Module 03 โ€ข Essential

Wallets, SafePal & Wallet Security

Learn wallet basics, addresses, seed phrases, private keys, SafePal navigation and the security habits that protect your crypto.

Wallet safety simulator

Safe action or warning sign?

Make the decision before revealing the explanation.

Scenario 1 / 7

A Telegram support agent asks for your recovery phrase to resynchronise SafePal.

Interactive wallet field guide

Which wallet is built for which job?

Compare custody, signing, KYC and practical use before choosing a wallet or exchange account.

13matches
YOU
Self-custody

You hold the signing credentials and the recovery responsibility.

CO
Custodial account

A company controls the wallets and authorises your withdrawals.

VIEW
Watch-only

You can monitor an address, but you cannot sign or spend.

Software

SafePal App

No wallet KYC

Everyday multichain use, Web3 access and managing a SafePal hardware wallet.

Custody
Self-custody
Who controls the keys?
You control the recovery phrase and signing keys.
Network fit
Bitcoin, Ethereum, BNB Chain, TRON, Solana and many more

Remember: Third-party buy, sell or swap providers inside an app may apply their own KYC rules.

Software

MetaMask

No wallet KYC

EVM networks, browser DApps, token approvals and contract interactions.

Custody
Self-custody
Who controls the keys?
You control the wallet credentials; setup can use a recovery phrase or supported social login.
Network fit
Ethereum and EVM-compatible networks

Remember: A MetaMask wallet is not the same as an on-ramp partner. A partner may still require identity checks.

Software

Trust Wallet

No wallet KYC

Mobile-first multichain asset management and DApp access.

Custody
Self-custody
Who controls the keys?
You control the recovery credentials; no personal sign-up is needed for the wallet itself.
Network fit
Bitcoin, EVM chains, TRON, Solana and many more

Remember: Never share the recovery phrase with support or enter it into an unexpected website.

Software

Rabby Wallet

No wallet KYC

EVM power users who want transaction simulation and clearer signing warnings.

Custody
Self-custody
Who controls the keys?
You control the keys or connect an external hardware signer.
Network fit
Ethereum and EVM-compatible networks

Remember: Simulation helps, but it cannot make an unsafe approval safe. Verify the DApp and permission.

Software

Phantom

No wallet KYC

Solana-focused activity, NFTs, tokens and supported multichain use.

Custody
Self-custody
Who controls the keys?
You control the wallet credentials and transaction signing.
Network fit
Solana and selected additional networks

Remember: Confirm which network is active before copying an address or approving a transaction.

Hardware

SafePal S1 / X1

No wallet KYC

Keeping signing keys away from an internet-connected phone or computer.

Custody
Self-custody
Who controls the keys?
The hardware device protects and uses your keys to sign.
Network fit
Used with the SafePal ecosystem across supported networks

Remember: Buy from an authorised source, initialise it yourself and never use a recovery phrase supplied by a seller.

Hardware

Ledger

No wallet KYC

Cold-key protection for long-term holdings and higher-value signing.

Custody
Self-custody
Who controls the keys?
The device is the signer; you remain responsible for the recovery phrase.
Network fit
Bitcoin, Ethereum, EVM chains and many other supported networks

Remember: Optional purchase or third-party services may collect information even though wallet setup itself does not require KYC.

Hardware

Trezor

No wallet KYC

Offline key protection and deliberate confirmation of outgoing transactions.

Custody
Self-custody
Who controls the keys?
The device signs; the user protects the backup and PIN.
Network fit
Bitcoin, Ethereum and other supported networks

Remember: A hardware wallet reduces online key exposure, but it cannot protect you from approving a malicious transaction.

Smart account

Safe{Wallet}

No wallet KYC

Teams, treasuries and families that need multiple approvals before funds move.

Custody
Self-custody
Who controls the keys?
A smart contract enforces signer and approval rules chosen by the owners.
Network fit
Ethereum and supported EVM-compatible networks

Remember: A poor signer threshold or compromised owners can still create risk. Test the recovery and approval process.

Custodial

Coinbase account

KYC required

Buying, selling and holding assets through a regulated centralised exchange account.

Custody
Custodial
Who controls the keys?
Coinbase controls the platform wallets; you access an account and request withdrawals.
Network fit
Supported deposit and withdrawal networks vary by asset

Remember: Coinbase Wallet is a separate self-custody product. Do not confuse it with a custodial Coinbase exchange account.

Custodial

Kraken account

KYC required

Fiat on-ramp, trading and exchange-based custody.

Custody
Custodial
Who controls the keys?
Kraken controls the platform wallets and withdrawal infrastructure.
Network fit
Supported deposit and withdrawal networks vary by asset

Remember: Verification requirements and available services depend on your location and account level.

Custodial

Binance account

Depends on service

Exchange trading, fiat services and custodial asset management where available.

Custody
Custodial
Who controls the keys?
Binance controls the platform wallets; the user controls account access, not the private keys.
Network fit
Many supported deposit and withdrawal networks

Remember: Identity requirements and service availability are jurisdiction-dependent; verify the current rules in your region.

