The four rules

  1. 01

    Never type your recovery phrase anywhere but the import screen

    Not into a website, not into a “wallet validator”, not into a support chat, not into a form that says it will restore your funds. There is no legitimate reason for any of those to exist.

  2. 02

    Never sign something you cannot read

    If a prompt does not clearly say what it does, decline. Approving is the moment a drain happens.

  3. 03

    Assume anyone who contacts you first is an attacker

    We will never message you first. Nor will any legitimate support team.

  4. 04

    Slow down when you are being hurried

    Urgency is the tell. Every scam has a deadline; no legitimate process does.

The attacks you will actually see

Fake support. You post a problem publicly and receive helpful replies within minutes. They direct you to a "verification portal" or a support form. It asks for your phrase.

The wallet drainer. A site — often reached through an airdropped NFT or an ad — asks you to connect and sign to "claim", "verify" or "unlock". The signature transfers your assets.

The address swap. Malware or a compromised account substitutes an address in a message or clipboard. The funds go to the attacker. Always verify addresses out of band.

The fake app. A convincing clone in a search result or a sideloaded build, which uploads your phrase the moment you enter it. Install only from the official listings.

The fake heir. Someone claims to be, or to represent, an heir and asks you to change your inheritance settings or share vault contents. Verify with the actual person, by a channel you already trust.

The recovery service. "We can recover lost crypto." They cannot. They take a fee, or your phrase, or both.

There is no recovery service, ever

Nobody can recover a lost recovery phrase — not us, not a specialist, not a hacker-for-hire. Every offer to do so is a second theft aimed at someone already desperate.

Specific to inheritance

Nobody legitimate asks you to "prove" you are alive outside the app. Your heartbeat is an in-app action. A link asking you to confirm liveness is phishing.

A claim notification you did not expect is worth checking calmly. Open the app yourself — do not follow a link in a message. The chain will tell you the truth.

Your heir does not need your recovery phrase, ever. The whole design exists so that they do not. Anyone arguing otherwise, including someone who really is your heir, is proposing something the system is built to make unnecessary.

If you think you have been compromised

  1. 01

    Move what you can, immediately

    If your phrase may be exposed, transfer everything to a wallet created on a clean device. Speed matters more than tidiness.

  2. 02

    Revoke token allowances

    Connection lists are not allowances. Use a Solana token-approval revocation tool to withdraw any allowances you granted.

  3. 03

    Reconfigure inheritance on the new wallet

    Set up the Switch afresh and have your heir accept at the new address.

  4. 04

    Assume the old wallet is permanently unsafe

    Do not reuse it, and do not send anything back to it later.

Keep reading

Still stuck?

Tell us what you were doing and what you expected — never your recovery phrase, private key, or a vault passphrase. Nobody from Legacy Wallet will ever ask for those.

Opens a support ticket and emails you the link. We reply by email, usually within a couple of days.