Before you use a crypto wallet: 10 security questions to ask
Use this beginner crypto wallet security checklist to protect keys, compare exchange custody, verify transfers, and question smart-contract approvals.
In this guide
A crypto wallet can look like an ordinary app, but the risk sits behind the screen in the keys, approvals, connected accounts, and contracts you are trusting. Before you deposit on an exchange, move assets into self-custody, or connect to a smart contract, you need to know who can authorize a transaction, what can restore access, and what happens when something goes wrong.
The central idea: a wallet does not hold coins in the way a physical wallet holds cash. It manages the credentials used to control assets recorded on a blockchain. The security question is therefore not only “Which wallet should I use?” It is “Who controls the keys, which systems do I trust, and what exactly am I authorizing?” The U.S. SEC’s investor-education staff makes the same distinction in its custody overview.1
This guide is a starting point for the Crypto & Digital Assets learning path. It does not rank products or make crypto safe. Security practices reduce particular risks; they do not remove market losses, software defects, fraud, legal uncertainty, or human error.
Pause rule: If you cannot explain who controls the keys, what a confirmation will do, and how you would recover or exit, do not add more money or sign the request yet.
Before you start: separate four things
Beginners are often asked to trust a single word—“wallet”—for several different systems. Separate them first:
- The asset and network: the blockchain records the asset and its transactions. Different assets and networks behave differently.
- The wallet: software, hardware, or another interface that helps manage keys and prepare or sign requests.
- The custodian: an exchange or other service that may control keys on your behalf.
- The smart contract: code on a network that can hold assets or act when its conditions are met. A contract may also depend on administrators, upgrade mechanisms, or outside data.
A strong setup in one layer does not repair a weakness in another. A hardware wallet cannot make a fraudulent contract fair. A regulated company label does not tell you the exact treatment of your assets in failure. A blockchain record does not prove that the data originally entered was true.
Crypto payments are generally irreversible, so a mistake or unwanted permission can be difficult to recover from. Check the controls before approving, not only after a transfer. See the FTC’s explanation.
1. Who controls the keys?
Start by asking whether you are using self-custody or third-party custody.
With self-custody, you—or a setup you control—hold the credentials that authorize transactions. You gain direct control, but you also take responsibility for backups, device security, transaction review, and recovery. If the relevant keys and recovery material are lost or stolen, access may be permanently lost.
With third-party custody, an exchange or custodian controls the keys and gives you access through an account. Password recovery and customer support may be more familiar, but your access now depends on the provider’s security, operations, terms, solvency, withdrawal controls, and legal structure. The SEC bulletin warns that a custodian’s hack, shutdown, or bankruptcy may prevent customers from accessing assets.1
Neither model is automatically safe. Write down the answer to three questions:
- Who can authorize a transfer today?
- Who can restore access if a device or password is lost?
- Whose failure could block or remove my access?
If the product description does not make those answers clear, the custody model is not clear enough yet.
2. What restores access—and who could use it?
Many self-custody wallets create a recovery phrase, also called a seed phrase. It can recreate control of the wallet. That makes it a recovery tool and a concentrated security risk: anyone who obtains it may be able to control the associated accounts.2
Treat a recovery phrase differently from an everyday app password:
- Never send it to support, a website, a form, a chatbot, or a person offering to “verify” or “sync” the wallet.
- Do not store it in a screenshot or ordinary cloud note. Screenshots can be uploaded or synchronized beyond the device you took them on.2
- Follow the wallet maker’s current, official recovery instructions. Wallet designs differ; some use other backup or account-recovery models.
- Plan for physical loss, damage, theft, and the possibility that you are unavailable. Avoid improvising a complicated backup system you cannot reliably operate.
- Before holding meaningful value, make sure you understand the recovery procedure without entering secret material into an unsolicited site or message.
A local wallet password may protect the app on one device, while the recovery phrase can restore control elsewhere. One does not necessarily replace the other. Confirm the exact design from the wallet’s official documentation.
3. How will I protect the accounts around the wallet?
Third-party custody makes your login, email account, recovery channel, and devices part of the security boundary. A strong exchange password is less useful if the email used to reset it is compromised.
For every online crypto account:
- use a long, unique password rather than reusing one from another service;
- enable multi-factor authentication (MFA);
- protect the connected email account with the same care;
- review login and withdrawal alerts where the service offers them;
- use verified support channels instead of links from an unexpected call, direct message, or search ad.
