12 min read Updated 2026-08-14 CryptoSumo guide

The Crypto Security Checklist: 20 Rules That Keep Your Funds Safe

The complete, actionable security system for crypto holders — seed phrase rules, hardware wallets, approval hygiene, scam defence and emergency response. Print it. Follow it.

Most people don't lose crypto to broken encryption. They lose it to one bad click, one copied-paste address, one 'support agent' who just needed their seed phrase. Cryptography is not your weak point — habits are. This checklist fixes the habits.

The non-negotiables: seed phrases and private keys

  • Never type your seed phrase into anything — not a website, not a form, not a document on your computer, not a photo. Paper or steel, offline, hidden. That's the entire list of acceptable places.
  • No legitimate person or service will ever ask for your seed phrase. Not Coinbase, not Ledger, not MetaMask, not 'blockchain support'. Anyone who asks is a scammer — end the conversation immediately.
  • Never store your seed phrase in cloud storage. Google Drive, iCloud, email drafts and notes apps are the first places attackers look. If it's on a device connected to the internet, consider it compromised.
  • Use steel backups for amounts that matter. Paper burns, floods and fades. A stamped steel plate costs less than a dinner and survives a house fire.
  • Split secrets only with Shamir or multisig — never 'half the words in two places'. Half a 12-word phrase is trivial to brute-force. Use proper schemes or don't split at all.

Device and account hygiene

  • Use a password manager with a unique, long password for every exchange and service
  • Enable 2FA with an authenticator app or hardware key — never SMS where avoidable (SIM-swap attacks are real)
  • Keep a dedicated browser profile for crypto with no other extensions installed
  • Update your OS, wallet apps and hardware-wallet firmware promptly — updates patch real attacks
  • Install software only from official websites and app stores; fake wallet apps are a top scam vector
  • Use a separate email address for crypto accounts that you never publish anywhere
  • Bookmark the official URLs of every service you use and only ever click your bookmarks

Where your money should live

  • Daily spending / trading money: on the exchange or in a hot wallet — amounts you can afford to lose in a worst-case scenario.
  • Long-term holdings: in a hardware wallet or multisig. 'Not your keys, not your coins' is the rule that survives every exchange collapse.
  • Large holdings: a 2-of-3 multisig (like Safe) with keys on separate hardware wallets in separate locations.
  • Never all of it in one place. Exchange account, hot wallet, cold wallet — separation means one compromise isn't a wipeout.

DeFi approval hygiene

When you use a dapp, you usually approve it to spend your tokens. Those approvals often have unlimited spending caps and never expire — even after you stop using the protocol. A compromised or exploited contract can drain tokens you'd forgotten you approved.

  • Review and revoke unused token approvals every quarter with Revoke.cash
  • Check the approval screen before signing: never grant unlimited allowances unless truly needed
  • Use a wallet with transaction simulation (Rabby) so you see exactly what a signature does
  • Disconnect your wallet from dapps you no longer use
  • Keep a 'burner' wallet for airdrops, mints and new protocols — never your vault wallet

Sending funds without losing them

  • Always verify the full address on your hardware wallet's screen, not just the first and last characters
  • Send a small test transaction first for any large or first-time transfer
  • Beware clipboard malware: if an address you copied 'changes', your device is compromised
  • Double-check the network — funds sent on the wrong chain are often unrecoverable
  • Don't transact while tired, rushed or under pressure — urgency is a scammer's favourite tool

Recognising social engineering

Scammers weaponise urgency, authority and greed. If anyone contacts you claiming to be support, demanding fast action, promising guaranteed returns, or asking for your seed phrase — it is a scam. Every time. There are no exceptions to this rule.

If you think you've been compromised

  1. Move first, investigate later. Transfer remaining funds to a clean wallet created on a clean device — before the attacker finishes what they started.
  2. Revoke approvals for the compromised wallet immediately (Revoke.cash works from any device).
  3. Change passwords and rotate 2FA for every connected service, starting with email.
  4. Scan the device you suspect was compromised — or better, wipe and reinstall it.
  5. Report it: the exchange (they may freeze funds), local authorities, and databases like Chainabuse.
  6. Ignore 'recovery experts' who DM you afterwards. Recovery scams prey on people who were just scammed — nobody can 'reverse' a blockchain transaction.
Security in crypto is not a product you buy. It's a set of habits you keep. The people who lose money are rarely the unlucky ones — they're the ones who skipped the boring steps.

Frequently asked questions

Is this guide up to date?
Last reviewed 2026-08-14. Crypto changes fast — we re-verify guides regularly. If you spot something outdated, tell us via the contact page.
Where should I go next?
Follow the links in the guide, browse the full directory, or start with the security checklist — it's the most important read on this site.