Wallet Security ManualWALLET SECURITY MANUAL
Kunci ADALAH kunci · Jangan pernah bagikan

Panduan Keamanan Dompet · DOK WH-2026-002

Dompet Anda hanya
memiliki satu kunci.

Seed phrase Anda ADALAH kunci itu. Begitu keluar dari tangan Anda — difoto, ditempel ke situs web, dikirim ke "dukungan" — dompet Anda tidak lagi milik Anda. Manual ini mencakup tiga hal: bagaimana kunci hilang, cara melindunginya, dan apa yang harus dilakukan jika hilang.

Prop demo · Yang paling diinginkan penipu

SEED PHRASE
Tersegel 0 / 12
Demo selesai. Anda baru saja mendemonstrasikan salah satu cara paling berbahaya untuk membocorkan seed Anda: membuat kata-kata terlihat satu per satu di layar. Ingat — seed phrase asli hanya harus ada di atas kertas, tidak pernah di layar apa pun, tidak pernah diketik di situs web mana pun.

* Di atas adalah kata-kata demo, bukan seed phrase sungguhan. Klik sel untuk membuka segel.

Buku Ancaman

Hanya ada tiga cara dompet Anda dikosongkan.

No elite hacker required. No device breach needed. Most thefts travel these three most ordinary paths. Know the enemy first, then know what to defend.

SEV-1 · Paling Umum

Situs Phishing & Airdrop Palsu

Fake official sites, forged airdrops, "official" DMs — all using pages that look completely legitimate to trick you into entering your seed phrase or signing malicious transactions. The FBI reported over $5.6 billion in crypto-related fraud losses in 2023 alone.

Metode: kepercayaan bersenjata · Target: siapa saja

SEV-1 · Paling Fatal

Kebocoran Seed Phrase

Screenshots, cloud sync, typing into "verification" sites, sending to "customer support." The seed phrase is the only key to your wallet. Once it leaves your hands — even once — treat it as compromised. No exceptions.

Metode: mencuri kunci · Hasil: tidak dapat dipulihkan

SEV-2 · Paling Tersembunyi

Persetujuan Tanpa Batas

Under the "mint""claim""stake" approval popup may hide an unlimited allowance. Scammers don't need you to send funds — they can drain everything within that limit yourself. You may not notice a thing.

Metode: jebakan tanda tangan · Hasil: pengosongan diam-diam

Manual Pertahanan

Enam aturan besi. Ikuti secara berurutan.

Ini bukan daftar harapan — ini urutan. Mulailah dari aturan satu. Ikuti setiap langkah.

01PERTAMA

Seed only on paper

Write it by hand on paper. Lock it in a drawer or safe. Never screenshot it, never type it into any website, never send it to anyone. A digital seed phrase is already compromised.

02PECAHKAN

Hot/cold separation

Store large holdings in a hardware wallet (cold). Use a separate hot wallet for daily small transactions. The two wallets must have different seed phrases — if the hot wallet is compromised, the principal stays safe in cold storage.

03VERIFIKASI

Verify full address before sending

After pasting, verify character by character. Focus on the first and last 8 characters. Save addresses to a contacts list. Compare every time — don't just glance at the first few.

04CAKUPAN

Control approval limits

Check the scope of approvals on unfamiliar contracts. Revoke unused ones at revoke.cash. Beware of clone domains — verify the tool's own URL before confirming anything.

05KUNCI

Lock large amounts

Large transactions should require hardware confirmation and second-factor auth. For team or family funds, use a multi-sig wallet — no single person can move everything.

06RENCANA

Prepare emergency plans

Write down in advance: what to do if your device is lost, if you suspect a leak, if you send to the wrong address. List the steps now, follow them later — don't decide in a panic.

Vault Seed

Bagaimana Anda harus menyimpan seed phrase agar benar-benar aman?

"Tulis di atas kertas" hanya separuh cerita. Menulisnya hanyalah awal — bagaimana Anda menyimpannya menentukan apakah ia bertahan 30 tahun, dan apakah ia pernah melewati jaringan.

