Security rule • Never share or type a recovery phrase into a website

Security guide

Your assets are on-chain. Your keys control access.

Learn what wallets actually manage, how custody changes responsibility, and the habits that prevent common, irreversible losses.

Secure digital-asset learning workspace
Private keyAuthorizes spending
Public keySupports address creation
Recovery phraseRecreates wallet keys
AddressIdentifies a destination

A wallet is a key manager

Cryptocurrency remains recorded on a network ledger. Wallet software helps generate and protect keys, derive addresses, display balances, build transactions, and create digital signatures. Whoever controls the relevant private keys can usually control the associated assets.

A wallet balance is an interpretation of network data. Deleting a wallet app does not erase the assets, but losing every usable key and backup can make them permanently inaccessible.

Hot, cold, software, and hardware wallets

TypeTypical useMain exposure
Mobile or desktop walletFrequent transactions and applicationsMalware, device compromise, fake updates
Browser walletWeb applications and token interactionsPhishing, malicious approvals, risky extensions
Hardware walletKeeping signing keys isolatedBad backups, supply-chain tampering, blind signing
Paper or metal backupOffline recovery materialTheft, fire, water, poor storage, unauthorized copies
Multisignature setupShared control or reduced single-key riskComplex recovery, coordination, configuration errors

Custodial versus self-custody

With custodial storage, an exchange or service controls the keys and grants access through an account. This shifts some key-management work to the provider but introduces account, operational, solvency, legal, and withdrawal risk.

With self-custody, you control the keys directly. That removes some provider dependency but makes you responsible for backups, device security, transaction verification, inheritance planning, and recovery tests.

Custody is a responsibility model, not a badge of safety.

Both approaches can fail in different ways. Choose only after understanding who can authorize transfers and how access is recovered.

Recovery phrases and backups

A recovery phrase can recreate a set of wallet keys. Anyone who obtains it may be able to recreate the wallet and transfer assets without the original device or password. Treat it as high-value access material.

  • Generate it only in the intended wallet setup flow on a trusted device.
  • Record it accurately and keep it offline.
  • Do not photograph it, email it, upload it, or save it in ordinary cloud notes.
  • Protect backups from theft, observation, fire, water, and accidental disposal.
  • Do not invent a complex scheme you cannot reliably reverse years later.
  • Test recovery procedures with a low-value setup before relying on them.

Common wallet threats

Phishing

A fake site, message, app, or support agent requests credentials, a signature, or a recovery phrase.

Address swap

Malware or a deceptive interface replaces the intended destination with an attacker’s address.

Malicious approval

A token permission or smart-contract signature grants broader access than the user expects.

SIM swap

An attacker takes over a phone number and uses SMS recovery to access an exchange account.

Fake investment

A person or platform promises returns, builds trust, then blocks withdrawals or demands more payments.

No legitimate support agent needs your recovery phrase.

Do not share it, enter it into a website, or disclose it in response to an unsolicited message. Possession can equal control.

Transaction safety checklist

  1. Confirm the asset and correct network before copying an address.
  2. Verify the destination through a second trusted channel when possible.
  3. Compare the first and last characters on the signing device itself.
  4. Read the amount, fee, network, and contract request before signing.
  5. Send a small test transaction before a high-value transfer.
  6. Wait for the test to settle and confirm the recipient can access it.
  7. Review token approvals and revoke permissions you no longer need.
  8. Keep account and transaction records appropriate for local tax rules.

If something goes wrong

Stop interacting with the suspicious site or person. Preserve transaction identifiers, addresses, messages, and screenshots. Move remaining assets only from a known-safe device and wallet when doing so will not expose additional keys. Contact the relevant service through a verified channel and report scams to the appropriate public agency in your location.

Blockchain transactions are often irreversible, and “recovery services” can themselves be scams. Be skeptical of anyone requesting an upfront payment or access credentials to recover funds.

Practice the safety model before value is at risk.

Build a learning route around custody, transaction checks, phishing defense, and recovery drills.

Open the security course →