Reference
Security & wallet safety
Know what Medusa asks you to sign and which secrets you should never provide.
Wallet ownership verification
Medusa links wallets by asking the wallet to sign a challenge that proves control of the public address. Solana can use message signing or the hardware-wallet transaction-signing path. Robinhood Chain uses an EVM personal-sign challenge.
Never provide these secrets
- Seed or recovery phrase.
- Private key.
- Wallet export file or secret-key JSON.
- Discord password.
- OAuth client secrets or Medusa backend credentials.
A legitimate Medusa linking flow does not need a recovery phrase
If any website or person asks for your seed phrase in order to connect a wallet to Medusa, do not provide it.
Admin safety
- Give delegated server administration only to people who need day-to-day configuration access.
- Remember that Billing, Team and ownership remain Owner responsibilities.
- Use Check wallet before changing a production rule during troubleshooting.
- Use Verification Logs to preserve an evidence-based troubleshooting path.
Still need help? Follow the troubleshooting checklist before escalating the issue.Open troubleshooting →