Not financial, legal, or tax advice. This guide is for general education only. Even with strong security practices, crypto carries risk, including loss due to theft, error, or market movements. Do your own research.
Keeping your crypto safe comes down to protecting your keys, guarding against scams, and following a few consistent habits. Because crypto transactions are irreversible and there is no bank to reverse fraud, security is the single most important skill a holder can build. This checklist walks through the essentials.
Table of Contents
- Why crypto security is different
- Wallet security basics
- Protecting your seed phrase
- Using two-factor authentication
- Spotting and avoiding scams
- Approvals: the risk people miss
- Planning for recovery
- If the worst happens
- The security checklist
- FAQ
Why crypto security is different
In traditional finance, a bank can freeze fraud, reverse a mistaken payment, or restore access to a locked account. Crypto offers none of that safety net. Transactions are final, and if someone gains control of your keys, the funds are usually gone for good.
The US Federal Trade Commission makes the same point bluntly: crypto payments do not come with the legal protections that card payments do, and transfers are typically irreversible. That shifts responsibility onto you. The upside is real control over your own money; the flip side is that a single careless moment can be costly. Understanding this is the foundation of everything that follows, and it builds on how wallets hold your keys and what owning a cryptocurrency really means.
The consequence worth absorbing is that in crypto there is no such thing as a small security mistake. In the ordinary financial system, most errors are recoverable: a fraudulent charge is reversed, a wrong transfer is clawed back, a compromised password is reset, and the worst outcome is usually an afternoon on the phone. Every one of those safety nets is a person or an institution with the power to undo something. Crypto removed that power deliberately, which is the entire point, and the cost is that the same finality protects a thief exactly as reliably as it protects you.
This is why security here is preventative rather than reactive, and why the habits look excessive to newcomers. In a system with no undo, there is no such thing as fixing it afterwards. There is only not letting it happen, which means the boring discipline is not paranoia. It is the only control that exists.
Wallet security basics
Your wallet is your front door, so treat it accordingly:
- Use reputable wallets only. Download from official sources, and be wary of copycat apps and sites.
- Keep meaningful holdings in cold storage. A hardware wallet keeps your keys offline and out of reach of malware.
- Separate your funds. Keep a small amount in a hot wallet for everyday use and the bulk in cold storage.
- Keep software updated. Updates often patch security flaws.
- Verify addresses carefully. Malware can swap a copied address. Always check before sending.
The fuller picture on wallet types and their trade-offs is worth reading, especially the split between hot and cold storage.
Separating your funds is the habit with the best return for the least effort, and it is worth doing deliberately rather than by accident. Keep a spending wallet with an amount you would be annoyed but not damaged to lose, and use it for anything experimental: connecting to a new application, claiming something, trying a protocol you have not used before. Keep the savings in cold storage that never touches an application at all. Then the worst realistic outcome of a bad decision is bounded by what was in the spending wallet, rather than by everything you own. Most catastrophic losses are not sophisticated attacks; they are ordinary mistakes made by someone whose entire holdings were sitting in the wallet they happened to be experimenting with.
Protecting your seed phrase
Your seed phrase is the master key to your wallet. Anyone who has it controls your funds, and losing it can mean losing access permanently. Protect it with care:
- Store it offline. Write it on paper or use a metal backup. Never keep it in a screenshot, email, or cloud note.
- Never share it. No legitimate support agent, app, or website will ever ask for your seed phrase. Anyone who does is trying to rob you.
- Keep multiple secure copies. Store backups in more than one safe location to protect against fire, loss, or damage.
- Never type it into a website. Seed phrases are entered into wallet software, never into random web forms.
Our guide explains what a seed phrase is and how to store it in more depth.
The failure people do not plan for is not theft, it is loss, and the two demand opposite things. Guarding against theft pushes you toward fewer copies, better hidden. Guarding against loss pushes you toward more copies, in more places. Optimize entirely for one and you have created the other: a phrase so well concealed that a house fire, a flood, or a moment of forgetfulness destroys everything, permanently. Realistically, more crypto has been lost to carelessness and bad luck than to hackers.
The workable compromise is two or three copies, on something that survives fire and water, in physically separate locations that are not all your house. Paper in a drawer is one incident away from gone; a metal backup in a safe plus a second in another building survives almost anything short of deliberate targeting. And the copies should be somewhere findable by design rather than by memory, because the last failure mode is the one nobody discusses: dying with the only knowledge of where it is. Estate planning is part of self-custody, not a contradiction of it.
Using two-factor authentication
Two-factor authentication (2FA) adds a second layer beyond your password, so a stolen password alone is not enough to access your accounts. A few guidelines:
- Prefer app-based or hardware 2FA over text-message codes, which can be intercepted through SIM-swapping attacks.
- Enable it everywhere it is offered, especially on exchange accounts and email.
- Protect your email account first, since it is often the key to resetting everything else.
- Store backup codes offline, so losing a phone locks out an attacker rather than you.
The warning about text-message codes deserves more than a line, because it is the mechanism behind a large share of exchange account thefts. In a SIM-swap, an attacker persuades your mobile provider to move your number to a device they control, usually with nothing more than public information and confidence. Every code sent to that number then arrives at their phone, and so does every password reset that relies on it. You do not need to be hacked in any technical sense; someone simply talks to your carrier. An authenticator app or a hardware key defeats this entirely, because the second factor never travels over the phone network at all.
Spotting and avoiding scams
Scams are one of the biggest threats to crypto holders, and they prey on urgency and greed. Common ones to recognize:
- Phishing. Fake emails, sites, and messages that try to capture your credentials or seed phrase.
- Fake giveaways. "Send us crypto and we'll send back double" is always a scam.
- Impersonation. Fraudsters posing as support staff, celebrities, or friends.
- Guaranteed returns. No legitimate investment guarantees profits. High, "risk-free" yields are a red flag.
- Malicious apps and links. Downloads and links that install malware or drain wallets.
- Address poisoning. A scammer sends you a tiny transaction from an address resembling one you use, hoping you later copy it from your history instead of the real one.
- Fake job offers and airdrops. A convincing recruiter or a free token claim that requires connecting your wallet and signing something you did not read.
Worth stating plainly, because it is the one rule that ends most attacks before they start: nobody legitimate will ever ask for your seed phrase. Not support, not a developer, not a wallet, not an exchange, not someone helping you in a chat. There is no situation, no error message, and no recovery process that requires it. Anyone who asks is robbing you, and there are no exceptions to check for.
The common thread is pressure to act fast, or an offer that seems too good to be true. Slow down and verify — our catalog of common scams covers the recurring patterns, and what to do if a wallet is compromised covers the worst case.
Approvals: the risk people miss
Almost all security advice concentrates on keeping your key secret, and it is correct as far as it goes. The problem is that the most common way people are drained today does not involve the key at all, and defeats a hardware wallet completely.
When you connect a wallet to any application, it typically asks for permission to spend a token on your behalf. You are not sending anything, which is exactly why it does not feel like a decision. What you are doing is granting a smart contract standing authority to move that token out of your wallet, whenever it likes, for as long as the permission stands, which by default is often unlimited and forever. If that contract turns out to be malicious, or is compromised months later, it does not need to steal anything. It simply uses the permission you gave it. Your key was never exposed. The theft is, mechanically, something you authorized.
Two habits close most of this off. Grant approvals deliberately, and prefer applications that request only the amount required rather than an unlimited allowance. And review your existing approvals periodically, revoking anything you no longer use, because the permission you granted to a protocol you tried once in 2022 is still live today.
The related discipline is reading what you sign. A hardware wallet shows the transaction on its own screen precisely so that malware on your computer cannot show you one thing and send another. That protection only works if you actually look at the device rather than clicking through it. A signature request you do not understand is a signature request to decline; there is no cost to walking away and no recovery if you are wrong.
Planning for recovery
Good security includes planning for the unexpected. Think through how you would recover access if a device is lost or damaged, and make sure your seed phrase backups are stored safely enough to survive that. Consider how your holdings could be accessed by a trusted person in an emergency, without exposing your keys during normal times. Documenting a simple, secure plan now can prevent permanent loss later.
If the worst happens
If you believe your wallet is compromised, speed matters more than certainty. Attackers frequently automate: the moment funds arrive, they leave.
Move whatever remains to a new wallet with a freshly generated seed phrase, immediately, and do not simply change a password or reinstall the app, because if the phrase is known then every wallet derived from it is compromised forever. Assume anything reachable by that phrase is already lost. Then work out how it happened, since restoring to a device that still has malware on it just repeats the exercise.
Be very careful about what comes next, because a second wave targets people who have just been robbed. Recovery services that guarantee they can retrieve stolen crypto are, essentially without exception, a scam preying on desperation. Funds moved on-chain cannot be reversed by anyone, and no fee changes that. Theft can be reported to law enforcement, and in the US that is the FBI's Internet Crime Complaint Center, which is worth doing for the record even though recovery is unlikely. Our step-by-step guide to a compromised wallet covers the sequence in detail.
The security checklist
A quick recap you can act on:
- Use reputable wallets, downloaded from official sources.
- Keep significant holdings in a hardware (cold) wallet.
- Store your seed phrase offline, in multiple secure locations, and never share it.
- Enable app-based or hardware 2FA on all accounts, starting with email.
- Verify every address before sending.
- Stay alert to phishing, fake giveaways, and "guaranteed return" scams.
- Keep software updated.
- Have a recovery plan for lost or damaged devices.
- Review and revoke old token approvals, and never grant an unlimited allowance you do not need.
- Read what you sign on the hardware wallet's own screen, not your computer's.
- Use a separate wallet for experimenting with new applications, and never the one holding your savings.