Security Best Practices
User security guide for wallet safety, phishing prevention, and protecting your Bitcoin on KhipuVault.
Security Best Practices
Your security is your responsibility. This guide covers essential best practices to protect your Bitcoin and stay safe while using KhipuVault.
Critical: You Control Your Keys
KhipuVault is non-custodial. We never have access to your private keys. If you lose your keys or get hacked, we cannot recover your funds.
Wallet Security
Choose the Right Wallet
For Large Amounts ($1,000+)
๐ Hardware Wallets (Most Secure)
- โ Ledger Nano X/S Plus: Industry standard, proven security
- โ Trezor Model T/One: Open-source hardware wallet
- โ GridPlus Lattice1: Advanced features, card-based signing
Benefits:
- Private keys never leave the device
- Protected against malware
- Requires physical confirmation for transactions
Setup Guide:
- Buy directly from manufacturer (never from third parties)
- Verify tamper-evident seals
- Generate new seed phrase (never use pre-generated)
- Store seed phrase securely offline
- Test recovery before depositing large amounts
For Small Amounts ($100-$1,000)
๐ป Software Wallets (Convenient)
- โ MetaMask: Most popular, well-audited
- โ Rainbow Wallet: User-friendly, mobile-first
- โ Frame: Privacy-focused desktop wallet
Security Tips:
- Use a dedicated browser profile for crypto
- Enable password protection
- Never use on public WiFi without VPN
- Regularly update the wallet software
For Testing Only
๐งช Testnet Wallets
- Use separate wallets for testnet
- Never put real funds in testnet wallets
- Clearly label test vs. production wallets
Seed Phrase Security
Your seed phrase (12-24 words) is the master key to your funds.
NEVER Share Your Seed Phrase
Anyone with your seed phrase can steal ALL your funds. No legitimate service will EVER ask for it.
โ DO:
Backup Securely
- โ Write on paper or steel (fireproof/waterproof)
- โ Store in multiple secure locations (safe, safety deposit box)
- โ Consider splitting across multiple locations
- โ Use a passphrase (25th word) for additional security
- โ Test your backup by restoring a small amount
Physical Security
- โ Store in fireproof/waterproof container
- โ Use tamper-evident bags
- โ Consider professional storage (bank vault)
โ DON'T:
Digital Storage
- โ Take photos of your seed phrase
- โ Store in cloud services (Google Drive, Dropbox, iCloud)
- โ Save in password managers
- โ Send via email, SMS, or messaging apps
- โ Type on any device connected to internet
Sharing
- โ Share with anyone (family, friends, support)
- โ Enter on any website
- โ Read aloud in public or on video calls
Private Key Hygiene
Create Dedicated Wallets
Use separate wallets for different purposes:
- ๐ฆ Savings Wallet: Large amounts, hardware wallet
- ๐ฐ DeFi Wallet: Active DeFi use, moderate amounts
- ๐งช Test Wallet: Trying new protocols, small amounts
- ๐ฎ NFT Wallet: NFTs and gaming, separate from funds
Never Reuse Wallets
Once a wallet is compromised or suspicious:
- โ Create a new wallet immediately
- โ Transfer funds to the new wallet
- โ Never use the old wallet again
- โ Revoke all approvals on old wallet
Manage Token Approvals
Check and revoke unnecessary approvals:
- Visit Revoke.cash or Etherscan Token Approvals
- Connect your wallet
- Review all approvals
- Revoke any unlimited or suspicious approvals
Token approvals allow contracts to spend your tokens. Unlimited approvals are a security risk if the contract is compromised.
Phishing Prevention
Phishing is the #1 way people lose crypto. Stay vigilant.
Verify URLs
Official KhipuVault Domains:
โ
https://khipuvault.com - Main website
โ
https://app.khipuvault.com - Web app
โ
https://docs.khipuvault.com - Documentation
โ
https://api.khipuvault.com - API
Phishing Detection:
โ khipuva1t.com - Number "1" instead of "l"
โ khipuvault.co - Different TLD
โ khipu-vault.com - Extra hyphen
โ khipuvault-app.com - Unofficial subdomain
Protection Steps:
- Bookmark the official site and always use the bookmark
- Check for HTTPS and valid SSL certificate
- Verify the exact domain before connecting wallet
- Use a password manager that auto-fills only on correct domains
Recognize Phishing Attempts
Email Phishing
๐จ Red Flags:
- Urgent action required ("Wallet will be locked!")
- Requests for seed phrase or private keys
- Links to "verify" or "validate" your wallet
- Misspelled sender addresses
- Poor grammar or formatting
โ Verify Legitimately:
- Go directly to official website (don't click links)
- Check our official social media for announcements
- Contact support through official channels only
Social Media Phishing
๐จ Red Flags:
- DMs offering "support" or "help"
- Fake customer service accounts
- Giveaways requiring you to "validate" wallet
- Links to "claim rewards"
- Impersonation of team members
โ Protect Yourself:
- Never respond to unsolicited DMs
- Verify official accounts (blue checkmarks)
- Never share personal information via DM
- Report suspicious accounts
Discord/Telegram Scams
๐จ Common Scams:
- Fake admins offering "support" in DMs
- "Exclusive investment opportunities"
- "Whitelist" or "early access" requiring payment
- Bots impersonating real users
โ Stay Safe:
- Our admins will NEVER DM you first
- All announcements are in public channels
- Never click links from strangers
- Enable 2FA on Discord/Telegram
Signature Safety
When interacting with KhipuVault, you'll be asked to sign transactions.
