Received a suspicious message? Pause before acting
Phishing scams impersonate familiar brands, websites, or support staff to trick you into sharing sensitive information, installing malicious software, or approving actions that could put your assets at risk.
If someone pressures you with claims such as “your wallet has a problem,” “an urgent update is required,” or “your assets will be frozen,” pause. Do not continue through links, QR codes, or attachments in the message. Do not share your seed phrase, private keys, PIN, or passphrase.
Open the official UKey website yourself and verify the message through official channels. Knowing your name, order number, or wallet address does not prove that someone represents UKey.
How do I verify official UKey channels?
Use these starting points when downloading software, checking a product, or contacting support:
Official UKey Wallet downloads: Follow the download page to the official distribution channel for your platform.
UKey product authenticity verification: Follow the instructions to check your product.
Contact UKey support: Find the current official support options.
Check the full domain in your browser’s address bar, not just the page title or link text. Extra letters, look-alike characters, or an additional domain suffix can lead to a different website. A search ad, profile picture, verification badge, or HTTPS padlock does not by itself prove that a source is officially associated with UKey.
To check a social account, follow the links provided on the official website. Do not rely on an “official account list” sent by a stranger.
What do impersonation scams look like?
The examples below illustrate common tactics. They are not a list of incidents confirmed by UKey.
Suspicious request | What to do |
“I’m from UKey support. Send your seed phrase so I can check your wallet.” | Do not share recovery information. End the conversation and verify through official support. |
“Install this update or your wallet will stop working.” | Do not install message attachments or software from unfamiliar links. Check for updates through official channels yourself. |
“Connect your wallet and sign to complete a security check.” | A “verification” label is not a reason to sign. Check what the request actually authorizes. |
“Move your assets to a safe address to unfreeze or migrate your wallet.” | Do not transfer assets to an address provided by the sender. Verify the notice independently. |
“Claim a UKey reward by approving wallet access or paying an unlocking fee.” | Verify the offer through official channels. Do not approve an unclear action because of a promised reward. |
“Pay a recovery fee or provide your private key to recover stolen assets.” | Do not share secrets or trust promises of guaranteed recovery. |
What should I protect when restoring or signing?
Do not disclose your seed phrase or private keys to anyone, including someone claiming to be UKey support. Do not expose your PIN, passphrase, or recovery backup through chat, email, screenshots, screen recordings, or remote assistance.
Restoring or importing a wallet yourself is different from handing recovery information to someone else. UKey software wallets, hardware wallets, and backup products may use different workflows. Follow the official instructions for the product you are using. Do not enter your seed phrase into a page or form supplied in a message asking you to “verify,” “sync,” or “repair” your wallet.
Before signing, confirm that you initiated the action. Review the destination address, asset, amount, and permissions requested. When using a hardware wallet, also check what appears on the device. If the information is incomplete or you do not understand the request, reject it.
“Zero amount” or “no gas fee” does not mean no risk. Some approvals or signatures may allow assets to be moved later. A hardware wallet helps protect private keys, but it cannot decide whether every website, message, or permission request is trustworthy.
What if I have already clicked or taken action?
Stop interacting with the suspicious site or sender, then assess what you actually did. Opening a page alone does not mean your seed phrase was exposed, but it does not establish that everything is safe.
You only opened the page, without downloading, entering information, or signing: Close it, reject further downloads or permission requests, and check for automatic downloads or unusual prompts.
You downloaded or ran suspicious software: Do not open a downloaded file that you have not run. If you already ran it, stop using that device for wallet operations. Use another trusted device to seek support and arrange a malware check.
You connected your wallet: Disconnect the site and review your interactions to check whether you also signed anything or granted permissions. Disconnecting does not automatically revoke existing on-chain approvals.
You approved a permission or signed a request: Promptly identify the network, assets, and permissions involved. Use independently verified, trusted tools to address revocable approvals. Not every signature can be revoked, and revoking an approval cannot recover assets already transferred.
You entered your seed phrase or private key: Treat it as potentially exposed even if you did not click “Send” or “Submit.” Changing your PIN or app password will not invalidate the exposed secret. Promptly create a wallet with a completely new seed phrase on a trusted device and assess how to move remaining assets safely. Stop depositing into affected addresses. A new account under the same seed phrase is not a safe replacement.
If incoming funds are quickly transferred out automatically, do not repeatedly add funds for transaction fees. An automated sweeper may be involved, requiring a response tailored to your situation.
Preserve relevant records, but do not reopen suspicious links just to collect evidence. Do not reset or uninstall your wallet without a reliable recovery backup.
How do I report suspected UKey impersonation?
Use the official channels listed on the Contact UKey support page. Explain what happened and which actions you have already taken.
Useful details include:
The suspicious website address, account name, or sender information;
When you received the message, its contents, and redacted screenshots;
Whether you downloaded software, entered information, connected a wallet, or signed a request;
The relevant network and transaction hash, if an on-chain transaction was involved.
Do not include seed phrases, private keys, PINs, passphrases, or complete recovery backups. If you ask for help publicly, keep order details, personal contact information, and other private information out of your post.
Reporting to UKey can provide information for investigation. It does not mean an on-chain transaction can be reversed or funds recovered. Independently verify anyone who subsequently contacts you offering to “unfreeze” assets or guarantee recovery.
