Reader stories

Feedback from consultation clients and regular readers of our Solana security guides.

The phishing link article saved me from connecting to a clone of Jupiter. I had the tab open and was about to click approve when I remembered the section about mismatched favicons. Closed the tab, checked the URL against the official site, and reported it in the project Discord.

— Tomás V., read online · Guide: Recognizing Phishing Links

Consultation was thorough. Hye-jin walked me through every connected dApp in my Phantom wallet and explained which approvals were still active from projects I stopped using in 2023. Took the full hour. My only wish is that we could have covered a second wallet in the same session — but I understand the scope limits.

— Yuna L., Daegu · Wallet Security Consultation

Our Busan meetup booked the group workshop before a token launch event. Sora brought printed checklists and ran a live revoke demo on Solscan. Three attendees said afterward they had never opened the approvals tab before. Practical, not preachy.

— Marcus H., Busan meetup organizer · Group Workshop

Extended case note: post-scam review for a drained NFT wallet

Client: Anonymous holder, Gwangju
Service: Scam Incident Review
Situation: Client clicked a link shared in a Telegram group promising a free NFT mint. The page requested a wallet connection and the client approved a transaction they believed was gas-free. Within minutes, three Solana NFTs and roughly 2.1 SOL moved to an unknown address.

What we did: We traced the draining transaction on Solscan and identified a token approval granted to a program the client had never consciously interacted with. The approval had been embedded in the malicious mint page. We documented the transaction hashes, the program ID, and the receiving wallet. We then walked the client through revoking all remaining approvals on that wallet and setting up a fresh wallet with a new seed phrase for future use.

Outcome: Funds were not recovered — the receiving address had already consolidated assets. The client received a four-page written report they shared with the Telegram group admin and used to warn other members. They later booked a Recovery Planning Session for the new wallet.

Client note: "I appreciated that they did not pretend recovery was possible. The report was detailed enough to file with local cybercrime reporting, even though I know prosecution is unlikely."

I read the seed phrase storage guide before my consultation and it answered most of my basic questions. The session itself focused on edge cases — what happens if my hardware wallet firmware updates, how to verify a receive address on a second device. Efficient use of time.

— James W., remote client (UK) · Recovery Planning Session

Share your experience or book a session