Safe Signatures:
โ Transaction signatures you initiated โ SIWE (Sign-In With Ethereum) for authentication โ Token approvals for specific amounts โ Contract interactions on verified contracts
Dangerous Signatures:
โ Blank signatures without clear purpose โ Off-chain signatures from unknown sources โ Unlimited token approvals to unverified contracts โ Permit signatures on unofficial sites
Before Signing:
- Read the transaction details carefully
- Verify the contract address matches official addresses
- Check the amount being approved or transferred
- Confirm the recipient is correct
- Question anything suspicious and cancel if unsure
Device Security
Your device security directly affects wallet security.
Computer Security
Operating System
โ Keep your OS updated (Windows, macOS, Linux) โ Enable automatic security updates โ Use antivirus software (Windows: Defender, Mac: built-in) โ Enable firewall
Browser Security
โ Use updated browsers (Chrome, Firefox, Brave) โ Install only verified extensions from official stores โ Review extension permissions regularly โ Consider a dedicated browser profile for crypto
Malware Protection
โ Install reputable antivirus software โ Scan downloads before opening โ Avoid pirated software โ Don't click suspicious links or attachments
Mobile Security
For Mobile Wallets
โ Enable device PIN/biometric lock โ Keep OS and apps updated โ Only install apps from official stores โ Review app permissions โ Enable remote wipe capability
Additional Protection
โ Use VPN on public WiFi โ Disable app auto-updates for wallet apps (review first) โ Backup your device regularly โ Don't jailbreak/root your device
Network Security
Public WiFi
โ NEVER access wallets on public WiFi without VPN โ NEVER sign transactions in public places โ NEVER check wallet balances on untrusted networks
Home Network
โ Change default router password โ Use WPA3 encryption (or WPA2 minimum) โ Update router firmware regularly โ Create guest network for untrusted devices
VPN Usage
โ Use VPN on public networks โ Choose reputable VPN providers โ Avoid free VPNs โ Enable VPN kill switch
Smart Contract Interactions
Verify Before Interacting
Check Contract Addresses
Before interacting with KhipuVault contracts:
- Verify on official docs: Contract Addresses
- Check block explorer: Verify source code is verified
- Compare addresses: Match exactly (character by character)
Official Contract Addresses (Mezo Testnet):
IndividualPool: 0xdfBEd2D3efBD2071fD407bF169b5e5533eA90393
CooperativePool: 0x323FcA9b377fe29B8fc95dDbD9Fe54cea1655F88
MezoIntegration: 0x043def502e4A1b867Fd58Df0Ead080B8062cE1c6
YieldAggregator: 0x3D28A5eF59Cf3ab8E2E11c0A8031373D46370BE6
MUSD: 0x118917a40FAF1CD7a13dB0Ef56C86De7973Ac503Approve Safely
Token Approvals
When approving tokens:
โ
Approve only the amount needed (not unlimited)
โ
Revoke approvals when done using the protocol
โ
Check existing approvals before adding new ones
โ
Use exact amounts instead of type(uint256).max
Example: Safe Approval
Approve Amount: 1000 MUSD (exact amount)
Spender: 0xdfBEd2D3efBD2071fD407bF169b5e5533eA90393 (verified contract)Example: Dangerous Approval
Approve Amount: Unlimited
Spender: 0x123abc... (unverified contract)Monitor Your Transactions
Use Block Explorers
Track all your transactions:
- Mezo Testnet: explorer.test.mezo.org
- Check transaction status
- Verify amounts and recipients
- Review contract interactions
Set Up Alerts
Enable wallet alerts for:
- Large transactions
- Token approvals
- Failed transactions
- Unusual activity
Account Security
Authentication
SIWE (Sign-In With Ethereum)
KhipuVault uses SIWE for authentication:
โ Cryptographic signatures prove wallet ownership โ No passwords to remember or leak โ Session expiration for added security โ One-time messages prevent replay attacks
Best Practices:
โ Sign out after each session (shared computers) โ Don't stay logged in on public devices โ Review the SIWE message before signing โ Clear browser cache regularly
Session Management
Wallet Connection Sessions
- Sessions expire after 24 hours
- Reconnect manually for added security
- Disconnect wallet when not actively using
Disconnect Wallet After Use
- Click wallet icon in top-right
- Select "Disconnect"
- Close browser tab
- Lock MetaMask
Privacy Protection
Data Minimization
What We Collect
KhipuVault collects minimal data:
- โ Wallet address (public on blockchain)
- โ Transaction history (public on blockchain)
- โ Session tokens (temporary)
What We DON'T Collect
- โ Personal information (name, email, phone)
- โ Private keys or seed phrases
- โ IP addresses (beyond temporary logs)
- โ Browsing history
On-Chain Privacy
Blockchain is Public
Remember:
- All transactions are public and permanent
- Wallet addresses can be linked to identity
- Transaction patterns can reveal information
Privacy Best Practices
โ Use different wallets for different purposes โ Don't reuse deposit addresses โ Be aware that on-chain data is permanent โ Consider using privacy tools for sensitive transactions
