Crypto Security Checklist: 10 Basic Rules to Protect Your Assets
CryptoRebateHub Editorial Team
From account security to anti-phishing, an actionable security self-check list
Most stolen crypto isn't lost to sophisticated attacks — it's basic discipline not followed. Check yourself against this list, item by item.
Account layer
- Enable 2FA: use an app like Google Authenticator, not SMS (vulnerable to SIM swaps).
- Unique strong password: don't reuse your exchange password elsewhere; generate with a password manager.
- Set a withdrawal whitelist: allow withdrawals only to preset addresses — even a hacked account can't easily drain funds.
Key/seed-phrase layer
- Write your seed phrase offline by hand: never screenshot, never store in cloud, never message it to yourself.
- Multiple physical backups: stored separately, fire/water-resistant; consider a steel plate.
- Never enter your seed into a webpage: any site/app asking for your seed is a scam (excluding local hardware-wallet operations).
Operations layer
- Test large transfers with a small amount first: confirm the address, then send the rest.
- Verify the full address: check first/last characters after pasting, to defend against clipboard-hijacking malware.
- Be careful with approvals: regularly review and revoke unused DeFi token approvals (use a revoke tool).
Anti-phishing layer
- Only enter via official channels: bookmark the official site; don't click search ads, airdrop DMs, or "support" links. Support impersonation, fake airdrops, and fake sites are the three most common scams.
Extra reminders
- Use a hardware (cold) wallet for large long-term holdings.
- Don't operate sensitive accounts on public WiFi.
- Beware "high-yield products" and "guaranteed profits" — standard scam scripts.
Turn these 10 into habits and you avoid 95% of asset losses.
For reference only. Not financial advice.
See also two-factor auth, hardware wallet setup, Spotting Crypto Scams: 6 Red Flags That Always Hold