Almost nobody loses funds to sophisticated hacking. They lose them to a handful of things, and all of them are avoidable by habit rather than by knowledge.
1. Giving away the seed phrase
Somebody helpful in a chat asks you to «verify your wallet», «sync it», or «restore it» by entering your seed phrase or private key on a page.
Nobody legitimate ever needs it. Not us — we cannot even receive it. There is no situation, ever, in which somebody else's instructions are the reason you type your seed phrase.
Your seed phrase goes in one place: the import form you opened yourself, from the connect button, on a site whose address you typed. Nowhere else — no support, no chat, no page inside a piece of artwork.
2. A convincing copy of the site
A page identical to this one, on an address that differs by one character. Everything you type into it goes to somebody else.
This site is zoide.io, and its documentation is docs.zoide.io. Type it yourself or use your own
bookmark. Do not reach a marketplace through a link in a direct message.
On the real site, connecting is this button and nothing else:
3. Signing something you did not read
A signature approves a specific action. A page can ask you to sign something whose real effect is to hand over what you own.
If you did not start the action, do not sign it. Cancel and get back to it from the site itself.
Two rules that make this checkable:
- The password prompt only ever comes after you pressed something that signs. A request that arrives because you opened a link, or that appears on its own, is not ours.
- Read the amount and the destination your wallet shows you, and stop if they are not the ones you agreed. What happens on chain lists what each action should show.
4. Buying a fake
Anybody can inscribe a copy of anything and call it whatever they like.
Check the collection and its author on Zoide itself, not the explanation somebody gives you. Proof of origin explains what the badge does and does not prove — and a missing badge is never, by itself, a reason to trust a piece.
5. Guaranteed returns
Anybody promising a fixed return, a «doubling», or a risk-free yield on a collectible is describing something that does not exist. Zoide has no yield, no staking and no promised return, and prices here can go to zero.
Anyone telling you otherwise in our name is not us.
6. What you install in the browser that holds your wallet
Your wallet lives in this browser. An extension you granted access to the sites you visit can read what this site stores, including your encrypted wallet — and then take its time trying passwords against it, offline, without you noticing.
- Keep few extensions, and none that you cannot justify.
- Never paste code into the browser console because somebody told you it would «diagnose» something. No support, no guide and no page of ours will ever ask you to.
- Do not share your screen while your wallet is unlocked.
How Zoide talks to you, and how it does not
This is the part that makes every warning above usable.
The official channels are these three, and there is no fourth:
| Channel | Where to find it |
|---|---|
| Discord | The link in the site's own sidebar |
| X and Treechat | The links next to it, in the same place |
| [email protected] | The support address, also in the Privacy Policy |
Reach them from the site, not from a link somebody sends you. Anybody contacting you anywhere else in Zoide's name — another Discord server, another handle, another address — is not Zoide, however convincing the name looks.
And:
- Zoide never contacts you first. There is no private message on Zoide — the chat is a single public room and nothing else. Anybody writing to you privately «from Zoide» is not from Zoide.
- Every notification appears inside the site, in the bell. If something reaches you by mail or push and is not there when you open the site yourself, it is not ours.
- Nothing is ever paid or completed through a link somebody sends you. Subscribing, renewing, minting, buying and completing an accepted offer all happen from a button inside the site.
- A username and a bio prove nothing. Anybody can call themselves what they like and write in their bio that they work here.
And the part that scammers rely on you not knowing:
We cannot undo anything either. Not a transfer to a wrong address, not a purchase, not a cancelled listing. The same property that stops us from recovering your keys stops us from reversing your transactions. Anybody offering to «reverse», «recover» or «refund» something for you is a thief, whatever they claim to be.
If you think your device is compromised
Changing the password is not enough: if somebody already copied the encrypted wallet or your seed phrase, they can keep working on it with the password you no longer use.
From a device you trust, create a new wallet and move your pieces and your funds to it. Treat the old one as public.
The two-minute checklist
- Back up your wallet and keep the password separately — not in the same folder, not in the same email as the export. How.
- Use a long password: several words, not one. It is the only thing between a leaked backup and somebody else's wallet.
- Send a small amount first when a destination is new to you.
- Ask for the ordinals address, not «their address», when transferring a piece — the two look identical.
- Check your balance before repeating any action that looked like it failed.
Related
- Keys, seed phrases and passwords
- I cleared my browser data
- Cookie Policy — what is kept on your device, and the one connection to a third party