What should I do if I already joined an unknown project?
What this guide covers
If you already opened an unknown campaign link, sent assets to someone’s address, or completed an approval/signature under coaching, follow this priority order to limit further loss and preserve evidence.
Scope and prerequisites
- For suspected fake yield, phishing links, induced transfers, or malicious approvals.
- This page does not guarantee fund recovery and is not legal or investment advice.
- Work on a trusted network in private; never send seed phrases, private keys, or codes to anyone again.
Officials will never ask for seed phrases, private keys, or PIN to “recover funds,” “unfreeze an account,” or “run a security check.” Anyone who asks for those is not trustworthy.
Emergency steps
1. Stop sending more funds
- Do not send more USDT, SOL, or other assets.
- Ignore requests to “top up gas,” “upgrade quota,” or “send one more unlock transfer.”
2. Stop approvals and signatures
- Don’t open more links from the other party.
- Don’t sign unknown wallet prompts, approvals, or transactions.
- If a prompt is still open, reject/close it.
3. Keep evidence
Save as completely as you can (screenshots/exports—never include seed phrases in images):
- Group or DM chat records
- Project name, creatives, alleged site/campaign links (paste into notes; don’t keep reopening)
- Counterparty address and your sending address
- Transaction hashes
- Approval-related records (if any)
4. Check and revoke suspicious approvals
- Open DeBox and go to Approval Check (in-app path: Me → Lab → Approval Check, subject to the App).
- Review recent approvals by chain—especially unlimited allowance and unknown contracts/DApps.
- Revoke approvals you no longer need (network fees may apply; follow on-screen guidance).
5. Decide whether to move remaining assets
If any of the following is true, move remaining assets soon to a wallet you control whose seed phrase was never exposed (back up any new wallet yourself):
- You entered or photographed a seed phrase/private key on an untrusted page
- You sent a seed phrase to someone
- The device may be remotely controlled or has unknown apps installed
Double-check the receive address before moving funds. Never use a “safe wallet address” provided by the other party.
6. Report through official channels
- Collect project name, related accounts, links, and tx details, then submit via feedback or the official DeBox support group.
- Include a timeline and the stop-loss steps you already took; don’t paste full private-key material in public groups.
FAQ
I already transferred—can DeBox recover my funds?
On-chain transfers are usually irreversible. Stop sending, keep evidence, and report; any assistance depends on the official reply. This page does not promise recovery time or outcome.
I only opened a link—no transfer and no signature?
Still check whether approvals look abnormal; avoid similar links for now. Read How do I spot fake “hold USDT and earn yield” scams? or How do I spot fake admins pushing phishing app downloads?.
I already installed a “meeting app” from a group notice?
Stop using it and uninstall. Don’t enter codes or connect a wallet. Full steps: How do I spot fake admins pushing phishing app downloads?.
After I revoke, a DApp stops working?
Expected. To use a legitimate DApp again, re-approve inside that DApp—not via a stranger’s “fix” link.
Related guides
- How do I spot fake “hold USDT and earn yield” scams?
- How do I spot fake admins pushing phishing app downloads?
- What are DeBox anti-fraud principles and common red flags?
- How do I revoke token approvals?
- How do I back up my account (seed phrase / private key)?
- How do I submit feedback?
Security content must be confirmed by product/security or ops before it is treated as final public guidance. If a dedicated governance/report channel exists, replace the feedback path with the accurate one during review.
