What to Do After Connecting to a Malicious dApp
If you connected Gem Wallet to a suspicious dApp, stop using the website and determine what you approved. The correct response depends on whether you only connected, signed a request, approved token access, sent a transaction, or exposed your Secret Phrase.
Do not return to the suspicious website to โdisconnect,โ โverify,โ or โsecureโ the wallet. Perform the response from Gem Wallet and independently verified blockchain tools.
Step 1: Stop New Requestsโ
Close the dApp in your browser and do not approve any new prompts. If Gem Wallet shows an unexpected connection, signature, or transaction request, cancel it.
Do not follow recovery instructions from the dApp, a pop-up, or someone contacting you after the incident.
Step 2: Disconnect the WalletConnect Sessionโ
Gem Wallet lets you review and disconnect active WalletConnect sessions:
- Open Gem Wallet > Settings > WalletConnect.
- Select the suspicious connection.
- Record the displayed dApp, website, wallet, and connection date if you need evidence.
- Select Disconnect.
Disconnecting prevents that session from sending additional approval requests. It does not cancel approvals, signatures, or transactions that you already confirmed.
Step 3: Identify What You Approvedโ
Use the following table to choose the remaining steps:
| What happened | Main exposure | What to do |
|---|---|---|
| You only connected | The dApp learned the selected public account and could send requests | Disconnect and monitor the wallet |
| You signed a message | The signature may authorize login or another action | Save the message and signature details; check the service and wallet activity |
| You approved token or NFT access | The approved spender may be able to transfer approved assets | Revoke the approval on-chain |
| You confirmed a transfer or contract transaction | The transaction may have moved assets or changed permissions | Check its confirmed result and secure the wallet |
| You entered a Secret Phrase or private key | The entire wallet is compromised | Move remaining assets to a new wallet immediately |
Connecting by itself does not reveal your Secret Phrase or private key. The dApp still needs a separate request for a signature or transaction, but you must review anything already approved.
Step 4: Review Wallet Activityโ
For each transaction you approved around the incident:
- Open the affected asset in Gem Wallet.
- Select the transaction from the activity list.
- Select View on explorer name.
- Confirm the status, network, asset, amount, destination, and contract.
- Record the public transaction ID and complete contract or recipient address.
Check for token approvals, NFT collection approvals, transfers, swaps, and other contract calls you did not intend. Do not interact with unexpected tokens that appear after the connection.
Step 5: Revoke Suspicious Approvalsโ
Disconnecting WalletConnect does not change an allowance stored on the blockchain. If you approved a token or NFT spender, use a trusted approval checker for the exact network and submit a revocation transaction.
Follow How to Revoke a Suspicious Token Approval to verify the token, spender, network fee, and confirmed result.
Revocation only takes effect after its transaction confirms. It cannot reverse transfers that already succeeded.
Step 6: Respond to Unauthorized Activityโ
If assets moved without your intent or you approved a harmful transaction:
- Save the transaction IDs, addresses, contract details, screenshots, and dApp URL.
- Check other networks and assets used by the same wallet.
- Revoke remaining suspicious approvals where it is still safe to do so.
- Do not send funds to anyone promising to recover or unlock the assets.
- Follow What to Do If Your Crypto Wallet Is Compromised.
Confirmed blockchain transactions are generally irreversible. Gem Wallet cannot cancel them or retrieve assets controlled by another address.
Step 7: Replace the Wallet If Secrets Were Exposedโ
If you typed, pasted, uploaded, photographed, or shared your Secret Phrase or private key, assume the entire wallet is compromisedโeven if no unauthorized transaction is visible yet.
Create a new wallet on a trusted device, back up its new Secret Phrase offline, and move remaining assets without reusing the exposed phrase. Follow the complete Secret Phrase exposure response.
Disconnecting sessions and revoking approvals cannot make an exposed Secret Phrase safe again.
Report the dApp Safelyโ
Preserve public evidence before closing accounts or deleting messages:
- The complete dApp URL and domain.
- WalletConnect connection details.
- Public wallet and contract addresses.
- Transaction IDs and timestamps.
- Screenshots that contain no Secret Phrase, private key, or authentication code.
Report the site to the browser, search engine, hosting provider, or platform where you found it. In Gem Wallet, open Settings > Support for help interpreting public transaction activity. See What Information Is Safe to Give Wallet Support?.
Malicious dApp Response Checklistโ
- Close the website and cancel new requests.
- Disconnect the session in Settings > WalletConnect.
- Determine whether you connected, signed, approved, transacted, or exposed secrets.
- Review related transactions on the correct explorer.
- Revoke suspicious token and NFT approvals on-chain.
- Move to a new wallet if the Secret Phrase or private key was exposed.
- Save public evidence and report the dApp through verified channels.
To reduce the risk before connecting, review WalletConnect Domain Verification in Gem Wallet.