KhipuVault Docs

Security Best Practices

User security guide for wallet safety, phishing prevention, and protecting your Bitcoin on KhipuVault.

Security Best Practices

Your security is your responsibility. This guide covers essential best practices to protect your Bitcoin and stay safe while using KhipuVault.

Critical: You Control Your Keys

KhipuVault is non-custodial. We never have access to your private keys. If you lose your keys or get hacked, we cannot recover your funds.

Wallet Security

Choose the Right Wallet

For Large Amounts ($1,000+)

๐Ÿ” Hardware Wallets (Most Secure)

  • โœ… Ledger Nano X/S Plus: Industry standard, proven security
  • โœ… Trezor Model T/One: Open-source hardware wallet
  • โœ… GridPlus Lattice1: Advanced features, card-based signing

Benefits:

  • Private keys never leave the device
  • Protected against malware
  • Requires physical confirmation for transactions

Setup Guide:

  1. Buy directly from manufacturer (never from third parties)
  2. Verify tamper-evident seals
  3. Generate new seed phrase (never use pre-generated)
  4. Store seed phrase securely offline
  5. Test recovery before depositing large amounts

For Small Amounts ($100-$1,000)

๐Ÿ’ป Software Wallets (Convenient)

  • โœ… MetaMask: Most popular, well-audited
  • โœ… Rainbow Wallet: User-friendly, mobile-first
  • โœ… Frame: Privacy-focused desktop wallet

Security Tips:

  • Use a dedicated browser profile for crypto
  • Enable password protection
  • Never use on public WiFi without VPN
  • Regularly update the wallet software

For Testing Only

๐Ÿงช Testnet Wallets

  • Use separate wallets for testnet
  • Never put real funds in testnet wallets
  • Clearly label test vs. production wallets

Seed Phrase Security

Your seed phrase (12-24 words) is the master key to your funds.

NEVER Share Your Seed Phrase

Anyone with your seed phrase can steal ALL your funds. No legitimate service will EVER ask for it.

โœ… DO:

Backup Securely

  • โœ… Write on paper or steel (fireproof/waterproof)
  • โœ… Store in multiple secure locations (safe, safety deposit box)
  • โœ… Consider splitting across multiple locations
  • โœ… Use a passphrase (25th word) for additional security
  • โœ… Test your backup by restoring a small amount

Physical Security

  • โœ… Store in fireproof/waterproof container
  • โœ… Use tamper-evident bags
  • โœ… Consider professional storage (bank vault)

โŒ DON'T:

Digital Storage

  • โŒ Take photos of your seed phrase
  • โŒ Store in cloud services (Google Drive, Dropbox, iCloud)
  • โŒ Save in password managers
  • โŒ Send via email, SMS, or messaging apps
  • โŒ Type on any device connected to internet

Sharing

  • โŒ Share with anyone (family, friends, support)
  • โŒ Enter on any website
  • โŒ Read aloud in public or on video calls

Private Key Hygiene

Create Dedicated Wallets

Use separate wallets for different purposes:

  • ๐Ÿฆ Savings Wallet: Large amounts, hardware wallet
  • ๐Ÿ’ฐ DeFi Wallet: Active DeFi use, moderate amounts
  • ๐Ÿงช Test Wallet: Trying new protocols, small amounts
  • ๐ŸŽฎ NFT Wallet: NFTs and gaming, separate from funds

Never Reuse Wallets

Once a wallet is compromised or suspicious:

  • โœ… Create a new wallet immediately
  • โœ… Transfer funds to the new wallet
  • โœ… Never use the old wallet again
  • โœ… Revoke all approvals on old wallet

Manage Token Approvals

Check and revoke unnecessary approvals:

  1. Visit Revoke.cash or Etherscan Token Approvals
  2. Connect your wallet
  3. Review all approvals
  4. Revoke any unlimited or suspicious approvals

Token approvals allow contracts to spend your tokens. Unlimited approvals are a security risk if the contract is compromised.

Phishing Prevention

Phishing is the #1 way people lose crypto. Stay vigilant.

