Crypto has no chargebacks, no fraud department, and no reset password link. That's the price of actually owning your money. It means security isn't an advanced topic you'll get to later — it's the first thing to learn, before you buy a single dollar of anything.

The seed phrase is the wallet

Those twelve or twenty-four words aren't a password to your wallet. They are your wallet. Anyone who has them owns everything in it, on every chain, forever. So:

Hardware wallets, honestly

A hardware wallet keeps your keys offline and makes you approve each transaction on the physical device. That defeats the entire class of attacks where malware on your computer signs things quietly. For anything you'd be genuinely upset to lose, it's the standard answer and it costs less than one bad trade.

Buy it directly from the manufacturer, never from a marketplace reseller. Tampered devices with pre-generated seeds are a real attack. And generate the seed yourself on first setup — a device that arrives with a seed already written down is a trap, one hundred percent of the time.

Wallet hygiene: use separate wallets for separate jobs. A cold wallet for long-term holdings that never touches a dApp. A hot wallet for daily DeFi. A burner with pocket change for minting, airdrops and anything experimental. When the burner gets drained — and eventually one will — you lose lunch money instead of your savings.

Approvals: the leak nobody watches

When you use a DeFi app you grant its contract permission to spend your tokens, often unlimited permission that persists forever. Years later, if that contract is exploited, the attacker can drain wallets that granted approvals and forgot. Audit and revoke your approvals quarterly with a revocation tool. It takes ten minutes and closes a door most people leave standing open.

The scams that actually work

  1. Fake support. You post a problem publicly; three "support agents" DM within minutes. Real support never DMs first, and never needs your seed.
  2. Drainer sites. A slick page — usually reached through a search ad or a hacked account — asks you to connect and sign. One signature, everything gone. Bookmark official sites and reach them only through bookmarks.
  3. Address poisoning. An attacker sends you a dust transaction from an address that looks almost identical to one you use. Later you copy the wrong one from your history. Always verify the full address, never just the first and last four characters.
  4. Poisoned airdrops. An unknown token appears in your wallet; interacting with it triggers a malicious approval. Ignore tokens you didn't acquire on purpose.
  5. SIM swap. Attackers port your phone number and defeat SMS two-factor. Use an authenticator app or a hardware key on every exchange account, and remove SMS as a recovery option wherever you can.

The five-minute quarterly ritual

Revoke stale approvals. Confirm your seed backup is readable and offline. Move long-term holdings back to cold storage. Check that exchange 2FA is app-based rather than SMS. Delete bookmarks you created from search results and re-add them from official sources. Do this four times a year and you've eliminated most of the ways ordinary people lose everything.