Skip to content
MyCryptoStart
Wallets Explainer beginner

Wallet Security: How to Keep Crypto Safe

The wallet security habits that prevent losses — protecting your seed phrase, reviewing token approvals, and spotting phishing — in one checklist.

Lucas Almeida 5 min read

Key takeaways

  • Most wallet losses are not hacks — they are a seed phrase typed into a fake site, a look-alike address pasted from history, or a malicious transaction signed in a hurry.
  • Protect the seed phrase above all: write it offline, in two places, and never type it into a website or share it with anyone.
  • Review every token approval before signing, prefer limited over unlimited approvals, and revoke old approvals monthly — a stale approval can drain your tokens.
  • Verify more than the first and last characters of an address, and keep long-term holdings in a wallet that never connects to dApps.
  • Layer the defenses: 2FA on exchanges, a hardware wallet for savings, and a separate hot wallet for everyday activity.

Wallet security is less about clever tools and more about a handful of habits. Most losses are not hacks of the cryptography — they are a seed phrase typed into a fake site, a look-alike address pasted from history, or a malicious transaction signed in a hurry. None of these require an attacker to be skilled; they only require you to be momentarily careless.

This guide is the complete checklist: protect the seed phrase, review what you approve, spot the phishing, and keep a simple maintenance routine. Defense in layers, none of it complicated.

The one thing that controls everything: your seed phrase

Every wallet security guide starts here because everything else is secondary. Your seed phrase — 12 to 24 words — is the master key to every account in the wallet. Anyone who reads it can spend everything, from anywhere, forever.

The non-negotiable rules:

  1. Write it on paper or stamped metal, by hand — never as a photo, screenshot, or note in an app.
  2. Keep two copies in two physical locations, so a single fire or flood does not end you.
  3. Never type it into a website. No legitimate service, dApp, or support team ever needs it on a webpage. Restoring a wallet happens only inside the official wallet app.
  4. Never share it with anyone, for any reason — anyone who asks is scamming you, “always, without exception.”
  5. Avoid entering it on untrusted devices — work computers, library laptops, borrowed phones.

For the complete picture of what the phrase is and how it works, read what a seed phrase is and the seed phrase glossary entry.

The optional extra layer: a passphrase (25th word)

For anyone holding a meaningful amount, there is an optional extra layer worth knowing about: a passphrase (sometimes called the “25th word”). You append a secret word or phrase of your own choosing to your seed phrase, and the wallet derives an entirely different set of accounts from it.

The effect is genuinely useful: even if someone finds your seed phrase, they cannot reach the passphrase-protected accounts without also knowing the passphrase. It is a second lock behind the first door.

The catch is equally real: the passphrase is not recoverable either. If you forget it, the passphrase-protected accounts are gone — the seed phrase alone will not restore them. This is an advanced feature for people who have already mastered the basics, not a first step. If you use one, store it with the same offline discipline as the phrase itself, and never on the same piece of paper.

For genuinely large holdings, the standard upgrades go further: a multisignature wallet requires several keys to approve a transaction, so no single key or person can move funds alone, and MPC (multi-party computation) splits the key across devices so a full key never exists in one place. Both are beyond beginner scope, but they are the right tools when “protect the phrase” stops feeling like enough. See how to store crypto safely for the larger picture.

Review every token approval before you sign

This is the security topic most beginner guides skip, and it is one of the biggest real loss vectors in DeFi. A token approval is permission you grant a smart contract to move a specific token on your behalf. The danger: a malicious or compromised contract with an active approval can drain your tokens without any further action from you.

Three habits that close the gap:

  • Read what you sign. If you cannot explain in one sentence what a transaction does, reject it. “Blind signing” is signing a blank check. A transaction simulator — a tool that previews what a transaction actually does before you confirm — is worth using for anything you are unsure about.
  • Prefer limited approvals. When a dApp lets you set a spending limit, set it close to the amount you actually plan to use — not “unlimited.”
  • Revoke old approvals monthly. Old approvals stay active until you revoke them. Use a tool like Revoke.cash or your network’s token-approval checker to review and revoke. Revoking costs a small gas fee.

Two signature types deserve extra suspicion, because they grant broad, ongoing access: setApprovalForAll (which lets a contract move every token of a type, not just one) and permit signatures (EIP-2612, which approve spending via an off-chain signature rather than a normal transaction). Treat any unexpected prompt for either as hostile until proven otherwise.

The rule of thumb: the only approvals you need are the ones you are actively using. Everything else is an open door.

Verify more than the first and last characters

Address verification is the cheapest defense that catches the nastiest attacks. Two of them in particular:

  • Address poisoning. An attacker sends you a dust transaction from an address that looks like one you recently used, hoping you copy it from your history instead of the real one.
  • Clipboard hijacking. Malware swaps a copied address for the attacker’s in the half-second between copy and paste.

The defense is the same for both: verify the address by eye, and check a middle chunk too — not just the first and last few characters, because address-poisoning attacks deliberately match those. Better still, use an address book for addresses you send to repeatedly, so you are not copy-pasting at all.

Separate your wallets by purpose

One of the highest-value habits is also one of the simplest: do not connect your long-term holdings to anything.

  • Keep your savings in a wallet (ideally a hardware wallet) that never connects to dApps.
  • Use a separate hot wallet for trading, DeFi, and anything that requires connecting to a website.

