Wallet & Security Best Practices
1. Introduction
1.1 Purpose of the Document
This document provides guidelines and practical instructions to help users maintain the security of their cryptocurrency wallets, private keys, and platform access credentials within the BatBet ecosystem. The primary goal is to reduce the risk of asset loss, data compromise, and fraudulent activity related to crypto holdings and esports betting.
1.2 Why Wallet and Key Security Is Critical in the BatBet Ecosystem
All activity on the BatBet platform - including betting, case opening, and DAO participation - is conducted via blockchain wallets such as Phantom and similar Solana-compatible solutions. These wallets serve as the sole means of user authentication and asset control. Losing access to a wallet or compromising a private key leads to irreversible loss of funds, as the platform neither stores nor has access to user keys. Therefore, protecting seed phrases and being aware of security threats is vital for safe and sustainable participation in the ecosystem.
1.3 User Responsibility for Security
While BatBet implements high security standards - including smart contract usage, transaction monitoring, and fraud prevention systems - the ultimate responsibility for wallet and asset protection lies with the user. Users are required to:
Secure their devices against malware and unauthorized access.
Keep their private keys and seed phrases confidential.
Use recommended tools such as two-factor authentication (2FA).
Any losses resulting from negligence or failure to follow security best practices will not be reimbursed by the platform.
2. Choosing and Using Crypto Wallets
2.1 Recommended Wallets
To interact securely and effectively with the BatBet platform, users should use trusted wallets that support the Solana blockchain. The following wallets are compatible with our ecosystem:
Phantom - One of the most popular browser and mobile wallets for Solana. It supports tokens, NFTs, and seamless dApp integration.
Solflare - A secure and feature-rich wallet with full support for Solana assets and multi-device access.
Backpack - A next-generation multifunctional wallet designed for the dApp ecosystem and XNFT support.
Ledger (hardware wallet) - A physical device used for cold storage of crypto assets. Recommended for storing large sums and long-term investment. Compatible with Phantom and Solflare via Ledger Live integration.
Important: Only use official wallet versions downloaded from verified sources (official websites, App Store, Google Play, or Chrome Web Store).
2.2 Criteria for a Reliable Wallet
When selecting a wallet to store your tokens and participate on the platform, consider the following criteria:
Solana compatibility - The wallet must fully support the Solana blockchain and its SPL token standard.
Open-source code - Transparency of the wallet's code allows community auditability and increased trust.
Reputation and audits - Check whether the wallet has undergone security audits and assess its standing within the crypto community. Give preference to actively maintained and reputable projects.
dApp integration - For full use of the BatBet platform, the wallet must support dApp features such as wallet connect and in-browser transaction signing.
Hardware wallet support - If you plan to use cold storage, ensure your wallet supports integration with devices like Ledger.
3. Protecting Your Seed Phrase and Private Keys
3.1 What is a Seed Phrase and Why It's Important
A seed phrase (recovery phrase) is a sequence of 12, 24, or 25 words generated when creating a crypto wallet. It serves as a master key to all funds and transactions associated with that wallet.
A private key is a unique cryptographic code that grants access to a specific wallet address and its funds.
⚠️ If an attacker gains access to your seed phrase or private key, they can fully control your wallet, transfer funds, sell assets, and act on your behalf. BatBet does not store your keys and cannot recover them. You are solely responsible for keeping them safe.
3.2 Best Storage Practices
Never store online Do not store your seed phrase or private key in cloud services, email drafts, messengers, screenshots, or on connected devices. These are prime targets for hackers and malware.
Use physical storage (paper or steel) Write your seed phrase on paper and store it securely, such as in a safe. For added resilience to physical damage (e.g., moisture or fire), consider using specialized steel backups.
Use hardware wallets Devices like Ledger or Trezor encrypt and isolate private keys, making them inaccessible even when connected to a compromised device. This is one of the safest methods for long-term storage.
3.3 Common Mistakes to Avoid
Storing screenshots Photos and screenshots can easily be accessed by malware or synced to cloud storage. Even temporary storage on a smartphone gallery can be dangerous.
Sharing with anyone - even under the pretense of support Never share your seed phrase or private key with anyone - not even with someone claiming to be "support staff," a "project moderator," or through an "official message."
BatBet will never ask you for your private information. Anyone who does is attempting to scam you.
4. Platform Security
Anti-Phishing Measures
Phishing is one of the most common attack vectors targeting cryptocurrency users. Attackers often create fake websites, emails, or messages impersonating the project to steal private keys or trick users into approving unauthorized transactions. Below are key protective measures:
Verify the Website Domain Before entering sensitive information, signing transactions, or connecting your wallet, always double-check the website's URL. The official domain of the BatBet platform is: batbet.io Avoid similar-looking or deceptive variations (e.g., batbett.io, betbat.io), especially if the link comes via a chat message, ad, or email. The safest method is to bookmark the official site and only access it through that saved link.
Never Click Suspicious Links Links sent through Discord, Telegram, X (Twitter), or other messengers are frequent sources of phishing attacks. Even if a message appears legitimate or "official", do not click without verifying its source. Any wallet interactions (e.g., connect wallet, mint, claim, airdrop) must be done only through the official project website.
Enable Anti-Phishing Phrases in Wallets Wallets like Phantom and Solflare allow you to set an anti-phishing phrase - a custom word or sentence that appears during wallet authorizations or transaction requests. Be sure to set one up and always check for it before approving any actions. If the phrase is missing, you may be on a fake page.
