Aides et financement
27 juillet 2026

A seed phrase or private key is not an ordinary login credential: possession can provide control over the wallet and its funds. Before sending, receiving, exchanging or restoring cryptocurrency, use the checks below to separate public transaction data from wallet secrets, verify the operation through independent sources and stop if any critical field changes. The process reduces avoidable errors but cannot eliminate phishing, device compromise, software defects, service failure, volatility or the consequences of an irreversible transfer.
Pause before opening a wallet, approving a transaction or transferring funds. If any of the following statements is true, do not proceed to signing or payment.
If a seed phrase or private key may already have been exposed, simply changing a wallet password is not an adequate response: the secret itself may still authorize control. Stop using the suspected wallet for new deposits, disconnect from the suspicious site or application, and follow the wallet provider’s official compromise procedure from a clean device. Never disclose the exposed words or key while seeking help.
A private key authorizes transactions for the corresponding blockchain account. A seed phrase, also called a recovery phrase, mnemonic or wallet backup, can be used by compatible wallet software to derive one or many private keys. BIP-39 describes how a mnemonic is converted into a seed for deterministic wallets; it is not a user-created password or a sentence that should be improvised. [2]
Anyone who obtains a valid private key can control the associated funds. A wallet backup can be even broader in scope because it may restore multiple accounts derived from the same seed. Official wallet guidance therefore treats both as secrets that must not be shared with support staff or entered into ordinary websites. [3]
| Data | Handling rule | Reason |
|---|---|---|
| Seed phrase or wallet backup | Keep offline and private; reveal only through the wallet’s documented recovery process on a trusted device. | It may restore the private keys and full wallet control. |
| Private key | Never send, publish, photograph or paste into support chats, exchange forms or unknown software. | It can authorize spending from the corresponding account. |
| Optional wallet passphrase | Protect separately according to the wallet’s official recovery design. | An exact passphrase may derive a different wallet; losing it can make that wallet inaccessible. [4] |
| PIN and device password | Keep private, but do not confuse them with a blockchain recovery backup. | They may protect a particular device or application without replacing the seed phrase. |
| Receiving address | Share when necessary, but verify it through a trusted channel. | It is intended for receiving funds, although publishing it may reduce financial privacy. |
| Transaction ID or txid | Record after broadcast if needed for tracking or support. | It identifies an on-chain transaction and can be checked with the appropriate block explorer. [5] |
| Order or application identifier | Store only as long as operationally necessary. | It can help the service locate an operation without exposing wallet secrets. |
Complete the first pass while preparing the operation. Complete the second pass immediately before the irreversible action: sending funds, confirming on a hardware device, approving a contract interaction or submitting a withdrawal. Do not reuse values from memory, transaction history or an old screenshot without checking them against the current operation.
| What to verify | Independent confirmation | What a discrepancy means |
|---|---|---|
| Seed phrase isolation: no part of the seed phrase or private key is required to create, receive, track or exchange an ordinary transaction. | Check the wallet’s official documentation from a known domain. Legitimate support should not request the recovery secret. Wallet providers explicitly warn that requests to “verify” a backup are phishing. [6] | Any unexpected request for the secret is a stop condition. Close the page or conversation without entering anything. |
| Backup integrity: the backup exists, preserves the exact word order and follows the wallet’s documented format. | Use only the wallet’s built-in backup-check function, if provided, and follow instructions shown by the trusted wallet or hardware device. Do not test a seed on a random “validator” website. | An incomplete, reordered or incompatible backup may fail during recovery. Resolve the backup issue before placing additional funds in the wallet. |
| Storage method: the recovery secret is protected from unauthorized access as well as fire, water, loss and accidental disposal. | Compare the arrangement with the wallet manufacturer’s official backup guidance. Common guidance warns against screenshots, email, cloud storage and other routine digital copies. [7] | A convenient but exposed copy increases theft risk; a single fragile copy increases loss risk. Redesign storage before continuing. |
| No improvised fragmentation: the phrase has not been casually divided among locations in a way that makes recovery ambiguous. | Confirm whether the wallet supports a standardized multi-share or threshold backup. Use only its documented creation and recovery process. | Homemade splitting may leave each fragment too revealing or make the complete backup impossible to reconstruct. Clarification is required before relying on it. |