Medium
01LOGAM

From Paper to Metal

Paper can be flooded, burned, eaten by insects. For long-term large holdings, metal backup (engraved stainless steel plates like Cryptosteel or Billfodl) is recommended, or at minimum waterproof paper cards with lamination. Any "digital seed phrase" in screenshots, documents, or cloud storage should be treated as compromised.

Shards
02FRAGMEN

Split the Key

Use Shamir Secret Sharing to split your seed phrase into multiple parts stored separately (e.g. 2-of-3, 3-of-5): losing any single shard isn't fatal, leaking any single shard isn't fatal either. Best for large long-term holdings — but the shard rules themselves must be stored as securely as the seed phrase.

Copies
03SALINAN

Three Locations Rule

Main copy + backup copy + emergency copy (at a trusted person's place), stored in different physical locations. Each copy must guard against being "seen" — a roommate, a security camera, a repair worker could all become witnesses.

Edge Case
04KASUS TEPi

What About Password Managers?

Generally no. Password managers live on internet-connected devices — one malware infection and your seed phrase is gone. The only truly safe "digital seed phrase" exists on a fully offline device, and even then there's still the risk of being photographed or cloud-backed up. Beginners should skip this route.

Verification
05PULIH

The Cost of a Wrong Word

One wrong word in your seed phrase and recovery will fail. After writing it down, practice recovery right away: delete your wallet, recover using only the paper words, confirm it works — this is the only way to verify your backup is actually good.

Iron Rule
06JANGAN

Four NEVERs

NEVER screenshot it. NEVER type it into any website. NEVER send it to anyone — including those claiming to be official, security experts, or customer support. NEVER put it on any internet-connected device.

Ingat: Seed phrase adalah satu-satunya kunci dompet Anda. Setiap layar tempat ia muncul, setiap field input di mana ia diketik, setiap jendela chat di mana ia muncul — itu dompet Anda yang telah dibuka sekali. Jadikan "bentuk digital = Kompromi" asumsi default Anda.

Bendera Merah

Kenali sekilas: ketika sinyal ini muncul, pergi.

Penipuan terus berevolusi, tetapi cacatnya tidak pernah berubah. Salah satu saja sudah cukup membuat Anda berhenti, verifikasi, dan pergi.

Urgency Buatan

"Last 2 hours""Account will be frozen if you don't act." Official channels never manufacture urgency. Pressure is scam's first hallmark.

Meminta Seed

No legitimate project will ever ask for your seed phrase or private key. If they ask, it's a scam. No exceptions. No "verification."

Kloning Domain

wallet-connect-verify.com, or one or two characters off from the official spelling. Check the address bar. Don't check the page content — the page itself is fake.

DM Dukungan

Official support never DMs you first, and they never pull you into a "recovery group." "Official" contacts that come to you are, by default, fake.

Airdrop Berbayar

An "airdrop" that asks you to send funds first is a pay-to-receive phishing trap. Real airdrops never require you to pay anything.

Tanda Tangan Tidak Terbaca

Can't understand the English in the approval popup? It says "unlimited"? If you don't understand it, don't sign. Close the page and come back later.

Berkas Penipuan

Mbedah penipuan: dari DM hingga dompet kosong.

Lewati bendera merah LEMBAR 04 dalam urutan realistis. Di setiap langkah, sisi kiri menunjukkan gerakan penipu, sisi kanan menunjukkan yang harus Anda lakukan sekarang.

01KONTAK
Penipuan · Apa yang mereka lakukan

You receive a DM (Telegram / Discord / X): "Hello, we're the official XX team. Congratulations — you qualify for an airdrop. Claim here: xxx-claim.com."

Tindakan · Apa yang Anda lakukan

Don't click. Links in DMs are phishing by default. Verify through official channels — cross-reference SHEET 06, or search the official announcement directly.

02UMPAN
Penipuan · Apa yang mereka lakukan

The fake site (domain xxx-claim.com) looks identical to the real one — even sporting a fake "official site" badge, with a giant claim button on the homepage.

Tindakan · Apa yang Anda lakukan

Check the address bar domain against the official entrances table, character by character. Page content can be faked. A domain cannot — you just have to look.

03MASUK
Penipuan · Apa yang mereka lakukan

The page asks you to "connect wallet," or directly asks you to "enter your seed phrase to verify identity." They claim this is a required step for the airdrop.

