You hold the signing credentials and the recovery responsibility.
Wallets, SafePal & Wallet Security
Learn wallet basics, addresses, seed phrases, private keys, SafePal navigation and the security habits that protect your crypto.
Safe action or warning sign?
Make the decision before revealing the explanation.
A Telegram support agent asks for your recovery phrase to resynchronise SafePal.
Which wallet is built for which job?
Compare custody, signing, KYC and practical use before choosing a wallet or exchange account.
A company controls the wallets and authorises your withdrawals.
You can monitor an address, but you cannot sign or spend.
SafePal App
Everyday multichain use, Web3 access and managing a SafePal hardware wallet.
- Custody
- Self-custody
- Who controls the keys?
- You control the recovery phrase and signing keys.
- Network fit
- Bitcoin, Ethereum, BNB Chain, TRON, Solana and many more
Remember: Third-party buy, sell or swap providers inside an app may apply their own KYC rules.
MetaMask
EVM networks, browser DApps, token approvals and contract interactions.
- Custody
- Self-custody
- Who controls the keys?
- You control the wallet credentials; setup can use a recovery phrase or supported social login.
- Network fit
- Ethereum and EVM-compatible networks
Remember: A MetaMask wallet is not the same as an on-ramp partner. A partner may still require identity checks.
Trust Wallet
Mobile-first multichain asset management and DApp access.
- Custody
- Self-custody
- Who controls the keys?
- You control the recovery credentials; no personal sign-up is needed for the wallet itself.
- Network fit
- Bitcoin, EVM chains, TRON, Solana and many more
Remember: Never share the recovery phrase with support or enter it into an unexpected website.
Rabby Wallet
EVM power users who want transaction simulation and clearer signing warnings.
- Custody
- Self-custody
- Who controls the keys?
- You control the keys or connect an external hardware signer.
- Network fit
- Ethereum and EVM-compatible networks
Remember: Simulation helps, but it cannot make an unsafe approval safe. Verify the DApp and permission.
Phantom
Solana-focused activity, NFTs, tokens and supported multichain use.
- Custody
- Self-custody
- Who controls the keys?
- You control the wallet credentials and transaction signing.
- Network fit
- Solana and selected additional networks
Remember: Confirm which network is active before copying an address or approving a transaction.
SafePal S1 / X1
Keeping signing keys away from an internet-connected phone or computer.
- Custody
- Self-custody
- Who controls the keys?
- The hardware device protects and uses your keys to sign.
- Network fit
- Used with the SafePal ecosystem across supported networks
Remember: Buy from an authorised source, initialise it yourself and never use a recovery phrase supplied by a seller.
Ledger
Cold-key protection for long-term holdings and higher-value signing.
- Custody
- Self-custody
- Who controls the keys?
- The device is the signer; you remain responsible for the recovery phrase.
- Network fit
- Bitcoin, Ethereum, EVM chains and many other supported networks
Remember: Optional purchase or third-party services may collect information even though wallet setup itself does not require KYC.
Trezor
Offline key protection and deliberate confirmation of outgoing transactions.
- Custody
- Self-custody
- Who controls the keys?
- The device signs; the user protects the backup and PIN.
- Network fit
- Bitcoin, Ethereum and other supported networks
Remember: A hardware wallet reduces online key exposure, but it cannot protect you from approving a malicious transaction.
Safe{Wallet}
Teams, treasuries and families that need multiple approvals before funds move.
- Custody
- Self-custody
- Who controls the keys?
- A smart contract enforces signer and approval rules chosen by the owners.
- Network fit
- Ethereum and supported EVM-compatible networks
Remember: A poor signer threshold or compromised owners can still create risk. Test the recovery and approval process.
Coinbase account
Buying, selling and holding assets through a regulated centralised exchange account.
- Custody
- Custodial
- Who controls the keys?
- Coinbase controls the platform wallets; you access an account and request withdrawals.
- Network fit
- Supported deposit and withdrawal networks vary by asset
Remember: Coinbase Wallet is a separate self-custody product. Do not confuse it with a custodial Coinbase exchange account.
Kraken account
Fiat on-ramp, trading and exchange-based custody.
- Custody
- Custodial
- Who controls the keys?
- Kraken controls the platform wallets and withdrawal infrastructure.
- Network fit
- Supported deposit and withdrawal networks vary by asset
Remember: Verification requirements and available services depend on your location and account level.
Binance account
Exchange trading, fiat services and custodial asset management where available.
- Custody
- Custodial
- Who controls the keys?
- Binance controls the platform wallets; the user controls account access, not the private keys.
- Network fit
- Many supported deposit and withdrawal networks
Remember: Identity requirements and service availability are jurisdiction-dependent; verify the current rules in your region.
