WStaking

    Wallet safety

    WStaking wallet and transaction safety

    Check the network, contract, token, spender, approval amount, and requested action before confirming a WStaking wallet request.

    Before connecting a wallet

    Confirm the following before connecting:

    • The browser domain is wstaking.net.
    • The page was opened directly or through a link on the WStaking official-links page.
    • The selected blockchain network is supported by WStaking.
    • The wallet shown in the application is the wallet you intend to use.
    • The page does not request a seed phrase, recovery phrase, private key, or wallet password.
    • The page does not request remote access to the device or installation of unknown software.
    • Connecting reveals the public wallet address to the website. It does not by itself authorize token spending; later approvals or transactions can grant permissions or move assets.

    Understanding token approvals

    An ERC-20 approval allows a spender address to transfer up to a specified amount of a token from the wallet. Before approving, verify the token contract, not only the displayed symbol; confirm the spender is the expected WStaking contract for the selected network; and check that the allowance matches the intended amount.

    An unlimited approval allows the spender to transfer the approved token up to the wallet's available balance until the allowance is changed or revoked. It is not automatically malicious, but it creates greater exposure if the spender contract or wallet is compromised. An approval is specific to the token and spender on the connected network.

    Disconnecting a website from a wallet does not revoke existing token approvals. Review and revoke allowances separately through a trusted approval-management service or the relevant blockchain explorer.

    Check every wallet request

    Do not confirm until the wallet request matches the action selected in WStaking.

    • Network: confirm the wallet is connected to the intended network.
    • Destination contract: compare the complete address with the WStaking contract-reference page.
    • Requested function: check that it matches staking, claiming, adding funds, renewing, partial unstaking, or full unstaking.
    • Token and amount: confirm the symbol, token-contract address, and deposit, claim, add-fund, unstake, or approval amount.
    • Native-token value: confirm whether the transaction also sends the network's native token; do not accept an unexplained transfer.
    • Spender and allowance: for approval requests, confirm both values.
    • Gas and fee: review the estimated network fee and fee token.
    • Wallet simulation: stop if the wallet shows an unexpected asset transfer, malicious-contract warning, failed simulation, or unexplained permission.
    • Action sequence: an approval may be followed by a separate contract transaction. Confirm both requests independently.

    Action-specific checks

    Staking

    Confirm the network, token, staking-contract address, amount, APR, duration, lock period, and approval spender. After approval, verify the separate staking transaction before signing.

    Claiming rewards

    Confirm the selected position, displayed reward amount, claim function, destination wallet, network fee, and any signature or operational requirement shown by the app.

    Adding funds

    Confirm the existing position and added amount. Review how adding funds affects the stake start time, APR, duration, lock period, and reward calculation.

    Renewal

    Confirm the selected position, new term, APR, start time, lock conditions, and requested contract function.

    Partial unstaking

    Confirm the amount removed, remaining principal, reward effect, penalty, waiting period, and whether the selected contract version supports partial unstaking.

    Full unstaking

    Confirm the intended position. Review reward effects, any early-unstaking penalty, the unlock period, and the later release transaction. Where enabled, the unlock request uses the verified seven-day waiting flow.

    Signature and message requests

    A message signature is not always a blockchain transaction, but it can authorize login, account actions, or application requests. Do not sign an unreadable, unexplained, or unrelated message.

    Before signing, check the requesting domain, wallet address, complete message, nonce, deadline, network, contract, permission details, and whether the request matches the action selected in WStaking. WStaking uses message signing for specific application workflows such as referral binding; follow the purpose shown by the app and never disclose sensitive wallet credentials.

    • Requesting domain
    • Wallet address
    • Full message
    • Nonce, deadline, network, contract, or permission shown
    • Match with the selected WStaking action

    Warning signs

    • Unknown spender address.
    • Unexpected unlimited approval.
    • Wrong blockchain network.
    • Wrong token contract.
    • Destination contract does not match the contract-reference page.
    • Transaction function does not match the selected action.
    • Unexpected native-token transfer.
    • Wallet warning or failed simulation.
    • Repeated signing requests after a failed action.
    • A prompt opened from a private message, advertisement, shortened link, or unknown website.
    • A request for a seed phrase, private key, recovery phrase, or wallet password.
    • A request to send funds to a support, recovery, migration, or verification wallet.

    Before confirming any wallet action

    • Stop and read the complete wallet request.
    • Confirm the domain.
    • Confirm the network.
    • Confirm the full contract or spender address.
    • Confirm the token contract and amount.
    • Confirm the requested function.
    • Review the approval allowance.
    • Review gas and any native-token value.
    • Check wallet simulation and warnings.
    • Cancel if any information is unexplained or does not match the intended action.
    • Never provide a seed phrase, private key, recovery phrase, or wallet password.

    After a suspicious approval or transaction

    If you approved an unknown spender, connected to a suspicious website, or signed an unexpected request:

    • Disconnect the suspicious website from the wallet.
    • Review existing token approvals for the affected network.
    • Revoke unnecessary or suspicious allowances using a trusted approval-management service or the relevant explorer.
    • Review recent transactions, token transfers, and signatures.
    • Save the domain, spender address, contract address, transaction hash, message, and screenshots.
    • Contact WStaking through the support details on the official website.
    • Report phishing, impersonation, or a suspected vulnerability through responsible disclosure.
    • If the seed phrase or private key was exposed, treat the wallet as compromised; revoking approvals alone is insufficient.
    • Moving assets to a new wallet may be necessary, but only from a secure device and with a newly generated seed phrase.

    Related information