Watch-only

Watch-only wallet

No wallet KYC

Monitoring a public address without placing spending keys on the device.

Custody
No signing authority
Who controls the keys?
No private key is imported, so the view cannot sign or spend.
Network fit
Any supported public blockchain address

Remember: A watch-only balance is not proof that you control the funds. Control requires the corresponding signing key.

No wallet KYC does not mean invisible or anonymous.

Public blockchain activity can be traced. A self-custody wallet may need no identity check to create, while a separate bank-card purchase, cash-out, exchange or regulated partner can still require KYC.

1
Lesson 1

Wallet types, custody and KYC

Wallets serve different jobs, and the key differences are who signs, who can recover access and whether an account provider must verify your identity.

With a custodial service, a company generally manages the private keys and gives you access through an account. With a non-custodial wallet, the user controls the wallet credentials and carries much more direct responsibility for backup and security.

Software wallets are convenient for everyday use and DApps. Hardware wallets isolate signing keys from an internet-connected device. Smart-account or multisig wallets can require several people or devices to approve an action. Watch-only wallets monitor an address without holding its spending key.

Creating a self-custody wallet generally does not require KYC because no company account is needed to generate the keys. A regulated exchange or fiat on-ramp may still require identity verification before it lets you buy, sell, deposit or withdraw. That separate KYC requirement does not turn the self-custody wallet into a custodial wallet.

Non-custodial control can increase independence, but it also removes many familiar account-recovery safety nets. Losing the recovery phrase or exposing the private key can have permanent consequences. A wallet application is an interface; your blockchain accounts and signing keys are the important underlying elements.

๐Ÿ’ก Why this matters

Understanding wallet type and custody tells you who can authorise transactions, whether support can restore access, and where KYC may enter the process.

๐Ÿงช Practical exercise

Use the wallet explorer above to compare one software wallet, one hardware wallet and one custodial exchange. For each, identify who controls the signing key and what would happen if you lost access.

โœ… Key takeaways
  • Wallet type describes how keys and signing are handled.
  • Self-custody wallet creation and a regulated on-ramp are separate services.
  • Greater control also means greater security responsibility.
2
Lesson 2

Wallet addresses

A public wallet address is used to receive assets, but the correct network still matters.

An EVM-style address usually begins with 0x. The same address can often be used across multiple EVM-compatible networks because it is derived from the same key, but the assets and transaction history on those networks remain separate.

A public address is designed to be shared when someone needs to send you assets. It does not give them permission to spend from your wallet.

Always verify copied addresses carefully. Malware and clipboard-replacement scams can substitute an attacker's address after you copy one.

๐Ÿ’ก Why this matters

Sending to the wrong address is usually irreversible, so address checking should become automatic behaviour.

๐Ÿงช Practical exercise

Retrieve the destination from the recipient's verified source or a saved SafePal address-book entry, then compare the complete address. Never copy an important destination directly from recent transaction history.

โœ… Key takeaways
  • Public addresses can be shared.
  • An address does not identify the network by itself.
  • Never reuse a destination from recent history without independent verification.
3
Lesson 3

Seed phrases and private keys

Recovery phrases and private keys are secrets that can give control over your wallet.

A recovery phrase is commonly used to restore wallet keys. Anyone who obtains it may be able to recreate the wallet and move assets without needing your phone, fingerprint or wallet-app password.

A local wallet password protects access to the app on a device; it is not a replacement for the recovery phrase. Resetting or reinstalling the app may still require the recovery phrase to restore access.

SafePal explicitly states that its support staff will never ask users for seed phrases, private keys or wallet passwords. Treat any person or website requesting them as a serious security threat.

๐Ÿ’ก Why this matters

Many crypto thefts do not involve breaking blockchain cryptography. Attackers simply convince users to reveal the credentials voluntarily.

โš ๏ธ
Security warning

Never type a recovery phrase into a website, form, chat message or support conversation. Only use it in a trusted wallet-recovery process that you intentionally initiated.

โœ… Key takeaways
  • Recovery phrases are wallet-control secrets.
  • Legitimate support does not need them.
  • Device passwords and recovery phrases serve different purposes.
4
Lesson 4

SafePal orientation

SafePal provides wallet interfaces for managing assets and interacting with Web3, but users still need to verify what they connect to and sign.

A wallet interface can display assets, switch networks, connect to decentralised applications and request transaction signatures. Those conveniences do not remove the need to inspect the network, destination and contract interaction.

Use official SafePal distribution channels and official support resources. Be especially cautious of unsolicited messages, QR codes, redirected links and people claiming they need wallet credentials to provide support.

A wallet connection is not automatically the same as transferring funds, but connected applications may later request signatures or token approvals. Read each request rather than assuming a previously trusted connection makes every action safe.

๐Ÿ’ก Why this matters

Most wallet mistakes happen at the human-interface layer, not because the underlying blockchain forgot how to verify a signature.

