Crypto security: protect your wallet
THE SHORT ANSWER
Wallet security depends on protecting access credentials and checking what you sign. A recovery phrase usually controls the funds: never share it with a website or person asking for it. A signed transaction may be irreversible.
Before a transaction, check two different things: who can use your keys, and what you are authorising.
Private keys and recovery phrase
A public address receives funds; a private key signs. Never give a private key to support staff or a website.
If your wallet uses a recovery phrase, back it up according to its documentation, away from messages, photos and online forms.
The app password does not replace the recovery phrase. Changing it does not revoke a phrase that was stolen.
Some wallets use passkeys or different recovery methods: check who can restore access and how recovery works after losing a device.
Hot or cold wallet?
Hot Wallet
Software on a connected device can sign transactions. It makes interactions convenient, but the device and granted permissions need protection.
Cold Wallet
The signing key is kept away from a connected device. A hardware wallet helps isolate it, but cannot stop a malicious transaction you approve.
Three common traps
Fake support and websites
An urgent message can impersonate a familiar brand. Find the official address independently of the message and reject requests for your recovery phrase.
Giveaways and malicious permissions
A promise to double your funds is a scam signal. A gas-free signature can also authorise a later transfer: no gas fee does not mean no risk.
Recipient address and network
Check the full address, network and token. Do not copy an address from transaction history: fake transfers can insert a lookalike address.
Sources and further reading
- Ethereum.org — Security and scam prevention · in English
- Bitcoin.org — Securing your wallet · in English
- MetaMask — Signature phishing · in English
Page updated on
Documentation checked on · WhyTheBlockchain · Editorial approach