Last updated 20 July 2026
Scammers target people, not cryptography. The wallet's design removes the most valuable prizes — there is no central password to steal and no document vault to raid — so scams against wallet users rely on tricking you into approving things or revealing things. These are the patterns to recognise.
The approval push
You get a call, text or email creating urgency: “your identity is compromised, approve this verification now to secure it.” The goal is to make you approve a consent request the scammer initiated.
Only approve requests you started yourself, moments ago, in a service you are actively using. There is no legitimate reason for anyone to phone you and ask you to approve a wallet request.
The fake wallet app
A copycat app or website imitates the wallet and asks you to “verify” by scanning your documents into it. The real wallet is open source and has no official app-store listing — treat any store listing or download link sent to you as hostile. Check sources against the official repository linked from this site's about section.
The impersonated service
A phishing email pretends to be a service you use and links to a lookalike site that asks you to connect your wallet. Before approving anything, check the request details your wallet shows you: the requesting service's identity is part of the consent screen. If the name does not match who you think you are dealing with, decline.
Habits that defeat all of these
- Slow down. Urgency is the scammer's only real tool. Nothing about your identity requires action in the next five minutes.
- Read the consent screen. Your wallet states who is asking, for what, and why — every time.
- Never share your screen or read out codes while dealing with your identity.
- Remember what can never happen: no one from identity.org.au, DETIO Foundation or VirtEngine will ever contact you asking for approvals, codes, documents or remote access.
- Report attempts to Scamwatch (scamwatch.gov.au) and, for wallet-related phishing, to [email protected].