Security Guide 2022 of Math Wallet

MathWallet has supported multi-dimensional security reminders

  • Blocking function for URL blacklist
  • Scoring function for BNBChain contract’s security
  • Reminder function for TOKEN or NFT approval signature
  • Approval management function for EVM public chain
  • etc

In the WEB3 world, security has always been the top concern for everyone. How to better protect our assets, in addition to choosing safe tools, what is more important is our own security awareness and usage habits.

——————————————————

MathWallet FunctionsRelated To Security Reminders

As a Multichain Wallet for Web3, while constantly enriching functions,we have also been doing our best in terms of security.

  • Blocking function for URL blacklist

If a blank page appears when you visit the URL, it means that you are likely to visit the reported and blocked website, please be vigilant to avoid being deceived.

(Welcome to report dangerous URLs, we will block them on our APP browser page after verification)

  • Scoring function for BNBChain contract’s security

When you do the operation with the contract, you can see this position, there is a score. This is the Meter system from AvengerDAO that we plugged in , which can realize the scoring function of BNBChain contract security.

AvengerDAO is a unique community-run security infrastructure project designed to protect users on BNB Chain from possible exploits, scams and malicious actors.

We are honored to be a part of AvengerDAO , and we continue our unwavering commitment to making the user experience on Web3 more secure and enjoyable

About AvengerDAO:

https://www.bnbchain.org/en/blog/introducing-avengerdao-the-security-initiative-protecting-users-from-malicious-actors/
  • Reminder function for TOKEN or NFT approval signature

When you do the operation with the contract, if you see this reminder in this position, it means that this is an approval signature, and the target address will have the right to transfer the approval asset without any operation from you. So you need to be vigilant and ensure its safety before proceeding.

(This reminder function can only identify some approval signatures, and only serves as a reminder. When performing any operation, you should confirm it again and again to ensure asset security)

  • Approval management function for EVM public chain

On the wallet page of the MathWallet APP, click the button in the upper right corner, and in the pop-up list, click the “Approvals” button

You will jump to REVOKE, a third-party DAPP that supports approvals management.

Through the DAPP, you can check the on-chain approval status of your wallet address, and you can revoke any time. This DAPP supports all EVM public chains.

—————————————————–

In order to further improve security awareness, we can learn about the common methods used by scammers

(General reasons for theft: 1. Private key leakage; 2. Contract approval)

Some Cases

  • Case 1: Phishing website steals private key 

AA is a new user entering the WEB3 world for the first time. The scammer put up special discounted items on a certain platform and trade with AA. Provide AA with a phishing website, guide him to download a pirated APP, and defraud his private key .Then the scammer transfers AA’s assets away.

Please remember the only official website of MathWallet:
mathwallet.org
  • Case 2: Fraud DAPP and Malicious Approve

BB has been in the WEB3 world for a while, and has a certain understanding of the basic functions of the wallet.

Through a certain social platform, BB learned about an unknown DAPP. And heard that it can make money, so he followed the tutorial given by others and interacted with it. One of the signatures was malicious approval . Subsequently, one of the tokens in the wallet account were secretly and totally transferred without any operation by BB.

What is malicious approval:

https://blog.mathwallet.org/?p=3638
  • Case 3: Malicious approval disguised as a transfer page

CC is trading with someone else, but this person is actually a scammer. The scammer provided CC with a QR code and guided him to scan the QR code to transfer token. The QR code jumps to a website, and the scammer carefully crafted it into a transfer page. As long as CC performs a signature operation, he will be maliciously approval. Subsequently, one of the tokens in the wallet account were secretly and totally transferred without any operation by CC.

(Tip: When using the mathwallet app, scan the QR code on the wallet token transfer page. If the QR code is not a wallet address, but a link, the app will pop up a window to prompt the link address details)

If you have other cases, please provide them to us to remind more people and avoid being deceived

—————————————————–

Raise safety awareness and Develop good usage habits

In the WEB3 world, security always comes first.

Remember:

  • Keep the mnemonic word and private key, and do not send it to others
  • Avoid mnemonics word and private keys touching the Internet
  • Don’t click on links provided by strangers
  • Don’t use unfamiliar third-party DAPPs
  • When performing on-chain operations, double-check the signature content
  • Regularly check the on-chain approval of wallet addresses

If you want to know more, you can read the previous security-related articles:

Security Guide of Math Wallet
Caution Malicious Approve
10 MathWallet Safety Tips
How to report scam DApp?
How to prevent fraud in discord/telegram community?

Please remember the only official website of MathWallet:

mathwallet.org