Crypto wallet security: the 10 rules that actually protect your coins
Nearly all wallet theft comes down to a handful of human errors — digital recovery phrases, phishing sites, and careless approvals. This guide covers the rules that actually protect your coins.
Why this page exists
Most wallet security advice is either too vague (“be careful”) or too technical to act on. The rules above are the ones that map directly to how wallets actually get drained — and they apply no matter which wallet or coin you use.
The uncomfortable fact: in crypto, you are the security. There is no bank to call, no chargeback, no password reset. Every loss below falls into one of a small number of patterns — and every one of them is preventable with the habits on this page.
The mental model: the phrase is the keys
Whatever wallet you use, the recovery phrase (or seedless-card backup) is the master key. Anyone with the phrase can restore the wallet on their own device and take everything. Treat the phrase with the same care as the PIN to your bank account — except there is no bank to call if it leaks.
Two corollaries that most people miss:
- The phrase outranks the wallet. If your wallet app disappears, the phrase restores your coins elsewhere. If the phrase leaks, no wallet security matters.
- The phrase is the backup, not the interface. You should be able to restore your wallet from scratch using only the phrase — test this once before depositing a meaningful amount.
Hot vs cold, in one sentence
- Hot wallet (phone or browser app): convenient, always online, always exposed.
- Cold storage (hardware wallet or offline paper): keys never touch an internet-connected device.
Use hot for spending, cold for holding, and keep the amounts proportional to your risk tolerance.
The practical split: spending money lives in a hot wallet, savings live in cold storage. Most people get this backwards and keep everything on an exchange “for convenience” — which is neither hot nor cold, it is someone else’s wallet.
The five ways wallets actually get drained
- The leaked phrase — screenshot, cloud note, email, or a “support” chat. This is the #1 cause of loss across every coin.
- Phishing sites — a lookalike site asks you to “connect” or “verify” your wallet. The site is the scam.
- Malicious approvals — a fake dApp or airdrop page asks you to approve token access. Once signed, the attacker can drain.
- Malware on your device — clipboard hijackers swap receiving addresses; keyloggers capture phrases typed into a “wallet”.
- Physical theft of the phrase or device — a written phrase stored next to the hardware wallet protects against nothing.
Phishing: the most common attack, explained
Phishing is not a hack — it is deception. A fake site, a fake app, or a fake “support” message gets you to reveal the phrase or sign the wrong thing. The defenses are boring and effective:
- Bookmark your wallets — never arrive via search, ads, or DMs.
- Verify URLs — one changed letter in a domain is the tell.
- Never enter your phrase on a website — no dApp, no “verification” service, no support chat ever needs it.
- “Verify your wallet” is always a scam — no legitimate service asks you to connect a wallet to prove ownership.
Approvals: the silent drain
On Ethereum, Solana and other smart-contract chains, an approval lets a dApp move your tokens. The attack pattern:
- A fake airdrop or NFT mint asks you to “connect wallet”.
- It requests approval for unlimited token access.
- You sign, thinking it is a login.
- The attacker drains your balance over time — no further signatures needed.
The defenses: approve limited amounts, revoke unused approvals (Rabby has a built-in tool), and use hardware signing for meaningful balances — the device shows exactly what you approve.
The recovery phrase, stored properly
- Write it on paper — or stamp it in metal for fire/flood resistance. Digital copies (screenshots, notes, password managers that sync) defeat the purpose.
- Store it offline — a drawer, a safe, a second location. Not in the same room as the hardware wallet.
- Split it deliberately — a single full phrase is a single point of failure; consider a metal backup or (for advanced users) SLIP-39 shares.
- Test the restore — wipe the wallet, restore from the phrase, confirm the balance appears. Do this before moving real money.
Hardware wallets: what they do and don’t do
A hardware wallet (Ledger, Trezor, Tangem, OneKeySponsored) keeps keys on a device that never exposes them to the internet. It defends against malware and phishing on your computer — a fake site cannot extract keys it cannot reach.
What it does not defend against: a leaked phrase, physical theft of the phrase, or social engineering that tricks you into confirming a malicious transaction. The device is a tool, not a force field.
Incident response: if you suspect a leak
- Move the funds now, ask questions later — create a new wallet on a clean device and transfer everything out.
- Do not reuse the compromised phrase — a leaked phrase is burned, even if nothing is missing yet.
- Revoke approvals on the compromised account before moving tokens.
- Check for clipboard malware — verify any receiving address on a second device before confirming.
Speed matters: the window between a leak and the theft can be minutes.
The ten-minute security audit
Run this monthly:
- ✅ Is the recovery phrase offline, on paper/metal, and untested-phrase-free?
- ✅ Are unused approvals revoked?
- ✅ Is the wallet software updated?
- ✅ Are you using hardware signing for anything meaningful?
- ✅ Would you recognize a phishing site or DM if you saw one?
