Wallet Security ManualWALLET SECURITY MANUAL
Ключ — это ключ · Никогда не делиться

Руководство по безопасности кошелька · ДОК WH-2026-002

Ваш кошелёк имеет
только один ключ.

Ваша сид-фраза — это и есть тот ключ. Как только она покидает ваши руки — сфотографирована, вставлена на сайт, отправлена "в поддержку" — ваш кошелёк больше не принадлежит вам. Это руководство охватывает три вещи: как теряются ключи, как их защитить, и что делать, если они потеряны.

Демо-реквизит · То, чего хотят мошенники больше всего

SEED PHRASE
Запечатано 0 / 12
Демо завершено. Вы только что продемонстрировали один из самых опасных способов утечки вашей сид-фразы: показ слов по одному на экране. Запомните — настоящая сид-фраза должна существовать только на бумаге, никогда на каком-либо экране, никогда не вводиться ни на каком сайте.

* Выше — демо-слова, не настоящая сид-фраза. Нажмите на ячейки, чтобы снять печать.

Книга угроз

Существует только три способа, которыми опустошают ваш кошелёк.

No elite hacker required. No device breach needed. Most thefts travel these three most ordinary paths. Know the enemy first, then know what to defend.

СРЯ-1 · Самый частый

Фишинговые сайты и фейковые эйрдропы

Fake official sites, forged airdrops, "official" DMs — all using pages that look completely legitimate to trick you into entering your seed phrase or signing malicious transactions. The FBI reported over $5.6 billion in crypto-related fraud losses in 2023 alone.

Метод: вооружённое доверие · Цель: любой

СРЯ-1 · Самый фатальный

Утечка сид-фразы

Screenshots, cloud sync, typing into "verification" sites, sending to "customer support." The seed phrase is the only key to your wallet. Once it leaves your hands — even once — treat it as compromised. No exceptions.

Метод: кража ключа · Результат: невозвратим

СРЯ-2 · Самый скрытный

Безлимитное одобрение

Under the "mint""claim""stake" approval popup may hide an unlimited allowance. Scammers don't need you to send funds — they can drain everything within that limit yourself. You may not notice a thing.

Метод: ловушка подписи · Результат: тихий дренаж

Руководство по защите

Шесть железных правил. Следуйте им по порядку.

Это не список желаний — это последовательность. Начните с правила первого. Следуйте каждому шагу.

01ПЕРВЫЙ

Seed only on paper

Write it by hand on paper. Lock it in a drawer or safe. Never screenshot it, never type it into any website, never send it to anyone. A digital seed phrase is already compromised.

02РАЗДЕЛИТЬ

Hot/cold separation

Store large holdings in a hardware wallet (cold). Use a separate hot wallet for daily small transactions. The two wallets must have different seed phrases — if the hot wallet is compromised, the principal stays safe in cold storage.

03ПРОВЕРИТЬ

Verify full address before sending

After pasting, verify character by character. Focus on the first and last 8 characters. Save addresses to a contacts list. Compare every time — don't just glance at the first few.

04ОХВАТ

Control approval limits

Check the scope of approvals on unfamiliar contracts. Revoke unused ones at revoke.cash. Beware of clone domains — verify the tool's own URL before confirming anything.

05ЗАПЕРЕТЬ

Lock large amounts

Large transactions should require hardware confirmation and second-factor auth. For team or family funds, use a multi-sig wallet — no single person can move everything.

06ПЛАН

Prepare emergency plans

Write down in advance: what to do if your device is lost, if you suspect a leak, if you send to the wrong address. List the steps now, follow them later — don't decide in a panic.

Сид-хранилище

Как вы должны хранить свою сид-фразу, чтобы truly держать её в безопасности?

「Написать на бумаге」— только половина истории. Написание — это только начало — как вы её храните определяет, переживёт ли она 30 лет, и будет ли она когда-либо рядом с сетью.

Medium
01МЕТАЛЛ

From Paper to Metal

Paper can be flooded, burned, eaten by insects. For long-term large holdings, metal backup (engraved stainless steel plates like Cryptosteel or Billfodl) is recommended, or at minimum waterproof paper cards with lamination. Any "digital seed phrase" in screenshots, documents, or cloud storage should be treated as compromised.

