NFT Art Wallet Security and Scams Questions and Answers — Questions and Answers
Question 1: You receive an unexpected direct message on social media from an account impersonating a famous NFT artist. The message contains a link to a 'surprise free mint' for their new collection. What is the most secure course of action?
- Use a 'burner' wallet with minimal funds to mint from the link, just in case.
- Ignore the message, block the user, and verify any official announcements on the artist's verified public channels. (Correct answer)
- Connect your main wallet to the site to check if it's legitimate, but do not sign any transactions.
- Reply to the message to ask for proof that they are the real artist before clicking the link.
Correct answer: Ignore the message, block the user, and verify any official announcements on the artist's verified public channels.
This scenario describes a classic phishing attack. Scammers impersonate trusted figures to create a sense of urgency and lure victims into clicking malicious links that drain their wallets. The safest action is to always disregard unsolicited links and independently verify information through official, public sources like a verified Twitter account or official website.
Question 2: What is the primary function of a 12 or 24-word 'seed phrase' (or recovery phrase) for a non-custodial crypto wallet?
- It is a public key used to receive NFTs and cryptocurrency from others.
- It is a master password used to restore access to all assets associated with the wallet if the device is lost or broken. (Correct answer)
- It is a temporary password that changes daily to enhance security against hackers.
- It is an encryption key for individual NFT files to prevent them from being copied.
Correct answer: It is a master password used to restore access to all assets associated with the wallet if the device is lost or broken.
A seed phrase, or recovery phrase, is a list of words that stores all the information needed to recover a crypto wallet and its contents. It acts as the master key, allowing you to restore your wallet on a new device. It must be kept private and secure, as anyone with access to it can control your assets.
Question 3: Which of the following is the most significant security advantage of using a hardware wallet (cold storage) over a software wallet (hot storage) for storing high-value NFTs?
- Hardware wallets allow for faster transaction speeds on the blockchain.
- Hardware wallets are typically free, while software wallets have subscription fees.
- Hardware wallets store private keys offline, making them immune to online threats like malware and phishing attacks. (Correct answer)
- Hardware wallets can store an unlimited number of NFTs, whereas software wallets have a storage limit.
Correct answer: Hardware wallets store private keys offline, making them immune to online threats like malware and phishing attacks.
The key difference is that hardware wallets store your private keys on a physical device, completely isolated from the internet. This 'cold storage' approach protects your assets from remote hacking, malware, or phishing scams that target internet-connected software ('hot') wallets. Transactions must be physically confirmed on the device itself, providing a crucial security layer.
Question 4: While attempting to list an NFT on a new, unverified marketplace, your wallet prompts you to sign a transaction with a 'Set Approval For All' request. What is the primary risk of approving this type of transaction on a malicious site?
- It gives the site permission to burn all the NFTs in your wallet.
- It allows the site's smart contract to transfer ALL NFTs from that specific collection out of your wallet without further permission. (Correct answer)
- It permanently links your wallet to the site's IP address, compromising your privacy.
- It only gives the site permission to transfer the single NFT you are trying to list.
Correct answer: It allows the site's smart contract to transfer ALL NFTs from that specific collection out of your wallet without further permission.
A 'Set Approval For All' transaction grants a smart contract permission to move all tokens of a specific type (like all NFTs from one collection) from your wallet. While legitimate marketplaces use this for listing, malicious sites exploit it. By tricking you into signing it, their contract can then drain every NFT from that collection from your wallet at any time.
Question 5: A scammer joins a project's Discord server, impersonates a member of the support team, and contacts you via direct message to help with a 'wallet issue'. They ask you to share your screen to guide you through the process. This is an example of what kind of attack?
- A blockchain 51% attack
- A smart contract exploit
- A Denial-of-Service (DoS) attack
- Social engineering (Correct answer)
Correct answer: Social engineering
Social engineering is a manipulation technique that exploits human psychology to gain access to sensitive information. In this scenario, the scammer uses impersonation and the pretense of offering help to build trust, with the ultimate goal of tricking the victim into revealing their seed phrase or approving a malicious transaction.
Question 6: You are interacting with a website and sign a transaction that you believe is for a simple action, like signing in. However, you later discover that NFTs have been transferred out of your wallet without a separate 'transfer' confirmation. What type of scam most likely occurred?
- A rug pull
- Wash trading
- Ice phishing (Correct answer)
- A pump and dump scheme
Correct answer: Ice phishing
Ice phishing is a Web3-specific scam where a user is tricked into signing a transaction that grants a malicious actor permissions to spend their tokens or NFTs. Unlike traditional phishing which aims to steal your private keys, ice phishing manipulates you into authorizing the scammer's contract, which can then execute transfers from your wallet on its own behalf.
You receive an unexpected direct message on social media from an account impersonating a famous NFT artist.
The message contains a link to a 'surprise free mint' for their new collection.
What is the most secure course of action?