Most avoidable crypto losses do not require a dramatic “hack.” They can begin with a fake website, compromised email, reused password, leaked seed phrase or rushed transaction approval. A security plan should protect the credentials and decisions that control access.
Protect the credentials first
Seed phrases and private keys can control self-custody wallets. Passwords and two-factor authentication can protect hosted accounts. These credentials have different roles, but the safety principle is similar: keep them private, use verified recovery processes and do not type them into unsolicited websites or messages.
- Never share a seed phrase or private key.
- Use unique passwords and strong available multi-factor authentication for exchange accounts and the email connected to them.
- Keep recovery information offline and protected from theft, fire and unauthorised access.
Recognise phishing and impersonation
Phishing attempts often use urgency: a fake security alert, support message, airdrop, refund, upgrade or “wallet verification.” The safest response is not to use a link in the message. Instead, open a known bookmark or type the verified official domain yourself.
- Check the full domain name, not only a logo or display name.
- Do not approve a transaction or signature you cannot explain.
- Support staff do not need a recovery phrase, private key or one-time code to help you.
- Be especially cautious with direct messages and sponsored search results.
Use the device and wallet deliberately
Keep operating systems, browsers and wallet software updated. Install applications through verified official sources. Use a screen lock. Consider separating a smaller transaction wallet from long-term holdings so a routine web interaction does not expose every asset.
Device hygiene
Update software and use a strong device lock.
Transaction review
Check domain, network, recipient, amount and contract prompt.
Permission hygiene
Review connected applications and token approvals when you understand the relevant network tools.
If you suspect compromise
Act quickly but do not panic. Stop interacting with suspicious prompts, preserve screenshots and transaction references, use only verified official support channels and consider transferring any remaining assets only if you understand the risk and can do so safely. For an exchange account, secure the connected email and contact the provider through its official site.
- Do not pay or engage with unsolicited “recovery agents.”
- Do not share seed phrases with someone offering to investigate.
- Report impersonation to the relevant platform and your local fraud-reporting route where appropriate.
- Document what happened; that can help an exchange, platform or authority assess the case.
A practical next step
Read the crypto scam guide for common fraud patterns and wallet basics for the role of seed phrases and private keys.