Shards
02ОСКОЛКИ

Split the Key

Use Shamir Secret Sharing to split your seed phrase into multiple parts stored separately (e.g. 2-of-3, 3-of-5): losing any single shard isn't fatal, leaking any single shard isn't fatal either. Best for large long-term holdings — but the shard rules themselves must be stored as securely as the seed phrase.

Copies
03КОПИИ

Three Locations Rule

Main copy + backup copy + emergency copy (at a trusted person's place), stored in different physical locations. Each copy must guard against being "seen" — a roommate, a security camera, a repair worker could all become witnesses.

Edge Case
04EDGE CASE

What About Password Managers?

Generally no. Password managers live on internet-connected devices — one malware infection and your seed phrase is gone. The only truly safe "digital seed phrase" exists on a fully offline device, and even then there's still the risk of being photographed or cloud-backed up. Beginners should skip this route.

Verification
05ВОССТАНОВЛЕНИЕ

The Cost of a Wrong Word

One wrong word in your seed phrase and recovery will fail. After writing it down, practice recovery right away: delete your wallet, recover using only the paper words, confirm it works — this is the only way to verify your backup is actually good.

Iron Rule
06НИКОГДА

Four NEVERs

NEVER screenshot it. NEVER type it into any website. NEVER send it to anyone — including those claiming to be official, security experts, or customer support. NEVER put it on any internet-connected device.

Запомните: Сид-фраза — единственный ключ вашего кошелька. Каждый экран, на котором она появляется, каждое поле ввода, куда она напечатана, каждое окно чата, где она появляется — это ваш кошелёк, который был открыт один раз. Сделайте 「цифровая форма = скомпрометировано」вашим предположением по умолчанию.

Красные флаги

Замечайте с первого взгляда: когда появляются эти сигналы, уходите.

Мошенники постоянно эволюционируют, но их недостатки никогда не меняются. Любой из них сам по себе достаточен, чтобы остановиться, проверить и уйти.

Сфабрикованная срочность

"Last 2 hours""Account will be frozen if you don't act." Official channels never manufacture urgency. Pressure is scam's first hallmark.

Запрос сид-фразы

No legitimate project will ever ask for your seed phrase or private key. If they ask, it's a scam. No exceptions. No "verification."

Клонирование домена

wallet-connect-verify.com, or one or two characters off from the official spelling. Check the address bar. Don't check the page content — the page itself is fake.

ДМ поддержки

Official support never DMs you first, and they never pull you into a "recovery group." "Official" contacts that come to you are, by default, fake.

Эйрдроп с оплатой

An "airdrop" that asks you to send funds first is a pay-to-receive phishing trap. Real airdrops never require you to pay anything.

Непрочитаемая подпись

Can't understand the English in the approval popup? It says "unlimited"? If you don't understand it, don't sign. Close the page and come back later.

Дело мошенничества

Вскрытие мошенничества: от ДМа до опустошённого кошелька.

Пройдитесь через красные флаги ЛИСТ 04 в реалистичной последовательности. На каждом шаге левая сторона показывает ход мошенника, правая сторона показывает что вы должны сделать сейчас.

01КОНТАКТ
Мошенничество · Что они делают

You receive a DM (Telegram / Discord / X): "Hello, we're the official XX team. Congratulations — you qualify for an airdrop. Claim here: xxx-claim.com."

Действие · Что вы делаете

Don't click. Links in DMs are phishing by default. Verify through official channels — cross-reference SHEET 06, or search the official announcement directly.

02ПРИМАНОЧКА
Мошенничество · Что они делают

The fake site (domain xxx-claim.com) looks identical to the real one — even sporting a fake "official site" badge, with a giant claim button on the homepage.

Действие · Что вы делаете

Check the address bar domain against the official entrances table, character by character. Page content can be faked. A domain cannot — you just have to look.

03ВХОД
Мошенничество · Что они делают

The page asks you to "connect wallet," or directly asks you to "enter your seed phrase to verify identity." They claim this is a required step for the airdrop.

