Security

How to Keep Your Crypto Safe: A Security Checklist

Most crypto losses aren’t sophisticated hacks — they’re avoidable mistakes: a seed phrase stored in a photo, an SMS code intercepted, a fake “support” DM. Get a handful of habits right and you remove the vast majority of the risk. Here’s the checklist.

1. Self-custody what you’re not actively trading

Crypto sitting on an exchange is exposed to that exchange failing, freezing withdrawals, or being hacked — and it’s not covered by any Australian government guarantee. The phrase the industry repeats is “not your keys, not your coins.” Keep only what you’re actively trading on an exchange, and move longer-term holdings into a wallet you control. See our wallet reviews for how self-custody works.

2. Use a hardware wallet for meaningful amounts

A hardware (cold) wallet keeps your private keys on an offline device, so they can’t be reached by malware or a compromised website. Two rules: buy it only from the manufacturer or an authorised reseller — never a marketplace listing or a “pre-configured” device — and set it up yourself.

3. Protect your recovery phrase above everything

Your 12- or 24-word recovery (seed) phrase is your crypto. Anyone who has it controls your funds; if you lose it, the funds are gone forever. So:

  • Write it on paper or steel and store it offline, in more than one secure place
  • Never photograph it, type it into a website or app, or store it in cloud, email or notes
  • No legitimate exchange, wallet, or “support agent” will ever ask for it — anyone who does is a scammer

4. Turn on real two-factor authentication

Enable 2FA on your exchange and email accounts using an authenticator app (or a hardware security key) — not SMS. SMS codes can be intercepted through SIM-swap attacks, where a scammer ports your number. An authenticator app closes that hole.

5. Defend against phishing

Phishing is the most common attack on everyday users:

  • Bookmark your exchange and wallet URLs and type them manually — never click login links in emails or DMs
  • Check sender addresses carefully; scammers use look-alike domains
  • Treat anyone who messages you first claiming to be “support” as a scam
  • Never let someone remote into your device (AnyDesk/TeamViewer) to “help”

Our guide to avoiding crypto scams covers the specific cons targeting Australians.

6. Be careful in DeFi

If you use decentralised apps, you’re signing transactions that grant permissions. Before you approve anything, check what it’s requesting, avoid unlimited token allowances you don’t need, and periodically revoke stale approvals with a revoke tool. Consider a separate “hot” wallet holding only small amounts for day-to-day DeFi, kept apart from your main savings.

7. General hygiene

Use a unique, strong password for every account (a password manager makes this painless), keep your device and wallet firmware updated, use a dedicated email just for crypto, and avoid accessing wallets or exchanges over public Wi-Fi.

The short version

Self-custody your savings, guard your seed phrase offline, use app-based 2FA, and slow down whenever something feels urgent. Do those four things and you’re already safer than most.

General information only — not financial advice. If you’re unsure about a platform or message, check it against ASIC’s Moneysmart before acting.

General information only — not financial or tax advice. Verified 2026-07-31; details can change.