Self-custody wallet guide · 4 min read

7 things every self-custody wallet holder should know.

Understand recovery phrases, cold wallets and dapp permissions—then use a read-only public-address tool inside the guide.

Remember these first

  • A recovery phrase never belongs in a website.
  • A cold wallet protects keys—not every decision.
  • Connecting, signing and approving are different actions.

The essentials

Understand the basics before you connect.

The first four checks explain what your wallet can protect—and what still depends on your judgment.

1

Keep recovery phrases and private keys offline

A recovery phrase can recreate a wallet, and a private key can authorize actions for an account. Never type either into a website, send it to “support,” save it in a cloud note, or store it as a screenshot. A public-address checker does not need them.

A public address is different: it cannot sign, but its blockchain activity is public.

2

Know what a cold wallet protects

A cold wallet keeps signing keys offline; a hardware wallet is a common example. It can reduce key-extraction risk, but a wrong recipient, unfamiliar contract or excessive approval can still take effect if you confirm it on the device.

3

Separate connecting, signing and approving

Connecting usually lets a dapp see your public address. Signing confirms a message or transaction. A token approval gives a contract a recorded spending allowance.

Disconnecting a site does not cancel an approval already recorded onchain.

4

Treat polished dapps as claims, not proof

A risky page may imitate a familiar project, or a previously legitimate site may be compromised. HTTPS, a logo and polished design are not proof of safety. Check the domain, network, contract, asset, recipient and allowance.

Put the guide into practice · optional tool

Review recorded token approvals using a public address.

No wallet connection, signature or transaction. Results are limited to the listed networks, token standards and data sources.

Start a read-only lookup

Choose a network and enter a public EVM address. We use it only to return this read-only report.

A public address reveals onchain activity. Never enter a recovery phrase or private key.

Query values and results are excluded from this page’s advertising and analytics events. How data is handled

  • No wallet connection
  • No signature
  • No transaction
  • No recovery phrase

Independent educational resource and public-data tool. It is not a wallet, exchange, recovery service or safety certification.

5supported EVM networks
ERC-20indexed approvals only
0signatures or transactions

From evidence to action

Read the result, then check your intent.

These final three checks help you interpret an allowance without turning a data point into a verdict.

5

Give maximum allowances extra attention

Some dapps request the maximum token allowance to avoid repeated approvals. The permission may remain until it is changed or revoked. This is not proof of wrongdoing; confirm that you recognize and still use the spender.

6

Match every request to your intent

A signature is not always a transfer, but it may still grant permission or have onchain consequences. If the request does not match what you intended, cancel and verify through an independent official source.

7

Review old approvals without treating the report as a verdict

Review every network you use after trying a new dapp, when you stop using one and as a regular habit. Unfamiliar does not mean malicious, and identified does not mean safe. Revoking is a separate onchain action that normally requires a network fee.

A report is evidence, not a verdict.

The tool organizes records returned by the named source. It does not inspect every token standard, prove a wallet is safe, or decide whether an approval should remain.

Maximum allowance
The provider returns the allowance as “Unlimited.” The interface does not invent a separate high-value threshold.
Approval date
The latest approval timestamp supplied by the source. Age alone is not treated as a risk signal.
Source code verified
The spender metadata reports published source code. This is context, not a safety endorsement.
Read the full methodology

Original references

Continue with primary sources.

Use official documentation and reputable explorers when a permission or request needs more context.

Questions before you check

Can someone control my wallet using only its public address?

A public address does not provide signing authority. It does expose public blockchain activity linked to that address, so do not treat it as private information.

Does “Not identified” mean an approval is harmful?

No. It means the listed source does not clearly associate the spender with a named project. Review the address, transaction and dapp you used at that time.

Can this page remove an approval?

No. This page is intentionally read-only. Changing or revoking an approval is a separate onchain action that should be reviewed in a trusted wallet or explorer.