Действие · Что вы делаете

A seed phrase must never be entered into any website. Connecting your wallet is fine — but watch the next approval popup carefully. That's the real battlefield.

04ПОДПИСЬ
Мошенничество · Что они делают

The signing popup reads "Approve unlimited amount of TOKEN," with a countdown timer designed to rush you.

Действие · Что вы делаете

If you don't understand it, don't sign. See unlimited? See a countdown? See any pressure? Click "Reject," close the page, and come back later.

05ЕСЛИ ПОДПИСАЛИ
Результат A · Вы ввели сид

Assets are drained in bulk within minutes. Once a chain transfer is confirmed, it cannot be reversed.

Действие · Что вы делаете

Immediately execute SHEET 07 Emergency Checklist Step 1: move remaining assets to a brand-new wallet (new seed phrase). Isolate first, investigate later.

06ПОСЛЕДСТВИЯ
Результат B · Вы подписали одобрение

The scammer doesn't rush — they slowly drain within the approved limit. You may not notice for days or weeks.

Действие · Что вы делаете

Immediately revoke that contract approval (revoke.cash — verify the domain first), then monitor your balance closely.

Почему это важно: Мошенничество — не одно движение — это четырёхшаговая цепочка: контакт, приманка, вход, подпись. На каждом шаге есть дефект, все задокументированы в ЛИСТЕ 04. Вам не нужно запоминать каждое мошенничество. Вам нужно просто приостановиться на одну секунду на каждом шаге: Это ДМ? Домен правильный? Просят ли мою сид? Понимаю ли я это всплывающее окно?

Официальные входы

Доверяйте только официальным сайтам: входите только через эту таблицу.

Большинство фишинга начинается с рекламных позиций в результатах поиска или ссылок в ДМах. Дайте себе фиксированную точку входа: получайте доступ к сайтам кошельков только через эту таблицу и всегда проверяйте домен адресной строки.

01Домен должен точно совпадать с таблицей ниже в точности — ни одного символа отличия
02Официальные каналы никогда не напишут вам в ДМ ссылки или не попросят вашу сид-фразу
03Рекламные слоты результатов поиска и бейджи 「официальный сайт」тоже могут быть поддельными
Total 18
Wallet
Type
Official Domain
MetaMaskBrowser Extension / Mobile · Ethereum Ecosystem
Хот-кошелёк
Trust WalletMobile · Multi-chain
Хот-кошелёк
PhantomBrowser Extension / Mobile · Solana Ecosystem
Хот-кошелёк
RabbyBrowser Extension / Desktop · Approval Risk Detection
Хот-кошелёк
imTokenMobile · Established Multi-chain Wallet
Хот-кошелёк
TokenPocketMobile / Extension · Multi-chain Cross-chain
Хот-кошелёк
Bitget WalletMobile / Extension · Web3 Wallet
Хот-кошелёк
OKX Web3 WalletИнтеграция с биржей · Web3 Wallet
Хот-кошелёк
ExodusDesktop / Mobile · Multi-currency
Хот-кошелёк
RainbowMobile / Extension · Ethereum
Хот-кошелёк
ZengoMobile · No Seed Phrase (MPC)
Хот-кошелёк
LedgerАппаратный кошелёк · Холодное хранение
Аппаратный
TrezorАппаратный кошелёк · Пионер открытого кода
Аппаратный
TangemHardware Wallet · Card-shaped
Аппаратный
KeystoneHardware Wallet · QR Air-gap
Аппаратный
OneKeyHardware / Software · Multi-chain (Chinese)
Аппаратный
SafeMulti-sig · Smart Account Standard
Мультиподпись
ElectrumDesktop · Bitcoin Legacy Open Source
Открытый код

Домены проверены в августе 2025 года. Если вы когда-нибудь получите 「новый URL」, вернитесь сначала к этой таблице или перепроверьте через официальные социальные аккаунты кошелька — клоны доменов часто отличаются всего на один-два символа. Скачивайте приложения только через ссылки на официальном сайте или ищите полное имя разработчика напрямую в официальном магазине приложений.
Примечание SSL: Легитимные сайты кошельков все используют HTTPS, но имейте в виду, что сертификат SSL означает только, что соединение зашифровано — это не значит, что сам веб-сайт заслуживает доверия. Проверка домена и адресной строки остаётся самой надёжной проверкой.