The SEC bulletin recommends strong passwords and MFA for online crypto accounts.1 MFA is an extra layer, not permission to ignore a suspicious request. A scammer may still try to trick you into approving a login, revealing a code, or installing remote-access software.
Unexpected urgency is a warning. The U.S. Federal Trade Commission says that impersonators may claim your account is at risk and instruct you to buy or transfer crypto for “safe keeping.” That is a scam pattern, not a security procedure.3
4. Is the wallet software or device authentic and maintained?
Before installing a wallet or connecting it to a site, establish the real publisher and domain through a source you already trust. A copied website, malicious browser extension, fake mobile app, or impersonated support account can look convincing.
Ask:
- Did I reach the download or application from the project’s verified domain rather than an ad or unsolicited message?
- Is the domain spelled exactly as expected?
- Does the publisher provide current setup and update instructions?
- Is my phone or computer receiving security updates?
- Have I removed browser extensions and software I do not need?
- If this is a hardware device, do I understand the maker’s official initialization and recovery process?
Do not type a recovery phrase into a normal support workflow. Ethereum’s public security guidance says that no legitimate service, support agent, or website should ask for the recovery phrase or private keys and advises checking the domain after following a link.2
A cold or hardware wallet can reduce exposure of private keys to an internet-connected device, but it introduces physical custody, backup, firmware, supply-chain, and transaction-review responsibilities. “Offline” is a risk trade-off, not a guarantee.
5. What happens if the exchange or custodian fails?
Do not stop at “Is this exchange regulated?” Regulation, licensing, customer-asset treatment, and compensation or insurance arrangements vary by service, activity, and jurisdiction. Find the provider’s current legal entity and terms for your location, then ask:
- Which company is my counterparty, and which regulator or authority oversees the relevant activity?
- Are customer assets held separately, pooled, lent, pledged, or otherwise used?
- Does the provider use another custodian or subcontractor?
- What happens to customer assets if the provider is hacked, suspends withdrawals, or enters insolvency?
- Is any insurance or compensation arrangement actually applicable to my assets and loss scenario? What are its exclusions and limits?
- What identity, account, network, minimum, delay, and fee rules apply when I withdraw?
- How is customer data used and protected?
These are questions, not implied protections. The SEC custody bulletin specifically tells U.S. retail investors to investigate regulation, failure, insurance terms, storage, subcontracting, commingling, rehypothecation, privacy, and account or transfer fees.1 Its bulletin represents staff views and is not a Commission rule or a legal conclusion. Readers outside the United States must check local law and provider terms.
Our separate guide to investment fees explains why the headline trading fee may not capture holding, transfer, or exit costs.
6. Are the asset, network, address, and amount all correct?
Blockchain transfers can be unforgiving. The FTC notes that crypto payments are typically not reversible, while Ethereum guidance says a transfer to the wrong address cannot normally be retrieved unless the recipient cooperates.23
Before confirming a transfer, independently check:
- Asset: Is the receiving service expecting this exact asset or token?
- Network: Is the sender using the same network the destination supports for this deposit?
- Address: Did you obtain the address from the intended recipient or the destination’s authenticated interface?
- Amount and fee: Are both what you intended, in the units the wallet displays?
- Tag or memo: Does the destination require an additional identifier?
- Final confirmation: Does the wallet or exchange confirmation still show the intended details?
When the service supports it and the fees and minimums are reasonable, a small test transfer can reduce the size of one kind of mistake. It is not proof that a later transfer, a different network, or a smart-contract interaction will be safe. Recheck the details for every transaction.
Do not accept a replacement address from an unexpected message—even if the sender claims to be support. When money is at risk, leave the message and navigate through a channel you independently verified.
7. Do I understand what I am signing?
“Connect,” “sign,” “approve,” and “send” are not interchangeable actions. A connection may share an address with an application. A signature may authenticate a message or authorize something more consequential. A transaction can move assets or change permissions. The exact effect depends on the request and network.
Your wallet confirmation is the final checkpoint. Read the destination, asset, amount, network, contract, and permission details it can display. If the confirmation is only opaque code or you cannot explain the outcome, reject it and investigate through independent documentation.
The Ethereum Foundation calls confirmations that users cannot meaningfully understand blind signing and is developing clearer, human-readable transaction descriptions.4 Clearer text is useful, but it still must come from a trustworthy interpretation. A polished screen is not proof that the underlying application is legitimate—just as a confident AI answer is not evidence by itself. See how to question AI-generated financial information.