| Correct domain and application: spelling, subdomain and application publisher match the expected service. | Use a previously saved bookmark, an independently obtained official-domain record or the provider’s verified application listing. HTTPS alone does not establish that a domain belongs to the intended operator. | A different domain, unexpected redirect or unfamiliar installer is a phishing signal. Stop and reopen the service through a trusted route. |
| Operation direction: send, receive, deposit, withdrawal or exchange direction matches the intended action. | Compare the wallet screen, service order and recipient instructions. Read the labels rather than relying on interface position or color. | A reversed direction can produce the wrong address, asset or payment requirement. Recreate the operation instead of editing it under pressure. |
| Asset identity: ticker, full asset name and, for tokens, the relevant contract identity are consistent. | Use the current deposit or withdrawal page and the project’s official documentation or a suitable block explorer. Do not identify a token only by its logo or ticker. | A matching ticker can still represent a different or counterfeit token. Stop until the asset is unambiguously identified. |
| Network compatibility: the same blockchain network is selected at the sending and receiving ends. | Check the recipient platform’s current deposit instructions and the sender’s network selector. Verify the network in a compatible explorer where applicable. | A format-compatible address does not prove that the intended network is supported. Wrong-network transfers may require complex recovery or may be unrecoverable. [8] |
| Current availability: the exact asset, network and direction are available for this operation. | Check the live order interface before creating the request. General support for an asset does not establish that every pair, network or direction is currently available. | If the requested route is absent, disabled or different, do not substitute another network without verifying both endpoints. |
| Terms and compliance requirements: displayed conditions are understood and can be met without exposing wallet secrets. | Review the current operation screen and official support information. Verification requirements can depend on the direction and the results of compliance checks. | Unclear requirements, conflicting instructions or a request to evade restrictions require clarification before an order is created. |
| Source of the destination data: the address and any routing fields came directly from the intended recipient or current deposit page. | Confirm through a second trusted channel where practical. Avoid copying an address from transaction history, unsolicited messages or public comments. | An address from an indirect source may have been replaced, poisoned or supplied by an impersonator. |
| Economic terms: send amount, network fee, service charges if displayed, rate basis and expected amount are distinguishable. | Compare the order summary with the wallet’s send screen. Treat estimates as estimates when the interface labels them that way. | An unexplained difference can indicate changed conditions, the wrong direction or an incorrect amount unit. Pause for clarification. |
| What to verify | Independent confirmation | What a discrepancy means |
|---|---|---|
| Full destination address: compare the entire address, including middle characters—not only a shortened prefix and suffix. | Read it from the recipient’s current instructions and compare it with the final wallet or hardware-device display. Address-poisoning attacks deliberately create lookalike entries in transaction histories. [9] | One different character means a different destination. Cancel the action and obtain a fresh address from the trusted source. |
| Clipboard result: the pasted address is identical to the source value. | Compare before and after pasting, preferably on a trusted hardware display when signing. | A changed value may indicate clipboard replacement, selection error or malicious software. Stop; do not correct only the visible field and continue on the same potentially compromised device. |
| Network: the wallet’s active network still matches the order and recipient deposit network. | Check the network name on both final confirmation screens and, where relevant, verify the expected chain identifier through official wallet documentation. | A network change after the first pass invalidates the earlier address and fee review. Return to Pass 1. |
| Memo, Tag, Payment ID or message field: determine whether it is required and, if so, compare every character. | Use the receiving platform’s current deposit screen. Some custodial platforms use an additional field to route a shared address to the correct account. [10] | A missing or incorrect required field can delay or prevent crediting. Do not send until the requirement is resolved. |
| Amount and unit: decimal placement, asset symbol and whether the field represents the amount sent or received. | Compare the final wallet confirmation with the operation summary. Recalculate independently if conversion between units is involved. | A different amount, unit or asset is a stop condition. Re-entering the value without finding the cause may repeat the error. |
| Final amount to receive: the current figure remains acceptable and is labeled as fixed, floating or estimated where applicable. | Use the latest summary shown before confirmation, not an earlier message or screenshot. | A changed figure may reflect updated conditions or a different operation configuration. Clarify it before transferring funds. |