Tindakan · Apa yang Anda lakukan

A seed phrase must never be entered into any website. Connecting your wallet is fine — but watch the next approval popup carefully. That's the real battlefield.

04TANDA TANGAN
Penipuan · Apa yang mereka lakukan

The signing popup reads "Approve unlimited amount of TOKEN," with a countdown timer designed to rush you.

Tindakan · Apa yang Anda lakukan

If you don't understand it, don't sign. See unlimited? See a countdown? See any pressure? Click "Reject," close the page, and come back later.

05JIKA DITANDATANGANI
Hasil A · Anda memasukkan seed

Assets are drained in bulk within minutes. Once a chain transfer is confirmed, it cannot be reversed.

Tindakan · Apa yang Anda lakukan

Immediately execute SHEET 07 Emergency Checklist Step 1: move remaining assets to a brand-new wallet (new seed phrase). Isolate first, investigate later.

06AKIBAT
Hasil B · Anda menandatangani persetujuan

The scammer doesn't rush — they slowly drain within the approved limit. You may not notice for days or weeks.

Tindakan · Apa yang Anda lakukan

Immediately revoke that contract approval (revoke.cash — verify the domain first), then monitor your balance closely.

Mengapa ini penting: Penipuan bukan satu gerakan — ini rantai empat langkah: kontak, umpan, masuk, tanda tangan. Setiap langkah memiliki cacat, semua didokumentasikan di LEMBAR 04. Anda tidak perlu menghafal setiap penipuan. Anda hanya perlu berhenti satu detik di setiap langkah: Apakah ini DM? Apakah domain benar? Apakah mereka meminta seed saya? Apakah saya mengerti popup ini?

Masukan Resmi

Percayai hanya situs resmi: masuk hanya melalui tabel ini.

Sebagian besar phishing dimulai dari posisi iklan di hasil pencarian atau tautan di DM. Berikan diri Anda titik masuk tetap: hanya akses situs dompet melalui tabel ini, dan selalu verifikasi domain address bar.

01Domain harus cocok dengan tabel di bawah secara tepat — tidak boleh satu karakter berbeda
02Saluran resmi tidak akan pernah DM Anda tautan atau meminta seed phrase Anda
03Slot iklan hasil pencarian dan lencana "situs resmi" juga bisa dipalsukan
Total 18
Wallet
Type
Official Domain
MetaMaskBrowser Extension / Mobile · Ethereum Ecosystem
Dompet Hot
Trust WalletMobile · Multi-chain
Dompet Hot
PhantomBrowser Extension / Mobile · Solana Ecosystem
Dompet Hot
RabbyBrowser Extension / Desktop · Approval Risk Detection
Dompet Hot
imTokenMobile · Established Multi-chain Wallet
Dompet Hot
TokenPocketMobile / Extension · Multi-chain Cross-chain
Dompet Hot
Bitget WalletMobile / Extension · Web3 Wallet
Dompet Hot
OKX Web3 WalletTerintegrasi dengan exchange · Web3 Wallet
Dompet Hot
ExodusDesktop / Mobile · Multi-currency
Dompet Hot
RainbowMobile / Extension · Ethereum
Dompet Hot
ZengoMobile · No Seed Phrase (MPC)
Dompet Hot
LedgerDompet perangkat keras · Penyimpanan dingin
Perangkat Keras
TrezorDompet perangkat keras · Pionir sumber terbuka
Perangkat Keras
TangemHardware Wallet · Card-shaped
Perangkat Keras
KeystoneHardware Wallet · QR Air-gap
Perangkat Keras
OneKeyHardware / Software · Multi-chain (Chinese)
Perangkat Keras
SafeMulti-sig · Smart Account Standard
Multi-sig
ElectrumDesktop · Bitcoin Legacy Open Source
Sumber Terbuka

Domain diverifikasi Agustus 2025. Jika Anda menerima "URL baru", kembali ke tabel ini dulu, atau periksa ulang melalui akun media sosial resmi dompet — domain klon sering berbeda hanya satu atau dua karakter. Unduh aplikasi hanya melalui tautan di situs resmi, atau cari nama lengkap pengembang langsung di app store resmi.
Catatan SSL: Situs dompet legitimate semua menggunakan HTTPS, tetapi perhatikan bahwa sertifikat SSL hanya berarti koneksi dienkripsi — tidak berarti situs web itu sendiri dapat dipercaya. Memverifikasi domain dan address bar tetap menjadi pemeriksaan paling andal.