Руководство по ЧС

Если вы подозреваете, что стали мишенью.

Существует только одна последовательность: сначала изолируйте, потом расследуйте. Безопасность активов всегда приходит раньше, чем понимание того, что произошло. Выполняйте каждый шаг:

1

Potential seed leak → Migrate immediately

Move assets to a brand-new wallet (new seed phrase) right now — don't wait a moment. The new seed phrase goes only on paper. Treat the old one as compromised; never use it again.

2

Approval may be abused → Revoke immediately

Revoke suspicious contract approvals at revoke.cash (verify the domain first), then watch your balance closely. Not sure which approvals are suspicious? Revoke them all. Re-authorize only what you actually need.

3

Funds already moved → Race the time window

Contact the project team and exchanges immediately to attempt freezing (the window is short). Preserve all evidence (transaction hashes, chat logs, links), then report to authorities. On-chain transfers are usually irreversible — that's why the first two steps always come first.

4

Under any circumstances → Refuse "recovery" services

Never pay anyone to "unlock funds" or "recover lost assets." Those claiming they can help you recover are the second wave of scammers, targeting people who just got burned.

Распространённые мифы

То, что вы думаете, может быть неправдой.

Четыре самых распространённых оправдания — каждое открывает ещё одну дверь к вашему кошельку.

У меня маленький баланс — мошенники не будут целиться в меня

Bulk-scanning scripts don't discriminate. They scan for assets and exposures on-chain. Small accounts are on the same list.

Аппаратные кошельки полностью безопасны

They protect against remote theft — they can't stop you from typing your seed phrase into a phishing page. A hardware wallet is only as safe as the hands holding its seed phrase.

В официальной группе поддержка не обманет меня

Groups are public. Anyone can rename themselves "support." Impersonating official staff is the most common starting point for scams in crypto.

Мне нужно проверить только первые несколько символов

Checksum addresses distinguish case. Imposters construct visually similar addresses. Verify completely — at least the first and last 8 characters, and cross-reference with your address book.

Глоссарий

Поймите слова, прежде чем говорить о безопасности.

Все разделы выше предполагают, что вы знаете эти термины. Если застрянете при чтении, вернитесь к этой таблице. Это приложение руководства — и также его начальная точка.

Seed Phrase
A "key backup" made of 12 or 24 words. Whoever holds the seed phrase owns the wallet — which is why it is the ultimate target of every scam.
Private Key
The ultimate key derived from the seed phrase, used to sign transactions. Just as confidential as the seed phrase — never share it either.
Hot / Cold Wallet
A hot wallet lives on internet-connected devices — convenient but high exposure. A cold wallet lives on offline devices (hardware wallets) — safer but less convenient. Keep large amounts cold, small amounts hot.
Approval
Allowing a contract to spend your tokens. The limit can be set to unlimited. Every approval is worth three seconds of scrutiny.
Signing
The act of confirming a transaction with your private key. Signing = authorizing a payment. If you don't understand the signing request, don't sign it.
Chain ID
The number that distinguishes different chains (Ethereum = 1, BNB = 56, etc.). Cross-chain phishing often tampers here. Confirm the chain in the popup is correct before signing.
Checksum Address
The mixed-case convention for Ethereum addresses. Fake addresses can mimic the appearance of real ones. Verify at least the first and last 8 characters when checking.
Мультиподпись
A wallet that requires multiple parties (or keys) to co-sign before transferring funds. One person's compromise doesn't mean all assets are lost.
Airdrop
Free token distribution by a project team. A real airdrop never asks you to pay any fee or provide your seed phrase — anything that does is a scam.
MPC Wallet
Splits the private key into fragments held by multiple parties, no seed phrase exists (e.g., Zengo). Losing a phone doesn't mean losing your wallet.