Skip to main content
How Harpie keeps you safe

The ways that Harpie keeps your wallet safe and what attacks to look out for.

Noah Chong avatar
Written by Noah Chong
Updated over a year ago

Introduction

We get it. Avoiding hacks and scams is hard, especially when crypto crime accounts for over $1 billion in lost funds every year. It can feel like protecting your wallet and hard-earned money is an uphill battle, like you're always one step behind the bad guys.

That's where Harpie comes in. Harpie gives you the tools to secure you and your wallet from the most basic to the most complex attacks.

How people become victims of theft

We've spent a considerable amount of time researching the behavior of those who have fallen victims to scams versus those that have never. We've determined 2 major factors that decide whether someone becomes a victim of crypto crime or not. These two factors are:

  • Not knowing common Web3 attacks and how to spot them

  • Not being 100% when using crypto, usually caused by:

    • Fatigue

    • FOMO

It's impossible to ask people to double, triple-check every transaction. And even then, people make mistakes. That's how Harpie helps. We fill in the gaps for your security, so that even when you do make a mistake, there's someone watching your back.

Read on to learn about common Web3 attacks and how Harpie can prevent them. Read more at What does Harpie protect me from?

Common Web3 Attacks

1. Frontend Attacks

Frontend attacks are one of the most effective attack vectors, able to trick even the most experienced crypto veterans. Attackers hijack legitimate websites, through methods like malicious code injection or DNS take-overs, and replace a website's code with code that steals your crypto.

Key Points:

  • Effective against experienced individuals

  • Difficult to detect, can remain dormant for extended periods

  • Exploit user trust for wallet access

Sure, you might not approve your tokens to a website you've never heard of, but what about a website trusted by millions like Coinbase or Uniswap?

2. Fake Sites and Phishing Sites

Fake sites and phishing sites are another common attack.

Attacks like this use a clean, well-designed website to trick victims into trusting the site. Afterwards, victims are asked to sign malicious smart contracts or send over their private keys to the attacker as part of a "user onboarding" process.

Key Points:

  • Common and convincingly designed

  • Prey on users during time-sensitive events (e.g., token airdrops, NFT mints)

  • Advertised under reputable company posts, relying on unnoticed URL errors

3. Accidental Transfers

Wrapping Gone Wrong: Ethereum User Loses Over $500k to WETH Transfer Error

Though not always an attack in the traditional sense, accidental transfers are still a devastating financial mistake. Any transaction that you send to a wallet that you don't own or control cannot be reversed.

There's no support line that you could call if you accidentally sent your NFT to address 0x123...ABC instead of 0xABC...123. Transactions on the blockchain are permanent and there's no way to recover that NFT after it's been sent.

Accidental transfers can happen for many different reasons:

  • Mistyping an address

  • Copy and pasting the wrong address

  • ... or even targeted attacks like "Copy Paste" viruses

How Harpie helps

We've covered a few ways that attackers can gain access to your wallet. Luckily, Harpie helps keep you safe by making sure that you don't fall victim to these types of attacks.

1. Wallet 2-Factor Authentication (2FA)

Harpie 2FA identifies potentially dangerous transactions and stops these dangerous transactions from completing.

Dangerous transactions can be anything from wallet drainers, like the ones you'll see on a frontend attack or phishing site, to more innocuous ones like accidental transfers.

The image above shows an email from Harpie warning you of a transaction that gives ownership of your NFT to an Unknown Address. From your email, you can choose to either let the transaction through or cancel it.

2. Advanced Security

Harpie Advanced Security is designed to protect your tokens by preventing transactions with untrusted addresses.

It's akin to a high-security vault, ideal for tokens that are valuable and not frequently moved or traded. This feature is perfect for long-term holdings or assets of significant worth that you want to safeguard at all costs.

It's a way to protect your wallet even when you're asleep. Harpie Advanced Security works 24/7, monitoring your wallet for any potential attacks or unexpected transfers. Read more about Harpie Advanced Security here: Is Harpie Advanced Security right for me?

3. Approval Revoking

Open Token Approvals are like backdoors into your wallet. Without careful management of what apps have access to your wallet's tokens, you may find yourself a victim.

Did this answer your question?