Skip to main content

Tangem

Crypto Wallet Security Checklist: 15 Ways to Protect Your Digital Assets

Crypto Wallet Security Checklist

You own crypto. You’ve got a nagging sense you’re not handling it as carefully as you should. And every guide you find is either a wall of jargon or fifteen tips of wildly unequal value presented as if they matter the same amount.

Crypto Wallet Security Checklist

They don’t. This crypto wallet security checklist is ordered by what actually prevents losses — the first five do most of the work, and most of the list costs nothing. Work through the top section this weekend and you’ll have closed the majority of your exposure.

Start here: the five that matter most

If you do nothing else on this page, do these. Between them they prevent the large majority of crypto losses.

1. Never enter a recovery phrase anywhere, for any reason

No legitimate wallet, exchange, support agent or app will ever ask for your recovery phrase. Not to verify you, not to fix an error, not to release funds.

Anyone asking is stealing. There is no context that makes it acceptable, and this single rule defeats the most successful attack in crypto.

2. Move long-term holdings off exchanges

An exchange balance is a claim against a company. If you’re not trading it this quarter, it has no functional reason to sit there carrying counterparty risk.

Keep a trading balance, move the rest. Our guide to wallet versus exchange storage covers where the threshold sits for your situation.

3. Test every backup before you fund the wallet

The most common cause of permanent loss isn’t theft it’s discovering your backup doesn’t work at the moment you need it.

Set up the wallet, then close the app and verify each backup device opens it independently. Only then transfer funds in. This takes five minutes and almost nobody does it.

4. Use app-based two-factor authentication, never SMS

SMS codes can be intercepted through SIM swapping, which is a documented and ongoing problem. An authenticator app is meaningfully harder to attack.

Change this on every exchange account you hold. It’s a five-minute job per account.

5. Verify addresses from your wallet app, never from your history

Address poisoning works by seeding a lookalike address into your transaction history so you copy the wrong one later.

Always copy from your wallet app, and read the first and last six characters before you send. A wrong address is irreversible.

The next five: worth an hour this weekend

More effort than the first five, still high value.

6. Review and revoke old token approvals

When you approve a contract to spend a token, that permission persists it doesn’t expire when your balance hits zero, and it survives long after you’ve forgotten the site.

Review your approvals and revoke anything you don’t actively use, particularly unlimited allowances. Each revocation costs a little gas and closes a door you didn’t know was open.

7. Bookmark the real sites and stop searching

Attackers buy search ads against wallet and exchange brand names, so the top result can be a cloned site that looks identical.

Bookmark every exchange, wallet and service you use, and reach them that way. Do it now, while you’re calm and not mid-transaction.

8. Store backup devices in genuinely separate locations

Three cards in one drawer is one fire, one flood or one burglary away from zero.

Different buildings at minimum. For one device, a different city or a professional’s custody. Our comparison of the 2-card and 3-card sets covers the storage strategy in detail.

9. Use a dedicated email address for crypto accounts

Your main email is exposed in every data breach you’ve ever been caught in. A separate address, with a unique password and its own 2FA, isolates your crypto accounts from that.

10. Keep a small hot wallet separate from your main holdings

If you use dApps at all, fund a small wallet for it and keep your long-term holdings elsewhere.

Losses there should be annoying, not devastating. This is the single best structural protection against a malicious approval.

The refinements: items 11 to 15

Lower priority. Worth doing once the first ten are done.

11. Set an access code you’ll remember under stress

Not something clever something you’ll recall in five years, in a hurry. And don’t store it on the phone you use to tap the card, which puts both halves in one place.

12. Keep records

Dates, amounts, transaction hashes and NZD values. Inland Revenue expects you to show your cost base, and reconstructing it two years later is miserable. Useful for your own reference too.

13. Plan for inheritance

If something happens to you, does anyone know the wallet exists or how to reach it? For a lot of people the honest answer is no, and that means the crypto is simply gone.

A backup device with an executor, a lawyer, or named in your will is the practical solution. Worth discussing digital assets when you next update it.

14. Check the FMA warnings list before investing in anything new

The Financial Markets Authority publishes warnings about entities it has concerns with. It’s free, it takes a minute, and almost nobody checks it before sending money rather than after.

15. Do a test withdrawal

Send a small amount out of your wallet to an address you control. Learn the exit path while you’re calm, rather than working it out for the first time in an emergency.

