Wallet Security: How to Keep Crypto Safe
The wallet security habits that prevent losses — protecting your seed phrase, reviewing token approvals, and spotting phishing — in one checklist.
Key takeaways
- Most wallet losses are not hacks — they are a seed phrase typed into a fake site, a look-alike address pasted from history, or a malicious transaction signed in a hurry.
- Protect the seed phrase above all: write it offline, in two places, and never type it into a website or share it with anyone.
- Review every token approval before signing, prefer limited over unlimited approvals, and revoke old approvals monthly — a stale approval can drain your tokens.
- Verify more than the first and last characters of an address, and keep long-term holdings in a wallet that never connects to dApps.
- Layer the defenses: 2FA on exchanges, a hardware wallet for savings, and a separate hot wallet for everyday activity.
Wallet security is less about clever tools and more about a handful of habits. Most losses are not hacks of the cryptography — they are a seed phrase typed into a fake site, a look-alike address pasted from history, or a malicious transaction signed in a hurry. None of these require an attacker to be skilled; they only require you to be momentarily careless.
This guide is the complete checklist: protect the seed phrase, review what you approve, spot the phishing, and keep a simple maintenance routine. Defense in layers, none of it complicated.
The one thing that controls everything: your seed phrase
Every wallet security guide starts here because everything else is secondary. Your seed phrase — 12 to 24 words — is the master key to every account in the wallet. Anyone who reads it can spend everything, from anywhere, forever.
The non-negotiable rules:
- Write it on paper or stamped metal, by hand — never as a photo, screenshot, or note in an app.
- Keep two copies in two physical locations, so a single fire or flood does not end you.
- Never type it into a website. No legitimate service, dApp, or support team ever needs it on a webpage. Restoring a wallet happens only inside the official wallet app.
- Never share it with anyone, for any reason — anyone who asks is scamming you, “always, without exception.”
- Avoid entering it on untrusted devices — work computers, library laptops, borrowed phones.
For the complete picture of what the phrase is and how it works, read what a seed phrase is and the seed phrase glossary entry.
The optional extra layer: a passphrase (25th word)
For anyone holding a meaningful amount, there is an optional extra layer worth knowing about: a passphrase (sometimes called the “25th word”). You append a secret word or phrase of your own choosing to your seed phrase, and the wallet derives an entirely different set of accounts from it.
The effect is genuinely useful: even if someone finds your seed phrase, they cannot reach the passphrase-protected accounts without also knowing the passphrase. It is a second lock behind the first door.
The catch is equally real: the passphrase is not recoverable either. If you forget it, the passphrase-protected accounts are gone — the seed phrase alone will not restore them. This is an advanced feature for people who have already mastered the basics, not a first step. If you use one, store it with the same offline discipline as the phrase itself, and never on the same piece of paper.
For genuinely large holdings, the standard upgrades go further: a multisignature wallet requires several keys to approve a transaction, so no single key or person can move funds alone, and MPC (multi-party computation) splits the key across devices so a full key never exists in one place. Both are beyond beginner scope, but they are the right tools when “protect the phrase” stops feeling like enough. See how to store crypto safely for the larger picture.
Review every token approval before you sign
This is the security topic most beginner guides skip, and it is one of the biggest real loss vectors in DeFi. A token approval is permission you grant a smart contract to move a specific token on your behalf. The danger: a malicious or compromised contract with an active approval can drain your tokens without any further action from you.
Three habits that close the gap:
- Read what you sign. If you cannot explain in one sentence what a transaction does, reject it. “Blind signing” is signing a blank check. A transaction simulator — a tool that previews what a transaction actually does before you confirm — is worth using for anything you are unsure about.
- Prefer limited approvals. When a dApp lets you set a spending limit, set it close to the amount you actually plan to use — not “unlimited.”
- Revoke old approvals monthly. Old approvals stay active until you revoke them. Use a tool like Revoke.cash or your network’s token-approval checker to review and revoke. Revoking costs a small gas fee.
Two signature types deserve extra suspicion, because they grant broad, ongoing access: setApprovalForAll (which lets a contract move every token of a type, not just one) and permit signatures (EIP-2612, which approve spending via an off-chain signature rather than a normal transaction). Treat any unexpected prompt for either as hostile until proven otherwise.
The rule of thumb: the only approvals you need are the ones you are actively using. Everything else is an open door.
Verify more than the first and last characters
Address verification is the cheapest defense that catches the nastiest attacks. Two of them in particular:
- Address poisoning. An attacker sends you a dust transaction from an address that looks like one you recently used, hoping you copy it from your history instead of the real one.
- Clipboard hijacking. Malware swaps a copied address for the attacker’s in the half-second between copy and paste.
The defense is the same for both: verify the address by eye, and check a middle chunk too — not just the first and last few characters, because address-poisoning attacks deliberately match those. Better still, use an address book for addresses you send to repeatedly, so you are not copy-pasting at all.
