Skip to content
Sat, Jul 25, 2026
BTC $00,000 ETH $0,000 SOL $000
Your keys are yours — we never ask for them Live
Wallet Security

Wallet Security Basics: Your Keys, Your Crypto, Your Responsibility

A cornerstone guide to non-custodial wallets: seed-phrase hygiene, hardware wallets, revoking approvals, spotting drainers, and why your keys are yours.

If you learn only one thing about crypto, make it this: whoever controls the keys controls the coins. A crypto wallet is not a place where your money is stored; it is a keychain that proves ownership of assets recorded on a blockchain. Understanding that single idea reshapes everything you do, because it means your security is mostly in your own hands. This cornerstone guide covers the essentials, calmly and thoroughly.

Custodial versus non-custodial: who holds the keys

A custodial wallet is one where a company holds the keys for you, much like a bank. It is convenient and can be recovered if you forget a password, but you are trusting that company entirely; if it is hacked, frozen, or fails, your funds are at its mercy.

A non-custodial wallet puts the keys in your hands alone. No company can freeze or lose your funds, but no company can rescue you either. This is the meaning of the phrase “your keys are yours”: total control paired with total responsibility. Most of this guide assumes non-custodial wallets, because that is where personal security habits matter most.

The seed phrase: the master key to everything

When you create a non-custodial wallet you are given a recovery phrase, usually twelve or twenty-four words, also called a seed phrase. This phrase can regenerate your entire wallet and all its keys. Anyone who has it has complete, irreversible control of your funds.

Seed-phrase hygiene

  1. Write it down offline, on paper or metal, and store it somewhere private and secure. Consider more than one physical copy in separate safe locations.
  2. Never type it into a website, chat, email, or app that did not generate it, and never take a photo of it or store it in cloud notes.
  3. Never tell it to anyone. No legitimate support agent, project, or platform will ever ask for it. Every single request for your seed phrase is an attempt to rob you.
  4. Be aware that anyone who watches you enter it, or finds your written copy, gains full control. Treat it like the deed to everything you own on-chain.

There is no “reset” for a seed phrase. If it is lost, your funds are usually gone forever; if it is stolen, your funds can be taken in seconds. This permanence is exactly why hygiene matters so much.

Hardware wallets: keeping keys off the internet

A hardware wallet is a small physical device that stores your keys offline and signs transactions internally, so the keys never touch your internet-connected computer or phone. Even if your everyday device is infected with malware, an attacker cannot extract keys that never leave the device, and dangerous transactions must be physically confirmed on the device itself.

For anything beyond small amounts, a hardware wallet is one of the most effective upgrades to your security. Buy it directly from the manufacturer or an authorised seller, never second-hand, set it up yourself, and record the seed phrase it generates with the same care described above. If a device arrives with a pre-filled seed phrase, it is compromised; a genuine device always generates the phrase in front of you.

Token approvals: the risk people forget

To use many applications, you grant them permission to move specific tokens on your behalf. These approvals are convenient but they persist, sometimes indefinitely, and a malicious or later-compromised contract can use a lingering approval to drain those tokens. Good practice is to review your active approvals periodically and revoke any you no longer need, using a reputable approval-management tool or your wallet’s built-in controls. We cover this in depth in our dedicated guide on revoking token approvals.

Spotting drainers and common attacks

A “drainer” is a malicious website or transaction designed to empty your wallet the moment you approve it. Attackers lure you to these with fake airdrops, fake support, urgent warnings, and cloned sites. Protect yourself with a few reflexes.

  1. Read every transaction before signing. If your wallet warns that you are granting spending permission or interacting with an unknown contract, stop.
  2. Reach sites by typing addresses yourself or using saved bookmarks, not by clicking links from messages, ads, or search results that could be spoofed.
  3. Distrust urgency. “Act now or lose access” is the language of attackers, not legitimate services.
  4. Ignore unsolicited direct messages offering help; real support does not slide into your messages first.
  5. Keep large holdings in a separate wallet you rarely connect anywhere, and use a small “hot” wallet for day-to-day interaction.