| Transaction type: the wallet is requesting the intended transfer rather than an unlimited token approval, contract signature or unrelated permission. | Read the confirmation screen and verify the spender, contract and permission details through the wallet’s official transaction decoder or an appropriate explorer when available. | An unexpected approval or unreadable signing request may grant powers beyond the intended payment. Reject it and investigate. |
| Hardware-device display: destination, amount, network-related context and transaction type match the computer or phone screen. | Treat the trusted device display as the final signing checkpoint rather than approving automatically. | A mismatch can indicate interface manipulation or compromised host software. Reject the transaction. |
| Backup remains unused: no confirmation step asks for recovery words or a raw private key. | Ordinary transaction signing should occur within the wallet. A seed phrase is for documented recovery, not routine payment authorization. | A late request for wallet secrets is still phishing, even if earlier fields were correct. |
| Test transfer decision: for a new destination or unfamiliar network, assess whether a small preliminary transfer is practical. | Confirm that the recipient can identify and credit a test transaction, including any required Memo or Tag. Official platform guidance commonly recommends a test amount for unfamiliar routing details. [11] | If a test cannot be recognized or its fields do not match, do not send the remaining amount. A successful test reduces uncertainty but does not guarantee a later transfer. |
After both passes are complete, one possible next step is to check the current exchange direction and operation conditions. Confirm the exact asset and network before creating an order; availability can change and support for an asset does not imply support for every possible route.
| Outcome | When it applies | Next action |
|---|---|---|
| Continue the reconciliation | Sources are trusted, secrets remain isolated, and the asset, network and direction are consistent so far. | Proceed to the next check. Repeat all Pass 2 fields at the signing or sending screen. |
| Clarification required | A fee, expected amount, Memo requirement, availability condition or compliance request is unclear but there is no direct secret-exposure signal. | Pause the operation and use the service or wallet’s official support route. Provide only the minimum non-secret data needed for diagnosis. |
| Stop | A seed phrase or key is requested, the address or network differs, the domain is suspect, the signing request is unexpected, or destination data changed after verification. | Do not sign, send or approve. Close the session, preserve non-secret evidence and investigate from a clean, trusted environment. |
A delay or mismatch does not identify the cause by itself. Diagnose the operation in a fixed order and avoid sending a second transaction until the first one is understood.
If a confirmed transaction went to the wrong address, wrong network or incorrect routing field, recovery depends on who controls the destination and whether its systems technically support the transferred asset. Confirmed blockchain transactions generally cannot simply be reversed, and assistance must not be interpreted as a promise of return. [8]
If the displayed amount differs from the expectation, first separate the network fee, service charge if disclosed, exchange-rate movement and an incorrect asset or unit. Record what the interfaces actually show; do not invent a missing figure or accept an unexplained discrepancy.
| Threat | Typical signal | Response |
|---|---|---|
| Seed-phrase phishing | A fake wallet update, security alert, support form or recovery page requests the words. | Enter nothing. Close the page and access the wallet through its official application or known domain. |
| Address replacement | The pasted address differs from the copied value, or only the first and last characters appear to match. | Cancel the operation, compare the full address and assess the device for clipboard or other malware. |
| Address poisoning | A tiny or zero-value transaction places a lookalike address in wallet history. | Do not copy destination addresses from history. Retrieve them from the recipient’s current trusted instructions and verify the middle characters as well. [9] |
| Wrong network | The same asset name is offered on several networks, or the recipient does not list the selected chain. | Require an exact match between both endpoints. Do not assume that a visually valid address proves compatibility. |
| Exposed seed phrase or private key | The secret was entered on a website, sent to another person, photographed on a connected device or found by someone else. | Treat the wallet as potentially compromised. Follow the wallet provider’s official emergency process from a clean environment and avoid further deposits to exposed accounts. |
| Guaranteed-profit or recovery promise | Someone claims a transfer will produce assured returns or asks for another payment to release or recover funds. | Stop communication and verify the claim independently. Guaranteed crypto returns and unsolicited recovery offers are established fraud indicators. [1] |
Keep only the information needed to reconcile the operation, document a discrepancy or communicate with official support:
Do not store the seed phrase, private key, optional wallet passphrase, authentication codes, identity documents or unrelated personal information beside the transaction record. The practical endpoint of the audit is a verifiable public trail—order ID, network and txid—while every recovery secret remains outside the operational workflow.