The Builder's Security Standard
Six controls. Fewer failure points.
Security works best when it does not depend on perfect judgment every time. These controls are designed to separate risk, protect credentials, slow down dangerous actions, and make common scams easier to recognize.
SeparateSeparate long-term storage from activity.
Do not make the wallet holding your most important assets the same wallet you routinely connect to unfamiliar apps, mints, links, or experiments. Keep a long-term wallet and a separate activity wallet funded only for what you need.
Why it matters: a mistake in an activity wallet does not have to expose your primary holdings.
ProtectTreat recovery credentials as the master key.
Your recovery phrase and private keys can provide control of your wallet. Keep recovery material private and offline when your wallet setup uses it. Do not send it through DMs, email, cloud notes, forms, support chats, or websites.
Rule: Mansioncoin, Phantom, Ledger, and legitimate support personnel do not need your recovery phrase to help you.
IsolateKeep long-term storage physically separated from daily activity.
A fresh or factory-reset phone can serve as a dedicated cold-storage device when it is reserved for the vault, kept away from normal browsing and apps, and kept offline except when deliberate wallet access requires otherwise. The protection comes from isolation and disciplined use, not from the device category printed on the box.
Important: every time any signing device is connected, updated, paired, or used to approve a transaction, its attack surface changes. Treat those moments deliberately.
VerifyVerify the destination before you connect.
Phishing sites can imitate legitimate brands closely. Verify the domain, token mint, destination address, and the action you are about to take. Use bookmarks or known official pages instead of trusting links delivered through unsolicited messages.
For $MANSION: use the official Verify page as the source for the project mint and official channels.
ReadRead the transaction before you sign.
A wallet signature is an authorization, not a routine popup to clear. Slow down. Read the transaction details your wallet presents, check the site and destination, and reject anything you do not understand or did not intend to initiate.
Default posture: uncertainty is a reason to reject the transaction, not a reason to click through it.
Distrust urgencyAssume unsolicited support is hostile.
Scammers use urgency, authority, giveaways, fake account warnings, and impersonation to get users to click, connect, disclose credentials, or sign. Do not troubleshoot a wallet through an unsolicited DM. Navigate to official support channels independently.
Remember: a professional-looking profile, website, or message is not proof of identity.