A complete crypto security pass takes about twenty minutes: enable app based two factor authentication on every exchange, verify your seed phrase backup exists in two physical locations, revoke unused token approvals, bookmark every site you use, separate a burner wallet from your main holdings, and confirm someone you trust could recover your funds if you could not.
Exchange accounts, five minutes
Two factor authentication is on and is not SMS
Authenticator app or hardware key. SMS is defeated by SIM swapping, which is a routine attack against crypto holders.
The password is unique
Not reused anywhere. A password manager makes this trivial.
Withdrawal addresses are whitelisted
Most exchanges support this. It means account access alone is not enough to move funds anywhere new.
The email account is itself secure
Your email is the recovery path for everything. It needs its own strong two factor.
Only a working balance sits there
Not your long term holdings. See self custody.
Wallets, eight minutes
The seed phrase is written on paper or steel
Not a photo, not a note, not a cloud file, not a password manager.
There are two copies in two locations
Far enough apart that one fire or flood cannot take both.
You have tested a restore
With a small amount. It is the only proof the backup works.
Your wallet software came from the official source
Check the extension publisher and install count. Fake wallet extensions are a persistent attack.
Large holdings are on hardware
Above a few thousand dollars, a hardware wallet is the clearest cost to benefit decision available.
Approvals, five minutes
Review approvals on each chain you use
At revoke.cash. Approvals are per network, so check each one separately.
Revoke anything you no longer use
Especially unlimited approvals on assets you actually hold.
Check NFT setApprovalForAll permissions
These grant control of an entire collection, not a single item.
Habits, two minutes to set up
| Habit | Why |
|---|---|
| Bookmark every crypto site you use | Removes the entire search ad attack channel |
| Always send a test transaction first | Prevents the most expensive class of mistake, permanently |
| Keep a separate burner wallet | Mints and unfamiliar protocols never touch anything valuable |
| Never act on a direct message | Nobody legitimate contacts you first about your funds |
| Verify addresses fully, not just the ends | Defeats address poisoning |
| Install Brave or an equivalent | Blocks malicious ads and many drainer scripts by default |
The part everyone skips
If something happened to you tomorrow, could anyone access your holdings? For most self custody users the honest answer is no, and the funds are simply lost.
Recovery planning covers workable approaches, from sealed instructions held by an attorney to multisig arrangements where a trusted person holds one of several keys.
The whole list, in one place
- App based two factor on every exchange, never SMS
- Unique password, and a secure email account behind it
- Withdrawal address whitelisting enabled
- Seed phrase on paper or steel, two copies, two locations
- Restore tested at least once
- Hardware wallet for anything above a few thousand
- Approvals reviewed and revoked, on every chain
- Every site bookmarked, none reached through search
- A burner wallet for anything unfamiliar
- Test transaction before every large send
- A recovery plan someone else could follow
Common questions
How often should I do this?
Twice a year is a reasonable cadence, plus immediately after anything unusual: a suspicious signature, a new device, or a breach notification from a service you use.
I am overwhelmed. What is the single most important item?
The seed phrase backup. Everything else protects against attackers. That one protects against losing everything through ordinary bad luck, which is statistically more likely.
Is this enough for large holdings?
It is a strong baseline. Above a certain size, look at multisig, geographically distributed backups and formal inheritance planning with a professional.
Where to go next
Get a second pair of eyes on your setup
A security session reviews what you hold, where it sits, what approvals are open and what would happen if your laptop were compromised tomorrow. Most people find at least one thing worth fixing.