Non-Custodial Architecture
Bookie never has access to your private keys or seed phrases.Read-Only Connection
Bookie only reads your public wallet address
Manual Approval
Every transaction requires your explicit confirmation
Client-Side Signing
All transaction signing happens in your wallet
No Server Storage
Private keys never leave your device
Burner Wallet Strategy
Use dedicated wallets with limited funds for DeFi interactions:Wallet Types by Security
| Type | Security | Use Case |
|---|---|---|
| Hardware Wallet | Highest | Long-term storage, large holdings |
| Cold Wallet | High | Offline storage, rarely accessed |
| Hot Wallet (Main) | Medium | Regular transactions, moderate funds |
| Burner Wallet | Low | DeFi interactions, limited funds |
Transaction Approval Checklist
Before approving any transaction in your wallet, verify:- Token addresses match expected tokens
- Amounts are correct (check decimals)
- Recipient address is accurate (for transfers)
- Slippage tolerance is reasonable
- Transaction fee is expected (~0.000005 SOL)
- No suspicious program interactions
Common Attack Vectors
Phishing
Fake websites that mimic legitimate DeFi apps. Protection:- Bookmark official Bookie URL
- Verify SSL certificate
- Never click links in unsolicited messages
Malicious Transaction Approval
Transactions that drain your wallet when approved. Protection:- Review all transaction details before approval
- Use burner wallets with limited funds
- Enable transaction simulation in wallet settings
Seed Phrase Theft
Attackers trick users into revealing seed phrases. Protection:- Never share your seed phrase with anyone
- Bookie will never ask for your seed phrase
- Store seed phrases offline in secure location
Wallet Permissions
When you connect to Bookie, you grant these permissions:| Permission | Purpose | Risk Level |
|---|---|---|
| View Address | Display your wallet address | None |
| View Balances | Show token holdings | None |
| Request Signatures | Propose transactions for approval | Low (requires manual approval) |
- Access to private keys
- Automatic transaction signing
- Ability to move funds without approval
Revoking Access
To disconnect your wallet from Bookie:Security Recommendations
Use Hardware Wallets
Ledger or Trezor for maximum security
Enable 2FA
Two-factor authentication on wallet accounts
Regular Audits
Review connected apps monthly
Update Software
Keep wallet software up to date
Incident Response
If you suspect unauthorized access:- Immediately disconnect wallet from all dApps
- Transfer funds to a new wallet with fresh seed phrase
- Revoke all permissions in wallet settings
- Report incident to wallet provider
- Monitor transactions for suspicious activity
Bookie’s security model ensures that even if the Bookie website is compromised, your funds remain safe because private keys never leave your wallet.
Additional Resources
Solana Security Best Practices
Official Solana security guidelines