Crypto security: protect your wallet

THE SHORT ANSWER

Wallet security depends on protecting access credentials and checking what you sign. A recovery phrase usually controls the funds: never share it with a website or person asking for it. A signed transaction may be irreversible.

Before a transaction, check two different things: who can use your keys, and what you are authorising.

Private keys and recovery phrase

A public address receives funds; a private key signs. Never give a private key to support staff or a website.

If your wallet uses a recovery phrase, back it up according to its documentation, away from messages, photos and online forms.

The app password does not replace the recovery phrase. Changing it does not revoke a phrase that was stolen.

Some wallets use passkeys or different recovery methods: check who can restore access and how recovery works after losing a device.

Hot or cold wallet?

Hot Wallet

Software on a connected device can sign transactions. It makes interactions convenient, but the device and granted permissions need protection.

Cold Wallet

The signing key is kept away from a connected device. A hardware wallet helps isolate it, but cannot stop a malicious transaction you approve.

Three common traps

Fake support and websites

An urgent message can impersonate a familiar brand. Find the official address independently of the message and reject requests for your recovery phrase.

Giveaways and malicious permissions

A promise to double your funds is a scam signal. A gas-free signature can also authorise a later transfer: no gas fee does not mean no risk.

Recipient address and network

Check the full address, network and token. Do not copy an address from transaction history: fake transfers can insert a lookalike address.

Sources and further reading

Page updated on
Documentation checked on · WhyTheBlockchain · Editorial approach