Secure Your Wallet and .base.eth Identity
1
Use a hardware wallet or trusted wallet app
Store the private key controlling your .base.eth name in a hardware wallet (such as Ledger or Trezor) or a well-audited mobile wallet (such as Coinbase Wallet). Hardware wallets keep your key off internet-connected devices, which eliminates the largest class of remote compromise attacks.
2
Never share your private key or seed phrase
Your private key and seed phrase provide complete, irrevocable control over your wallet and everything associated with it. Write your seed phrase down on paper, store it in a physically secure location, and never enter it into any website, app, or form — including anything that appears to be Fundwork.
3
Verify you're on https://fundwork.app before signing
Before you connect your wallet or sign any transaction, confirm that your browser’s address bar shows https://fundwork.app exactly. Bookmark the real URL and navigate from your bookmark rather than search results or links in messages. One character of difference in a URL can send you to a phishing site built to steal your credentials.
4
Review every transaction before signing
Never approve a wallet transaction without reading what it does. Fundwork payments are in USDC on Base — if a signing request asks you to approve a different token, an unexpected amount, or interact with an unfamiliar contract address, reject it and contact support.
5
Keep your Privy session secure
Fundwork uses Privy to connect your Base identity to the platform. Sign out of your Privy session when you finish working, especially on shared or public devices. Do not grant Privy access to third-party apps you don’t recognise.
Recognise and Avoid Phishing
Phishing attacks targeting Base and crypto users are common. Attackers often impersonate platforms, project teams, and support staff to trick you into handing over credentials or signing malicious transactions.Fake support messages
Be suspicious of unsolicited messages claiming to be from Fundwork support, especially those that create urgency (“your account will be suspended”) or ask you to connect your wallet via a link.
Lookalike URLs
Attackers register domains that look nearly identical to the real one — for example,
fundw0rk.app or fundwork.io. Always check the full URL carefully before connecting your wallet.Malicious signing requests
A phishing site may prompt you to sign a transaction that transfers your tokens or grants token approval to an attacker’s contract. Read every signing prompt before approving.
Social engineering via DMs
Attackers may contact you via Discord, Telegram, or X claiming to offer opportunities or support. Fundwork’s official communications come through the platform and verified channels only.
