Three different things, and telling them apart is most of staying safe.
| What it is | What it protects | If somebody else gets it | |
|---|---|---|---|
| Private key | The secret number that owns your coins and pieces | everything | they own everything |
| Seed phrase | 12 or 24 words that regenerate your keys | everything | they own everything |
| Password | What encrypts your wallet in this browser and your backup file | both of those | time to try passwords |
The first two are the wallet. The third is the lock on every copy of it.
The only one of the three you will ever see on screen is your address, which is not on that list — it is public by design:
The seed phrase is the wallet, written down
A dozen ordinary words, in order. From them, the same keys can be rebuilt on any device, in any app, forever. That is why it is a backup — and why a photo of it in your phone gallery is a copy of your wallet in your phone gallery.
Where to keep it: on paper, offline, somewhere you would keep a passport. Not in email, not in a chat with yourself, not in a note synced to a cloud.
The password is the lock on your copies
Your password encrypts the wallet stored in this browser, and it also encrypts the backup file you export. Someone with your password and neither of those has nothing. And you with your password but no backup, on a wiped browser, also have nothing — see I cleared my browser data.
The other direction is the one people underestimate: whoever gets hold of your backup file has all the time in the world to try passwords against it — offline, with no limit on attempts, and without you finding out. That is why:
- Use a long password: several words, not one word with a number on the end.
- Keep it apart from the backup. The two in the same folder, or in the same email, is one thing and not two.
- Your backup file is your wallet. Treat it like the seed phrase: not in a shared drive, not in a synced note, not in your downloads folder for the next year.
A fingerprint or a face unlock does not change this. It unlocks your wallet for you, here; it does not protect the encrypted file, because the password route to it stays open for anybody who has the file. That is the real reason the password has to be a good one even if you rarely type it.
The one rule
Nobody legitimate will ever ask you for your seed phrase or your private key. Not support, not a moderator, not an admin, not a giveaway, not a «wallet validator», not us. Ever.
There is no exception to learn. Any message that asks is a theft attempt, however well it is written and however urgent it sounds. On Zoide there is nobody to ask, because we never receive your keys — a request in our name is proof it is not us.
Two habits that cost nothing
- Type the address of the site yourself or use your own bookmark. A convincing copy of a website is cheap to make; a wallet given to one is gone.
- Read what you are signing. A signature authorises a specific transaction. If a page asks you to sign something you did not initiate, stop.