The logic is blunt: one bad signature can only reach the wallet that signed it. If your long-term wallet has never approved a single contract, a phishing site has nothing to drain even if it tricks you. See our hot vs cold wallet comparison for how to split your holdings across layers.

Spot the phishing and social engineering

Nearly every drainer campaign starts the same way: an unsolicited link. The patterns to recognize:

Red flagWhat it looks likeWhat to do
Fake supportSomeone messages you first, “from” a wallet or exchange, asking for your phrase or a codeReal support never DMs first or asks for keys — block and report
Look-alike domainsA site at a near-miss URL, e.g. a misspelled wallet nameType URLs yourself or use bookmarks, never arrive via ad or link
Urgency“Claim now,” countdown timers, “your wallet is compromised”Pressure is a scam’s tool — slow down
Unexpected signatureA pop-up asking you to sign after you connect a walletRead it; if you cannot explain it, reject it

The one rule that defeats most of it: treat every DM and every link as hostile until proven otherwise. For the full catalog, read the most common crypto scams and our phishing field guide.

Lock down your exchange accounts too

Self-custody is only half the picture — if you also hold funds on an exchange, that account needs the same care.

  • Use an authenticator app for 2FA, not SMS. SMS is vulnerable to SIM-swapping, where an attacker convinces your carrier to transfer your number. See what two-factor authentication is.
  • Secure your email with a hardware key too. Your email is the reset route for most accounts, so a compromised email can unlock everything else. A hardware security key (or at minimum an authenticator app) on your primary email closes that back door.
  • Use a strong, unique password — a password manager beats reuse.
  • Turn on withdrawal allowlists (whitelists) so a compromised account can only withdraw to addresses you approve in advance.

These are the account-level defenses that pair with the wallet-level habits above.

A simple maintenance routine

Security is not a one-time setup; a few recurring checks keep the whole stack honest.

CadenceWhat to do
MonthlyRevoke unused token approvals, disconnect unused dApps, scan for transactions you did not make, update wallet software
QuarterlyTest your recovery on a small test wallet, inspect your physical seed-phrase backups for damage, remove unused browser extensions
AnnuallyReview every device and wallet, refresh settings and firmware, update your inheritance plan if you have one

The quarterly recovery test deserves emphasis: a backup you have never tested is a hypothesis, not a backup. Restore a small test wallet from your phrase once in a while to confirm the words still work — it is the difference between “I think my backup is fine” and “I know it is.”

What to do if you think you are compromised

If you believe your phrase, key, or wallet has been exposed, speed is the whole game. Act immediately:

  1. Create a fresh wallet on a clean, trusted device.
  2. Write down the new seed phrase offline, and verify it restores.
  3. Move every asset from the compromised wallet to the new addresses as fast as you can.
  4. Abandon the old wallet — treat the old phrase as permanently burned.
  5. Revoke any approvals on the old wallet where possible.

If the exposure is an exchange account, change your password, turn on authenticator-app 2FA, freeze withdrawals if the platform offers it, and contact support. There is no undo for a compromised key — prevention is the only real protection.

The bottom line

Wallet security is a stack of simple habits, not a single clever tool. Protect the seed phrase above all, review every token approval and revoke the stale ones, verify addresses beyond the first and last characters, and keep your long-term holdings in a wallet that never touches a dApp. Layer the rest — authenticator-app 2FA on exchanges, a hardware wallet for savings, and a monthly maintenance routine — and you have closed the doors that actually cost people their crypto.

If you are building your security from scratch, learn the foundations in order: what a private key is, then what a seed phrase is, then how to store crypto safely.

Don't have a Binance account yet?Sign up nowenter the referral codeBN2688

Frequently asked questions

What is the most important rule of wallet security?
Protect your seed phrase. Write it on paper or metal, keep it offline in two physical locations, and never type it into a website or share it with anyone. Every real theft starts with the phrase being seen, not guessed — the phrase is the master key to everything in the wallet.
What is a token approval and why should I review it?
A token approval is permission you grant a smart contract to move a specific token on your behalf. A malicious or compromised contract with an active approval can drain your tokens without further action from you. Review what you approve, prefer limited spending limits, and revoke old approvals regularly.
How do I check if my seed phrase or wallet has been compromised?
You usually cannot tell until it is too late, which is why prevention matters. If you believe a phrase or key was exposed — in a photo, a message, or a lost device — treat it as compromised and move your funds to a fresh wallet immediately. There is no way to make a leaked phrase secret again.
Should I use SMS two-factor authentication for my crypto accounts?
No. SMS is vulnerable to SIM-swapping, where an attacker convinces your carrier to transfer your number. Use an authenticator app or a hardware security key instead — the code stays on your device rather than on a channel an attacker can hijack.
Is a hardware wallet enough to keep my crypto safe?
A hardware wallet protects your keys from remote attackers, but it does not stop you from signing a malicious transaction or storing your seed phrase badly. It is one strong layer in a stack — the phrase, your approvals, and your judgment are the others.
How often should I check my wallet security?
Do the quick checks monthly — revoke unused approvals, disconnect unused dApps, and scan for unauthorized transactions. Quarterly, test your recovery on a small wallet and inspect your physical backups. Annually, review all your devices, wallets, and settings, and update your inheritance plan if you have one.

Editor-in-Chief & Lead Researcher

Lucas Almeida

Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.

View author page →

Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.