Ghostbag

Wallet security

Protect the wallet
before chasing the trade.

A fast entry is worthless if a fake link, malicious approval or exposed recovery phrase empties the wallet. Use a small trading wallet and make verification part of the setup.

01

Never share the recovery phrase

No legitimate support agent, airdrop, bot or verification page needs it. Anyone with the phrase can control every account derived from it.

02

Use official downloads and typed URLs

Bookmarks are safer than search ads or direct messages. Check the full domain before connecting, and do not open links embedded in unexpected tokens or NFTs.

03

Separate trading from storage

Keep only the amount needed for active trading in a hot wallet. A second wallet limits the value exposed to one bad approval, but it still needs independent, secure recovery.

04

Read every transaction

Confirm the destination, token, amount and requested authority. An unexpected transfer, approval or ownership change is a reason to reject the request.

05

Revoke and move after compromise

Disconnect suspicious apps, revoke token approvals where possible and transfer remaining assets to a fresh wallet created from a new phrase. Do not reuse a phrase that may be exposed.

06

Verify contract identity

Search by contract address, not token name or symbol. Scam assets can copy familiar branding while pointing to a different mint.

These practices follow guidance from Phantom’s scam-response guide and its warning about unexpected tokens and links.