Verify URLs

Official KhipuVault Domains:

โœ… https://khipuvault.com - Main website โœ… https://app.khipuvault.com - Web app โœ… https://docs.khipuvault.com - Documentation โœ… https://api.khipuvault.com - API

Phishing Detection:

โŒ khipuva1t.com - Number "1" instead of "l" โŒ khipuvault.co - Different TLD โŒ khipu-vault.com - Extra hyphen โŒ khipuvault-app.com - Unofficial subdomain

Protection Steps:

  1. Bookmark the official site and always use the bookmark
  2. Check for HTTPS and valid SSL certificate
  3. Verify the exact domain before connecting wallet
  4. Use a password manager that auto-fills only on correct domains

Recognize Phishing Attempts

Email Phishing

๐Ÿšจ Red Flags:

  • Urgent action required ("Wallet will be locked!")
  • Requests for seed phrase or private keys
  • Links to "verify" or "validate" your wallet
  • Misspelled sender addresses
  • Poor grammar or formatting

โœ… Verify Legitimately:

  • Go directly to official website (don't click links)
  • Check our official social media for announcements
  • Contact support through official channels only

Social Media Phishing

๐Ÿšจ Red Flags:

  • DMs offering "support" or "help"
  • Fake customer service accounts
  • Giveaways requiring you to "validate" wallet
  • Links to "claim rewards"
  • Impersonation of team members

โœ… Protect Yourself:

  • Never respond to unsolicited DMs
  • Verify official accounts (blue checkmarks)
  • Never share personal information via DM
  • Report suspicious accounts

Discord/Telegram Scams

๐Ÿšจ Common Scams:

  • Fake admins offering "support" in DMs
  • "Exclusive investment opportunities"
  • "Whitelist" or "early access" requiring payment
  • Bots impersonating real users

โœ… Stay Safe:

  • Our admins will NEVER DM you first
  • All announcements are in public channels
  • Never click links from strangers
  • Enable 2FA on Discord/Telegram

Signature Safety

When interacting with KhipuVault, you'll be asked to sign transactions.

Safe Signatures:

โœ… Transaction signatures you initiated โœ… SIWE (Sign-In With Ethereum) for authentication โœ… Token approvals for specific amounts โœ… Contract interactions on verified contracts

Dangerous Signatures:

โŒ Blank signatures without clear purpose โŒ Off-chain signatures from unknown sources โŒ Unlimited token approvals to unverified contracts โŒ Permit signatures on unofficial sites

Before Signing:

  1. Read the transaction details carefully
  2. Verify the contract address matches official addresses
  3. Check the amount being approved or transferred
  4. Confirm the recipient is correct
  5. Question anything suspicious and cancel if unsure

Device Security

Your device security directly affects wallet security.

Computer Security

Operating System

โœ… Keep your OS updated (Windows, macOS, Linux) โœ… Enable automatic security updates โœ… Use antivirus software (Windows: Defender, Mac: built-in) โœ… Enable firewall

Browser Security

โœ… Use updated browsers (Chrome, Firefox, Brave) โœ… Install only verified extensions from official stores โœ… Review extension permissions regularly โœ… Consider a dedicated browser profile for crypto

Malware Protection

โœ… Install reputable antivirus software โœ… Scan downloads before opening โœ… Avoid pirated software โœ… Don't click suspicious links or attachments

Mobile Security

For Mobile Wallets

โœ… Enable device PIN/biometric lock โœ… Keep OS and apps updated โœ… Only install apps from official stores โœ… Review app permissions โœ… Enable remote wipe capability

Additional Protection

โœ… Use VPN on public WiFi โœ… Disable app auto-updates for wallet apps (review first) โœ… Backup your device regularly โœ… Don't jailbreak/root your device

Network Security

Public WiFi

โŒ NEVER access wallets on public WiFi without VPN โŒ NEVER sign transactions in public places โŒ NEVER check wallet balances on untrusted networks

Home Network

โœ… Change default router password โœ… Use WPA3 encryption (or WPA2 minimum) โœ… Update router firmware regularly โœ… Create guest network for untrusted devices

