Avalanche wallet security guide
A non-custodial wallet gives the user direct control of the private key. That removes a custodian from the transaction path, but it also means recovery phrases and private keys must be protected carefully.
Protect the recovery phrase and private key
Anyone who obtains either secret can control the wallet. Store recovery information offline in a location you control. Do not paste it into support chats, email, cloud notes or websites claiming to verify or synchronize a wallet.
Check the site before entering secrets
Use the wallet only from the intended HTTPS address. A visually identical phishing page can ask for the same recovery phrase. Bookmark the correct production address after the domain is selected and verify it before opening an existing wallet.
Start with a small transaction
When using a new wallet build, browser, device or recipient address, first send a small amount. Confirm the destination and transaction in an independent Avalanche explorer before transferring a larger balance.
Browser storage
This wallet can keep the currently opened wallet available after a page reload or browser restart. That convenience means secret wallet material is stored in the browser storage for this site until the user chooses Close wallet. Use this feature only on a trusted personal device with a protected operating-system account.
Tokens and contract addresses
Token symbols and names are not unique. When adding a token manually, verify its C-Chain contract address from a source you trust. A token using a familiar ticker can still be a completely different contract.
Practical checklist
- Use an updated browser and operating system.
- Keep the recovery phrase offline.
- Verify recipient addresses before signing.
- Keep enough AVAX for network fees.
- Avoid unknown browser extensions on a device used for crypto.
- Use Close wallet on shared or serviced devices.
For operational questions, see Help.