Skip to main content

Information only — not financial advice. Read the disclaimer

Scams & SafetyEvergreen guide

How to Verify a Wallet Download Before You Install It

Fake wallet apps and cloned download pages are among the cheapest attacks to run and the hardest to undo. Here is how to check a wallet before it ever touches your funds.

By Editorial Desk · GlobalCryptoWallets newsroomPublished

A counterfeit wallet does not need to break any cryptography. It only needs you to install it and type your recovery phrase once. That makes the download itself one of the highest-leverage moments in self-custody, and one of the few where a few minutes of checking closes the whole attack path.

Reach the site the boring way

Type the domain by hand, or use a bookmark you created from a source you already trusted — an official repository, the wallet's verified account, a printed card that shipped with a hardware device. Search results and sponsored links are bought, and paid placement above a real result is a routine way to distribute a cloned download page.

Attackers register domains that differ by one character, or that swap a letter for a lookalike from another alphabet. The page can be a pixel-perfect copy; the domain is where the difference lives.

Check the app store listing, not just the app name

  • Look at the publisher name, not only the app title — a clone copies the title and cannot copy the developer account.
  • Check the install count and review history. A wallet with a long track record does not appear last week.
  • Read the one-star reviews first. Victims of a fake listing say so there, and they say so early.

Verify the file where the publisher lets you

Desktop wallets are often published with a checksum or a signature. Verifying a checksum means comparing the hash of the file you downloaded with the hash the publisher lists, so a file swapped in transit will not match. Signature verification goes further: it proves the file was produced by the holder of the publisher's key. Where a project offers either, use it — it is the only check that inspects the file itself rather than the page that served it.

Watch what the app asks for on first run

A wallet asks you to create a new wallet or restore one you already control. It does not ask you to:

  1. Enter a recovery phrase to "verify", "sync", "validate" or "unlock" anything.
  2. Approve a transaction before you have funded the wallet.
  3. Disable a security setting to complete setup.

Any of those on first launch is a reason to stop, uninstall, and start again from a source you reached differently.

Fund it like a stranger

Send a small amount first and confirm it arrives and that you can send it back out. A wallet that receives but cannot spend, or that shows a balance the block explorer does not, has failed the only test that matters before you trust it with more.

If you have already entered a phrase

Treat the phrase as public from that moment. Move funds to a wallet created on a device you trust, using a new phrase — the compromised one cannot be repaired, revoked or re-secured, because knowing it *is* control of the wallet. Record what happened and when: the timeline is what makes a report to a platform or an authority actionable.

Topics in this article

  • crypto-scams
  • wallet-security
  • phishing

GlobalCryptoWallets.com publishes news, reviews, and educational information only. Nothing on this website is financial, investment, trading, legal, or tax advice. Cryptocurrency involves substantial risk, and readers should conduct independent research and consult a qualified professional before making decisions.

Published 4 Feb 2026 · Canonical: https://globalcryptowallets.com/scams-safety/how-to-verify-a-wallet-download-before-you-install-it