Crypto Security Checklists
Security knowledge is only useful if it translates into action. These checklists give you concrete, actionable steps to protect your cryptocurrency at every level.
Work through each section at your own pace. Every item you complete reduces your risk.
✅ Seed Phrase Security Checklist
Your seed phrase is the master key. This list is non-negotiable.
- Written down on paper — every word, in order, accurately
- Verified by doing a test restore on a fresh device
- Stored completely offline — never photographed, never typed anywhere
- Stored in at least two separate secure physical locations
- Protected from fire and flooding (metal backup plates recommended for significant holdings)
- Not stored with your hardware wallet (if they're stolen together, you lose everything)
- A trusted person knows where to find it in case of your death or incapacity
- You have NEVER: emailed it, saved it in notes, screenshotted it, or entered it anywhere online
✅ Hardware Wallet Checklist
For anyone holding more than a few hundred dollars in crypto, a hardware wallet is essential.
- Purchased directly from the manufacturer (Ledger, Trezor, Coldcard — never third-party sellers)
- Packaging tamper-evident seals intact upon receipt
- Device initialized yourself — seed phrase generated by the device, not pre-supplied
- Firmware updated to latest version
- Strong PIN set (not your birthday, not 1234)
- Test transaction completed successfully before storing significant funds
- Recovery from seed phrase tested on a second device
- Device stored securely, separate from the seed phrase
- You always verify receive addresses on the device screen (not just the computer screen)
- You always read what the device screen shows before confirming any transaction
✅ Software Wallet (Hot Wallet) Checklist
For wallets like MetaMask, Trust Wallet, and Phantom:
- Downloaded from the official website or official app store listing only
- Seed phrase backed up offline immediately after creation
- Wallet password is unique and strong
- Phone/computer has a strong lock screen PIN or password
- Operating system and wallet app kept up to date
- Only small amounts kept in hot wallets (treat it like cash in a physical wallet)
- Suspicious apps or browser extensions not installed on the same device
- You regularly review token approvals at revoke.cash and revoke unnecessary permissions
✅ Exchange Account Security Checklist
For funds you keep on Coinbase, Kraken, Binance, or other exchanges:
- Strong, unique password (not used anywhere else)
- Stored in a password manager — not written down or memorized
- Two-factor authentication (2FA) enabled — using an authenticator app (Google Authenticator, Authy), NOT SMS
- Email account associated with the exchange is also secured with 2FA
- Withdrawal whitelist enabled (only pre-approved addresses can receive withdrawals)
- Anti-phishing code set up (Binance and some others offer this — a custom phrase in every real email)
- You access the exchange only by typing the URL directly or via your bookmarks
- You are aware that exchange funds are not protected by your seed phrase
✅ Anti-Phishing Checklist
See our full phishing guide for context on each of these:
- Key crypto sites bookmarked (MetaMask, your exchanges, DeFi apps)
- You never click links in unsolicited emails or DMs
- You never enter your seed phrase on any website — ever
- You know that Google Ads can link to phishing sites — you go to bookmarks, not search results
- Discord/Telegram: you ignore all DMs offering help or opportunities
- You double-check URLs for subtle misspellings before entering any credentials
✅ Ongoing Security Habits Checklist
Security isn't a one-time setup — it requires ongoing vigilance:
- You stay up to date with security news in the crypto space
- You periodically review and revoke unnecessary smart contract approvals (revoke.cash)
- You don't discuss your crypto holdings publicly or on social media
- You use different email addresses for exchanges vs. general use
- You have a plan for what happens to your crypto if you die or become incapacitated
- You approach "too good to be true" opportunities with strong scepticism
- You take your time on transactions — scammers create artificial urgency
Priority Order: Start Here
If you're just getting started, do these five things first:
- Back up your seed phrase offline and store it securely
- Enable 2FA (authenticator app, not SMS) on all exchange accounts
- Use a hardware wallet for any holdings you'd be upset to lose
- Bookmark your crypto sites and never click email links to them
- Review your token approvals and revoke anything unnecessary
These five steps address the vast majority of how crypto is actually stolen.
Continue Learning
- Seed Phrases — your most critical security asset
- Hardware Wallets — the most effective security upgrade
- Self-Custody — why you should hold your own keys
- Common Scams — what you're protecting against
- Phishing Protection — the most common attack method
For a comprehensive security education, read Understanding Seed Phrases from the Mastering Crypto series.