ENS Security Basics

GuideRead time: 6 min

Your .eth name is an asset, and like any asset it can be lost, stolen, or misused. The good news: most losses are preventable. Here is how to keep your names safe.

Protect your wallet

Your ENS name is controlled by the wallet that owns it. If your wallet is compromised, your name is too.

Manage contract approvals

Many attacks happen not by stealing your key, but by tricking you into signing an approval that lets an attacker move your assets.

Common scams to avoid

Fake "expiry" messages

Scammers send messages claiming your name is about to expire and you must renew now through a link. The link goes to a fake site that steals your approval or seed phrase. Real renewals happen on the official ENS app or trusted platforms - never through a random link in a message.

Fake support

Scammers pose as support in DMs, forums, or on social media. Real teams do not message you first to "help fix" a problem you did not report.

Fake airdrops

Offers of free tokens or names that ask you to connect a wallet and sign a transaction. The "free" thing is bait for a malicious approval.

Lookalike domains

Fake sites with slightly misspelled names. Always check the exact URL before connecting a wallet or entering a seed phrase.

If you hold many names

Consider a separate, more secure wallet for your highest-value names, and a lower-balance wallet for daily activity. This limits your exposure if the daily wallet is compromised.

The rule that prevents almost every loss: never sign anything you do not fully understand, and never share your seed phrase or private key with anyone.

Next steps

Learn about renewals so a scammer cannot catch you off guard with a fake expiry message, and understand subname ownership so you know who controls your names.