CryptoDrawz

Crypto wallet security checklist

Most crypto losses are not clever hacks. They are phrase theft, fake sites and careless approvals. These twenty habits close the doors that thieves use most. Go through them once and keep them as routine.

4 min readUpdated October 7, 2026By the CryptoDrawz editorial team

Part of the complete guide: Crypto lottery: the complete guide

The recovery phrase

  1. 1Write it on paper, in order, with the exact spelling.
  2. 2Store it offline in a safe place. Consider a second copy in a different location.
  3. 3Never photograph it or store it in notes, email, chat or cloud storage.
  4. 4Never type it into any website, app or form. Only a wallet restore screen needs it.
  5. 5No one legitimate will ever ask for it.

Devices and accounts

  1. 1Keep your phone and computer updated.
  2. 2Install apps and extensions only from official sources, and check the publisher.
  3. 3Use a strong, unique password manager and two-factor authentication (an authenticator app, not SMS) on exchanges and email.
  4. 4Lock your phone with a strong passcode and biometric.
  5. 5Do not use public computers or shared devices for wallets.

Transactions and approvals

  1. 1Read the wallet prompt: what network, what token, what amount, which address?
  2. 2Reject requests for unlimited token approvals. Set an exact amount.
  3. 3Reject signatures you cannot read, especially ones that mention permit, setApprovalForAll or "verify".
  4. 4Check the first and last characters of any address you paste.
  5. 5Send a small test before a large transfer.
  6. 6Review and revoke old approvals regularly with a reputable approvals checker.

Websites and messages

  1. 1Bookmark the sites you use and open them from the bookmark.
  2. 2Do not click links in emails, chats or ads about wallets, airdrops or winnings.
  3. 3Be suspicious of anyone who contacts you first offering "help".
  4. 4Check URLs for look-alike letters and extra words.

Structure your funds

  • A hot wallet (phone or browser) with only what you will use soon, such as your ticket budget.
  • A cold wallet (hardware) for long-term holdings, rarely connected to websites.
  • Do not mix them. If a hot wallet is compromised, the cold wallet is untouched.

If you suspect compromise

  1. 1Create a new wallet on a clean device with a new recovery phrase.
  2. 2Move remaining funds to it immediately, starting with the most valuable.
  3. 3Revoke approvals from the old wallet.
  4. 4Change passwords and enable two-factor authentication on related accounts.
  5. 5Treat the old phrase as burned. Never reuse it.

The "two wallet" rule in practice

If the spending wallet is compromised, the loss is capped at the small balance it held.

WalletHoldsConnects to sites?
Spending wallet (hot)This week's ticket budget and a few cents of feesYes, when you play
Savings wallet (cold)Everything elseRarely or never

Signs a prompt is dangerous

  • It asks for approval of an unlimited amount.
  • The message is unreadable data and the site will not explain it.
  • It asks you to sign something to "verify" or "claim" an airdrop.
  • It refers to permit, approveForAll or transfers from your wallet when you only meant to connect.
  • The site address or the recipient is not what you expected.

Review and clean up routine

  1. 1Every few months, list the sites connected to your wallet and disconnect those you no longer use.
  2. 2Check token approvals with a reputable approvals checker and revoke old ones.
  3. 3Update your wallet software.
  4. 4Check that your recovery phrase backup is intact.

Example: how an attack on a careless user usually goes

A user sees an ad for a "free token claim", clicks, and lands on a site that looks like a legitimate project. It asks to connect a wallet, then to sign a transaction "to claim". The transaction is actually an approval that lets the attacker's contract spend all of the user's USDC. Days later, the balance is drained. Each step could have been caught: the ad was the wrong place to start, the site address was one letter off, and the wallet prompt asked for an approval the user did not understand. Reading the prompt would have stopped it.

A monthly security routine

  1. 1Check your wallet software and browser are up to date.
  2. 2Review connected sites and token approvals and revoke what you do not use.
  3. 3Confirm you can still find your recovery phrase backup.
  4. 4Look at your exchange accounts for unexpected logins.
  5. 5Rotate any password you reused.

Ready?

A weekly draw you can check yourself.

$5 tickets, a public random value, and every result published with the data to recompute it.

Frequently asked questions

Is a hardware wallet worth it?

For any amount you would hate to lose, yes. It keeps keys offline and makes you confirm each action on the device.

Can someone steal crypto with only my address?

No. Addresses are public. They need your keys or an approval from you.

Are exchange accounts safe?

They are only as safe as the exchange and your account security. Use two-factor authentication and withdrawal whitelists.

How often should I revoke approvals?

A regular review every few months is a good habit, and any time you used a site you no longer trust.

Is a software wallet safe enough?

For small amounts with good habits, yes. Use a hardware wallet for savings.

Should I use a password manager?

Yes, for exchange and email accounts. Never store your recovery phrase in it.

What is a seed phrase attack?

Any attempt to get your recovery words, most often phishing or fake support.

Keep reading