Separate your wallets by purpose
One of the highest-value habits is also one of the simplest: do not connect your long-term holdings to anything.
- Keep your savings in a wallet (ideally a hardware wallet) that never connects to dApps.
- Use a separate hot wallet for trading, DeFi, and anything that requires connecting to a website.
The logic is blunt: one bad signature can only reach the wallet that signed it. If your long-term wallet has never approved a single contract, a phishing site has nothing to drain even if it tricks you. See our hot vs cold wallet comparison for how to split your holdings across layers.
Spot the phishing and social engineering
Nearly every drainer campaign starts the same way: an unsolicited link. The patterns to recognize:
| Red flag | What it looks like | What to do |
|---|---|---|
| Fake support | Someone messages you first, “from” a wallet or exchange, asking for your phrase or a code | Real support never DMs first or asks for keys — block and report |
| Look-alike domains | A site at a near-miss URL, e.g. a misspelled wallet name | Type URLs yourself or use bookmarks, never arrive via ad or link |
| Urgency | “Claim now,” countdown timers, “your wallet is compromised” | Pressure is a scam’s tool — slow down |
| Unexpected signature | A pop-up asking you to sign after you connect a wallet | Read it; if you cannot explain it, reject it |
The one rule that defeats most of it: treat every DM and every link as hostile until proven otherwise. For the full catalog, read the most common crypto scams and our phishing field guide.
Lock down your exchange accounts too
Self-custody is only half the picture — if you also hold funds on an exchange, that account needs the same care.
- Use an authenticator app for 2FA, not SMS. SMS is vulnerable to SIM-swapping, where an attacker convinces your carrier to transfer your number. See what two-factor authentication is.
- Secure your email with a hardware key too. Your email is the reset route for most accounts, so a compromised email can unlock everything else. A hardware security key (or at minimum an authenticator app) on your primary email closes that back door.
- Use a strong, unique password — a password manager beats reuse.
- Turn on withdrawal allowlists (whitelists) so a compromised account can only withdraw to addresses you approve in advance.
These are the account-level defenses that pair with the wallet-level habits above.
A simple maintenance routine
Security is not a one-time setup; a few recurring checks keep the whole stack honest.
| Cadence | What to do |
|---|---|
| Monthly | Revoke unused token approvals, disconnect unused dApps, scan for transactions you did not make, update wallet software |
| Quarterly | Test your recovery on a small test wallet, inspect your physical seed-phrase backups for damage, remove unused browser extensions |
| Annually | Review every device and wallet, refresh settings and firmware, update your inheritance plan if you have one |
The quarterly recovery test deserves emphasis: a backup you have never tested is a hypothesis, not a backup. Restore a small test wallet from your phrase once in a while to confirm the words still work — it is the difference between “I think my backup is fine” and “I know it is.”
What to do if you think you are compromised
If you believe your phrase, key, or wallet has been exposed, speed is the whole game. Act immediately:
- Create a fresh wallet on a clean, trusted device.
- Write down the new seed phrase offline, and verify it restores.
- Move every asset from the compromised wallet to the new addresses as fast as you can.
- Abandon the old wallet — treat the old phrase as permanently burned.
- Revoke any approvals on the old wallet where possible.
If the exposure is an exchange account, change your password, turn on authenticator-app 2FA, freeze withdrawals if the platform offers it, and contact support. There is no undo for a compromised key — prevention is the only real protection.
The bottom line
Wallet security is a stack of simple habits, not a single clever tool. Protect the seed phrase above all, review every token approval and revoke the stale ones, verify addresses beyond the first and last characters, and keep your long-term holdings in a wallet that never touches a dApp. Layer the rest — authenticator-app 2FA on exchanges, a hardware wallet for savings, and a monthly maintenance routine — and you have closed the doors that actually cost people their crypto.
If you are building your security from scratch, learn the foundations in order: what a private key is, then what a seed phrase is, then how to store crypto safely.
Don't have a Binance account yet?Sign up nowenter the referral codeBN2688
Frequently asked questions
What is the most important rule of wallet security?
What is a token approval and why should I review it?
How do I check if my seed phrase or wallet has been compromised?
Should I use SMS two-factor authentication for my crypto accounts?
Is a hardware wallet enough to keep my crypto safe?
How often should I check my wallet security?
Editor-in-Chief & Lead Researcher
Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.
View author page →Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.
Continue reading
Hardware Wallets Explained: Cold Storage Guide
What a hardware wallet does, when it's worth buying, how Ledger and Trezor differ, and the setup rules that keep cold storage secure.
Hot Wallet vs Cold Wallet: Key Differences
Hot wallets are connected to the internet and convenient; cold wallets keep keys offline and secure. A comparison of security, cost, and convenience.
How to Set Up MetaMask: A Beginner's Guide
How to install MetaMask, create a wallet, and back up your secret recovery phrase — plus how to fund it and the phishing warnings to watch for.