The full checklist at a glance

#ItemPriorityTimeCostPrevents
1Never enter a recovery phraseCriticalOngoingFreePhishing — the most common attack
2Move long-term holdings off exchangesCriticalAn hourDevice costExchange failure, freezes
3Test backups before fundingCritical5 minFreePermanent loss on device failure
4App-based 2FA, not SMSCritical5 min eachFreeAccount takeover, SIM swap
5Verify addresses from the appCriticalOngoingFreeAddress poisoning, wrong sends
6Revoke old token approvalsHigh20 minSmall gas feeDrainer contracts
7Bookmark real sitesHigh10 minFreeCloned sites, ad-based phishing
8Separate backup locationsHighAn hourFreeFire, flood, burglary
9Dedicated crypto emailHigh15 minFreeBreach cross-contamination
10Small separate hot walletHigh15 minFreeMalicious approvals
11Memorable access codeMedium5 minFreeLockout, and casual access
12Keep recordsMediumOngoingFreeTax problems
13Inheritance planMediumAn hourFreeTotal loss on death
14Check FMA warningsMedium1 minFreeInvestment scams
15Test withdrawalLow10 minNetwork feePanic during an emergency

Eleven of the fifteen are free. Nine of them take under twenty minutes.

Two things on most checklists that are wrong

Worth calling out, because both appear on reputable-looking security guides and both make your position worse.

“Store your seed phrase in a password manager”

This takes a secret whose entire value comes from being offline and puts it on an internet-connected service one with an account, a login, and a company behind it.

Password managers are genuinely good for passwords. A recovery phrase is a different class of secret, and the whole point is that it never touches a networked device.

“Photograph it as a backup”

A photo syncs to cloud storage within seconds, usually without you thinking about it. It’s then sitting in a service you don’t control, attached to an account that can be compromised, in a place you’ll forget it exists.

This is one of the most common ways phrases leak not through a sophisticated attack, but through a phone backup working exactly as designed.

What to do instead: keep the phrase offline on paper or metal, in separate locations. Or use a wallet with no phrase at all our explanation of how seedless wallets work covers why the backup being hardware removes this problem entirely.

What a hardware wallet actually covers

Being straight about it: a hardware wallet handles roughly a third of this list.

It removes entirely: items 1 and 11 in their most dangerous form with a seedless device there’s no phrase to phish, photograph or store badly. It also covers item 2, since it’s where your holdings go.

It helps with: items 3 and 8, because the backup is physical devices you can test and distribute.

It does nothing for: items 4, 5, 6, 7, 9, 10, 12, 13, 14 and 15. Hardware signs what you approve. It won’t catch a poisoned address, won’t revoke an old approval, and won’t evaluate whether an investment is real.

That’s why the free items on this list matter more than the purchase. If you only have an hour, spend it on 2FA, approvals, bookmarks and backup testing not on shopping.

How often to revisit this

  • Token approvals — every few months, and after any period of heavy dApp use
  • Backup verification — annually, and after moving house
  • Storage locations — whenever you move, or when circumstances change
  • 2FA and passwords — after any breach notification
  • Inheritance plan — whenever you update your will

FAQs

What’s the single most important crypto security step?

Never entering your recovery phrase anywhere. It defeats the most common and most successful attack in crypto, it costs nothing, and it’s a rule with no exceptions.

Is a password manager safe for a seed phrase?

No. A recovery phrase’s value depends on being offline, and a password manager is an internet-connected service with an account attached. Keep phrases offline, or use a wallet that doesn’t have one.

How often should I check my token approvals?

Every few months, and after any period of heavy dApp use. Approvals persist after your balance hits zero, so an old one can drain funds you add to that address later.

Do I need a hardware wallet to be secure?

Not for small amounts you’re actively trading. It becomes the sensible answer as holdings grow but note it covers about a third of this list, and the free items matter more if you only do some of it.

What should I do if I think I’ve been compromised?

Move remaining funds to a genuinely new wallet, revoke approvals on the affected address, stop engaging, document everything, and report it. Our guide to protecting your crypto from scams covers the reporting channels.

Is SMS two-factor authentication safe enough?

It’s better than nothing and worse than an authenticator app. SIM swapping is a real and documented attack, and SMS is the weakest widely-offered second factor.

How do I test my wallet backup?

Close the app, then open the wallet using each backup device independently before you transfer any funds in. If a device doesn’t open the wallet, you’ve found out at the only time it’s free to fix.