How can I protect my crypto wallet?

Crypto works differently from money in a bank. Whoever holds the keys owns the coins, transactions cannot be reversed, and there is no support line that can claw a payment back. That makes it unforgiving - but also simple to protect, because it all comes down to two things: guarding your keys, and being careful what you approve.

How crypto gets stolen

  • Seed-phrase theft. Someone gets the recovery phrase that unlocks your wallet - often through a fake "support" chat, a phishing site, or a photo of it saved in the cloud.
  • Fake apps and sites. A look-alike wallet or exchange page captures your details or phrase the moment you enter them.
  • Malicious approvals. A dodgy site asks you to "connect wallet" and sign a transaction that quietly grants it permission to move your tokens.
  • Address swapping. Malware watches your clipboard and replaces a copied wallet address with the attacker's.
  • Account takeover. If your exchange login leans on text-message codes, a SIM swap can hand it over. See how can I protect myself against a SIM swap?

What you can do

Guard your seed phrase

Your recovery phrase is the wallet. Anyone who reads it can take everything, so treat it like the keys to a safe. Never type it into a website or app except when you are deliberately restoring a wallet, and never as a response to someone who contacted you - no genuine support will ever ask for it. Keep it offline, written down or stamped in metal, in more than one secure place. A photo, a cloud note, or an email is exactly where thieves look first.

Use a hardware wallet for anything significant

A hardware wallet keeps your keys on a small offline device, and every transaction is approved on the device itself. Even a fully compromised computer cannot pull the keys out, which is why it is the single biggest upgrade for anything you would be upset to lose. Buy it directly from the maker, never second-hand or from a marketplace reseller.

Check what you are signing

Many drains happen because someone approved them without realising. Be wary of "connect wallet" prompts on sites you do not know, read what a transaction actually does before you sign, and periodically review and revoke the approvals you have granted to apps you no longer use.

Verify the address

Before sending, check the first and last characters of the destination address against what you expect, in case malware has swapped it. For a large transfer, send a tiny test amount first and confirm it arrives.

Lock down your exchange accounts

Protect any exchange login with an authenticator app or a hardware key rather than text-message codes, and turn on a withdrawal address allow-list if the exchange offers one, so funds can only leave to addresses you pre-approved.

If you only do one thing

Move anything you cannot afford to lose to a hardware wallet, and keep your recovery phrase offline in a safe place. Everything else is a distant second to those two.

Related: How can I tell if a message is a scam?

← All guides

General information, correct when last reviewed. Platforms and threats change - always confirm critical steps on the official source. Product names are used only to describe their features; Monkleton Labs is not affiliated with, or endorsed by, them. No ads, no affiliate links.