NFT Wallet Security and Scams 4 — Questions and Answers
Question 1: Which on-chain tool allows you to review and revoke token approvals you have previously granted?
- Etherscan's token approval checker or Revoke.cash (Correct answer)
- Your wallet's backup recovery tool
- The NFT marketplace's refund portal
- MetaMask's gas estimation dashboard
Correct answer: Etherscan's token approval checker or Revoke.cash
Tools like Revoke.cash and Etherscan's token approval section let you see and cancel active approvals before scammers can exploit them.
Question 2: What is 'social engineering' in the context of NFT scams?
- Using blockchain analytics to trace stolen NFTs
- Manipulating people psychologically to reveal private keys or sign malicious transactions (Correct answer)
- Automating bot purchases during high-demand mints
- Creating fake NFT collections using AI-generated art
Correct answer: Manipulating people psychologically to reveal private keys or sign malicious transactions
Social engineering exploits human trust and emotion rather than technical vulnerabilities to trick victims into compromising their own wallets.
Question 3: A pop-up on an NFT site says your wallet is 'compromised' and asks you to enter your seed phrase to secure it. What is this?
- A legitimate security alert from your wallet provider
- A phishing attack designed to steal your seed phrase (Correct answer)
- A mandatory KYC verification process
- An official smart contract migration prompt
Correct answer: A phishing attack designed to steal your seed phrase
No legitimate service ever asks for your seed phrase; this is a classic phishing technique to gain full control of your wallet.
Question 4: Which action is considered best practice before interacting with a new NFT smart contract?
- Sending your entire ETH balance to test gas costs
- Checking the contract's audit status and reading community feedback (Correct answer)
- Approving all token permissions upfront to save gas later
- Sharing the contract address in Discord for fast feedback
Correct answer: Checking the contract's audit status and reading community feedback
Reviewing third-party security audits and community reports helps identify red flags before committing funds to an unknown contract.
Question 5: What is 'wash trading' and why is it considered deceptive in NFT markets?
- Cleaning metadata from stolen NFTs to resell them
- Selling an NFT between wallets you control to inflate apparent trading volume and price (Correct answer)
- Using multiple accounts to vote on governance proposals
- Submitting false ownership records to a marketplace
Correct answer: Selling an NFT between wallets you control to inflate apparent trading volume and price
Wash trading creates the illusion of demand and rising prices by cycling an NFT between self-controlled wallets, misleading genuine buyers.
Question 6: What risk does connecting your primary wallet to an unknown decentralized application (dApp) carry?
- Your wallet address becomes publicly visible on-chain
- You may unknowingly grant the dApp approval to move your assets (Correct answer)
- Your internet service provider is notified of the connection
- Your NFTs are automatically listed for sale on the dApp
Correct answer: You may unknowingly grant the dApp approval to move your assets
Malicious dApps can present deceptive transaction approval requests that give them control over your tokens and NFTs.
Question 7: Which red flag suggests that an NFT influencer promotion may be a paid pump-and-dump scheme?
- The influencer discloses a paid partnership clearly in the post
- The influencer hypes the project urgently without disclosing compensation (Correct answer)
- The influencer compares the project to existing verified collections
- The influencer asks followers to do their own research
Correct answer: The influencer hypes the project urgently without disclosing compensation
Undisclosed paid promotions with artificial urgency are a hallmark of pump-and-dump schemes designed to inflate prices before insiders sell.
Which on-chain tool allows you to review and revoke token approvals you have previously granted?