Wallet & Key Management
- Use a hardware wallet for any balance you wouldn't want to lose. Ledger, Trezor, Coldcard, Keystone — pick one and buy it directly from the manufacturer.
- Never photograph your seed phrase. Photos sync to iCloud and Google Photos instantly.
- Back up your seed in at least two physical locations. Fire, flood, and burglary should each require two events to defeat your backup.
- Never type your seed into any internet-connected device. No "wallet verification" site is legitimate.
- Consider a BIP-39 passphrase for high-value wallets — adds a 25th word known only to you.
- Separate daily-use wallet from cold storage. If the hot wallet gets drained, the cold one stays safe.
Account Hardening
- Hardware key 2FA (YubiKey, Titan) on every exchange account and the email attached to it.
- Separate crypto-only email that's never posted publicly or used for any other service.
- Withdrawal allowlist on every exchange — lock outbound withdrawals to addresses you've pre-approved with a time delay.
- Anti-phishing code on exchanges that support it (Binance, OKX, Bitget).
- Unique password per site, stored in a password manager with its own hardware-key MFA.
- Carrier port-freeze on your phone line to prevent SIM swaps.
Transaction Hygiene
- Verify every recipient address on the hardware device's screen, not your computer monitor. Clipboard malware is real.
- Read what you're signing. "Approve" transactions grant ongoing permission — "unlimited approve" gives the contract the right to drain the full balance any time.
- Revoke old approvals quarterly using revoke.cash or Etherscan's approval checker.
- Never connect your main wallet to experimental dApps, airdrops, or unknown sites. Use a burner wallet for those.
- Double-check the URL before connecting. opensea.io is real; 0pensea.io and opensea-connect.com are not.
The one habit that prevents most lossesBefore confirming any transaction, stop and ask: "What exactly am I authorizing this contract to do?" If you can't answer, don't sign.
Social Engineering Defense
- No real support ever DMs you first. Any inbound DM offering "help" with your wallet is a scam.
- Never share your seed phrase. No legitimate party ever needs it.
- Never install "support" software like AnyDesk or TeamViewer to "fix" a crypto issue.
- Ignore "guaranteed return" offers. No legitimate investment pays guaranteed yields above low-single-digit percentages.
- Verify unexpected outreach. Old friend's Telegram message about a "crypto opportunity"? Their account was likely hacked.
Device Hygiene
- Dedicated browser profile for crypto activity. No extensions except what you actually need.
- Keep OS and browser updated. Stealer malware exploits known vulnerabilities.
- Don't pirate software. Pirated installers are the most common delivery vehicle for crypto-stealer malware.
- Lock screen when away — a minute of physical access is enough.
- Avoid public Wi-Fi for any crypto transaction. Use a VPN if you must.
Annual Review Checklist
- Test-restore your seed phrase on a second device — confirm the backup works.
- Revoke unused token approvals on every chain you use.
- Review exchange withdrawal allowlist — remove addresses you no longer use.
- Update firmware on every hardware wallet.
- Rotate passwords on any account without hardware-key MFA.
- Verify the inheritance path — can a trusted person access funds if something happens to you?
What to Do If You Suspect Compromise
If you suspect any of the above defenses has failed — seed exposed, account accessed, suspicious transactions — move funds to a new wallet on a clean device immediately. Don't wait for certainty. See our first 72 hours after theft guide.
Bottom Line
Crypto security isn't about being paranoid — it's about having the right habits in place before you need them. The users we investigate after losses almost never lacked knowledge; they lacked one or two specific practices from this list. Pick the gaps in yours and close them now.