Crypto has no chargebacks, no fraud department, and no reset password link. That's the price of actually owning your money. It means security isn't an advanced topic you'll get to later — it's the first thing to learn, before you buy a single dollar of anything.
The seed phrase is the wallet
Those twelve or twenty-four words aren't a password to your wallet. They are your wallet. Anyone who has them owns everything in it, on every chain, forever. So:
- Never type them into anything except the wallet app itself during setup or recovery. No website, no support agent, no "verification" tool, no browser extension will ever legitimately ask.
- Never photograph or cloud-store them. Photos sync. Cloud accounts get breached. Write them on paper or steel, and store them where a fire or a flood wouldn't take them out.
- Test the backup. Restore the wallet on a spare device once so you know your handwriting is legible and the order is right. People discover a bad backup at the worst possible moment.
- Don't split it cleverly. Homemade schemes to hide a seed in three places usually end with a lost seed, not a secure one.
Hardware wallets, honestly
A hardware wallet keeps your keys offline and makes you approve each transaction on the physical device. That defeats the entire class of attacks where malware on your computer signs things quietly. For anything you'd be genuinely upset to lose, it's the standard answer and it costs less than one bad trade.
Buy it directly from the manufacturer, never from a marketplace reseller. Tampered devices with pre-generated seeds are a real attack. And generate the seed yourself on first setup — a device that arrives with a seed already written down is a trap, one hundred percent of the time.
Approvals: the leak nobody watches
When you use a DeFi app you grant its contract permission to spend your tokens, often unlimited permission that persists forever. Years later, if that contract is exploited, the attacker can drain wallets that granted approvals and forgot. Audit and revoke your approvals quarterly with a revocation tool. It takes ten minutes and closes a door most people leave standing open.
The scams that actually work
- Fake support. You post a problem publicly; three "support agents" DM within minutes. Real support never DMs first, and never needs your seed.
- Drainer sites. A slick page — usually reached through a search ad or a hacked account — asks you to connect and sign. One signature, everything gone. Bookmark official sites and reach them only through bookmarks.
- Address poisoning. An attacker sends you a dust transaction from an address that looks almost identical to one you use. Later you copy the wrong one from your history. Always verify the full address, never just the first and last four characters.
- Poisoned airdrops. An unknown token appears in your wallet; interacting with it triggers a malicious approval. Ignore tokens you didn't acquire on purpose.
- SIM swap. Attackers port your phone number and defeat SMS two-factor. Use an authenticator app or a hardware key on every exchange account, and remove SMS as a recovery option wherever you can.
The five-minute quarterly ritual
Revoke stale approvals. Confirm your seed backup is readable and offline. Move long-term holdings back to cold storage. Check that exchange 2FA is app-based rather than SMS. Delete bookmarks you created from search results and re-add them from official sources. Do this four times a year and you've eliminated most of the ways ordinary people lose everything.