Risk warning: Crypto is volatile and you can lose money. This is educational content, not financial advice. Never invest more than you can afford to lose.

How to Keep Your Crypto Safe (Security Basics)

By the Crypto Plainly team · Updated July 15, 2026 · 9 min read · A practical checklist
Disclosure: Some links below are affiliate links; if you sign up through them we may earn a commission at no extra cost to you. Educational only — not financial advice. Full disclosure & risk warning.
Short answer: Keeping crypto safe comes down to a few habits: use a strong, unique password with a password manager, turn on app-based two-factor authentication (not SMS), and never store your seed phrase digitally. Keep only spending money on exchanges, use a hardware wallet for larger holdings, and slow down before clicking links or trusting "support".

Most people who lose crypto do not lose it to some genius hacker breaking encryption. They lose it to ordinary mistakes: a reused password, a fake support agent, a screenshot of a seed phrase saved in the cloud, or a rushed click on a link that looked real. The good news is that the same handful of habits protect against nearly all of it. You do not need to be technical — you need to be careful and consistent.

This is a plain-English checklist for beginners. Work through it once, set things up properly, and most of your risk disappears. Remember that no security setup makes crypto a safe investment — prices are volatile and you can lose money regardless of how well you protect your keys. Security is about not losing coins to theft or error, not about avoiding market losses.

The one idea that explains everything: "not your keys, not your coins"

You will hear this phrase constantly, so it helps to understand it plainly. In crypto, whoever controls the private keys controls the coins. A private key is a secret that proves ownership and lets you move funds.

When you hold crypto on an exchange, the exchange holds the keys — not you. Your balance is really a promise from the company. That is convenient, and reputable exchanges are useful, but it means your coins depend on that company staying solvent, honest and un-hacked. If it freezes withdrawals or collapses, you are a creditor waiting in line.

When you move crypto to a wallet where you hold the keys (a "self-custody" wallet), you are in full control — and also fully responsible. There is no reset button and no support line to recover a lost key. "Not your keys, not your coins" simply means: if you do not hold the keys, you do not truly own the coins, you are trusting someone else to. Both approaches are valid; the trick is knowing which one you are using and protecting each accordingly.

The beginner security checklist

1. Use strong, unique passwords and a password manager

Reusing one password across sites is the single most common way accounts get taken over. If one service is breached, attackers try that same email-and-password combination everywhere else. Use a long, unique password for every crypto account — especially your email, because whoever controls your email can often reset everything else.

You cannot remember dozens of strong passwords, so let a password manager do it. It generates and stores long random passwords and fills them in for you. Protect the manager itself with one strong master password and its own 2FA.

2. Turn on app-based 2FA — not SMS

Two-factor authentication (2FA) adds a second step to logging in, so a stolen password alone is not enough. But not all 2FA is equal. SMS codes are the weakest option because of "SIM swapping", where an attacker convinces your mobile provider to move your number to their device and intercepts the codes.

Prefer an authenticator app (the kind that shows a rotating six-digit code) or a physical security key. Enable it on your exchange accounts, your email and your password manager. If a platform only offers SMS, use it — it is better than nothing — but treat those accounts as lower-trust and keep less on them.

3. Protect your seed phrase offline — never digital

When you set up a self-custody wallet, it gives you a seed phrase (also called a recovery phrase): usually 12 or 24 words. That phrase is your wallet. Anyone who reads it can recreate your wallet and drain it, from anywhere in the world.

The golden rule: your seed phrase should never touch anything connected to the internet. Do not photograph it, do not type it into your phone's notes, do not email it to yourself, do not store it in the cloud, and never enter it into a website or "support" chat. No legitimate wallet or exchange will ever ask for your full seed phrase.

Write it on paper (or stamp it into metal for durability), store it somewhere private and safe, and consider a second copy in a separate location in case of fire or loss. If anyone — a "wallet support agent", a giveaway site, a browser pop-up — asks for your seed phrase, it is a scam. There are no exceptions.

