{"id":4111,"date":"2022-11-08T09:25:47","date_gmt":"2022-11-08T09:25:47","guid":{"rendered":"https:\/\/blog.mathwallet.org\/?p=4111"},"modified":"2022-11-08T10:58:48","modified_gmt":"2022-11-08T10:58:48","slug":"security-guide-2022-of-math-wallet","status":"publish","type":"post","link":"https:\/\/blog.mathwallet.org\/?p=4111","title":{"rendered":"Security Guide 2022 of Math Wallet"},"content":{"rendered":"\n<p>MathWallet has supported multi-dimensional security reminders<\/p>\n\n\n\n<ul><li><strong>Blocking function for URL blacklist <\/strong><\/li><li><strong>Scoring function for BNBChain contract&#8217;s security<\/strong><\/li><li><strong>Reminder function for TOKEN or NFT approval signature<\/strong><\/li><li><strong>Approval management function for EVM public chain<\/strong><\/li><li><strong>etc<\/strong><\/li><\/ul>\n\n\n\n<p>In the WEB3 world, security has always been the top concern for everyone.&nbsp;How to better protect our assets, in addition to choosing safe tools, what is more important is our own security awareness and usage habits.<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<h4>MathWallet FunctionsRelated To Security Reminders<\/h4>\n\n\n\n<p>As a Multichain Wallet for Web3, while constantly enriching functions,we have also been doing our best in terms of security.<\/p>\n\n\n\n<ul><li><strong>Blocking function for URL blacklist<\/strong><\/li><\/ul>\n\n\n\n<p>If a blank page appears when you visit the URL, it means that you are likely to visit the reported and blocked website, please be vigilant to avoid being deceived.<\/p>\n\n\n\n<p>(Welcome to report dangerous URLs, we will block them on our APP browser page after verification)<\/p>\n\n\n\n<ul><li><strong>Scoring function for BNBChain contract&#8217;s security<\/strong><\/li><\/ul>\n\n\n\n<p>When you do the operation with the contract, you can see this position, there is a score. This is the <strong>Meter<\/strong> system from <strong>AvengerDAO<\/strong> that we plugged in , which can realize the scoring function of BNBChain contract security.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" src=\"https:\/\/mathwallet.oss-cn-hangzhou.aliyuncs.com\/blog\/2022\/11\/11.07\/%E5%9B%BE004%E5%90%88%E7%BA%A6%E6%89%93%E5%88%86.png\" alt=\"\" width=\"302\" height=\"621\"\/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote\"><p><strong>AvengerDAO<\/strong> is a unique community-run security infrastructure project designed to protect users on BNB Chain from possible exploits, scams and malicious actors.<\/p><p>We are honored to be a part of&nbsp;<strong>AvengerDAO<\/strong>&nbsp;, and we continue our unwavering commitment to making the user experience on Web3 more secure and enjoyable<\/p><p><strong>About AvengerDAO:<\/strong><\/p><cite><a href=\"https:\/\/www.bnbchain.org\/en\/blog\/introducing-avengerdao-the-security-initiative-protecting-users-from-malicious-actors\/\">https:\/\/www.bnbchain.org\/en\/blog\/introducing-avengerdao-the-security-initiative-protecting-users-from-malicious-actors\/<\/a><\/cite><\/blockquote>\n\n\n\n<ul><li><strong>Reminder function for TOKEN or NFT approval signature<\/strong><\/li><\/ul>\n\n\n\n<p>When you do the operation with the contract, if you see this <strong>reminder<\/strong> in this position,&nbsp;it means that this is an <strong>approval signature<\/strong>, and the target address will have the right to transfer the approval asset without any operation from you. So you need to be vigilant and ensure its safety before proceeding.<\/p>\n\n\n\n<p><strong>(This reminder function can only identify some approval signatures, and only serves as a reminder.&nbsp;When performing any operation, you should confirm it again and again to ensure asset security)<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" src=\"https:\/\/mathwallet.oss-cn-hangzhou.aliyuncs.com\/blog\/2022\/11\/11.07\/%E5%9B%BE005%E6%8E%88%E6%9D%83%E6%8F%90%E9%86%92.png\" alt=\"\" width=\"306\" height=\"629\"\/><\/figure>\n\n\n\n<ul><li><strong>Approval management function for EVM public chain<\/strong><\/li><\/ul>\n\n\n\n<p>On the wallet page of the MathWallet APP, click the button in the upper right corner,&nbsp;and in the pop-up list,&nbsp;click the &#8220;<strong>Approvals<\/strong>&#8221; button<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" src=\"https:\/\/mathwallet.oss-cn-hangzhou.aliyuncs.com\/blog\/2022\/11\/11.07\/%E5%9B%BE007%E6%8E%88%E6%9D%83%E7%AE%A1%E7%90%86.png\" alt=\"\" width=\"303\" height=\"625\"\/><\/figure>\n\n\n\n<p>You will jump to <strong>REVOKE<\/strong>, a third-party DAPP that supports <strong>approvals management<\/strong>.<\/p>\n\n\n\n<p>Through the DAPP, you can check the on-chain approval status of your wallet address, and you can revoke any time. This DAPP supports all EVM public chains.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" src=\"https:\/\/mathwallet.oss-cn-hangzhou.aliyuncs.com\/blog\/2022\/11\/11.07\/%E5%9B%BE006%E6%8E%88%E6%9D%83%E7%AE%A1%E7%90%86.png\" alt=\"\" width=\"306\" height=\"631\"\/><\/figure>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2013<\/p>\n\n\n\n<p>In order to further improve security awareness, we can learn about the common methods used by scammers<\/p>\n\n\n\n<p><strong>(General reasons for theft:   1. Private key leakage;   2. Contract approval)<\/strong><\/p>\n\n\n\n<h4>Some Cases<\/h4>\n\n\n\n<ul><li><strong>Case 1: Phishing website steals private key&nbsp;<\/strong><\/li><\/ul>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>AA is a new user entering the WEB3 world for the first time. The scammer put up special discounted items on a certain platform and trade with AA. Provide AA with a phishing website, guide him to download a pirated APP, and <strong>defraud his private key<\/strong> .Then the scammer transfers AA&#8217;s assets away.