Crypto wallet security: the 10 rules that actually protect your coins

Nearly all wallet theft comes down to a handful of human errors — digital recovery phrases, phishing sites, and careless approvals. This guide covers the rules that actually protect your coins.

✓ Last verified: 19 Aug 2026Updated: 8 Aug 20261 min read

Why this page exists

Most wallet security advice is either too vague (“be careful”) or too technical to act on. The rules above are the ones that map directly to how wallets actually get drained — and they apply no matter which wallet or coin you use.

The uncomfortable fact: in crypto, you are the security. There is no bank to call, no chargeback, no password reset. Every loss below falls into one of a small number of patterns — and every one of them is preventable with the habits on this page.

The mental model: the phrase is the keys

Whatever wallet you use, the recovery phrase (or seedless-card backup) is the master key. Anyone with the phrase can restore the wallet on their own device and take everything. Treat the phrase with the same care as the PIN to your bank account — except there is no bank to call if it leaks.

Two corollaries that most people miss:

Hot vs cold, in one sentence

Use hot for spending, cold for holding, and keep the amounts proportional to your risk tolerance.

The practical split: spending money lives in a hot wallet, savings live in cold storage. Most people get this backwards and keep everything on an exchange “for convenience” — which is neither hot nor cold, it is someone else’s wallet.

The five ways wallets actually get drained

  1. The leaked phrase — screenshot, cloud note, email, or a “support” chat. This is the #1 cause of loss across every coin.
  2. Phishing sites — a lookalike site asks you to “connect” or “verify” your wallet. The site is the scam.
  3. Malicious approvals — a fake dApp or airdrop page asks you to approve token access. Once signed, the attacker can drain.
  4. Malware on your device — clipboard hijackers swap receiving addresses; keyloggers capture phrases typed into a “wallet”.
  5. Physical theft of the phrase or device — a written phrase stored next to the hardware wallet protects against nothing.

Phishing: the most common attack, explained

Phishing is not a hack — it is deception. A fake site, a fake app, or a fake “support” message gets you to reveal the phrase or sign the wrong thing. The defenses are boring and effective:

Approvals: the silent drain

On Ethereum, Solana and other smart-contract chains, an approval lets a dApp move your tokens. The attack pattern:

  1. A fake airdrop or NFT mint asks you to “connect wallet”.
  2. It requests approval for unlimited token access.
  3. You sign, thinking it is a login.
  4. The attacker drains your balance over time — no further signatures needed.

The defenses: approve limited amounts, revoke unused approvals (Rabby has a built-in tool), and use hardware signing for meaningful balances — the device shows exactly what you approve.

The recovery phrase, stored properly

Hardware wallets: what they do and don’t do

A hardware wallet (Ledger, Trezor, Tangem, OneKeySponsored) keeps keys on a device that never exposes them to the internet. It defends against malware and phishing on your computer — a fake site cannot extract keys it cannot reach.

What it does not defend against: a leaked phrase, physical theft of the phrase, or social engineering that tricks you into confirming a malicious transaction. The device is a tool, not a force field.

Incident response: if you suspect a leak

  1. Move the funds now, ask questions later — create a new wallet on a clean device and transfer everything out.
  2. Do not reuse the compromised phrase — a leaked phrase is burned, even if nothing is missing yet.
  3. Revoke approvals on the compromised account before moving tokens.
  4. Check for clipboard malware — verify any receiving address on a second device before confirming.

Speed matters: the window between a leak and the theft can be minutes.

The ten-minute security audit

Run this monthly:

The passphrase option, explained

Ledger, Trezor, OneKeySponsored and a few software wallets support an optional passphrase — an extra word added on top of the 24-word phrase. Its effect is dramatic:

The honest trade: it adds a second secret to protect, and losing it is as final as losing the phrase. For large holdings, the passphrase is the cheapest security upgrade available; for small holdings, it is optional complexity.

The hardware wallet checklist

If you hold a meaningful amount, the checklist before buying is short but strict:

What no wallet can protect you from

It is worth stating plainly: no wallet, hardware or software, protects you from yourself — a phrase written on a sticky note, a passphrase shared with “support”, a transaction confirmed without reading it. The wallets in this guide reduce the attack surface; they do not replace judgment.

The final rule: treat every request for your phrase, your approval, or your “verification” as hostile until proven otherwise. That one habit prevents more losses than any device.

Step-by-step

  1. Rule 1 — Never store your recovery phrase digitally

    No screenshots, cloud notes, password managers that sync to the cloud, or chat messages. Write the phrase on paper (or stamp it into metal) and keep it offline.

  2. Rule 2 — Use a hardware wallet for large amounts

    Hot wallets are convenient; hardware wallets are for holding. If you own more than you can afford to lose in a hack, move it to Ledger, Trezor, Tangem or similar.

  3. Rule 3 — Type URLs yourself and bookmark them

    Most wallet theft starts with a phishing site that looks like your wallet. Never click wallet links from search ads, emails or Discord DMs. Bookmark the official URL.

  4. Rule 4 — Double-check every receiving address

    Malware can swap a clipboard address at the last second. Compare the address character-by-character, and verify it on the hardware device screen when possible.

  5. Rule 5 — Revoke unused token approvals

    A single malicious approval can drain your tokens. Review and revoke unused approvals on networks that support it (Ethereum, BNB Chain, Solana).

  6. Rule 6 — Test recovery before depositing a large amount

    Create the wallet, note the phrase, wipe or reset, restore from the phrase, and confirm the balance appears. If you cannot restore, the wallet is not ready.

  7. Rule 7 — Keep software updated

    Update your wallet app, browser and device firmware. Updates close the holes attackers use.

  8. Rule 8 — Beware 'support' and 'giveaways'

    No legitimate service asks for your phrase or keys — including 'support'. Giveaways that require a deposit to receive crypto are always scams.

  9. Rule 9 — Separate spending from savings

    Keep a small hot-wallet balance for daily use and the bulk of your funds in cold storage. Compromise of the hot wallet then costs little.

  10. Rule 10 — Plan what happens if the wallet disappears

    Your recovery phrase is the backup — it imports into other compatible wallets. Know your wallet's backup format (BIP39 words, seedless cards, etc.) before you need it.

How we evaluate

Every recommendation is based on our published methodology: we separate self-custody wallets, hardware wallets, custodial exchanges and buying platforms, and score each with its own criteria. We label everything as hands-on tested, documentation reviewed, or not yet tested. Commissions never determine rankings.

Read our full methodology

Sources & evidence

Changelog

Frequently asked questions

What is the single most common cause of wallet theft?

A recovery phrase stored digitally — in a screenshot, cloud note, or a chat message — combined with a compromised device or service that can read it.

Should I use a password manager for my recovery phrase?

If the password manager syncs to the cloud, no. The phrase is the keys — a single leaked copy means the wallet can be drained. Paper or stamped metal, kept offline, is the standard.

Are hardware wallets unhackable?

No device is unhackable, but hardware wallets remove the most common attack surface: a compromised phone or computer cannot sign transactions without the device. For most people they are the right cold-storage choice.

I think my wallet was compromised. What do I do?

Immediately move remaining funds to a fresh wallet created on a clean device, revoke any approvals you can, and report the incident.