Assess information security risks and decide how to address them.
Make ownership clear.
Define responsibilities and document the controls that support them.
Keep improving.
Review the system as threats, technology and organizational needs change.
ISO/IEC 27701
Privacy information management.
Our privacy information management system is certified to ISO/IEC 27701. The standard addresses how organizations manage personal information and take responsibility for its processing.
Verify the full address through a trusted source. Confirm the asset, network and any required memo.
02
Read what you authorize.
Check the amount and spender. A transfer, a token allowance and a message signature can give different kinds of authority.
03
Follow the result.
A pending transaction may still complete. A failed one may still use gas. Check the network result before deciding what to do next.
If something changes
Find the issue. Take the right step.
A lost device, an exposed secret and an unwanted approval need different responses. Start with the access that may be affected.
You no longer have the device.
Use your existing recovery plan on a trusted device, then verify the restored accounts. Consider whether someone could access the original device. Recovery depends on having the required backup.
Recovery information was exposed.
Treat the wallet’s authority as compromised. Changing an app password does not invalidate a copied secret. Plan a move to an independently secured wallet; support cannot reverse completed transfers.
A service has too much access.
Identify the network, token and spender. Review and revoke the relevant allowance where supported, allow for the network fee and verify the result.
An app’s name and icon are easy to copy. Open the publisher’s website through a source you already trust, then check where its download link leads. Treat an installer sent in a message as a separate trust decision.
Gatekeeper checks developer identification and whether downloaded software has been altered. Apple’s notarization adds checks for known malicious content. If macOS blocks an app, investigate the warning and the app’s origin before opening it.
Microsoft Defender SmartScreen evaluates the reputation of downloaded apps and files. Read a warning, verify the source and review your protection settings in Windows Security. A familiar filename alone does not establish who supplied the program.
A public address can receive things you never requested. An entry in your history or collection does not establish a trusted relationship with its sender.
An NFT with a claim link.
An unsolicited NFT can carry a website address in its image or description. That site may ask for a secret or a harmful signature under the guise of claiming a reward. Do not follow claim, swap or burn instructions from an unexpected item.
Address poisoning places a lookalike address in transaction history, often through a tiny or zero-value transfer. The first and last characters can resemble a known contact while the middle differs. Get the destination from an independently verified record rather than copying the most recent history entry.