Your crypto wallet security checklist
Check the source before the setup
Reach the manufacturer's website yourself and follow its model-specific authenticity and setup instructions. Treat a device supplied with a completed recovery phrase as compromised. A convincing box or seal cannot establish that only you control the keys.
Recognise counterfeit and pre-seeded devices →Separate your backup from online support
Keep a recovery backup private and offline. Never provide it to a website, direct-message helper, or supposed verification service. A genuine recovery procedure depends on your exact device; start it yourself and follow the manufacturer's trusted instructions. A wallet PIN and a recovery phrase serve different purposes.
Understand cold storage and backups →Read the action, network, and recipient
Check the actual domain and the full destination, not just a familiar logo or an address fragment copied from transaction history. Confirm important details on the hardware device when supported. If the request is undecodable, stop and find out what it authorises. A zero-gas signature can still grant a permission.
Understand blind signing →Review the spender and its allowance
For an ERC-20 approval, identify the token, chain, spender, and amount. Permission is recorded in the token contract. It can outlast the browser session and may allow a later transfer without another confirmation. Check NFT operator permissions separately; they are not the same as one token's spending allowance.
Understand token approvals and wallet drainers →Remove old permissions deliberately
Use a verified allowance-checking tool reached from a trusted source. Check the correct network and account. An onchain allowance revocation is a transaction with a network fee; disconnecting a website merely ends a connection. Record the transaction hash and confirm the new allowance. Revocation cannot reverse an already completed theft.
MetaMask's allowance-revocation guidance ↗Identify who holds the keys
An exchange account and a self-custody wallet have different failure paths. Account security cannot settle questions about a custodian's solvency, withdrawal controls, or your legal claim. Identify the provider, custody arrangement, and applicable terms before treating a displayed balance as the same thing as control of an onchain address.
Understand exchange failure and custody →A permission check in practice
Suppose a fictional site asks you to approve a 50-token swap. The wallet shows an unlimited allowance to an unfamiliar spender. The useful question is whether that spender and limit match the action you intended. Neither the site's design nor the hardware wallet's confirmation button answers it. Verify the spender independently, understand the requested scope, and decline a request you cannot explain.
If you suspect a compromise
Stop interacting with the suspicious site and preserve the address, network, transaction hashes, timestamps, and messages. Distinguish leaked keys from a harmful allowance before deciding what to do next. A leaked recovery phrase affects accounts derived from it; another account under that same phrase is not a clean replacement. If a sweeper may be present, sending more gas funds can lose more money. Use your wallet provider's official incident guidance and independently verified support.
Tracing a transfer does not promise recovery. Report suspected fraud through the appropriate official channels and be sceptical of anyone offering guaranteed recovery for an advance fee.