Watch-only wallet
Monitoring a public address without placing spending keys on the device.
- Custody
- No signing authority
- Who controls the keys?
- No private key is imported, so the view cannot sign or spend.
- Network fit
- Any supported public blockchain address
Remember: A watch-only balance is not proof that you control the funds. Control requires the corresponding signing key.
Public blockchain activity can be traced. A self-custody wallet may need no identity check to create, while a separate bank-card purchase, cash-out, exchange or regulated partner can still require KYC.
Wallet types, custody and KYC
Wallets serve different jobs, and the key differences are who signs, who can recover access and whether an account provider must verify your identity.
With a custodial service, a company generally manages the private keys and gives you access through an account. With a non-custodial wallet, the user controls the wallet credentials and carries much more direct responsibility for backup and security.
Software wallets are convenient for everyday use and DApps. Hardware wallets isolate signing keys from an internet-connected device. Smart-account or multisig wallets can require several people or devices to approve an action. Watch-only wallets monitor an address without holding its spending key.
Creating a self-custody wallet generally does not require KYC because no company account is needed to generate the keys. A regulated exchange or fiat on-ramp may still require identity verification before it lets you buy, sell, deposit or withdraw. That separate KYC requirement does not turn the self-custody wallet into a custodial wallet.
Non-custodial control can increase independence, but it also removes many familiar account-recovery safety nets. Losing the recovery phrase or exposing the private key can have permanent consequences. A wallet application is an interface; your blockchain accounts and signing keys are the important underlying elements.
Understanding wallet type and custody tells you who can authorise transactions, whether support can restore access, and where KYC may enter the process.
Use the wallet explorer above to compare one software wallet, one hardware wallet and one custodial exchange. For each, identify who controls the signing key and what would happen if you lost access.
- Wallet type describes how keys and signing are handled.
- Self-custody wallet creation and a regulated on-ramp are separate services.
- Greater control also means greater security responsibility.
Wallet addresses
A public wallet address is used to receive assets, but the correct network still matters.
An EVM-style address usually begins with 0x. The same address can often be used across multiple EVM-compatible networks because it is derived from the same key, but the assets and transaction history on those networks remain separate.
A public address is designed to be shared when someone needs to send you assets. It does not give them permission to spend from your wallet.
Always verify copied addresses carefully. Malware and clipboard-replacement scams can substitute an attacker's address after you copy one.
Sending to the wrong address is usually irreversible, so address checking should become automatic behaviour.
Retrieve the destination from the recipient's verified source or a saved SafePal address-book entry, then compare the complete address. Never copy an important destination directly from recent transaction history.
- Public addresses can be shared.
- An address does not identify the network by itself.
- Never reuse a destination from recent history without independent verification.
Seed phrases and private keys
Recovery phrases and private keys are secrets that can give control over your wallet.
A recovery phrase is commonly used to restore wallet keys. Anyone who obtains it may be able to recreate the wallet and move assets without needing your phone, fingerprint or wallet-app password.
A local wallet password protects access to the app on a device; it is not a replacement for the recovery phrase. Resetting or reinstalling the app may still require the recovery phrase to restore access.
SafePal explicitly states that its support staff will never ask users for seed phrases, private keys or wallet passwords. Treat any person or website requesting them as a serious security threat.
Many crypto thefts do not involve breaking blockchain cryptography. Attackers simply convince users to reveal the credentials voluntarily.
Never type a recovery phrase into a website, form, chat message or support conversation. Only use it in a trusted wallet-recovery process that you intentionally initiated.
- Recovery phrases are wallet-control secrets.
- Legitimate support does not need them.
- Device passwords and recovery phrases serve different purposes.
SafePal orientation
SafePal provides wallet interfaces for managing assets and interacting with Web3, but users still need to verify what they connect to and sign.
A wallet interface can display assets, switch networks, connect to decentralised applications and request transaction signatures. Those conveniences do not remove the need to inspect the network, destination and contract interaction.
Use official SafePal distribution channels and official support resources. Be especially cautious of unsolicited messages, QR codes, redirected links and people claiming they need wallet credentials to provide support.
A wallet connection is not automatically the same as transferring funds, but connected applications may later request signatures or token approvals. Read each request rather than assuming a previously trusted connection makes every action safe.
Most wallet mistakes happen at the human-interface layer, not because the underlying blockchain forgot how to verify a signature.
- Use official wallet software and support channels.
- Inspect every signature or approval request.
- A connected DApp should not receive blind trust.
Adding networks and tokens
A wallet may need a network or token to be added manually before it appears in the interface.
If a token is visible on a blockchain explorer but not in the wallet, first confirm that the wallet is viewing the correct network. Then verify the official token contract before importing the token manually.
Do not search social media for a random contract address. Prefer the token issuer's official documentation, the application's official documentation or another authoritative source that can be independently cross-checked.