โœ… Key takeaways
  • Use official wallet software and support channels.
  • Inspect every signature or approval request.
  • A connected DApp should not receive blind trust.
5
Lesson 5

Adding networks and tokens

A wallet may need a network or token to be added manually before it appears in the interface.

If a token is visible on a blockchain explorer but not in the wallet, first confirm that the wallet is viewing the correct network. Then verify the official token contract before importing the token manually.

Do not search social media for a random contract address. Prefer the token issuer's official documentation, the application's official documentation or another authoritative source that can be independently cross-checked.

On BNB Smart Chain, BscScan can help confirm a transaction and identify the token contract involved. Later modules will teach that verification process step by step.

๐Ÿ’ก Why this matters

Manually adding the wrong contract can make a fake token look legitimate inside a wallet interface.

๐Ÿงช Practical exercise

If a token is missing: check transaction hash โ†’ confirm network โ†’ confirm token contract โ†’ then add the verified token to the wallet if needed.

โœ… Key takeaways
  • Missing display does not prove missing funds.
  • Verify the contract before importing a token.
  • Use a blockchain explorer to confirm what happened on-chain.
6
Lesson 6

Random tokens, dusting and wallet phishing

Scammers can send tokens, NFTs or tiny transactions to any public address, then use curiosity, urgency or look-alike information to lure the recipient into a dangerous action.

A public blockchain address can receive assets from strangers without asking permission. An unknown token, NFT or tiny dust transaction appearing in a wallet does not by itself reveal your private key or give the sender control of your funds. Do not panic, but do not assume the item has value or is safe to use.

Scam airdrops often include a website in the token name, NFT image, metadata or failed-transaction message. The site may ask for a recovery phrase, request a dangerous token approval, or present a misleading signature that lets a scammer move assets. Do not follow instructions embedded in an unsolicited asset and do not attempt to swap, claim, burn or return it through an unknown contract.

Dusting can refer to tiny transfers used to study or link wallet activity. A related address-poisoning scam sends a tiny or zero-value transaction from a look-alike address so that it appears in transaction history. The attacker hopes you later copy that address instead of the real destination. Retrieve important addresses from a trusted source or verified address book and compare more than only the first and last characters.

Phishing can arrive through fake wallet extensions, cloned websites, sponsored search results, QR codes, emails, social-media messages, fake support agents and compromised community accounts. A scammer does not always ask for the recovery phrase; a malicious on-chain transaction, token approval, permit or off-chain signature may be enough to steal assets.

The safest response to an unsolicited asset is normally to ignore or hide it using the wallet's built-in controls. Viewing public transaction information in a reputable explorer is generally different from connecting a wallet or signing. If you already signed something suspicious, disconnecting the site alone may not cancel permissions; review and revoke approvals through a trusted tool and move assets if key material was exposed.

๐Ÿ’ก Why this matters

Modern wallet scams frequently use harmless-looking on-chain clutter as the first step in a social-engineering or approval attack.

๐Ÿงช Practical exercise

When an unknown asset appears, classify it without interacting: verify the network and contract in a reputable explorer, note whether it contains a URL or reward claim, and practise choosing Ignore/Hide rather than Swap/Claim. Never test it with your primary wallet.

โš ๏ธ
Security warning

Do not visit URLs embedded in random tokens or NFTs, do not copy destination addresses from unexplained dust transactions, and never sign a request merely to remove or unlock an unsolicited asset.

โœ… Key takeaways
  • Receiving an unknown asset does not by itself compromise the wallet.
  • Interaction, phishing and malicious signatures create the real danger.
  • Dust and look-alike history entries can support privacy analysis or address poisoning.
  • Ignore or hide unsolicited assets and verify destinations independently.
7
Lesson 7

Critical wallet security rules

Strong wallet security is mostly a set of repeatable habits.

Never share seed phrases or private keys. Do not trust unsolicited support. Verify website domains before connecting a wallet. Be suspicious of unexpected tokens, NFTs, QR codes and urgent messages designed to make you act before thinking.

Keep wallet software and devices updated through official channels. Use device security such as a strong screen lock and avoid installing unknown remote-access or screen-sharing software at the request of a stranger.

If you believe a recovery phrase or private key has been exposed, assume the wallet may be compromised. SafePal's current security guidance recommends creating a new trusted wallet and moving remaining assets when a seed phrase or private key has been disclosed.

๐Ÿ’ก Why this matters

Security improves dramatically when safe behaviour becomes routine rather than something you remember only after a suspicious message arrives.

โš ๏ธ
Security warning

No legitimate Stable Circle, SafePal or Academy support process should ever require your recovery phrase or private key.

โœ… Key takeaways
  • Secrets stay secret.
  • Verify links and identities independently.
  • Treat urgency as a warning sign.
  • If key material is exposed, act as though the wallet is compromised.
Primary-source references

Verify the learning material

The Academy uses authoritative primary sources wherever practical and converts them into beginner-friendly explanations.