Control, custody, seeds, signing, funding, recovery, and the mistakes that cost people everything.
It isn’t the app name. It’s whoever controls valid signing authority.
You control the keys, the signing, and the responsibility.
The exchange controls the keys. Your balance may only exist inside its database until withdrawal.
You can view the account without holding signing authority.
Seeing an account in an app doesn’t prove you control it. Signing authority proves control.
Your seed isn’t a password. There’s no reset desk behind the ledger.
An account becomes active on-ledger when it receives enough $XRP to meet the current reserve.
The public destination beginning with r.
An extra identifier exchanges often use to route a deposit.
The minimum $XRP the account and its owned objects require.
The wallet should show exactly what you’re authorizing.
Payment, trustline, offer, NFT offer, or account setting?
Is the address correct?
Is the amount and asset right?
For issued assets, is the issuer right?
Are permissions or settings changing?
Is the transaction cost reasonable?
The website’s button can lie. The signed transaction is what the ledger executes.
XRPL lets accounts separate everyday signing from the master key and require multiple signers.
An alternate signing key you can rotate.
The original account authority.
A multisigning setup requiring enough signer weight.
Most wallet disasters are simple authority failures.
Answer these without guessing.
Open the next application and keep building the full picture.