8. How much token access am I granting?
On Ethereum and compatible token systems, an application may ask for an allowance: permission for a smart contract to spend a token from your address. That permission can be larger than the transaction you plan to make and may remain after you disconnect the wallet from the site.
Before approving, ask:
- Which token can the contract spend?
- What is the maximum amount?
- Is the request limited to what this action needs, or is it unlimited?
- Does the permission expire?
- How will I review and revoke it later?
- Will reducing or revoking it require a separate network transaction and fee?
Ethereum.org advises limiting spending permissions to the amount needed and explains that disconnecting a wallet is not the same as revoking an existing token allowance.25 This is Ethereum-specific guidance; permission models differ across networks and wallet types. Use the current instructions for the network and wallet you actually use, and verify any allowance-review tool before connecting.
9. What trust remains in the smart contract?
“Runs on a blockchain” does not mean “has no one to trust.” A smart contract may contain defects, grant administrators powerful controls, route through upgradeable components, or depend on outside data from an oracle.
You do not need to become a developer before every interaction, but you should be able to find plain answers to these questions:
- What exact contract address and network does the official application use?
- Can an administrator pause the system, move funds, change fees, or upgrade the code?
- If the contract is upgradeable, who controls the upgrade and how is that control protected?
- Does the outcome depend on a price feed, bridge, custodian, or other external system?
- Has the relevant deployed version received an independent security review, and when?
- What did the review exclude, and what has changed since it was performed?
- Is there a documented response plan for a vulnerability or failed dependency?
Ethereum’s developer documentation warns that audits do not catch every bug and should not be treated as a silver bullet.6 Its upgrade documentation also shows that an immutable address can route calls to changeable logic, while its oracle documentation explains that offchain data must be brought onchain through additional infrastructure.7
An audit badge, long operating history, or public source code can inform due diligence, but none guarantees the contract, governance, inputs, or economic design is safe or fair.
10. What is my exit and incident plan?
Decide what you will do before urgency makes the decision for you.
Your plan should identify:
- how to reach the exchange, wallet publisher, or application through a verified channel;
- how to lock or recover an online account;
- which devices and recovery materials must remain available;
- how to review and revoke contract permissions where the network supports it;
- which transaction IDs, addresses, timestamps, screenshots of non-secret information, and messages you would preserve;
- where to report fraud or theft in your jurisdiction;
- how a trusted person could follow your instructions if you were unavailable—without exposing secret material casually.
If account credentials were exposed, change them from a device you believe is clean and secure the connected email account. If a self-custody recovery phrase or private key may be exposed, treat the situation as urgent, but do not follow a stranger’s rescue instructions or enter the phrase into a website. Use the wallet maker’s verified incident guidance or qualified help you independently selected.
For a suspected fraudulent payment, the FTC advises U.S. consumers to contact the exchange or ATM operator immediately, ask whether reversal is possible, and report the incident to the relevant authorities.8 Recovery is often difficult, and reporting channels and legal rights differ by location.
A ten-minute preflight checklist
Before you fund, withdraw, connect, or sign, stop if any answer is unclear:
- I know whether I or a third party controls the keys.
- I understand the recovery method and have not shared secret material or put it in screenshots or ordinary cloud storage.
- My exchange and email accounts use unique passwords and MFA.
- I reached the wallet, exchange, or application through a verified domain or publisher.
- I read the custodian’s current withdrawal, failure, asset-use, insurance, privacy, and fee terms for my jurisdiction.
- I checked the exact asset, network, address, amount, fee, and any memo or tag.
- I can explain what the wallet confirmation will do.
- Any token allowance is limited to what I intend and I know how to review it later.
- I understand the contract’s remaining administrator, upgrade, oracle, bridge, and audit assumptions.
- I have an incident and exit plan that does not depend on an unsolicited helper.
Good security is layered and specific. It reduces the chance that one mistake becomes a total loss, but it cannot make an asset valuable, a provider solvent, a contract correct, or a transaction reversible. Keep the amount at risk proportional to what you actually understand, and keep learning before adding complexity.
Continue with the broader Technology topic, then read about diversification to separate operational security from investment and concentration risk.
Sources
- Crypto Asset Custody Basics for Retail Investors — Investor Bulletin
- Ethereum security and scam prevention
- What To Know About Cryptocurrency and Scams
- Clear Signing: Making Transaction Approvals Safer on Ethereum
- How to revoke smart contract access to your crypto funds
- Smart contract security
- Oracles
- What To Do if You Were Scammed
- Upgrading smart contracts