The passphrase option, explained
Ledger, Trezor, OneKeySponsored and a few software wallets support an optional passphrase — an extra word added on top of the 24-word phrase. Its effect is dramatic:
- A stolen phrase without the passphrase is useless — the attacker sees an empty wallet.
- The passphrase is not stored anywhere — forget it and the coins are gone, exactly like the phrase itself.
- Different passphrases create different wallets from the same phrase — a useful “decoy wallet” trick for high-risk situations.
The honest trade: it adds a second secret to protect, and losing it is as final as losing the phrase. For large holdings, the passphrase is the cheapest security upgrade available; for small holdings, it is optional complexity.
The hardware wallet checklist
If you hold a meaningful amount, the checklist before buying is short but strict:
- Does the device support your coins? Ledger/Trezor differ on AVAX, BNB, KAS, HBAR, VET and ALGO — check per coin.
- Buy from the manufacturer — never second-hand; a tampered device defeats the security model.
- Verify the device on first use — Ledger and Trezor both ship with authenticity checks; use them.
- Test recovery before depositing — the ten-minute test applies to hardware too.
What no wallet can protect you from
It is worth stating plainly: no wallet, hardware or software, protects you from yourself — a phrase written on a sticky note, a passphrase shared with “support”, a transaction confirmed without reading it. The wallets in this guide reduce the attack surface; they do not replace judgment.
The final rule: treat every request for your phrase, your approval, or your “verification” as hostile until proven otherwise. That one habit prevents more losses than any device.
Step-by-step
Rule 1 — Never store your recovery phrase digitally
No screenshots, cloud notes, password managers that sync to the cloud, or chat messages. Write the phrase on paper (or stamp it into metal) and keep it offline.
Rule 2 — Use a hardware wallet for large amounts
Hot wallets are convenient; hardware wallets are for holding. If you own more than you can afford to lose in a hack, move it to Ledger, Trezor, Tangem or similar.
Rule 3 — Type URLs yourself and bookmark them
Most wallet theft starts with a phishing site that looks like your wallet. Never click wallet links from search ads, emails or Discord DMs. Bookmark the official URL.
Rule 4 — Double-check every receiving address
Malware can swap a clipboard address at the last second. Compare the address character-by-character, and verify it on the hardware device screen when possible.
Rule 5 — Revoke unused token approvals
A single malicious approval can drain your tokens. Review and revoke unused approvals on networks that support it (Ethereum, BNB Chain, Solana).
Rule 6 — Test recovery before depositing a large amount
Create the wallet, note the phrase, wipe or reset, restore from the phrase, and confirm the balance appears. If you cannot restore, the wallet is not ready.
Rule 7 — Keep software updated
Update your wallet app, browser and device firmware. Updates close the holes attackers use.
Rule 8 — Beware 'support' and 'giveaways'
No legitimate service asks for your phrase or keys — including 'support'. Giveaways that require a deposit to receive crypto are always scams.
Rule 9 — Separate spending from savings
Keep a small hot-wallet balance for daily use and the bulk of your funds in cold storage. Compromise of the hot wallet then costs little.
Rule 10 — Plan what happens if the wallet disappears
Your recovery phrase is the backup — it imports into other compatible wallets. Know your wallet's backup format (BIP39 words, seedless cards, etc.) before you need it.
How we evaluate
Every recommendation is based on our published methodology: we separate self-custody wallets, hardware wallets, custodial exchanges and buying platforms, and score each with its own criteria. We label everything as hands-on tested, documentation reviewed, or not yet tested. Commissions never determine rankings.
Sources & evidence
- OfficialLedger — security architecture ↗
- OfficialTrezor — security documentation ↗
- OfficialPhantom — security best practices ↗
- ResearchRekt — wallet attack archive ↗
Changelog
- New guide. Cornerstone security content linking every wallet page.
Frequently asked questions
What is the single most common cause of wallet theft?
A recovery phrase stored digitally — in a screenshot, cloud note, or a chat message — combined with a compromised device or service that can read it.
Should I use a password manager for my recovery phrase?
If the password manager syncs to the cloud, no. The phrase is the keys — a single leaked copy means the wallet can be drained. Paper or stamped metal, kept offline, is the standard.
Are hardware wallets unhackable?
No device is unhackable, but hardware wallets remove the most common attack surface: a compromised phone or computer cannot sign transactions without the device. For most people they are the right cold-storage choice.
I think my wallet was compromised. What do I do?
Immediately move remaining funds to a fresh wallet created on a clean device, revoke any approvals you can, and report the incident.
Related
Exchange wallet vs self-custody wallet: what you actually control
The single most important distinction in crypto: who controls the private keys. This guide explains the difference, the risks on each side, and when each makes sense.
WalletsBest Kaspa (KAS) wallet in 2026
Kaspa uses a custom BlockDAG network, so the usual wallets do not work. These are the wallets that genuinely support KAS — verified against official sources in August 2026.
WalletsBest Solana meme coin wallets in 2026
Solana meme coins are SPL tokens, so any Solana wallet can hold them — but they differ in scam protection. These are the best picks, verified August 2026.