Skip to main content

What to Do After Connecting to a Malicious dApp

If you connected Gem Wallet to a suspicious dApp, stop using the website and determine what you approved. The correct response depends on whether you only connected, signed a request, approved token access, sent a transaction, or exposed your Secret Phrase.

danger

Do not return to the suspicious website to โ€œdisconnect,โ€ โ€œverify,โ€ or โ€œsecureโ€ the wallet. Perform the response from Gem Wallet and independently verified blockchain tools.

Step 1: Stop New Requestsโ€‹

Close the dApp in your browser and do not approve any new prompts. If Gem Wallet shows an unexpected connection, signature, or transaction request, cancel it.

Do not follow recovery instructions from the dApp, a pop-up, or someone contacting you after the incident.

Step 2: Disconnect the WalletConnect Sessionโ€‹

Gem Wallet lets you review and disconnect active WalletConnect sessions:

  1. Open Gem Wallet > Settings > WalletConnect.
  2. Select the suspicious connection.
  3. Record the displayed dApp, website, wallet, and connection date if you need evidence.
  4. Select Disconnect.

Disconnecting prevents that session from sending additional approval requests. It does not cancel approvals, signatures, or transactions that you already confirmed.

Step 3: Identify What You Approvedโ€‹

Use the following table to choose the remaining steps:

What happenedMain exposureWhat to do
You only connectedThe dApp learned the selected public account and could send requestsDisconnect and monitor the wallet
You signed a messageThe signature may authorize login or another actionSave the message and signature details; check the service and wallet activity
You approved token or NFT accessThe approved spender may be able to transfer approved assetsRevoke the approval on-chain
You confirmed a transfer or contract transactionThe transaction may have moved assets or changed permissionsCheck its confirmed result and secure the wallet
You entered a Secret Phrase or private keyThe entire wallet is compromisedMove remaining assets to a new wallet immediately

Connecting by itself does not reveal your Secret Phrase or private key. The dApp still needs a separate request for a signature or transaction, but you must review anything already approved.

Step 4: Review Wallet Activityโ€‹

For each transaction you approved around the incident:

  1. Open the affected asset in Gem Wallet.
  2. Select the transaction from the activity list.
  3. Select View on explorer name.
  4. Confirm the status, network, asset, amount, destination, and contract.
  5. Record the public transaction ID and complete contract or recipient address.

Check for token approvals, NFT collection approvals, transfers, swaps, and other contract calls you did not intend. Do not interact with unexpected tokens that appear after the connection.

Step 5: Revoke Suspicious Approvalsโ€‹

Disconnecting WalletConnect does not change an allowance stored on the blockchain. If you approved a token or NFT spender, use a trusted approval checker for the exact network and submit a revocation transaction.

Follow How to Revoke a Suspicious Token Approval to verify the token, spender, network fee, and confirmed result.

warning

Revocation only takes effect after its transaction confirms. It cannot reverse transfers that already succeeded.

Step 6: Respond to Unauthorized Activityโ€‹

If assets moved without your intent or you approved a harmful transaction:

  • Save the transaction IDs, addresses, contract details, screenshots, and dApp URL.
  • Check other networks and assets used by the same wallet.
  • Revoke remaining suspicious approvals where it is still safe to do so.
  • Do not send funds to anyone promising to recover or unlock the assets.
  • Follow What to Do If Your Crypto Wallet Is Compromised.

Confirmed blockchain transactions are generally irreversible. Gem Wallet cannot cancel them or retrieve assets controlled by another address.

Step 7: Replace the Wallet If Secrets Were Exposedโ€‹

If you typed, pasted, uploaded, photographed, or shared your Secret Phrase or private key, assume the entire wallet is compromisedโ€”even if no unauthorized transaction is visible yet.

Create a new wallet on a trusted device, back up its new Secret Phrase offline, and move remaining assets without reusing the exposed phrase. Follow the complete Secret Phrase exposure response.

Disconnecting sessions and revoking approvals cannot make an exposed Secret Phrase safe again.

Report the dApp Safelyโ€‹

Preserve public evidence before closing accounts or deleting messages:

  • The complete dApp URL and domain.
  • WalletConnect connection details.
  • Public wallet and contract addresses.
  • Transaction IDs and timestamps.
  • Screenshots that contain no Secret Phrase, private key, or authentication code.

Report the site to the browser, search engine, hosting provider, or platform where you found it. In Gem Wallet, open Settings > Support for help interpreting public transaction activity. See What Information Is Safe to Give Wallet Support?.

Malicious dApp Response Checklistโ€‹

  • Close the website and cancel new requests.
  • Disconnect the session in Settings > WalletConnect.
  • Determine whether you connected, signed, approved, transacted, or exposed secrets.
  • Review related transactions on the correct explorer.
  • Revoke suspicious token and NFT approvals on-chain.
  • Move to a new wallet if the Secret Phrase or private key was exposed.
  • Save public evidence and report the dApp through verified channels.

To reduce the risk before connecting, review WalletConnect Domain Verification in Gem Wallet.