Wallets: where to keep tokens you did not pay for

Written by the Crypto Gratis editorial team · Last reviewed

If you take one thing from this site: use a separate wallet for free-token activity, and keep nothing in it you would mind losing.

The throwaway wallet pattern

Claiming anything means connecting your wallet to software written by strangers. Most of it is fine. Some is designed to empty you out, and telling them apart in advance is harder than it sounds.

The fix is structural rather than vigilant. Keep two wallets:

A malicious contract can only take what the connected wallet holds.

What a recovery phrase is

Your twelve or twenty-four words are your wallet. Not a password protecting an account held somewhere — the mathematical origin of every key in it. Anyone with those words has the wallet, permanently, from anywhere.

Write it on paper. Store it somewhere physically safe. Never type it into anything except the wallet app itself when restoring — not a support chat, not a verification page, not a photo on your phone.

Which wallet, and which network

Any mainstream self-custody wallet is adequate. What matters far more than the brand is that you downloaded it from the official source, and that you understand it is self-custody: nobody can restore access for you.

Network matters here more than usual, because the projects on this site were deliberately built on cheap chains. GoodDollar uses Celo and Fuse, impactMarket uses Celo, Circles uses Gnosis. A wallet showing only Ethereum will not display those balances — the tokens are still there; adding the network reveals them. Never move these balances to Ethereum to "consolidate": the fees will exceed the value. See cashing out.

Token approvals: how wallets actually get drained

Most losses are not stolen recovery phrases. They are approvals the owner granted.

To let a contract move your tokens you sign an approval. Many interfaces request an unlimited approval for convenience, valid forever unless revoked. A contract that is later compromised — or was malicious all along — can use it months afterwards.

Read what you approve, prefer a capped amount, and revoke old approvals periodically through the relevant block explorer's approval tool.

Checklist

  1. Separate wallet for claims, holding nothing valuable.
  2. Recovery phrase on paper, offline, never typed elsewhere.
  3. Downloads only from the official domain, typed by hand.
  4. Read approval prompts; cap them where you can.
  5. Revoke old approvals occasionally.
  6. Ignore unexpected tokens that appear on their own.

See also: how the drains work in detail.

Sources

Everything above is based on the following. Where they and we disagree, they are right — check them before you act on anything here.