<\/p><cite>Please remember the only official website of MathWallet:<br><strong><a href=\"http:\/\/mathwallet.org\/\">mathwallet.org<\/a><\/strong><\/cite><\/blockquote>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" src=\"https:\/\/mathwallet.oss-cn-hangzhou.aliyuncs.com\/blog\/2022\/11\/11.07\/%E5%9B%BE002%E5%81%87%E5%AE%98%E7%BD%91%E6%8F%90%E9%86%92.jpg\" alt=\"\" width=\"303\" height=\"347\"\/><\/figure>\n\n\n\n<ul><li><strong>Case 2: Fraud DAPP and Malicious Approve<\/strong><\/li><\/ul>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>BB has been in the WEB3 world for a while, and has a certain understanding of the basic functions of the wallet.<\/p><p>Through a certain social platform, BB learned about an unknown DAPP. And heard that it can make money, so he followed the tutorial given by others and interacted with it. One of the signatures was <strong>malicious approval<\/strong> . Subsequently, one of the tokens in the wallet account were secretly and totally transferred without any operation by BB.<\/p><p><strong>What is malicious approval:<\/strong><\/p><cite><a href=\"https:\/\/blog.mathwallet.org\/?p=3638\">https:\/\/blog.mathwallet.org\/?p=3638<\/a><\/cite><\/blockquote>\n\n\n\n<ul><li><strong>Case 3: Malicious approval disguised as a transfer page<\/strong><\/li><\/ul>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>CC is trading with someone else, but this person is actually a scammer. The scammer provided CC with a QR code and guided him to scan the QR code to transfer token. The QR code jumps to a website, and the scammer carefully crafted it into a transfer page. As long as CC performs a signature operation, he will be <strong>maliciously approval<\/strong>. Subsequently, one of the tokens in the wallet account were secretly and totally transferred without any operation by CC.<\/p><cite><strong>(Tip: When using the mathwallet app, scan the QR code on the wallet token transfer page. If the QR code is not a wallet address, but a link, the app will pop up a window to prompt the link address details)<\/strong><\/cite><\/blockquote>\n\n\n\n<p>If you have other cases, please provide them to us to remind more people and avoid being deceived<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2013<\/p>\n\n\n\n<h4>Raise safety awareness and Develop good usage habits<\/h4>\n\n\n\n<p>In the WEB3 world, security always comes first.<\/p>\n\n\n\n<p><strong>Remember:<\/strong><\/p>\n\n\n\n<ul><li><strong>Keep the mnemonic word and private key, and do not send it to others<\/strong><\/li><li><strong>Avoid mnemonics word and private keys touching the Internet<\/strong><\/li><li><strong>Don&#8217;t click on links provided by strangers<\/strong><\/li><li><strong>Don&#8217;t use unfamiliar third-party DAPPs<\/strong><\/li><li><strong>When performing on-chain operations, double-check the signature content<\/strong><\/li><li><strong>Regularly check the on-chain approval of wallet addresses<\/strong><\/li><\/ul>\n\n\n\n<p>If you want to know more, you can read the previous security-related articles:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p><a rel=\"noreferrer noopener\" href=\"https:\/\/blog.mathwallet.org\/?p=399\" target=\"_blank\">Security Guide of Math Wallet<\/a><br><a href=\"https:\/\/blog.mathwallet.org\/?p=3638\">Caution Malicious Approve<\/a><br><a href=\"https:\/\/blog.mathwallet.org\/?p=3591\">10 MathWallet Safety Tips<\/a><br><a href=\"https:\/\/blog.mathwallet.org\/?p=867\">How to report scam DApp?<\/a><br><a href=\"https:\/\/blog.mathwallet.org\/?p=1665\">How to prevent fraud in discord\/telegram community?<\/a><\/p><\/blockquote>\n\n\n\n<p><strong>Please remember the only official website of MathWallet:<\/strong><\/p>\n\n\n\n<p><strong><a href=\"http:\/\/mathwallet.org\/\">mathwallet.org<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>MathWallet has supported multi-dimensional security reminders Blocking function for URL blacklist Scoring function for BNBChain contract&#8217;s security Reminder function for TOKEN or NFT approval signature Approval management function for EVM public chain etc In the WEB3 world, security has always been the top concern for everyone.&nbsp;How to better protect our assets, in addition to choosing [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"unlock_protocol_post_locks":""},"categories":[1],"tags":[136,9],"_links":{"self":[{"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=\/wp\/v2\/posts\/4111"}],"collection":[{"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4111"}],"version-history":[{"count":8,"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=\/wp\/v2\/posts\/4111\/revisions"}],"predecessor-version":[{"id":4120,"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=\/wp\/v2\/posts\/4111\/revisions\/4120"}],"wp:attachment":[{"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mathwallet.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}