How we checked this
We reviewed the linked sources and keep this page updated when the record changes. Use the source list below to verify the details.
Summary box
If you think you signed or approved something suspicious, a cautious first step is to preserve what you can without interacting further than necessary. In practice, that can mean saving a screenshot of the request screen if it is still visible, plus a screenshot of any visible wallet activity or transaction record afterward. Those images may help preserve fast-changing context, but they do not by themselves prove the full incident, identify the other party, or guarantee any recovery outcome.
Short answer
There is no single universal screenshot rule for every wallet, chain, or signing flow. But if a suspicious request is still on screen, a practical evidence-preservation approach is often to save:
- what you were shown, and
- what appears to have happened afterward, if a visible record exists.
Just as important: stop further interaction if you suspect risk. If you think your seed phrase, private key, password, or device access may be exposed, prioritize containment over collecting perfect records.
Context
Suspicious wallet incidents can change quickly. Pages may refresh, close, or disappear, and visible details may be harder to reconstruct later. General public cyber-safety guidance supports preserving basic records early and avoiding extra interaction with suspicious content where possible.
A screenshot is only a snapshot of what was visible on your screen at one moment. It can help with later checking, reporting, or support conversations, but it should be treated as supporting evidence rather than final proof of the whole event.
Why these records are useful
If the wallet request screen is still visible, it may preserve immediate context such as the site or app, warning text, the action label, or other visible identifiers. That can matter if the page later changes or disappears.
2. The visible record afterwardIf your wallet, activity page, or another visible record shows something after the event, that screenshot can preserve what you could see after the request was approved or signed.
Important limitThis article does not claim that every suspicious signature creates the same kind of visible history, or that every wallet shows the same information. The sources currently support narrow, general evidence-preservation advice, not wallet-specific technical rules.
Step-by-step guide
- Stop clicking through the suspicious site or app.
- Save a screenshot of the request screen if it is still visible.
- Save a screenshot of any visible record afterward, such as wallet activity or another visible confirmation/history view, if available.
- Save the page or app context only if you can do so safely without reopening the suspicious content.
- Keep the original image files. If you later crop or redact, keep an untouched copy for your own records.
- Do not share seed phrases, private keys, passwords, or remote access with anyone offering help.
- Do not reopen a suspicious page just to recreate a missing screenshot.
- Do not approve more requests to see what happens.
- Do not assume screenshots alone prove the full scope of loss or control.
- Do not send wallet credentials to strangers, fake support accounts, or paid recovery services.
Comparison table
| Record to save | Why it can help | What it may show | What it does not prove by itself |
|---|---|---|---|
| Request screen screenshot | Preserves what you were shown at the time | Visible warnings, site or app context, action labels, partial identifiers | The full downstream impact or the identity of the other party |
| Wallet activity or other visible history screenshot | Preserves what you could see afterward | Timing context, visible status, related activity entry | The full scope of loss or whether all consequences are visible yet |
| Browser URL or app-context screenshot | Adds supporting context | Domain, app name, surrounding page context | That the site or app was legitimate |
Practical checklist
- Save the suspicious request screen if it is still open.
- Save any visible history, activity, or confirmation screen afterward.
- Save surrounding context only if doing so does not require more risky interaction.
- Keep original files before editing them.
- Check whether the screenshots contain personal information before sharing them.
- Stop further interaction if you suspect broader compromise.
Myth vs reality
Reality: A screenshot records what was visible on your screen. It may be useful evidence, but it does not automatically prove the full sequence of events or any legal outcome.
Myth: “I should keep clicking so I can document more.”Reality: General cyber-safety guidance favors preserving what you safely can, then limiting further interaction with suspicious content.
Myth: “Anyone asking for my seed phrase to help is legitimate.”Reality: Sharing seed phrases, private keys, passwords, or remote access creates serious additional risk.
Reader examples
That can still be useful because it preserves what you were shown at the moment of concern. Save it, keep the original, and look for any safe-to-view record of what happened afterward.
Example: you only captured a history or activity screenThat can still help preserve visible aftermath. Keep it together with any other safe context you already have, such as the app name or browser address bar.
Example: someone says your screenshots guarantee recoveryTreat that as a warning sign. Evidence preservation may help with reporting or later review, but it does not guarantee recovery, refunds, or legal results.
What to verify next
- Whether the visible activity or history matches the time of the incident.
- Whether the site or app context shown in the screenshot matches what you intended to use.
- Whether the images include sensitive information you should redact before sharing them.
- Whether you need country-specific reporting guidance from a government cyber or fraud-reporting body.
Date checked: 2025-02-14. This article is limited to general public cyber-safety and evidence-preservation guidance from the cited official sources. It does not verify wallet-specific display behavior, chain-specific signing flows, or platform-specific reporting paths. Those details should be checked against current official documentation for the wallet, service, or authority involved.
FAQ
Not in every case. Different wallets and incidents may surface different information. This article presents a cautious starting point for general evidence preservation, not a universal rule.
What if the request screen vanished before I could save it?Save any visible history, confirmation, or surrounding context you still have. Do not reopen a suspicious page just to recreate the screen.
Should I keep documenting everything if I think my wallet or device is compromised?No. If you suspect broader exposure, prioritize safety and containment. Preserve only what you can collect without increasing risk.
Is this legal or recovery advice?No. This is general evidence-preservation guidance. Reporting options, legal steps, and platform processes vary by country and service.
Sources
- CERT Polska — public cybersecurity alerts and incident-safety guidance.
- NASK — public cybersecurity and digital safety resources.
- Gov.pl: Cyberbezpieczeństwo — government cyber-safety guidance.
Update log
- 24 Jun 2026Published with source tracking and reader-safety context.
- CorrectionsIf a source changes or a claim needs clarification, this page can be updated from the editorial desk.