Security Guide

Crypto security is your responsibility. Learn how to protect yourself.

What is Self-Custody?

Sora Wallet is a self-custody wallet. This means you have complete control over your funds — no one, including us, can access, freeze, or recover your assets.

This is powerful, but it also means you are responsible for your own security. If you lose your recovery phrase or fall for a scam, there's no way to reverse it.

Key Security Tips

Never share your recovery phrase

Your recovery phrase is the master key to your wallet. Anyone who has it can steal all your funds. No legitimate service, including Sora, will ever ask for it.

Verify website URLs carefully

Scammers create fake websites that look identical to real ones. Always double-check the URL before connecting your wallet or signing transactions.

Read transaction details before signing

Malicious dApps can request transactions that drain your wallet. Always read what you're signing. If something looks suspicious, reject it.

Use a strong, unique password

Your wallet password protects access on your device. Use a strong password that you don't use anywhere else.

Common Scams to Avoid

Fake Airdrops

You receive random tokens or NFTs in your wallet. When you try to interact with them, you're taken to a malicious site that steals your funds.

Prevention: Ignore unexpected tokens/NFTs. Never visit links from tokens you didn't buy.

Phishing Sites

Fake websites that look like real dApps or wallet sites. They ask you to enter your recovery phrase to "connect" or "verify" your wallet.

Prevention: Bookmark trusted sites. Never enter your recovery phrase on any website.

Fake Support

Someone on Twitter/Discord/Telegram claims to be from "Sora support" and offers to help with your issue, then asks for your recovery phrase.

Prevention: We never DM first. We never ask for your recovery phrase. Ever.

Malicious Transactions

A dApp requests you to sign a transaction that looks harmless but actually transfers all your assets to the attacker.

Prevention: Read transaction details carefully. If you don't understand it, don't sign it.

Red Flags

Be immediately suspicious if:

  • Anyone asks for your recovery phrase or private key
  • A website asks you to "validate" or "sync" your wallet
  • You receive an unexpected airdrop with a link to claim more
  • Someone DMs you offering help with a crypto issue
  • An offer seems too good to be true (guaranteed returns, free money)

What Sora Will Never Do

  • We will never ask for your recovery phrase
  • We will never DM you first on social media
  • We will never ask you to send us crypto
  • We will never offer guaranteed investment returns

Report a Scam

If you encounter a scam targeting Sora users, please let us know so we can warn others.

Report to [email protected]