Wallet guide
Crypto Wallet Security Guide
A practical security routine for protecting wallet backups, avoiding phishing and reducing the damage one bad signature can cause.
Updated August 4, 2026 · 9 minute read
Rule 1
Never share the wallet backup
Anyone with your recovery phrase or private key can control the wallet. Legitimate support teams do not need it. Never type it into a website, message, support form or unsolicited app.
Rule 2
Keep backups offline
Do not save a plain-text photo, cloud document, email or note containing the recovery phrase. Store a clear physical backup somewhere protected from theft, fire, water and accidental disposal.
Rule 3
Use official software and updates
Navigate to the provider’s verified domain yourself. Avoid search ads, unsolicited links and direct messages. Keep the wallet, browser, phone and computer updated.
Rule 4
Verify every transaction
Check the full destination address, network and amount before signing. On a hardware wallet, verify the information on the device screen—not only on the connected computer.
Rule 5
Treat dApp approvals as access
A wallet connection is not automatically safe. Read the transaction or permission request, reject unexpected approvals and periodically revoke permissions you no longer use.
Rule 6
Separate savings from activity
Use a smaller wallet for new apps, NFTs and frequent transactions. Keep long-term holdings in a separate wallet that is rarely connected.
If you think the wallet is compromised
- Stop interacting with suspicious websites or software.
- Using a clean device and verified wallet software, create a new wallet with a new backup.
- Move remaining assets to the new wallet, prioritizing the most valuable assets and required gas.
- Revoke token approvals where useful, but do not rely on revocation if the recovery phrase itself is exposed.
- Contact the wallet provider only through its verified support channel. Do not respond to unsolicited “support.”
Monthly security check
- Install verified wallet, browser and operating-system updates.
- Review connected apps and token approvals.
- Confirm your physical backup remains readable and secure without exposing it.
- Remove unused extensions and applications.
