Most crypto losses do not come from clever attacks on the blockchain itself. They come from lost keys, stolen credentials, fake websites and mistakes made in a hurry. If you plan to hold digital assets, understanding wallet security is one of the most useful things you can do. This guide explains the main concepts and habits, without promising that any setup is perfectly safe, because none is.
If you are new to the topic, our overview of crypto basics gives helpful background first.
What a wallet really is
A crypto wallet does not store coins the way a purse stores cash. The assets live on the blockchain. What the wallet stores is the set of private keys that prove you can move them. Whoever controls the keys controls the assets. That is why the phrase “not your keys, not your coins” is so often repeated: if a company holds the keys, you are trusting the company.
Custodial and non-custodial wallets
A custodial wallet is run by a service, such as an exchange, that holds keys on your behalf. It is convenient and often includes password recovery, but you rely on the provider’s security and solvency.
A non-custodial wallet gives you the keys. Nobody can freeze or seize your assets through the provider, but nobody can rescue you if you lose access either.
Neither is automatically better. Many careful people keep small amounts for active use in one place and longer-term holdings under their own control, after thinking carefully about what they can manage safely.
Hot wallets and cold wallets
A hot wallet is connected to the internet, such as a mobile app, a browser extension or a desktop program. It is convenient for frequent use, but exposed to malware, phishing and device theft.
A cold wallet keeps keys offline. The best-known type is a hardware wallet, a small dedicated device that signs transactions without exposing your keys to your computer. It is generally considered safer against remote attacks, though it can be lost, damaged or bought from an untrustworthy source.
Buy hardware wallets only directly from the manufacturer or an authorised reseller, and check that the packaging and device are untampered. Avoid second-hand devices.
Seed phrases: the master key
Most non-custodial wallets generate a seed phrase, usually twelve or twenty-four words, from which all your keys can be recreated. Anyone who has it can take everything, and if you lose it, you may lose access permanently.
Good habits include:
- Write it on paper or a durable backup made for the purpose, and store it somewhere secure, such as a safe.
- Keep more than one copy in separate secure places, in case of fire or flood.
- Never photograph it, type it into a note app, email it or store it in cloud storage.
- Never enter it on a website, in a chat, or to “verify” or “sync” your wallet. Genuine support staff never need it.
- Consider what happens to your holdings if something happens to you, and whether a trusted person should know where to find instructions.
Protecting your accounts and devices
Your exchange and email accounts are also targets. Use a unique, long password for each, stored in a reputable password manager. Turn on two-factor authentication, preferably with an authenticator app or a hardware security key instead of text messages, which can be intercepted through SIM-swap attacks. Keep your operating system and apps updated, and be careful about installing software from unknown sources.
Consider using a separate device or browser profile for crypto activity, with few extensions. Every extension is additional risk.
Checking before you sign
Many thefts happen when people approve a malicious transaction or permission. Before confirming, read what you are approving. Be wary of anything that asks for “unlimited” access to your tokens, or that arrives after you clicked a link in a message. Bookmark the sites you use instead of searching for them each time, since fake sites can appear in search adverts. Sending a small test transaction before a large transfer is a sensible habit, and always check the full address, not only the first and last few characters.
A simple security checklist
Before you hold meaningful value, check that you have: a unique password and two-factor authentication on every exchange and email account; a hardware wallet or another storage method you understand; a tested, offline backup of your seed phrase in two secure places; and a habit of verifying addresses and websites before you send anything. If any item is missing, fix it before adding more funds.
Planning for mistakes
Decide in advance how you will handle problems. Keep a written, offline record of which accounts you hold and where, without including secrets. Practise restoring a wallet from a backup using a small balance so you know the process works. Review your setup periodically, and update it as your holdings grow.
To understand the tricks attackers use, read our guide to spotting crypto scams. And if you are thinking about how much to hold and for how long, see long-term portfolio thinking.
No setup is risk-free
Even careful storage has trade-offs: convenience against control, and simplicity against protection. Aim for a setup that is secure enough for the amount involved and simple enough that you will not make errors under stress.
This article is for general education only. It is not financial, investment or security advice, and no method can guarantee protection. Crypto assets are high-risk and you can lose some or all of your money.