VPN Usage

โœ… Use VPN on public networks โœ… Choose reputable VPN providers โœ… Avoid free VPNs โœ… Enable VPN kill switch

Smart Contract Interactions

Verify Before Interacting

Check Contract Addresses

Before interacting with KhipuVault contracts:

  1. Verify on official docs: Contract Addresses
  2. Check block explorer: Verify source code is verified
  3. Compare addresses: Match exactly (character by character)

Official Contract Addresses (Mezo Testnet):

IndividualPool:  0xdfBEd2D3efBD2071fD407bF169b5e5533eA90393
CooperativePool: 0x323FcA9b377fe29B8fc95dDbD9Fe54cea1655F88
MezoIntegration: 0x043def502e4A1b867Fd58Df0Ead080B8062cE1c6
YieldAggregator: 0x3D28A5eF59Cf3ab8E2E11c0A8031373D46370BE6
MUSD:            0x118917a40FAF1CD7a13dB0Ef56C86De7973Ac503

Approve Safely

Token Approvals

When approving tokens:

โœ… Approve only the amount needed (not unlimited) โœ… Revoke approvals when done using the protocol โœ… Check existing approvals before adding new ones โœ… Use exact amounts instead of type(uint256).max

Example: Safe Approval

Approve Amount: 1000 MUSD (exact amount)
Spender: 0xdfBEd2D3efBD2071fD407bF169b5e5533eA90393 (verified contract)

Example: Dangerous Approval

Approve Amount: Unlimited
Spender: 0x123abc... (unverified contract)

Monitor Your Transactions

Use Block Explorers

Track all your transactions:

  • Mezo Testnet: explorer.test.mezo.org
  • Check transaction status
  • Verify amounts and recipients
  • Review contract interactions

Set Up Alerts

Enable wallet alerts for:

  • Large transactions
  • Token approvals
  • Failed transactions
  • Unusual activity

Account Security

Authentication

SIWE (Sign-In With Ethereum)

KhipuVault uses SIWE for authentication:

โœ… Cryptographic signatures prove wallet ownership โœ… No passwords to remember or leak โœ… Session expiration for added security โœ… One-time messages prevent replay attacks

Best Practices:

โœ… Sign out after each session (shared computers) โœ… Don't stay logged in on public devices โœ… Review the SIWE message before signing โœ… Clear browser cache regularly

Session Management

Wallet Connection Sessions

  • Sessions expire after 24 hours
  • Reconnect manually for added security
  • Disconnect wallet when not actively using

Disconnect Wallet After Use

  1. Click wallet icon in top-right
  2. Select "Disconnect"
  3. Close browser tab
  4. Lock MetaMask

Privacy Protection

Data Minimization

What We Collect

KhipuVault collects minimal data:

  • โœ… Wallet address (public on blockchain)
  • โœ… Transaction history (public on blockchain)
  • โœ… Session tokens (temporary)

What We DON'T Collect

  • โŒ Personal information (name, email, phone)
  • โŒ Private keys or seed phrases
  • โŒ IP addresses (beyond temporary logs)
  • โŒ Browsing history

On-Chain Privacy

Blockchain is Public

Remember:

  • All transactions are public and permanent
  • Wallet addresses can be linked to identity
  • Transaction patterns can reveal information

Privacy Best Practices

โœ… Use different wallets for different purposes โœ… Don't reuse deposit addresses โœ… Be aware that on-chain data is permanent โœ… Consider using privacy tools for sensitive transactions

Browser Privacy

Protect Your Activity

โœ… Use privacy-focused browsers (Brave, Firefox) โœ… Enable tracking protection โœ… Use ad blockers โœ… Clear cookies and cache regularly โœ… Consider using Tor for maximum privacy (advanced)

Emergency Response

If Your Wallet is Compromised

Act Immediately:

  1. Stop using the wallet - Don't make more transactions
  2. Create a new wallet on a secure device
  3. Transfer remaining funds to the new wallet
  4. Revoke all approvals on the compromised wallet
  5. Report the incident to support@khipuvault.com

