MultiversX Tracker is Live!

Clicking a link, Connecting a wallet, Signing a transactions - Know the difference

All Cryptocurrencies

by COINS NEWS 80 Views

Clicking a link, Connecting a wallet, Signing a transactions - Know the difference

This post is inspired by numerous "No way I'm clicking that link" comments which make crypto look a lot more dangerous than it is. In reality, even scams have to follow rules and require certain steps, so let's look at what is dangerous and what isn't.

Clicking a link

With an up-to-date Operating System and browser you don't have to worry about clicking links. If a website asks you for additional permissions, wants to initiate a download or connect to your wallet, simply don't do it. If you downloaded something, move it to the trash.

Life Pro Tip: Use browser add-ons like NoScript to explore unknown websites and using a different browser for DeFi can give you additional peace of mind.

Connecting a wallet

This is the point where many beginners will become unsure, but in fact it's not risky to just connect a wallet. This is how connecting a wallet in Metamask looks like:

https://preview.redd.it/78886a0dwhgb1.png?1450&format=png&auto=webp&s=8863d404b89be6522d42b3a4abda2e23d277d3a8

Note the text in the red circle. You allow websites to see your address (this includes balance and activity) and suggest transaction. While this might compromise your privacy, a wallet connection can not make transactions of any kind without your explicit approval.

Making a signature

One step scarier, and still safe: Prove someone you are the owner of a wallet by providing a signature. This can look like this:

https://preview.redd.it/xe3xsfsaxhgb1.png?722&format=png&auto=webp&s=b65d1e4c068234b11a9ff7c4afc7242a3d772d3c

Note the message is shown and clearly human-readable clear text. Sometimes you might just be asked to sign an arbitrary number ("Nonce"). If you are just signing a number or clear text message, this can't possibly be used against you.

While there are 100% safe signature methods today, there are older signature methods ("eth_sign") which allow to sign messages which can be disguised transactions. If the text appears to be some gibberish, binary or even code, reject it.

Metamask has eth_sign disabled on default.

Signing transactions

This is the critical step without a doubt. Here are two examples:

https://preview.redd.it/zm00afj3zhgb1.png?1444&format=png&auto=webp&s=e540803d0357177b34d3ca9cfdc81b87dd2a4ad8

The left one asks for an approval, the right one for a contract interaction. A malicious website could use both methods to steal your funds. Before confirming a transaction, always make sure you are on the correct website. Do you remember how you got there? Did you use a bookmark or google it? In doubt just reject the tx and start over.

Note Metamask now uses limited approvals on default. If a limited approval gets exploited, only the approved amount can be stolen. This is an extremely handy feature on chains with low fees and you should always use it.

Once an approval is given, it can be used at any time by the contract without requiring an additional confirmation from you.

Revoke approvals

If you have an open or unlimited approval for a website you don't trust any longer, you can always revoke them. Websites like revoke.cash can be used to get an overview over them.

Also most block explorers allow viewing and revoking approvals by visiting the /tokenapprovalchecker url. This is supported by Etherscan, Polygonscan, Arbiscan and many more!

If you don't plan to use a contract again and have an approval for it, you should revoke it.

Stay safe

This post is not an invitation to click links to clearly fraudulent websites or connect your wallet to anything that asks for it. I believe education is the best way to make people confident and safe in using DeFi, and a part of that is knowing what each of this steps does and what it doesn't.

tl;dr:

  • Clicking a link is not dangerous if your computer is up to date and not infected my malware.
  • You can make sure nothing bad happens by using NoScript and/or a different browser for DeFi.
  • Connecting a wallet alone is not dangerous - the website is only allowed to see addresses and suggest transacitons.
  • Giving a signature of a clear text message is not dangerous - be careful if your wallet supports the obsolete eth-sign method which can be exploited to sign transactions.
  • Only your explicitly confirmed transactions and approvals can be used to steal your funds.
  • Revoke approvals you don't longer need with tools like revoke.cash or the block explorer.
submitted by /u/Maxx3141
[link] [comments]

Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments