← Back to Prevention

Crypto Safety Best Practices

Most crypto theft is preventable. Not through paranoia, but through a small number of habits that close off the attack vectors investigators see over and over. Here's the full checklist.

Wallet & Key Management

  • Use a hardware wallet for any balance you wouldn't want to lose. Ledger, Trezor, Coldcard, Keystone — pick one and buy it directly from the manufacturer.
  • Never photograph your seed phrase. Photos sync to iCloud and Google Photos instantly.
  • Back up your seed in at least two physical locations. Fire, flood, and burglary should each require two events to defeat your backup.
  • Never type your seed into any internet-connected device. No "wallet verification" site is legitimate.
  • Consider a BIP-39 passphrase for high-value wallets — adds a 25th word known only to you.
  • Separate daily-use wallet from cold storage. If the hot wallet gets drained, the cold one stays safe.

Account Hardening

  • Hardware key 2FA (YubiKey, Titan) on every exchange account and the email attached to it.
  • Separate crypto-only email that's never posted publicly or used for any other service.
  • Withdrawal allowlist on every exchange — lock outbound withdrawals to addresses you've pre-approved with a time delay.
  • Anti-phishing code on exchanges that support it (Binance, OKX, Bitget).
  • Unique password per site, stored in a password manager with its own hardware-key MFA.
  • Carrier port-freeze on your phone line to prevent SIM swaps.

Transaction Hygiene

  • Verify every recipient address on the hardware device's screen, not your computer monitor. Clipboard malware is real.
  • Read what you're signing. "Approve" transactions grant ongoing permission — "unlimited approve" gives the contract the right to drain the full balance any time.
  • Revoke old approvals quarterly using revoke.cash or Etherscan's approval checker.
  • Never connect your main wallet to experimental dApps, airdrops, or unknown sites. Use a burner wallet for those.
  • Double-check the URL before connecting. opensea.io is real; 0pensea.io and opensea-connect.com are not.
The one habit that prevents most lossesBefore confirming any transaction, stop and ask: "What exactly am I authorizing this contract to do?" If you can't answer, don't sign.

Social Engineering Defense

  • No real support ever DMs you first. Any inbound DM offering "help" with your wallet is a scam.
  • Never share your seed phrase. No legitimate party ever needs it.
  • Never install "support" software like AnyDesk or TeamViewer to "fix" a crypto issue.
  • Ignore "guaranteed return" offers. No legitimate investment pays guaranteed yields above low-single-digit percentages.
  • Verify unexpected outreach. Old friend's Telegram message about a "crypto opportunity"? Their account was likely hacked.

Device Hygiene

  • Dedicated browser profile for crypto activity. No extensions except what you actually need.
  • Keep OS and browser updated. Stealer malware exploits known vulnerabilities.
  • Don't pirate software. Pirated installers are the most common delivery vehicle for crypto-stealer malware.
  • Lock screen when away — a minute of physical access is enough.
  • Avoid public Wi-Fi for any crypto transaction. Use a VPN if you must.

Annual Review Checklist

  1. Test-restore your seed phrase on a second device — confirm the backup works.
  2. Revoke unused token approvals on every chain you use.
  3. Review exchange withdrawal allowlist — remove addresses you no longer use.
  4. Update firmware on every hardware wallet.
  5. Rotate passwords on any account without hardware-key MFA.
  6. Verify the inheritance path — can a trusted person access funds if something happens to you?

What to Do If You Suspect Compromise

If you suspect any of the above defenses has failed — seed exposed, account accessed, suspicious transactions — move funds to a new wallet on a clean device immediately. Don't wait for certainty. See our first 72 hours after theft guide.

Bottom Line

Crypto security isn't about being paranoid — it's about having the right habits in place before you need them. The users we investigate after losses almost never lacked knowledge; they lacked one or two specific practices from this list. Pick the gaps in yours and close them now.