GloveCat Security and Risk Checklist
A pre-transaction checklist for official addresses, network, pair, approvals, wallet prompts, live readiness, and crypto risks.
Published · Updated · 10 min read
Maintained by the GloveCat project team.
What changed on September 2, 2026
Added a concrete threat model and a compact evidence record for investigating suspicious wallet or contract interactions.
1. Start from an independently reached source
Type or bookmark the official domain instead of trusting a promoted result, social reply, direct message, or forwarded link. Compare important addresses between the official website, documentation, and Basescan.
- Domain: glovecatcoin.com
- Network: Base mainnet, chain ID 8453
- GCAT: 0x59df0577C7A5014954C0d6Cc12616e92E34d9fF4
- Official pair: 0x6330Bb184d90D78F336270485C3d17AB8AE8dD54
2. Read every wallet request
A familiar website appearance does not make a wallet prompt safe. The wallet confirmation is the final opportunity to compare the actual on-chain action with your intent.
- Confirm the network and destination contract.
- Distinguish a transaction from a message or typed-data signature.
- Reject unlimited or unrelated token allowances.
- Check the amount, spender, gas, and any minimum received value.
- Never enter a seed phrase into a website or support conversation.
3. Use action-specific checks
For staking, mutable availability comes from live contract reads and the validated public-status response. A historical launch announcement is not a substitute for the current state.
- Buy or sellVerify token, pair, router, quote, and slippage
- StakeVerify staking address, allowance, amount, duration, and readiness
- ClaimVerify contract call and expected incentive accounting
- NFTVerify collection address, token ID, activation, and transfer state
4. Plan for market and liquidity risk
GCAT can lose value, liquidity can change, DEX quotes can move between review and execution, and a locked position can prevent access to principal during volatility. Only use assets you can afford to lose and keep Base gas available for later actions.
5. Match checks to realistic failure modes
Address substitution is only one risk. A copied site can display the correct GCAT address while requesting an approval for a malicious spender. A compromised social account can link to a real DEX with the wrong token preselected. A legitimate contract can be paired with a misleading promise about returns. A stale readiness snapshot can look healthy after conditions have changed. Each failure mode requires a different check.
Use domain and certificate checks for site identity, complete address comparison for contract identity, wallet calldata and allowance review for transaction intent, fresh block-referenced reads for mutable state, and independent risk judgment for market claims. No single badge, verified-source indicator, audit, or public lock replaces the other checks. Stop if the evidence layers disagree.
- Correct token, wrong spender: reject the allowance or transaction.
- Correct domain, stale state: refresh from the official live endpoint and verify its validity window.
- Correct contract, misleading promise: rely on contract mechanics and risk disclosures, not the promise.
- Correct-looking interface, wrong chain: switch back to Base only after independently verifying the request.
6. Create an evidence record before seeking help
For a suspicious interaction, record the domain, full destination and spender addresses, network, transaction or signature type, amount, timestamp, wallet warning, and any transaction hash. Capture public information only; never record or send a seed phrase, private key, recovery code, or authentication secret. Use the record to review allowances and mined events from a trusted explorer.
When contacting official support, describe the intended action and provide only the public identifiers needed to reproduce the issue. A legitimate support process can investigate public transactions without controlling the wallet. Treat requests to install remote-access software, share a screen containing secrets, or move funds to a 'safe' address as hostile.
7. If something looks wrong
Blockchain transactions are generally irreversible. Fast containment matters more than responding to an unsolicited helper.
- Do not sign, approve, or continue troubleshooting through the suspicious channel.
- Disconnect the site from the wallet and review token allowances from a trusted explorer or wallet tool.
- Record the transaction hash, destination, time, and observed behavior without sharing secrets.
- Contact [email protected] from the address published on the official site.
Sources and evidence
Dated transactions prove historical events; balances, ownership, readiness, and quotes must be checked again when used.
Official support
Questions about published evidence can be sent to [email protected].
Risk disclaimer
GCAT is an experimental meme token with no intrinsic value or expectation of financial return. Public contracts and locks do not guarantee price, liquidity, rewards, or safety. Verify current evidence and make your own risk decision.