Crypto Wallet Security Checklist

    Reviewed and updated September 14, 2026 by the SmartCryptoEarnings editorial team · editorial policy

    Most wallet losses come from a small set of repeated mistakes rather than sophisticated attacks. A checklist works because it turns security into something you finish rather than something you worry about.

    Each item includes why it matters. Skip the ones that do not apply to how you use crypto; do not skip the backup section.

    Setup

    • Download wallet software only from the link in the project's own official documentation, and bookmark it afterwards.
    • Buy hardware wallets from the manufacturer or an authorised reseller, and generate the phrase yourself on the device.
    • Never accept, use or restore a recovery phrase that came with a device or from anyone else.
    • Set a device PIN or password that is not reused anywhere.
    • Record which wallet software and derivation settings you used — it makes restoration far easier years later.

    Backups

    • Write the recovery phrase on paper or metal, by hand, offline.
    • Never photograph it, type it into a note, email, spreadsheet, password manager screenshot or cloud drive.
    • Verify the backup by restoring it on a wiped device or a spare wallet, before funding it.
    • Store at least one copy in a second physical location that is safe from fire, water and casual discovery.
    • If you use an extra passphrase, back it up separately — losing it loses the wallet even with the phrase.

    An unverified backup is not a backup. The most common irreversible loss is discovering a transcription error years later.

    Day-to-day habits

    • Separate a small hot wallet for interacting with applications from the wallet holding long-term funds.
    • Reach sites through your own bookmarks, never through search advertisements, messages or QR codes sent to you.
    • Verify the first and last characters of a destination address and send a small test amount to any new address.
    • Read every signature request; reject anything you cannot understand or did not initiate.
    • Review and revoke token approvals you no longer use.
    • Never enter the recovery phrase anywhere except the wallet's own restore screen on a device you control.

    Accounts and devices

    • Use an app-based authenticator or a hardware security key for exchange accounts rather than SMS, which is exposed to SIM-swap attacks.
    • Use a unique password per account, stored in a password manager.
    • Protect the email account behind your exchange logins as carefully as the exchange itself.
    • Keep the operating system, browser and wallet software updated.
    • Do not install cracked software or unknown browser extensions on a device that holds keys.

    Planning ahead

    • Decide how someone you trust would access the funds if you could not — without leaving the phrase where it can be read casually today.
    • Keep written instructions that describe where things are and how to proceed, separately from the phrase itself.
    • Review the whole checklist on a schedule, for example each quarter, and after any device change.

    Frequently Asked Questions

    Is a password manager safe for a recovery phrase?

    We do not recommend it. It converts an offline secret into one reachable by any compromise of that device or account. Keep the phrase offline.

    How often should I review wallet security?

    A quarterly review is a reasonable habit, plus a check after changing a phone or computer, and after any suspicious interaction.

    Does splitting a phrase into parts improve safety?

    Improvised splitting often creates a new way to lose everything. Formal schemes exist, but a single well-stored backup plus a second copy in another location is more reliable for most people.

    Sources

    Spotted something out of date? See our corrections policy and fact-checking policy.

    Continue reading

    Educational information only. Nothing here is financial, legal or tax advice.