Core principles
Apply least exposure, explicit verification and “stop when you cannot explain it” to seed phrases, private keys and offline backup. Security is not a guarantee; it is a process for turning sensitive actions into verifiable decisions.
Understand the boundary of seed phrases
Seed Phrases and Private Keys: Custody Principles is easier to use correctly when seed phrases is treated as a verifiable part of an on-chain workflow rather than a label in the interface. Clarify control of seed phrases and private keys, offline backup practices, screenshot and cloud risks, and why any request for these secrets should be treated as high risk. The key distinction is between what a wallet displays for convenience and what the target blockchain records as state. A balance, network name, contract reference or transaction status should therefore be checked in the context of the network where the action actually occurs.
Looking at seed phrases together with private keys prevents many avoidable mistakes. Similar address formats can appear on different networks, familiar token names can refer to different contracts, and a request can look routine while asking for broader permissions than expected. Before acting on offline backup, confirm the source of the request, the selected network, the destination or contract and the exact action being authorized.
A robust routine keeps enough information to review the action later. Save a transaction hash when relevant, use an appropriate block explorer to check on-chain status, read signature or approval details before confirming and stop when a request cannot be explained. Familiar names, icons or balances are not substitutes for verification, and confirmed on-chain actions are generally not reversible by a wallet on its own.
- Confirm that you are evaluating seed phrases, not a similar-looking concept.
- Tie private keys to the intended network, address or contract.
- Keep at least one verifiable reference before proceeding with offline backup.
How private keys changes the workflow
Seed Phrases and Private Keys: Custody Principles is easier to use correctly when private keys is treated as a verifiable part of an on-chain workflow rather than a label in the interface. Clarify control of seed phrases and private keys, offline backup practices, screenshot and cloud risks, and why any request for these secrets should be treated as high risk. The key distinction is between what a wallet displays for convenience and what the target blockchain records as state. A balance, network name, contract reference or transaction status should therefore be checked in the context of the network where the action actually occurs.
Looking at private keys together with offline backup prevents many avoidable mistakes. Similar address formats can appear on different networks, familiar token names can refer to different contracts, and a request can look routine while asking for broader permissions than expected. Before acting on screenshot risk, confirm the source of the request, the selected network, the destination or contract and the exact action being authorized.
A robust routine keeps enough information to review the action later. Save a transaction hash when relevant, use an appropriate block explorer to check on-chain status, read signature or approval details before confirming and stop when a request cannot be explained. Familiar names, icons or balances are not substitutes for verification, and confirmed on-chain actions are generally not reversible by a wallet on its own.
- Confirm that you are evaluating private keys, not a similar-looking concept.
- Tie offline backup to the intended network, address or contract.
- Keep at least one verifiable reference before proceeding with screenshot risk.
What to verify around offline backup
Seed Phrases and Private Keys: Custody Principles is easier to use correctly when offline backup is treated as a verifiable part of an on-chain workflow rather than a label in the interface. Clarify control of seed phrases and private keys, offline backup practices, screenshot and cloud risks, and why any request for these secrets should be treated as high risk. The key distinction is between what a wallet displays for convenience and what the target blockchain records as state. A balance, network name, contract reference or transaction status should therefore be checked in the context of the network where the action actually occurs.
Looking at offline backup together with screenshot risk prevents many avoidable mistakes. Similar address formats can appear on different networks, familiar token names can refer to different contracts, and a request can look routine while asking for broader permissions than expected. Before acting on cloud risk, confirm the source of the request, the selected network, the destination or contract and the exact action being authorized.
A robust routine keeps enough information to review the action later. Save a transaction hash when relevant, use an appropriate block explorer to check on-chain status, read signature or approval details before confirming and stop when a request cannot be explained. Familiar names, icons or balances are not substitutes for verification, and confirmed on-chain actions are generally not reversible by a wallet on its own.
- Confirm that you are evaluating offline backup, not a similar-looking concept.
- Tie screenshot risk to the intended network, address or contract.
- Keep at least one verifiable reference before proceeding with cloud risk.
How screenshot risk relates to cloud risk
Seed Phrases and Private Keys: Custody Principles is easier to use correctly when screenshot risk is treated as a verifiable part of an on-chain workflow rather than a label in the interface. Clarify control of seed phrases and private keys, offline backup practices, screenshot and cloud risks, and why any request for these secrets should be treated as high risk. The key distinction is between what a wallet displays for convenience and what the target blockchain records as state. A balance, network name, contract reference or transaction status should therefore be checked in the context of the network where the action actually occurs.
Looking at screenshot risk together with cloud risk prevents many avoidable mistakes. Similar address formats can appear on different networks, familiar token names can refer to different contracts, and a request can look routine while asking for broader permissions than expected. Before acting on seed phrases, confirm the source of the request, the selected network, the destination or contract and the exact action being authorized.
A robust routine keeps enough information to review the action later. Save a transaction hash when relevant, use an appropriate block explorer to check on-chain status, read signature or approval details before confirming and stop when a request cannot be explained. Familiar names, icons or balances are not substitutes for verification, and confirmed on-chain actions are generally not reversible by a wallet on its own.
- Confirm that you are evaluating screenshot risk, not a similar-looking concept.
- Tie cloud risk to the intended network, address or contract.
- Keep at least one verifiable reference before proceeding with seed phrases.
Common mistakes and safer habits
Seed Phrases and Private Keys: Custody Principles is easier to use correctly when cloud risk is treated as a verifiable part of an on-chain workflow rather than a label in the interface. Clarify control of seed phrases and private keys, offline backup practices, screenshot and cloud risks, and why any request for these secrets should be treated as high risk. The key distinction is between what a wallet displays for convenience and what the target blockchain records as state. A balance, network name, contract reference or transaction status should therefore be checked in the context of the network where the action actually occurs.
Looking at cloud risk together with seed phrases prevents many avoidable mistakes. Similar address formats can appear on different networks, familiar token names can refer to different contracts, and a request can look routine while asking for broader permissions than expected. Before acting on private keys, confirm the source of the request, the selected network, the destination or contract and the exact action being authorized.
A robust routine keeps enough information to review the action later. Save a transaction hash when relevant, use an appropriate block explorer to check on-chain status, read signature or approval details before confirming and stop when a request cannot be explained. Familiar names, icons or balances are not substitutes for verification, and confirmed on-chain actions are generally not reversible by a wallet on its own.
- Confirm that you are evaluating cloud risk, not a similar-looking concept.
- Tie seed phrases to the intended network, address or contract.
- Keep at least one verifiable reference before proceeding with private keys.