Everyday habits that keep you safe

  1. Keep your device and wallet software updated, and download wallets only from official sources.
  2. Verify addresses carefully before sending; transactions are irreversible.
  3. Use the separation of a hardware wallet or a dedicated cold wallet for savings, and a small hot wallet for activity.
  4. Assume every unexpected message, token, or offer is a test of your discipline, and slow down.

TokenSpin will never ask you to connect your wallet to us, never ask for your seed phrase, private keys, or password, and never run a page that requests wallet access. We do not need any of that to inform you, and anyone claiming otherwise in our name is a fraud. Participation in anything we describe should happen only through the relevant project’s own official channels, after you have verified them yourself.

Building a personal security model you will actually follow

The best security setup is the one you will maintain in real life, not the theoretical ideal you abandon after a week. A practical model most people can sustain is a two-tier arrangement. Your first tier is a “cold” wallet, ideally a hardware wallet, that holds the bulk of your assets and connects to almost nothing. Its seed phrase lives offline, in a private and secure place, and it approves only occasional, carefully-read transactions. Your second tier is a small “hot” wallet on your phone or computer that holds only what you are comfortable losing and does the day-to-day exploring. Damage from a mistake or a malicious site is then naturally capped at the small wallet.

Layered on top of that structure are a few habits that cost little and prevent much: bookmark the sites you trust and reach them through those bookmarks rather than search results; slow down whenever a message or page makes you feel excited or hurried; and periodically review and revoke token approvals you no longer need. Each habit closes off a whole category of attack. None of them requires technical brilliance, only consistency.

What to do if you think you have been compromised

  1. Move quickly but calmly. Transfer any remaining funds from the affected wallet to a fresh, uncompromised wallet with a new seed phrase.
  2. Revoke token approvals connected to the suspicious site or contract, using a reputable tool or your wallet’s built-in controls.
  3. Stop using the compromised wallet for anything of value; assume its keys may be exposed.
  4. Be especially wary of “recovery services” that appear afterwards offering to retrieve stolen funds, as these are frequently a second scam targeting victims of the first.

Acting fast to move funds out of reach is far more effective than trying to out-argue an attacker or waiting to see what happens.

Security in crypto is less about clever tricks and more about steady habits: protect the seed phrase, keep keys offline where you can, read what you sign, revoke what you do not need, and refuse to be rushed. Do those consistently and you remove the overwhelming majority of the risk. Your keys are yours, and so is the responsibility that makes them safe.

Frequently asked questions

What is the difference between a wallet and a seed phrase?

A wallet is software or a device that manages your keys and lets you interact with the blockchain. The seed phrase is the master secret, usually twelve or twenty-four words, that can regenerate the entire wallet and all its keys on any compatible device. Losing the wallet app is recoverable if you have the seed phrase; losing or exposing the seed phrase itself is not. Guard the phrase above all else.

Do I really need a hardware wallet?

For small, experimental amounts, a reputable software wallet with good habits can be enough. For any meaningful holding, a hardware wallet is strongly worth it because it keeps your keys offline and forces physical confirmation of every transaction, defeating most malware. Buy only from the manufacturer or an authorised seller, set it up yourself, and never accept a device that arrives with a pre-filled seed phrase.

Someone from 'support' is asking for my seed phrase. Is that ever okay?

Never. No legitimate wallet provider, exchange, project, or support agent will ever ask for your seed phrase, private key, or wallet password, under any circumstance. Every such request is an attempt to steal your funds. Real support can help without ever needing your secrets. If anyone asks, stop talking to them, and remember that genuine support never messages you first offering help.

What is a drainer and how do I avoid one?

A drainer is a malicious site or transaction built to empty your wallet the instant you approve it, usually reached via fake airdrops, cloned sites, or urgent messages. Avoid it by reaching sites through your own bookmarks rather than forwarded links, reading every transaction before signing, declining unknown spending permissions, and keeping large funds in a separate wallet you rarely connect anywhere.

Get The Spin

The week's vetted rewards + the scams to avoid — free, every week. Informational. Not financial advice. We never ask for your keys.