How to Protect your Metamask Wallet

Baran Orhan
Hacettepe Blockchain Topluluğu

--

Let's start wallet protection with the most crucial part. As you can guess, that is a 12-word seed phrase.

You have a couple of ways to store this phrase, but for keeping it more secure, we can give some steps:

  • You can write down the words in 2–3 places and store those notes in places that you think it is safe. You can visit here if you wonder how Vitalik Buterin stores his seed phrase.
  • As Metamask suggests at the beginning of wallet setup, you can use password manager applications. "Store this phrase in a password manager like 1Password."
  • While setting up your wallet, taking screenshots or taking pictures can cause security problems for your wallet.
  • The coolest but also near to impossible one is memorizing the seed phrase. It can be nearly impossible because you will have several wallets for different purposes most of the time. But also be careful about bad guys asking you about your seed phrase.

Adding Account and Private Key

In some blockchain projects, you may need more than one account. Instead of setting up new Metamask wallets, you can add an account with a new address to your wallet.

In this way, you can access your other accounts easily and connect them in seconds.

How do we add new accounts, and what is this private key they are talking about all the time?

Go to the Metamask website and select Create Account
Giving some suitable names for your account will make your job easier
As you can see, we have a new account with a new address.

Another good thing about adding new accounts to your wallet is quickly transferring tokens or coins between your accounts. Don't forget about the fee you will pay. Maybe selecting not busy times will make the fee lower and lower.

You can check the Ethereum gas fee from here. We want "gwei" to be at the lowest level while doing transactions. Every network has outstanding fees, so you better follow them.

Private Key

Friendly Reminder: Someone with access to your seed phrase can access all of your accounts in the wallet.

But why we are mentioning the private key. A private key is a long and hard-to-break key produced for every account. With this key, encrypted transactions in the blockchain are decrypted because we are in the "How to Protect your Metamask Wallet" article, explaining how Public/Private Key and Sign is tough.

You can check the video here, or you can wait for us to write about Keys and Signing :)

The most important thing about this key is those who have access to this key can also access your wallet.

!!!Please store your private key in secure places. As we mentioned above, it is as crucial as your seed phrase.

Now it is time for how to access your private key:

Checking the connected sites and permissions

Another way to ensure your wallet's security is

  • Check the sites you connected to before and disconnect them if you feel insecure about that site.
  • Checking the tokens or coins, you permitted and revoking them when you need to make your wallet more secure.

As seen with most people who have just started using "Hot Wallets":

Hold on, but what is Hot Wallet. "A hot wallet is a wallet that is always connected to the internet; they allow you to store, send, and receive tokens. Hot wallets are linked with public and private keys that help facilitate transactions and act as security measures." Investopedia says.

  • Give permissions to unproven sites with your main wallet. Instead of using the main wallet for all sites, create a new Metamask wallet for trying new unknown sites.
  • Using the main wallet for different airdrops. While trying to get some airdrop, your connected -sites page will be full of non-secure sites.
  • Interact with SCAM tokens. Most of the time, they have too many holders and total supply. And interacting with them via Decentralized Exchanges are making your wallet un-secure.

Let's see how we can disconnect from the connected sites:

You can see the sites you have connected to before, and you can disconnect from the sites when you feel it is not secure.

How to take permissions you have given to tokens or coins from sites that you traded before:

Step 1-Copying the wallet address.
Step 2-After reaching the https://etherscan.io/, paste your wallet address in the search bar.
Step 3- On the page More>Token Approvals.
Step 4- We can see the permissions we have given before and revoke them on this page. But do not forget about the fees you will pay.

With all the steps, you can make your Metamask wallet or Hot wallets more secure.

Thank you for your time.

We are waiting for your comments about the article.

hacettepe.blockchain@gmail.com | a.baranorhan@gmail.com | LinkedIn

--

--