Wallets & Security glossary
Keys, seed phrases and wallet approvals. Get the language behind self-custody, the prompts you sign and common security risks.
Address
A blockchain identifier used to receive assets or refer to an account or contract.
Address poisoning
An attack that plants a lookalike address in transaction history to encourage a later transfer to the wrong recipient.
Admin key
A key or authorization role with privileged control over part of a contract or protocol.
Air-gapped wallet
A signing setup disconnected from networks that exchanges transaction data through a separate transfer method.
Approval revocation
An onchain action that removes or reduces an existing token-spending permission.
Blind signing
Signing a transaction or message without meaningfully seeing or understanding what it authorizes.
Cold wallet
A wallet setup that keeps signing keys offline during ordinary storage.
Custody
Practical control over the keys or other mechanisms that authorize movement of assets.
Derivation path
A sequence of indexes that identifies a key within a hierarchical wallet's key tree.
Extended public key
A public key plus derivation information that can generate eligible non-hardened descendant public keys.
Formal verification
Using mathematical methods to check whether software satisfies explicitly stated properties.
Hardware wallet
A dedicated device designed to generate, protect and use signing keys without exposing them to a general-purpose computer.
HD wallet
A hierarchical deterministic wallet that derives a tree of keys from shared seed material.
Hot wallet
A wallet whose signing capability is available on an internet-connected system.
Multisig
An authorization arrangement that requires signatures from a specified number of distinct keys.
Oracle manipulation
Influencing data an application treats as an authoritative input, such as its collateral price.
Passphrase
An additional secret that some wallet recovery schemes combine with recovery words to derive a wallet.
Phishing
Deception that impersonates a trusted person or service to obtain secrets or harmful authorizations.
Reentrancy
A pattern where an external call re-enters a contract before an earlier operation has finished.
Replay attack
Reusing a valid authorization where it should no longer apply or should never have applied.
Rug pull
A scam where project controllers use their position to take value from users after attracting funds.
Sandwich attack
A trading attack that places transactions before and after another trader's trade to exploit its price movement.
Seed phrase
Recovery words used by many wallets to derive the keys that control an account.
Self-custody
Controlling the authorization needed to move your own blockchain assets.
Page 1 of 2
Looking for an earlier definition? Explore the original collection
Concept entries explain ideas. Our separate asset registry identifies coins, tokens and networks by source metadata. Sources & standards