On BNB Smart Chain, BscScan can help confirm a transaction and identify the token contract involved. Later modules will teach that verification process step by step.
Manually adding the wrong contract can make a fake token look legitimate inside a wallet interface.
If a token is missing: check transaction hash โ confirm network โ confirm token contract โ then add the verified token to the wallet if needed.
- Missing display does not prove missing funds.
- Verify the contract before importing a token.
- Use a blockchain explorer to confirm what happened on-chain.
Random tokens, dusting and wallet phishing
Scammers can send tokens, NFTs or tiny transactions to any public address, then use curiosity, urgency or look-alike information to lure the recipient into a dangerous action.
A public blockchain address can receive assets from strangers without asking permission. An unknown token, NFT or tiny dust transaction appearing in a wallet does not by itself reveal your private key or give the sender control of your funds. Do not panic, but do not assume the item has value or is safe to use.
Scam airdrops often include a website in the token name, NFT image, metadata or failed-transaction message. The site may ask for a recovery phrase, request a dangerous token approval, or present a misleading signature that lets a scammer move assets. Do not follow instructions embedded in an unsolicited asset and do not attempt to swap, claim, burn or return it through an unknown contract.
Dusting can refer to tiny transfers used to study or link wallet activity. A related address-poisoning scam sends a tiny or zero-value transaction from a look-alike address so that it appears in transaction history. The attacker hopes you later copy that address instead of the real destination. Retrieve important addresses from a trusted source or verified address book and compare more than only the first and last characters.
Phishing can arrive through fake wallet extensions, cloned websites, sponsored search results, QR codes, emails, social-media messages, fake support agents and compromised community accounts. A scammer does not always ask for the recovery phrase; a malicious on-chain transaction, token approval, permit or off-chain signature may be enough to steal assets.
The safest response to an unsolicited asset is normally to ignore or hide it using the wallet's built-in controls. Viewing public transaction information in a reputable explorer is generally different from connecting a wallet or signing. If you already signed something suspicious, disconnecting the site alone may not cancel permissions; review and revoke approvals through a trusted tool and move assets if key material was exposed.
Modern wallet scams frequently use harmless-looking on-chain clutter as the first step in a social-engineering or approval attack.
When an unknown asset appears, classify it without interacting: verify the network and contract in a reputable explorer, note whether it contains a URL or reward claim, and practise choosing Ignore/Hide rather than Swap/Claim. Never test it with your primary wallet.
Do not visit URLs embedded in random tokens or NFTs, do not copy destination addresses from unexplained dust transactions, and never sign a request merely to remove or unlock an unsolicited asset.
- Receiving an unknown asset does not by itself compromise the wallet.
- Interaction, phishing and malicious signatures create the real danger.
- Dust and look-alike history entries can support privacy analysis or address poisoning.
- Ignore or hide unsolicited assets and verify destinations independently.
Critical wallet security rules
Strong wallet security is mostly a set of repeatable habits.
Never share seed phrases or private keys. Do not trust unsolicited support. Verify website domains before connecting a wallet. Be suspicious of unexpected tokens, NFTs, QR codes and urgent messages designed to make you act before thinking.
Keep wallet software and devices updated through official channels. Use device security such as a strong screen lock and avoid installing unknown remote-access or screen-sharing software at the request of a stranger.
If you believe a recovery phrase or private key has been exposed, assume the wallet may be compromised. SafePal's current security guidance recommends creating a new trusted wallet and moving remaining assets when a seed phrase or private key has been disclosed.
Security improves dramatically when safe behaviour becomes routine rather than something you remember only after a suspicious message arrives.
No legitimate Stable Circle, SafePal or Academy support process should ever require your recovery phrase or private key.
- Secrets stay secret.
- Verify links and identities independently.
- Treat urgency as a warning sign.
- If key material is exposed, act as though the wallet is compromised.
Verify the learning material
The Academy uses authoritative primary sources wherever practical and converts them into beginner-friendly explanations.
- SafePal โ Self-custody security and no wallet KYC โ
- Trust Wallet โ Self-custody security โ
- MetaMask โ Creating a self-custody wallet โ
- MetaMask โ NFT and token airdrop scams โ
- MetaMask โ Failed-transaction token scams โ
- MetaMask โ Address-poisoning scams โ
- MetaMask โ Understanding malicious token approvals โ
- Ledger Academy โ Custodial vs non-custodial wallets โ
- Coinbase โ Identity verification โ
- Kraken โ Verification levels โ
- Safe โ Smart-account and multisig wallets โ
- SafePal โ Security update and anti-phishing guidance โ
- SafePal โ Revoke a token with Approval Manager โ
- BNB Chain Docs โ Tokens not showing in wallet โ