Back

Wallet source and phishing verification

P03-L02 · P03 · P03-M01

Check origin domain and distribution provenance

ILLUSTRATIVE · needs_review

Prerequisites: P03-L01

Learning objectives

  • Check origin domain and distribution provenance
  • Compare complete origins and distribution records.
  • Keep suspicious provenance separate from operator attribution.

EN source master · P03-L02 · needs_review

Offline/read-only study only. Never provide secrets, passwords or authentication codes. No wallet connection, real approval, live revocation, transaction signature, transfer, funds or trade. Visuals are specifications only.

Why this matters

A familiar logo or link prefix may lead to a different origin. Exact comparisons can justify withholding interaction without inventing who controls a suspicious site.

Explanation

Inspect the full source

Security guidance recommends actual-domain checks and caution around unofficial support channels [SECURITY]. A preview, title or logo is not the origin. All fixture names below use reserved .invalid domains and must not be visited. R1 is a stipulated classroom reference, not a real wallet endorsement.

Compare literal hostnames

R2 begins with the reference's text but ends in helper.invalid. The complete host is different. R3 changes punctuation and is also a different host. Record the full string and the source of the reference before interpreting the visual similarity. If redirect history or the address bar is missing, mark the resulting source gap UNKNOWN.

Transport encryption, if shown, would concern a connection to a hostname. It would not independently authenticate that hostname as the intended issuer. The fixture supplies no certificate check or person record, so no such finding can be added.

Inspect software provenance independently

R4 gives an app name, version and publisher label but no distribution integrity record. R5 supplies matching package/reference digests within the fixture. The match supports the narrow byte comparison under the stipulated reference, not a full security audit. If the reference were compromised, equal bytes would not resolve that separate concern.

For a bounded note, include URL, source of reference, package/version, collection context and any supplied integrity method. Do not download or run an unknown package as a classroom test. Missing fields stay missing. An app name is not a substitute for the distribution record.

Avoid unsupported allegations

OBSERVED: literal names, labels and supplied digests. INFERRED: their equality/difference under the fixture. UNKNOWN: actual operators, vulnerabilities and unsupplied redirects. INSUFFICIENT EVIDENCE: a named person's phishing ownership from domain similarity alone. The learner can decide to pause interaction pending provenance without making that accusation.

Key terms

  • Origin: scheme/host/port context.
  • Reference: basis independently chosen for comparison.
  • Digest: a cryptographic fingerprint of bytes used for an integrity comparison; matching fingerprints do not establish safety.
  • Distribution provenance: package source, version and integrity chain.
  • Lookalike: textual similarity without established operator identity.

Historical example

ILLUSTRATIVE offline cards. R1 https://wallet.example.invalid. R2 https://wallet.example.invalid.helper.invalid with copied logo. R3 https://wallet-example.invalid. R4 APP-SIM v2 publisher label ‘Wallet’, integrity absent. R5 APP-SIM v2 digest SIM-DIGEST-A equals stipulated reference SIM-DIGEST-A. Never browse/download these cards.

Visual specifications

Full-origin comparison panel, wrapping LTR hostnames; highlight actual suffix in R2. Separate publisher claim, digest comparison and unknown operator columns. No confirmed-phisher identity badge.

What the evidence proves

Stipulated hostname differences and package/reference digest equality.

What the evidence does not prove

Actual domain ownership, confirmed phishing attribution, clean software or uncompromised reference.

Common mistakes

  • Matching a prefix/logo.
  • Treating encryption as issuer identity.
  • Calling hash equality a complete audit.

Practical exercise

Compare R2/R3 to R1. Grade R4/R5 distribution evidence and write a decision note withholding interaction pending exact provenance, with no human accusation.

Submit a table and bounded conclusion using only supplied offline material. Editorial time allocation: study 12 min, exercise 8 min, correction/quiz 10 min.

Show worked correction

R2/R3 differ from R1's full host. Branding supplies a claim only. R4 integrity UNKNOWN. R5 supports equality to the stipulated reference, not flawless software. Operator identity UNKNOWN; a named-person phishing claim is INSUFFICIENT EVIDENCE. Pause interaction and request exact source/distribution context.

Rubric: exact scope, source provenance, reasoning, explicit limits and safe offline handling, one point each. Invented observations or unsupported identity attribution require correction regardless of score. Formative only.

Checklist

  • Read full origin.
  • Choose reference independently.
  • Record package/version/integrity.
  • Do not execute unknown software.
  • Separate concern and attribution.

Summary

Origin and distribution comparisons support narrow provenance findings. Similar names and matching bytes do not identify a human or guarantee safety.

Summary

  • Check origin domain and distribution provenance
  • Compare complete origins and distribution records.
  • Keep suspicious provenance separate from operator attribution.

Next lesson

P03-L03 after prerequisite and correction review.

Tools

NONE in authoritative catalog. Provided offline data suffice; no product purchase or wallet operation required.

Sources & claim boundaries

Documentation explains mechanisms. Historical records retain their declared source class. Source inspection is not independent editorial acceptance.

Visual specifications

P03-L02-V01

SPECIFICATION_ONLY · ILLUSTRATIVE

Check origin domain and distribution provenance

ILLUSTRATIVE sanitized offline cards, not a live screen

Full-origin comparison panel, wrapping LTR hostnames; highlight actual suffix in R2. Separate publisher claim, digest comparison and unknown operator columns. No confirmed-phisher identity badge.

Full-origin comparison panel, wrapping LTR hostnames; highlight actual suffix in R2. Separate publisher claim, digest comparison and unknown operator columns. No confirmed-phisher identity badge.

390px stacked cards/text equivalent; 768px/desktop render acceptance pending

RTL prose; identifiers isolated LTR; factual edge directions preserved

FIX-P03-L02

Sources & claim boundaries

SECURITY · PRIMARY_DOCUMENTATION

Ethereum security and scam prevention

Supported claim
Secret confidentiality, exact-domain checks and unofficial support caution.
Verification boundary
Primary source inspected for associated mechanism or attributed statement; no authentication of illustrative data.
Checked at
2026-10-01
Open primary source
https://ethereum.org/en/security/

Dataset provenance

id: FIX-P03-L02

dataStatus: ILLUSTRATIVE

source: Original embedded offline cards; no real observations

observedAt: null

timeBasis: SIM/T markers are fictional order, not UTC timestamps

Test your reasoning

P03-L02-Q1 · Does R2 match R1?
P03-L02-Q2 · Copied logo proves?
P03-L02-Q3 · R5 supports?
P03-L02-Q4 · Differing domain identifies a human operator?
P03-L02-Q5 · Safe follow-up?