← Back to BlogSecurity

Crypto Security: A Practical Guide to Not Losing Your Coins

Most crypto losses are not sophisticated hacks. They are a handful of ordinary mistakes, repeated endlessly, every one of them preventable.

Cryptocurrency transactions are final. No bank reverses them, no card network charges them back, and no support desk restores access to a wallet whose recovery phrase is gone. That property is what makes the system work without intermediaries, and it is also what makes ordinary carelessness permanently expensive.

The good news is that the losses are not exotic. A small number of failure modes account for most of them, and every one has a countermeasure that takes minutes to put in place.

Start by deciding who holds the keys

A cryptocurrency is controlled by a private key. Whoever has the key can move the coins; nobody else can, ever, by any means. Every security decision follows from where that key lives.

Custodial, meaning an exchange holds the key and credits your account. Your claim is against the company. This is convenient β€” password resets exist, support exists β€” and it depends entirely on that company remaining solvent, secure and willing to process withdrawals. Those conditions have failed repeatedly, most visibly when FTX collapsed in 2022 and customers discovered that balances shown in an interface are not the same as coins they control.

Self-custody, meaning you hold the key in a wallet. No company can freeze, lose or misappropriate your funds. There is also no recovery: lose the key material and the coins are unreachable permanently.

Neither is universally correct. The workable answer for most people is a split β€” modest, actively traded amounts on a reputable exchange, and anything they would be genuinely upset to lose in self-custody.

Securing an exchange account

If coins are on an exchange, the account is the vault.

Use an authenticator app, not SMS. SIM swapping β€” persuading a mobile carrier to move your number to an attacker's device β€” is a mature, industrialised attack, and SMS codes fall to it entirely. An authenticator app on your phone, or better a hardware security key, is not vulnerable in the same way. This single change eliminates a large share of real-world account takeovers.

Use a unique password from a manager. Credential stuffing works because passwords are reused. A password manager makes uniqueness free.

Use a dedicated email address that is not published anywhere and is itself protected by strong two-factor authentication. Email is the root of most account recovery flows; compromise it and everything downstream follows.

Turn on withdrawal address allowlisting where the exchange offers it, with a delay on adding new addresses. An attacker who gets in still cannot send funds anywhere you have not pre-approved, and the delay gives you time to notice.

Store the recovery codes offline, somewhere other than the device running your authenticator. People lock themselves out routinely by keeping both on one phone.

Self-custody: the recovery phrase is the wallet

When you create a self-custody wallet it generates twelve or twenty-four words. Those words are the wallet. Anyone who reads them can reconstruct it and take everything; anyone who loses them loses everything. The application, the device and the brand are all replaceable β€” the phrase is not.

Write it on paper, or stamp it into metal. Paper survives most things; metal survives fire and flood, and plates for this purpose cost about the price of a meal.

Never let it touch a connected device. Do not photograph it, do not type it into a note, a document, a password manager or a cloud drive, and do not email it to yourself. Malware that searches devices for seed phrases is common and effective.

Never enter it into a website. This deserves stating as an absolute. No legitimate wallet, exchange, support agent, airdrop, migration, validator or "wallet verification" tool will ever ask for it. A request for a recovery phrase is not a red flag; it is the theft itself.

Store copies in more than one physical place. A single copy is one house fire from total loss. Two or three copies in separate secure locations is the standard approach.

Consider a passphrase β€” an extra word you choose, supported by most wallets, that produces an entirely different wallet from the same seed. It defends against someone finding your written phrase. It also means forgetting it loses the funds, so it is a genuine trade-off rather than free security.

Hardware wallets

A hardware wallet is a small device that stores the key and signs transactions internally, so the key never reaches your computer even when that computer is compromised. For meaningful holdings it is the standard recommendation, and it costs between fifty and two hundred dollars.

Two rules matter more than the model you pick. Buy directly from the manufacturer β€” never second-hand, never through a marketplace listing, never from a reseller you cannot verify β€” because tampered devices with pre-generated seeds are a documented attack. And generate the seed on the device yourself. A device that arrives with a phrase already written down is compromised, without exception; the phrase is on a card because someone else has a copy.

Verify the receiving address on the device's own screen before confirming any transfer. That screen is the part an attacker on your computer cannot rewrite, which is the entire point of the device.

The mistakes that cannot be undone

Sending to the wrong address. Clipboard-hijacking malware waits for a copied crypto address and substitutes its own, banking on the fact that people check the first four characters and the last four. Check the middle too, or verify on a hardware wallet screen. For any large transfer, send a small test amount first and confirm it arrives.

Sending on the wrong network. The same asset often exists on several chains β€” USDT on Ethereum, Tron, Solana and others are different tokens with the same name. Coins sent over a network the receiving wallet or exchange does not support are usually unrecoverable, and where recovery is possible it is slow and discretionary. Match the network at both ends before sending anything.

Leaving token approvals open. Interacting with a decentralised application often grants a smart contract permission to move tokens from your wallet. Many request unlimited permission by default, and that permission persists indefinitely β€” including after the site is abandoned, or its contract is exploited months later. Review and revoke approvals periodically using an approval-checker tool, and grant only the amount needed where the interface allows it.

Recognising the scams

Nearly every crypto scam runs on one of two engines: urgency, or an offer that would not exist if it were real.

Giveaways and doubling. Nobody sends back twice what you send them. These persist because they cost nothing to run and occasionally work.

Impersonated support. Genuine support does not contact you first, does not ask for your seed phrase, and does not ask you to move funds to a "safe" address for protection. Scammers monitor public channels for people asking for help and reach out within minutes.

Fake applications and sites. Search results and app stores both carry counterfeit wallets. Reach wallet and exchange sites through a bookmark you created yourself, and install applications from links on the official site.

Romance and long-con investment fraud. A conversation that begins on a dating app or social platform and gradually moves toward a trading site with impressive returns is a recognised pattern that has cost people their savings. Small withdrawals are allowed early precisely to build confidence; the large one is refused.

Airdrop-claim sites. Many exist to obtain a signature or approval that drains the wallet, rather than to distribute anything.

Address-poisoning. An attacker sends a dust transaction from an address whose first and last characters match one you use, so that a later copy-paste from your transaction history goes to them instead. Never copy an address out of your history; copy it from the source each time.

A ten-minute audit

Worth doing today, and again every few months. Is two-factor authentication on every exchange account, and is it an app rather than SMS? Is the recovery phrase for every self-custody wallet written down, offline, in more than one place, and nowhere digital? Is withdrawal allowlisting enabled where available? Have you revoked stale token approvals? And does one other person know how to reach your holdings if something happens to you β€” because inheritance is the loss category nobody plans for and it is entirely permanent.

Security in crypto is unglamorous and mostly consists of a few habits held consistently. The people who lose funds are rarely defeated by sophisticated attacks. They are defeated by a text-message code, a photographed seed phrase, or an address they did not read all the way through.


Coinvilo is not an exchange, wallet provider or custodian, and will never ask for your recovery phrase, private keys or exchange credentials. This article is educational and is not financial, investment or tax advice.