Installing the right app
Fake wallet apps are a persistent problem in both major stores, often ranking for the real wallet's name. Reach the store through the link on the project's official site, then verify the developer name and the install count.
An app that asks for your recovery phrase before letting you create a new wallet is malicious. There is no legitimate reason for that order.
Device settings that matter
A strong device passcode, not a four-digit PIN. Biometric unlock for the wallet app itself. Automatic screen lock on a short timer. Disabled lock-screen notification previews, so a recovery code or transaction alert is not readable to anyone holding the phone.
Keep the operating system current. Most practical mobile compromises use vulnerabilities that were patched months earlier.
Physical and shoulder risk
The realistic threat for a phone wallet is someone taking the unlocked device, or watching you enter a PIN before doing so. Both are solved by the lock timer and by never entering a recovery phrase in a public place.
If a phone is lost, the key is protected by the device lock, and your recovery phrase lets you restore elsewhere immediately. Having that phrase stored somewhere other than the phone is the entire plan.
Connecting to applications
Mobile wallets connect to sites via WalletConnect or an in-app browser. Both surface approval prompts in the wallet, and those prompts are the authoritative view of what you are signing — not the page behind them.
FBT Swap runs as a web app, an installable progressive web app and an Android build. In all three, the signature happens in your own wallet, and the recovery phrase of an external wallet never reaches us.