5. Transaction Security
5.1 Manual Transaction Approval
Every blockchain transaction must be manually confirmed by the user. Before signing any operation in your wallet (e.g., NFT mint, placing a bet, withdrawing funds), always carefully review the following:
Transaction type -- Know exactly what action you're confirming.
Recipient address -- Ensure the destination wallet is correct and intended.
Amount -- Double-check the value being transferred, especially for large amounts.
Website source -- Always confirm that you're interacting with the official domain.
Never sign transactions blindly or under pressure. Interface spoofing is a common tactic used by attackers.
5.2 Smart Contract Verification Before Signing
When interacting with decentralized applications (dApps) - especially during initial wallet connections - it's essential to verify the smart contract:
Ensure the contract is published and audited (especially when using third-party dApps).
On the BatBet platform, all wallet interactions are conducted through officially verified smart contracts on the Solana blockchain.
Avoid signing unnecessary "Approve" or "Sign Message" prompts - such requests may give unauthorized access to your tokens.
Advanced users are encouraged to use blockchain explorers like Solana Explorer, Solscan, or SolanaFM to inspect contract details if there is any doubt about a transaction.
6. Protection Against Fraud and Hacks
6.1 Recognizing Social Engineering Scams
Social engineering is a manipulation technique where attackers trick users into voluntarily revealing confidential information. Common tactics include:
"Support agents" asking for your seed phrase or private key "to help solve an issue."
Fake admins in Discord/Telegram offering assistance or help.
Promises of prizes, bonuses, or exclusive access in exchange for wallet connection or transaction signing.
⚠️ BatBet will never ask for private keys, seed phrases, or message users first. Enable login alerts and always verify who you are communicating with before taking action.
6.2 Fake Tokens and Airdrop Scams
Users may receive unfamiliar tokens or messages about receiving a "gift." These are often traps:
Fake tokens mimic legitimate ones to lure users into interacting with them.
Airdrop scams redirect users to fake websites, asking them to "activate" a bonus by signing a malicious transaction.
Never interact with unknown tokens or connect your wallet to unverified sites. Only trust official links and sources.
6.3 Use of Official Information Sources
Always confirm information through BatBet's verified communication channels:
Official website: batbet.io
Discord, Twitter - only via links from the official website.
Avoid trusting the first search results, advertisements, or unsolicited messages. Impersonation is common in crypto.
6.4 Platform-Level Fraud Detection Measures
BatBet implements automated systems to detect suspicious behavior:
AI-based behavior analysis monitors for anomalies such as large withdrawals or multiple logins from different IPs.
Anti-fraud systems validate transactions against known secure patterns.
Immediate account restrictions may be applied upon detection of suspicious activity, followed by a request for identity verification or re-authentication.
These measures help protect users even in cases of partial account or device compromise.
7. Information Hygiene
"Information hygiene" refers to the consistent practice of digital safety habits that protect your devices and access to crypto wallets from malware, spyware, and unauthorized access. Even the most secure wallet can be compromised if your system is vulnerable.
7.1 Regular Software Updates
Always update your operating system, browsers, and wallets as soon as new versions are released.
Developers frequently patch vulnerabilities that can be exploited by attackers.
This is especially important for browser wallet extensions like Phantom and Solflare, which are common attack targets.
Enable automatic updates wherever possible to maintain maximum protection.
7.2 Device Protection (Antivirus, Firewall)
Use a trusted antivirus program and regularly perform full system scans.
Install and configure a firewall to monitor incoming and outgoing connections.
Avoid installing software from untrusted sources - even one malicious program can steal your seed phrase or redirect funds during a transaction.
⚠️ On mobile devices, avoid using rooted or jailbroken operating systems, as they introduce critical security vulnerabilities that can bypass app-level protections.
8. Recommendations for Professional Users
Users who manage significant amounts of tokens or NFTs, or who regularly interact with the BatBet platform, should apply additional layers of security beyond the basic guidelines. The following are advanced recommendations to ensure maximum safety.
8.1 Store Large Amounts Only in Cold Wallets
Cold wallets are wallets not connected to the internet (e.g., Ledger, Trezor, or paper wallets).
All long-term holdings and large balances should be stored exclusively in cold wallets.
Use them only when transferring funds, not for daily operations.
This ensures that even if your computer or browser wallet is compromised, your primary assets remain secure.
8.2 Wallet Separation: Storage vs. Betting
Storage wallet: highly isolated, used strictly for cold storage.
Active wallet: a separate "hot" or "working" wallet with limited funds, used for betting and interaction with BatBet and other dApps.
Benefits of separation:
Risk mitigation in case one wallet is compromised.
Clear risk control when interacting with external websites and smart contracts.
Easy replacement or reset of the working wallet without affecting long-term holdings.
9. Conclusion
9.1 Reminder of User Responsibility
The BatBet ecosystem is built on principles of decentralization and full user autonomy. This means that you alone own and control your assets-and you alone are responsible for their security.
No technical support team, administrator, or even the platform itself will be able to restore access to your wallet if you lose your private keys or seed phrase. Following the best practices outlined in this document is the minimum required to ensure safe participation in the project and the protection of your digital assets.
9.2 Useful Links and Resources
For your safety and convenience, always use official sources:
phantom.app - Phantom Wallet
solana.com - Solana Blockchain
docs.batbet.io - BatBet Project Documentation