What NOT to Do:

โŒ Don't panic and make hasty decisions โŒ Don't try to "negotiate" with attackers โŒ Don't click links in ransom messages โŒ Don't send funds to recover services (likely scams)

If You Suspect Phishing

If You Clicked a Phishing Link:

  1. Don't enter any information
  2. Close the tab immediately
  3. Run antivirus scan
  4. Check wallet for unauthorized transactions
  5. Revoke approvals on Revoke.cash
  6. Report the phishing site

If You Signed a Malicious Transaction:

  1. Transfer funds immediately to a new wallet
  2. Revoke all approvals on the compromised wallet
  3. Monitor for unauthorized transactions
  4. Contact support for guidance

Lost Access Recovery

If You Lost Your Device:

Hardware Wallet:

  1. โœ… Use your seed phrase to recover on new device
  2. โœ… Buy new hardware wallet from official source
  3. โœ… Restore using your seed phrase
  4. โœ… Transfer funds to verify recovery
  5. โœ… Optionally create new wallet for additional security

Software Wallet:

  1. โœ… Install MetaMask on new device
  2. โœ… Select "Import using seed phrase"
  3. โœ… Enter your 12/24 word seed phrase
  4. โœ… Verify all accounts are recovered

If You Lost Your Seed Phrase:

โŒ Cannot Recover - This is why backups are critical

Options:

  • If you still have access to the wallet, transfer funds NOW to a new wallet
  • If you lost the device too, funds may be permanently lost
  • No one (including us) can recover funds without the seed phrase

Advanced Security

Multi-Signature Wallets

For large amounts or shared funds:

Benefits:

  • Requires multiple signatures to approve transactions
  • Reduces single point of failure
  • Ideal for DAOs, treasuries, or family savings

Popular Solutions:

  • Gnosis Safe (multi-sig standard)
  • Safe Wallet (formerly Gnosis Safe)

Setup:

  1. Create multi-sig wallet with 2-of-3 or 3-of-5 configuration
  2. Use different hardware wallets for each signer
  3. Store backups separately
  4. Test with small transactions first

Cold Storage

For long-term savings:

What is Cold Storage?

  • Hardware wallet never connected to internet
  • Maximum security for large holdings
  • Not convenient for frequent transactions

Setup:

  1. Initialize hardware wallet offline
  2. Generate and backup seed phrase
  3. Transfer funds to cold wallet address
  4. Store hardware wallet and seed separately
  5. Only connect to verify balance (not transact)

Smart Contract Wallets

Advanced wallet features:

Benefits:

  • Social recovery options
  • Spending limits
  • Programmable security rules

Options:

  • Argent Wallet
  • Safe Wallet
  • Gnosis Safe

Security Checklist

Daily Habits

  • Verify URLs before connecting wallet
  • Read transaction details before signing
  • Check contract addresses match official docs
  • Disconnect wallet after use
  • Ignore unsolicited DMs and emails

Weekly Maintenance

  • Review token approvals and revoke unnecessary ones
  • Check transaction history for anomalies
  • Update wallet software if available
  • Review connected dApps and disconnect unused ones
  • Backup new wallet data if applicable

Monthly Security Review

  • Update operating system and security software
  • Change passwords for related services
  • Review browser extensions and remove unused ones
  • Test seed phrase recovery process
  • Review security settings on Discord/Telegram
  • Check for KhipuVault security announcements

Before Large Transactions

  • Verify contract address multiple times
  • Test with small amount first
  • Ensure device is secure (antivirus, VPN)
  • Double-check recipient address
  • Review gas fees and transaction details
  • Confirm you have backups of everything

Resources

Security Tools

Wallet Security:

Phishing Protection:

Device Security:

Educational Resources

Beginner Guides:

Advanced Security:

Support

If You Have Questions:

If You Find a Vulnerability:


Remember: Security is a continuous practice, not a one-time setup. Stay vigilant, keep learning, and never compromise on security.

Your Bitcoin, your responsibility. ๐Ÿ›ก๏ธ

On this page