Manual Darurat

Jika Anda mencurigai telah dijadikan target.

Hanya ada satu urutan: isolasi dulu, selidiki kedua. Keamanan aset selalu datang sebelum memahami apa yang terjadi. Eksekusi setiap langkah:

1

Potential seed leak → Migrate immediately

Move assets to a brand-new wallet (new seed phrase) right now — don't wait a moment. The new seed phrase goes only on paper. Treat the old one as compromised; never use it again.

2

Approval may be abused → Revoke immediately

Revoke suspicious contract approvals at revoke.cash (verify the domain first), then watch your balance closely. Not sure which approvals are suspicious? Revoke them all. Re-authorize only what you actually need.

3

Funds already moved → Race the time window

Contact the project team and exchanges immediately to attempt freezing (the window is short). Preserve all evidence (transaction hashes, chat logs, links), then report to authorities. On-chain transfers are usually irreversible — that's why the first two steps always come first.

4

Under any circumstances → Refuse "recovery" services

Never pay anyone to "unlock funds" or "recover lost assets." Those claiming they can help you recover are the second wave of scammers, targeting people who just got burned.

Mitos Umum

Yang Anda pikir mungkin tidak benar.

Empat rasionalisasi paling umum — setiap satu membuka pintu lain ke dompet Anda.

Saldo saya kecil — penipu tidak akan menargetkan saya

Bulk-scanning scripts don't discriminate. They scan for assets and exposures on-chain. Small accounts are on the same list.

Dompet perangkat keras sepenuhnya aman

They protect against remote theft — they can't stop you from typing your seed phrase into a phishing page. A hardware wallet is only as safe as the hands holding its seed phrase.

Di grup resmi, dukungan tidak akan menipu saya

Groups are public. Anyone can rename themselves "support." Impersonating official staff is the most common starting point for scams in crypto.

Saya hanya perlu memeriksa beberapa karakter pertama

Checksum addresses distinguish case. Imposters construct visually similar addresses. Verify completely — at least the first and last 8 characters, and cross-reference with your address book.

Glosarium

Pahami kata-katanya sebelum berbicara tentang keamanan.

Semua bagian di atas mengasumsikan Anda mengetahui istilah-istilah ini. Jika tersendat saat membaca, kembali ke tabel ini. Ini adalah lampiran manual — dan juga titik mulainya.

Seed Phrase
A "key backup" made of 12 or 24 words. Whoever holds the seed phrase owns the wallet — which is why it is the ultimate target of every scam.
Private Key
The ultimate key derived from the seed phrase, used to sign transactions. Just as confidential as the seed phrase — never share it either.
Hot / Cold Wallet
A hot wallet lives on internet-connected devices — convenient but high exposure. A cold wallet lives on offline devices (hardware wallets) — safer but less convenient. Keep large amounts cold, small amounts hot.
Approval
Allowing a contract to spend your tokens. The limit can be set to unlimited. Every approval is worth three seconds of scrutiny.
Signing
The act of confirming a transaction with your private key. Signing = authorizing a payment. If you don't understand the signing request, don't sign it.
Chain ID
The number that distinguishes different chains (Ethereum = 1, BNB = 56, etc.). Cross-chain phishing often tampers here. Confirm the chain in the popup is correct before signing.
Checksum Address
The mixed-case convention for Ethereum addresses. Fake addresses can mimic the appearance of real ones. Verify at least the first and last 8 characters when checking.
Multi-sig
A wallet that requires multiple parties (or keys) to co-sign before transferring funds. One person's compromise doesn't mean all assets are lost.
Airdrop
Free token distribution by a project team. A real airdrop never asks you to pay any fee or provide your seed phrase — anything that does is a scam.
MPC Wallet
Splits the private key into fragments held by multiple parties, no seed phrase exists (e.g., Zengo). Losing a phone doesn't mean losing your wallet.