4. Use a hardware wallet for larger holdings

A hardware wallet is a small physical device that keeps your private keys offline and signs transactions without ever exposing the keys to your internet-connected computer or phone. Even if your laptop is riddled with malware, the keys stay on the device, and you physically confirm each transaction on its screen. For anything you would be genuinely upset to lose, this is the meaningful upgrade.

A widely used option is Ledger, which makes hardware wallets aimed at beginners and experienced users alike. Buy hardware wallets only from the manufacturer or an authorised reseller — never second-hand and never from a marketplace listing, because a tampered device can be pre-loaded with an attacker's seed phrase. When it arrives, generate a brand-new seed phrase yourself; if a device comes with a phrase "already set up", do not use it. For a broader look at custody options, see our guide to the best crypto wallets for beginners.

5. Verify addresses and app sources every time

Two quiet risks deserve constant attention. First, address-swapping malware can change a crypto address you have copied to your clipboard, so you paste the attacker's address instead. Always check the first and last several characters of an address after pasting, and send a tiny test amount first for large transfers.

Second, fake apps and websites. Download wallet and exchange apps only from official links on the provider's own site or the official app stores, and double-check the URL before logging in — scammers buy lookalike domains and ads. Bookmark the real sites and use the bookmark rather than searching each time.

6. Beware phishing and fake "support"

Phishing is the number-one threat to ordinary users. It looks like an urgent email about "suspicious activity", a direct message from "support", a too-good giveaway, or a pop-up telling you to "validate" your wallet. The goal is always the same: to rush you into revealing a password, a 2FA code or a seed phrase.

Real companies do not DM you first, do not ask for your password or seed phrase, and do not pressure you to act in the next five minutes. When in doubt, stop, and reach the company through its official website — never through a link someone sent you. Urgency is the tell. Our full walkthrough on how to avoid crypto scams covers the common playbooks in detail.

7. Do not flaunt your holdings

Talking publicly about how much crypto you own paints a target on your back — online and, in extreme cases, offline. Keep balances, screenshots and wallet addresses private, be sceptical of unsolicited "investment" friends in DMs, and avoid linking your identity to a public wallet address you actively use. Quiet is safe.

8. Keep only spending money on exchanges

Exchanges are convenient for buying, selling and short-term holding, but the balance is in someone else's custody. A sensible habit is to treat an exchange like a current account: keep there what you are actively trading or about to spend, and move longer-term holdings into a wallet you control. If you do keep funds on an exchange, choose an established, well-run one — see our notes on the safest crypto exchanges for beginners — and lock it down with a unique password and app-based 2FA.

Quick FAQ

Is a hardware wallet really necessary for a beginner?

Not for small, spending-sized amounts you are actively using — good passwords, app-based 2FA and careful habits cover a lot. It becomes worth it once you are holding an amount you would be genuinely upset to lose, because it removes your everyday devices as a point of failure.

What happens if I lose my seed phrase?

If you lose the seed phrase to a self-custody wallet and still have access to the wallet, move the funds to a new wallet immediately and back up the new phrase properly. If you lose the phrase and access to the device, the funds are generally unrecoverable — there is no central authority to reset it. This is exactly why offline backups matter.

Someone from "support" messaged me about my wallet — is that normal?

No. Legitimate support does not contact you first by DM, and never needs your seed phrase or password. Treat any unsolicited message as a scam until proven otherwise, and only ever contact companies through their official website.

Protect your larger holdings offline

If you are ready to move beyond exchange storage, a hardware wallet keeps your keys off your internet-connected devices. Buy only from the official source, and always set up a fresh seed phrase yourself.

See Ledger hardware wallets → Compare beginner wallets

Reminder: none of this is financial advice. Crypto is volatile, you can lose money, and you should only ever risk what you can afford to lose. Fees, features and availability vary by country and change over time — always verify details on the provider's own site.

Read next