NFT Security Guide
Millions of dollars in NFTs are stolen every month. Even experienced collectors get scammed. This guide could save your entire collection.
Know the Common Scams
Phishing Sites
Fake websites that look identical to OpenSea, Blur, etc. When you connect, they drain your wallet.
- Always type URLs directly or use bookmarks
- Check the URL letter by letter
- Never click links from Discord/Twitter DMs
Malicious Airdrops
Random NFTs appear in your wallet. If you try to sell/interact with them, they drain your wallet.
- Never interact with unexpected NFTs
- Leave them in "Hidden" forever
- Don't try to sell or transfer them
Fake Support
"Support" DMs you about a "problem" with your account and asks you to verify or connect wallet.
- Real support NEVER DMs first
- Real support NEVER needs your seed phrase
- Block and report immediately
Fake Collections
Copies of popular collections with stolen art but different contracts.
- Always check the blue verification badge
- Verify contract address matches official
- If price is too low, it's probably fake
Secure Your NFT Wallet
The Multi-Wallet Strategy:
| Wallet | Use For | Security |
|---|---|---|
| Burner Wallet | New mints, risky sites | Only small amounts |
| Active Wallet | Regular trading on trusted sites | Moderate amounts |
| Vault Wallet | Valuable NFT storage | Never connect anywhere |
Hardware Wallet for NFTs:
- Store valuable NFTs on Ledger/Trezor
- Transactions require physical button press
- Immune to most remote attacks
- Can use with MetaMask for trading
Keep your most valuable NFTs in a wallet that NEVER connects to any website. Only transfer in/out as needed. This eliminates most attack vectors.
Verify Everything
Before Buying - Verify:
- Blue checkmark on OpenSea/marketplace
- Contract address matches official project
- Floor price is reasonable (not suspiciously low)
- Volume/activity looks legitimate
- Official links from project's real Twitter/Discord
Before Connecting - Verify:
- URL is correct (every character)
- HTTPS padlock is present
- Site is official (check on Twitter)
- What permissions are being requested
Before Signing - Verify:
- What transaction does - read the details
- Amount being approved - is it what you expect?
- Contract address - is it the right one?
- If unsure - DON'T SIGN
If you see "SetApprovalForAll" in a transaction, be VERY careful. This gives complete control over an entire NFT collection to the requester. Only approve for trusted marketplaces.
Daily Safe Practices
DO:
- ✓ Bookmark official sites
- ✓ Use a hardware wallet for valuable NFTs
- ✓ Regularly revoke old approvals (revoke.cash)
- ✓ Keep software updated
- ✓ Use strong, unique passwords + 2FA
- ✓ Be paranoid about DMs and links
DON'T:
- ✗ Click links from DMs/emails
- ✗ Connect to unknown sites
- ✗ Rush into "limited time" mints
- ✗ Share screens while wallet is open
- ✗ Use public WiFi for transactions
- ✗ Trust anyone asking for seed phrase
Before signing ANY transaction, pause for 10 seconds and ask:
- Did I initiate this?
- Do I understand what it does?
- Is the site/contract legitimate?
This simple pause has saved many people from scams.
If You're Compromised:
- Don't panic
- Create new wallet immediately
- Transfer remaining assets to new wallet
- Never use compromised wallet again
- Report to marketplace if applicable