Official Security & Custody Guide

Protect what you own.

In self-custody, security is part of ownership. A wallet can be protected by strong cryptography and still be lost through a stolen recovery phrase, a malicious signature, a fake support account, or one careless connection. The goal of this guide is simple: reduce the number of ways that can happen.

!
There is no legitimate reason to give anyone your recovery phrase or private key.

Anyone who has either can control the wallet. Mansioncoin support will never ask for them.

SEE WHAT WE WILL NEVER ASK FOR →

The Builder's Security Standard

Six controls. Fewer failure points.

Security works best when it does not depend on perfect judgment every time. These controls are designed to separate risk, protect credentials, slow down dangerous actions, and make common scams easier to recognize.

Separate

Separate long-term storage from activity.

Do not make the wallet holding your most important assets the same wallet you routinely connect to unfamiliar apps, mints, links, or experiments. Keep a long-term wallet and a separate activity wallet funded only for what you need.

Why it matters: a mistake in an activity wallet does not have to expose your primary holdings.

Protect

Treat recovery credentials as the master key.

Your recovery phrase and private keys can provide control of your wallet. Keep recovery material private and offline when your wallet setup uses it. Do not send it through DMs, email, cloud notes, forms, support chats, or websites.

Rule: Mansioncoin, Phantom, Ledger, and legitimate support personnel do not need your recovery phrase to help you.

Isolate

Keep long-term storage physically separated from daily activity.

A fresh or factory-reset phone can serve as a dedicated cold-storage device when it is reserved for the vault, kept away from normal browsing and apps, and kept offline except when deliberate wallet access requires otherwise. The protection comes from isolation and disciplined use, not from the device category printed on the box.

Important: every time any signing device is connected, updated, paired, or used to approve a transaction, its attack surface changes. Treat those moments deliberately.

Verify

Verify the destination before you connect.

Phishing sites can imitate legitimate brands closely. Verify the domain, token mint, destination address, and the action you are about to take. Use bookmarks or known official pages instead of trusting links delivered through unsolicited messages.

For $MANSION: use the official Verify page as the source for the project mint and official channels.

Read

Read the transaction before you sign.

A wallet signature is an authorization, not a routine popup to clear. Slow down. Read the transaction details your wallet presents, check the site and destination, and reject anything you do not understand or did not intend to initiate.

Default posture: uncertainty is a reason to reject the transaction, not a reason to click through it.

Distrust urgency

Assume unsolicited support is hostile.

Scammers use urgency, authority, giveaways, fake account warnings, and impersonation to get users to click, connect, disclose credentials, or sign. Do not troubleshoot a wallet through an unsolicited DM. Navigate to official support channels independently.

Remember: a professional-looking profile, website, or message is not proof of identity.

Storage Levels

Different tools protect against different risks.

There is no breach-proof wallet category. What matters is how keys are generated, where they are stored, how often the signing environment is exposed, what software or firmware must be trusted, and how carefully transactions are approved.

Everyday activity

Activity wallet

For routine swaps, app connections, and normal Web3 use. Keep only the amount needed for current activity and keep this wallet separate from long-term storage.

Optional alternative

Hardware signing device

Hardware wallets can isolate signing keys, but they are not automatically immune to vulnerabilities or operational failures. Device hardware, firmware, supply chain, companion software, integrations, recovery procedures, and the transaction being approved all remain part of the security model.

Non-Negotiable

Mansioncoin will never ask for:

If a person claiming to represent Mansioncoin asks for any of these, stop the conversation. Do not click their link, connect your wallet, or send them anything.

×
Your recovery phraseNo Mansioncoin employee, admin, moderator, or support process needs it.
×
Your private keyA private key controls the associated wallet. Do not disclose it.
×
Your wallet backup or exported credentialsDo not upload wallet backups or credential files for “verification” or troubleshooting.
×
Remote access to your deviceDo not install remote-control software so someone can “fix” or “secure” your wallet.
×
A screen share while exposing credentialsNever reveal recovery material or sensitive wallet screens during a call or screen share.
×
Tokens sent to “verify,” “unlock,” or “protect” your walletSending funds to a stranger is not a wallet-verification procedure.

Verify Before You Trust

Start from the official source.

Names, avatars, and screenshots can be copied. Addresses and official destinations should be checked independently. For Mansioncoin, the mint below is the primary token identifier.

Official $MANSION mint

Compare this full address before swapping or interacting with the token.

3srdiFxca22oK1g7qdbGGe9qXy4aS9QGVdTETCBFpump

Incident Response

Think your wallet may be compromised?

Stop interacting with the suspicious site, app, account, or message.

Do not keep clicking in an attempt to “undo” the problem through the same source.

Protect remaining assets using a fresh wallet and clean setup where appropriate.

If credentials may be exposed, moving remaining assets to newly generated credentials can be safer than continuing to use the affected wallet.

Do not reuse a recovery phrase you believe may have been exposed.

A new account derived from compromised recovery material does not solve the underlying credential problem.

Use the wallet provider's official support and security documentation.

Navigate to it independently. Do not use a “support” link delivered by the person or site you suspect.

Document what happened.

Save transaction signatures, wallet addresses, timestamps, screenshots, and relevant URLs without exposing recovery credentials.

Mansioncoin-Specific Control

What locking can and cannot protect.

An active on-chain time lock can prevent the locked tokens from being transferred before the lock expires. That can reduce accidental or impulsive transfer risk for those tokens during the lock period. It is not a replacement for wallet security: protect the wallet, recovery credentials, devices, and every unlocked asset independently. Review the exact lock terms before using any locking service.

Independent Security References

Read the platform guidance too.

Mansioncoin does not treat any wallet manufacturer or device category as infallible. These independent resources provide additional guidance on wallet safety, credential protection, and offline signing.

The Standard

Protect first.
Interact second.

Strong custody is not one clever trick. It is a system that keeps important credentials private, limits exposure, verifies destinations, and makes dangerous actions harder to take by accident.