Browser Privacy
Protect Your Activity
โ Use privacy-focused browsers (Brave, Firefox) โ Enable tracking protection โ Use ad blockers โ Clear cookies and cache regularly โ Consider using Tor for maximum privacy (advanced)
Emergency Response
If Your Wallet is Compromised
Act Immediately:
- Stop using the wallet - Don't make more transactions
- Create a new wallet on a secure device
- Transfer remaining funds to the new wallet
- Revoke all approvals on the compromised wallet
- Report the incident to support@khipuvault.com
What NOT to Do:
โ Don't panic and make hasty decisions โ Don't try to "negotiate" with attackers โ Don't click links in ransom messages โ Don't send funds to recover services (likely scams)
If You Suspect Phishing
If You Clicked a Phishing Link:
- Don't enter any information
- Close the tab immediately
- Run antivirus scan
- Check wallet for unauthorized transactions
- Revoke approvals on Revoke.cash
- Report the phishing site
If You Signed a Malicious Transaction:
- Transfer funds immediately to a new wallet
- Revoke all approvals on the compromised wallet
- Monitor for unauthorized transactions
- Contact support for guidance
Lost Access Recovery
If You Lost Your Device:
Hardware Wallet:
- โ Use your seed phrase to recover on new device
- โ Buy new hardware wallet from official source
- โ Restore using your seed phrase
- โ Transfer funds to verify recovery
- โ Optionally create new wallet for additional security
Software Wallet:
- โ Install MetaMask on new device
- โ Select "Import using seed phrase"
- โ Enter your 12/24 word seed phrase
- โ Verify all accounts are recovered
If You Lost Your Seed Phrase:
โ Cannot Recover - This is why backups are critical
Options:
- If you still have access to the wallet, transfer funds NOW to a new wallet
- If you lost the device too, funds may be permanently lost
- No one (including us) can recover funds without the seed phrase
Advanced Security
Multi-Signature Wallets
For large amounts or shared funds:
Benefits:
- Requires multiple signatures to approve transactions
- Reduces single point of failure
- Ideal for DAOs, treasuries, or family savings
Popular Solutions:
- Gnosis Safe (multi-sig standard)
- Safe Wallet (formerly Gnosis Safe)
Setup:
- Create multi-sig wallet with 2-of-3 or 3-of-5 configuration
- Use different hardware wallets for each signer
- Store backups separately
- Test with small transactions first
Cold Storage
For long-term savings:
What is Cold Storage?
- Hardware wallet never connected to internet
- Maximum security for large holdings
- Not convenient for frequent transactions
Setup:
- Initialize hardware wallet offline
- Generate and backup seed phrase
- Transfer funds to cold wallet address
- Store hardware wallet and seed separately
- Only connect to verify balance (not transact)
Smart Contract Wallets
Advanced wallet features:
Benefits:
- Social recovery options
- Spending limits
- Programmable security rules
Options:
- Argent Wallet
- Safe Wallet
- Gnosis Safe
Security Checklist
Daily Habits
- Verify URLs before connecting wallet
- Read transaction details before signing
- Check contract addresses match official docs
- Disconnect wallet after use
- Ignore unsolicited DMs and emails
Weekly Maintenance
- Review token approvals and revoke unnecessary ones
- Check transaction history for anomalies
- Update wallet software if available
- Review connected dApps and disconnect unused ones
- Backup new wallet data if applicable
Monthly Security Review
- Update operating system and security software
- Change passwords for related services
- Review browser extensions and remove unused ones
- Test seed phrase recovery process
- Review security settings on Discord/Telegram
- Check for KhipuVault security announcements
Before Large Transactions
- Verify contract address multiple times
- Test with small amount first
- Ensure device is secure (antivirus, VPN)
- Double-check recipient address
- Review gas fees and transaction details
- Confirm you have backups of everything
Resources
Security Tools
Wallet Security:
- Revoke.cash - Manage token approvals
- Etherscan - Verify contracts and transactions
- Pocket Universe - Transaction simulation
Phishing Protection:
- MetaMask Phishing Detector - Built-in protection
- Scam Sniffer - Phishing database
- Web3 Security Extension - Additional protection
Device Security:
- Malwarebytes - Antivirus
- 1Password - Password manager
- ProtonVPN - Privacy-focused VPN
Educational Resources
Beginner Guides:
Advanced Security:
Support
If You Have Questions:
- ๐ Security FAQ
- ๐ฌ Discord #security
- ๐ง support@khipuvault.com
If You Find a Vulnerability:
- ๐ security@khipuvault.com
- ๐ฐ Bug Bounty Program
Remember: Security is a continuous practice, not a one-time setup. Stay vigilant, keep learning, and never compromise on security.
Your Bitcoin, your responsibility. ๐ก๏ธ