Ad slot — 970 × 90 leaderboard
Safety

Keeping your coins

Most losses are not sophisticated hacks. They are signatures, screenshots and reused passwords.

How do you keep your crypto safe?

Write your seed phrase on paper and never type or photograph it. Use app-based two-factor authentication rather than SMS. Separate funds across a burner wallet for new sites, a hot wallet for trading, and a cold wallet for holdings. Review and revoke token approvals quarterly.

The reason security matters more in crypto than in banking is simple: transactions are final and there is nobody to call. That makes prevention the entire strategy.

In plain words

Your seed phrase is not a password you can reset. Anyone who sees it owns everything, forever, and there is no complaint department.

The seed phrase

  1. Write it on paper. Not in a photo, not in notes, not in email, not in a password manager you access from a phone.
  2. Never type it anywhere except when restoring a wallet you deliberately chose to restore. Every site asking for it is a theft, without exception.
  3. Store two copies in separate physical places. Fire and loss are as real as theft.
  4. Never photograph it. Photos sync to clouds automatically, and clouds get breached.

Exchange accounts

The mistake that drains the most wallets

Token approvals. Connecting a wallet to a site and signing an approval can grant unlimited permission to move a token on your behalf. The transaction looks harmless. Months later the allowance is used. Review and revoke approvals periodically, and never sign a request you did not initiate.

Separation

Use more than one wallet, deliberately:

Social engineering

No legitimate support agent will contact you first. No airdrop requires a seed phrase. No exchange asks you to move funds to a "safe wallet". Every one of those is a script, and every one still works because it arrives at a moment of urgency or excitement.

Preflight will never contact you first, never ask for a signature, and never request a payment. Anyone doing so using our name is impersonating us.

Understanding what you are actually protecting

A crypto wallet does not hold coins. It holds a private key, and that key is the only thing that can authorise moving the balance recorded on the blockchain. Your seed phrase is a human-readable form of that key.

This has one consequence that shapes everything else: possession of the phrase is ownership. There is no separate identity check, no account recovery, no name attached. Anyone who reads those words owns the funds, immediately and permanently, and no authority anywhere can reverse it.

Every rule below follows from that single fact.

The threats, in order of how often they succeed

  1. Malicious approvals. You connect a wallet and sign a transaction granting a contract permission to move a token on your behalf. It looks routine. Weeks later the allowance is used. This is the leading cause of drained wallets, and it is not a hack — you authorised it.
  2. Fake sites and support. A claim page reached through a search advertisement, or a helpful stranger who contacts you first. Both are scripts, and both still work.
  3. Clipboard hijacking. Malware replaces a copied address with the attacker's. You paste, glance, and send.
  4. SIM swapping. An attacker moves your phone number to their device and receives your SMS codes. This is why SMS is not a second factor.
  5. Physical discovery. A photographed seed phrase in a cloud backup, or a written one somewhere obvious.

Notice how few of these involve breaking anything. Almost all of them involve persuading you to authorise something, which is why judgment matters more than technology.

A wallet structure that limits the damage

1Burnerclaims and new sites2Hotactive trading only3Coldlong-term, never connected
The burner exists to be the thing that gets drained

Use three separate wallets deliberately, and never merge them.

Separation of risk

Burnerclaims, new sites, airdrops — funded with almost nothing
Hotactive trading and familiar protocols only
Coldlong-term holdings, hardware, never connected to any site

The burner is the important one and the one most people skip. If a malicious approval drains it, you lose the small amount it held and nothing else. Its entire purpose is to be the thing that gets drained.

Move rewards out of the burner promptly. Its value as a firewall depends on it staying empty.

Approvals: the maintenance nobody does

Every approval you have ever signed remains active until revoked. A protocol you used once two years ago may still hold permission to move your tokens today, and if that protocol is later compromised, the permission is exploitable.

Review approvals quarterly and revoke everything you do not actively use. Revoking costs a small network fee — check the gas panel and do it during a cheap window. It is the closest thing to routine maintenance that self-custody has.

Prefer setting a specific allowance rather than unlimited when a site offers the choice. Unlimited approval is convenient exactly once and dangerous permanently.

Storing a seed phrase properly

  1. Handwrite it on paper, or stamp it into metal if the amount justifies it. Paper survives most things; fire and water it does not.
  2. Two copies in two physical locations. Loss is as real a risk as theft, and far more common.
  3. Never photograph it. Phone photos sync to clouds automatically, and clouds get breached.
  4. Never type it anywhere except restoring a wallet you deliberately chose to restore. Every website asking for it is a theft without exception.
  5. Consider a passphrase — an extra word only you know, stored separately. It means finding the paper is not enough.
  6. Tell one trusted person where it is, without telling them what it says. Funds lost to death or incapacity are a large and quiet category.

Common questions

Is a hardware wallet necessary?

For amounts you would be distressed to lose, yes. It keeps the key on a device that never touches the internet, so malware on your computer cannot extract it. For small trading balances the extra friction usually outweighs the benefit.

Are exchange accounts safe if I use strong security?

Safer, but you still do not hold the keys — the exchange does. Every collapse in this industry has taught the same lesson to people who assumed their venue was the exception. Keep on an exchange only what you are actively trading.

What should I do if I think I signed something malicious?

Move the remaining funds to a fresh wallet immediately, before revoking anything. Revoking takes time to confirm; moving funds does not. Then revoke the approval, and treat the compromised wallet as permanently untrusted.

Try it on the desk.

Free, no account, nothing stored on our servers.

Open Preflight