Ready X is self-custodial, which means you are responsible for protecting access to your wallet.
Following a few basic security practices can significantly reduce the risk of losing your assets.
Security checklist
- Never share your recovery phrase or private key with anyone.
- Never store recovery phrases or private keys in plain text, email, chat, cloud documents, screenshots, or photos.
- Use a unique password for your email and other important accounts. A password manager such as 1Password can help.
- Enable 2FA for your email, exchanges, and Ready X accounts wherever available.
- Install Ready X and other wallet software only from official sources.
- Never enter your wallet details into third-party recovery tools, dapps, or extensions.
- Check the complete destination address before every transaction.
- Review every transaction before approving it.
- Never trust unsolicited support messages or direct messages.
- Keep your devices, operating system, browser, and Ready X up to date.
Protect your recovery phrase and private key
Your recovery phrase and private key can provide access to your wallet.
Never:
- Save them in a plain-text file or notes app.
- Send them by email or messaging apps.
- Upload them to cloud storage.
- Take screenshots or photos of them.
- Share your screen while they are visible.
- Send them to someone claiming to be Ready Support.
Screen-recording, screenshotting, remote-access, or malicious software may capture sensitive information displayed on your device.
Ready Support will never ask you to send us your recovery phrase or private key.
There is one specific exception where an official Ready tool may ask you to enter your private key yourself. If you have assets in a deprecated Ready/Argent wallet, you may be directed to:
https://security.argent.xyz/recover/index.html
This page does not collect the information you enter. It is a self-service recovery tool for older accounts.
More technical users can also follow the open-source account upgrade instructions directly:
https://github.com/argentlabs/upgrade-v0-account
Do not enter your private key on any other website because it claims to provide Ready recovery or account-upgrade services.
Do not use third-party wallet recovery software
Be particularly careful with websites, dapps, browser extensions, or downloadable tools claiming that they can:
- Recover "hidden" or missing accounts.
- Restore inaccessible funds.
- Repair or upgrade your wallet.
- Find accounts that Ready X cannot display.
Do not provide these tools with your recovery phrase, private key, or other wallet credentials.
Malicious tools may use your credentials to modify your account, including changing its owner key. This can leave you unable to control or access your own funds.
If you're having trouble recovering an account, contact help@ready.co before using any third-party recovery tool.
Protect your email and other accounts
Use a different, strong password for your email, exchanges, and other important services.
We recommend using a password manager such as 1Password rather than reusing or manually storing passwords.
Enable 2FA wherever possible. For eligible Ready X accounts, email-based 2FA provides an additional layer of protection if your recovery phrase is compromised.
Use an email address you actively monitor
Make sure the email address associated with Ready X is real, accessible, and one you regularly check. We use email to send important security notifications, including alerts related to account recovery, verification attempts, and changes to your 2FA protection.
Do not block or mute emails from help@ready.co or no-reply@ready.co. If your recovery phrase has been compromised or someone is attempting to remove your 2FA protection, missing these alerts could prevent you from acting in time.
Watch out for fake support and social engineering
Scammers may pretend to be Ready employees, moderators, developers, or support agents.
They may ask you to:
- Share your recovery phrase, private key, password, or verification code.
- Visit a "verification" or "recovery" website.
- Install software or a browser extension.
- Share your screen or give them remote access.
- Sign an unexpected transaction.
- Move your assets to a "safe" wallet.
Ready does not provide support through Discord. Do not use Discord DMs to contact Ready Support, and do not trust someone who contacts you there claiming to represent Ready.
Ready may occasionally contact you proactively via email, for example:
- If additional verification is required.
- If we receive a request to recover your account or change account details.
- If one of our partners requires additional information from you.
If you receive an unexpected message claiming to be from Ready, do not rely on the contact details provided in that message. Email help@ready.co separately and ask us to confirm that the request is legitimate before providing information or taking any action.
Check addresses carefully
Always verify the complete destination address before sending assets.
Address poisoning is a scam where an attacker creates an address that looks similar to one you've used before and sends a small transaction to your wallet. The goal is to make you accidentally copy the attacker's address from your transaction history.
Do not rely only on the first and last few characters. Check the complete address against a trusted source before confirming.
Also check the address again after pasting it, as malicious software can replace cryptocurrency addresses in your clipboard.
Be careful with websites, extensions, and dapps
Check the website address before connecting Ready X or approving a transaction. Fake websites can closely imitate legitimate dapps and wallet services.
Where a trusted native app is available, consider using it instead of a web-based version. Browser sessions and malicious extensions can introduce additional risks, including session theft.
Keep unnecessary browser extensions to a minimum and install wallet software only from official sources.
Before approving a transaction
Take a moment to check:
- The destination address.
- The token and amount.
- The dapp or service you're interacting with.
- Any permissions or actions you're being asked to approve.
If something looks unexpected, do not approve it.
If you're unsure whether a request, website, transaction, recovery tool, or support message is legitimate, contact Ready Support at help@ready.co before taking further action.