Okay, before we get into the full list, here's the one move that saves most people from instant regret on Solana. Every time your wallet pops up a transaction to sign, hit that simulate button if it's there-like in Phantom or Solflare. It shows you exactly what changes: your SOL balance dropping by 0.5? Some random token approval for unlimited spending? Boom, red flag. Why? Scammers hide nasty instructions in there, like draining all your tokens in one sneaky sig. I do this every time now. Saved me like 20 SOL last month from a fake airdrop site.
In my experience, Solana's fast as hell-transactions fly through at ~0.000005 SOL fees-but that speed means you gotta pause. Simulation fails sometimes on weird contracts, but when it works? Gold. Sound familiar? You've probably signed something blind before.
Look, phishing sites are everywhere on Solana. They copy Phantom's page perfectly but swap one letter-like phanton.app instead of phantom.app. You click a DM link from some "support" account, boom, you're typing your seed phrase.
So here's what I do: bookmark official sites only. Solana.com, phantom.app, solflare.com-drag 'em to your browser bar. Never type 'em fresh. And always eyeball the URL before connecting your wallet. Hover over links in Telegram or Twitter. If it's short.sol or some sketch domain? Nope.
But wait, there's more. Use sites like solscan.io or explorer.solana.com to verify any dApp address first. Paste the contract, see if it's got history or if it's brand new with zero txns. New contracts scream pump and dump.
This habit alone blocks 80% of wallet drainers. Trust me, I've seen friends lose stacks clicking bad links.
Real talk: your 12- or 24-word seed is god mode. Anyone with it owns your wallet. Scammers pose as Solana support on Discord, Telegram- "Hey, your wallet's hacked, send seed to verify!" Laughable, but it works on newbies.
Official rule: no legit team ever asks for it. Not Solana Foundation, not Phantom support, nobody. If they do? Block and report.
Store it right too. Write on paper or metal plate-fireproof stuff like steel bills for ~$20. Split into two spots: home safe and a bank box. No photos, no cloud, no Notes app. Screenshots sync everywhere. I keep mine in a waterproof pouch under lock and.
Why does this matter? Once leaked, it's gone forever-no chargebacks like banks. Solana's non custodial, you're the bank.
Don't put all eggs in one basket. I run three:
How to make 'em? In Solflare or Phantom, hit "Add/Recover Wallet" and generate new seeds. Fund via main wallet-send test 0.01 SOL first always.
| Wallet Type | What For | Max Hold | Security Level |
|---|---|---|---|
| Main | Staking, HODL | 100+ SOL | Hardware (Ledger/Keystone) |
| Daily | Swaps on Jupiter | 5-10 SOL | Software + Biometrics |
| Burner | Testing scams basically0.1 SOL | Software, no sweat if gone |
See? Layered risk. Scammers hit the burner, you're laughing. In my experience, this setup feels overkill till you need it.
Bonus: Revoke permissions monthly. In Phantom, go Settings > Trusted Apps > Revoke all sketchy dApps. They linger and approve spends quietly.
These are classic. Fake Elon Musk account: "Solana giveaway! Send 1 SOL, get 2 back!" Or Telegram group hyping a "100x gem" token with charts going parabolic.
Red flags? Unsolicited DMs promising riches. "Double your SOL" BS. Requests to send to unknown addresses for "unlocking."
Test it: they send first? Never happens. Real airdrops don't need your deposit. Pump and dumps crash after whales dump-early buys look legit till volume spikes and poof.
What's next? Verify teams on official Solana Twitter or Discord. No doxxed founders? Run. Poor grammar in messages? Instant no.
I usually ignore all "free money" noise. Pressure to act fast? That's the hook.
Solana txns bundle instructions. Scammers slip in "approve all tokens" or delegate ownership mid transaction. You see "claim airdrop," but it drains USDC too.
Before signing:
Fees ~0.000005 SOL, dirt cheap-but watch for high "priority fees" on fakes. Use Solscan to track post sign. Alerts on? Solflare pings your phone for every txn.
Hardware tip: Ledger shows details on device screen. Can't fake that. Software? Enable 2FA, biometrics, auto lock at 1 min.
Pro tip: small test txn first. Send 0.001 SOL to new address. Lands? Good. No? Wrong addr.
Software wallets? Handy but hackable via malware. Go hardware for real money-Ledger Nano or Solflare's card thing. Keys stay offline, you tap to sign. Costs ~$60-150, pays itself dodging one scam.
Habits I swear by:
Never mainnet on shared PC. Burner only.
The thing is, Solana's secure by design-parallel txns, no double spends easy-but user error kills most. Build these in, you're golden.
Drained? Stop. Cease all comms with scammer-they'll "help recover" for more cash. Check wallet history on Solscan for what/where.
Revoke all approvals via revoke.cash or wallet tools. Report to platform (Phantom support), Solana Discord, even FBI IC3 if US based-details matter for tracing.
Bank involved? APP scam rules might refund if you bought SOL via debit. But crypto? Gone usually. Lesson learned.
Honestly, most "recoveries" are secondary scams. Walk away, rebuild smarter. I've seen guys lose 100k chasing ghosts.
One more: stay in communities like Solana Reddit, but lurk-don't share wallet deets. Knowledge shared, not keys.