How to Spot a Fake Wallet App

My Wallet
How to Spot a Fake Wallet App

Fake wallet apps are phishing in installable form: they look like My Wallet, MetaMask, Trust Wallet, Phantom, or Keeper—then ask for your seed and empty the real accounts.

Quick answer

Only install from official links you typed or saved yourself—not from search ads, DMs, or “support” agents. A real non-custodial wallet like My Wallet will never need your seed phrase to “verify,” “boost,” or “unlock” anything. If an app demands the 12/24 words up front without a clear import flow you initiated, stop.

Why fakes work

  • Brand names are easy to misspell in store listings.
  • Screenshots and icons are trivial to copy.
  • Victims are rushed (“your wallet will be deleted in 1 hour”).
  • Seed entry looks normal during legitimate import—fakes abuse that screen.

Red flags before you install

  1. Download link arrived in a DM, Telegram reply, email, or pop-up.
  2. Search ad sits above the real site—check the URL character by character.
  3. Publisher name is a lookalike (MyWallet Official Support LLC style noise).
  4. App asks for seed immediately with fear language.
  5. Reviews are all five-star clones posted the same week.
  6. Spelling errors in the brand: My Wallet vs random “MyWall3t” builds.
  7. Requests for seed and SMS codes, remote desktop, or screen share.

Red flags inside a “wallet”

  • “Support mode” that uploads your phrase.
  • Airdrop claim that needs mnemonic entry on a website.
  • Transaction prompts you do not understand—especially infinite token approvals.
  • Customer “agent” in chat asking you to type words to prove ownership.

Official My Wallet support (@mysupport and documented channels) will not ask for your seed. Same rule for MetaMask, Phantom, Keeper, Rabby, Trust Wallet, Coinbase Wallet, and Ledger support.

Verification checklist

CheckPass looks like
Sourceget.mywallet.io or official store listing linked from the real site
URLExact domain; HTTPS; no extra hyphens/subdomains you do not recognize
PublisherMatches what the official site names
PermissionsNo bizarre demands unrelated to a wallet
CommunityCross-check announcement channels you already trust—not a new “help desk”

When in doubt, do not import a seed with real funds. Create a fresh empty wallet first and test.

If you already typed a seed into something shady

  1. Treat the phrase as burned.
  2. On a clean device with a verified app, create a new wallet.
  3. Move funds from the old wallet to the new address immediately (you may still have access until thieves finish draining).
  4. Never reuse the burned phrase.
  5. Review approvals on smart-contract chains if you signed unknown permits.

Healthy habits

  • Bookmark official download pages.
  • Prefer app-store links from the project site over generic search.
  • Keep a hardware cold path for large balances (hot vs cold).
  • Talk through scams with friends new to crypto—social pressure helps more than jargon.

Download My Wallet

Download My Wallet from the official link every time; you hold the seed—nobody else should ask for it.

FAQ

Can the App Store / Play Store host fakes?

Listings get abused. Publisher identity and the link path from the official website still matter.

Is a browser bookmark enough?

Bookmarks help. Still re-check after password-manager autofill to a lookalike you once mistyped.

What about WalletConnect QR codes?

Only scan codes on sites you intended to open. A QR can initiate signatures the same as a malicious button.

Does My Wallet store my seed on a server?

No. Non-custodial means the phrase stays with you. Anyone claiming they can “look it up” for you is lying.