Most losses we investigate did not require sophisticated attacks. They required one seed phrase entered on the wrong page, one SMS code read aloud, or one approval signed without reading. These are the controls that prevent the common cases.
Seed phrases
Your recovery phrase is the wallet. Anyone with it has full, irreversible control.
- Never type it into a website, app, or form. No legitimate support process ever asks for it. Not for verification, not for migration, not for a refund.
- Store it offline — written on paper or stamped into metal, kept somewhere fireproof.
- Never photograph it, never store it in cloud notes, never email it to yourself, never put it in a password manager that syncs.
- Consider splitting storage across two secure locations so a single event cannot expose or destroy it.
- If a phrase has ever touched an internet-connected device, generate a new wallet and move the assets.
Wallets
- Use a hardware wallet for anything you would be materially hurt to lose. It keeps keys off the computer entirely.
- Keep a separate "hot" wallet with small balances for interacting with new sites, and never connect the main wallet to an unfamiliar dApp.
- Read every signature request.
setApprovalForAlland unlimited allowances grant ongoing spending rights, not a one-off transfer. - Review and revoke stale approvals every few months.
- Verify the destination address in full on the hardware device's own screen — clipboard-hijacking malware swaps addresses at the moment of paste.
- Send a small test transaction first when using a new address.
Exchange accounts
- Enable app-based or hardware two-factor authentication. Avoid SMS: SIM-swap attacks defeat it, and they are not rare.
- Use a unique password per exchange, generated and stored in a reputable password manager.
- Turn on withdrawal address allowlisting where offered, with the cool-down period enabled.
- Enable withdrawal confirmation emails and read them.
- Do not keep long-term holdings on an exchange you are not actively trading on.
The identity layer
Your email account is the master key to everything else. Protect it first.
- Hardware security key or authenticator app on the primary email account.
- A separate email address used only for financial accounts, never posted publicly.
- A PIN or port-freeze on your mobile number with your carrier, to blunt SIM-swap attacks.
- Regular review of connected apps and OAuth grants on your email and exchange accounts.
Devices
- Keep the operating system and browser current; most drive-by compromises target known, patched flaws.
- Install browser extensions sparingly and review their permissions — a malicious extension can read and alter every page.
- Never install remote-access software at the request of someone who contacted you.
- Avoid conducting wallet operations on public Wi-Fi without a trusted VPN.
- Consider a dedicated device, kept clean, for high-value transactions.
Habits that prevent most incidents
- Bookmark the real URLs for your exchanges and wallets, and use only those bookmarks. Search-engine ads regularly serve phishing clones above genuine results.
- Verify contact independently. If "support" contacts you, close the message and reach support through the official site. Legitimate support does not initiate contact about your funds.
- Treat urgency as a warning, not a reason to hurry. Any message engineering panic deserves more scrutiny, not less.
- Say nothing publicly about holdings. Visible wealth attracts targeted approaches.
- Assume unsolicited is hostile — airdrops, DMs, job offers, investment tips.
Household and family
Fraud frequently reaches people through someone close to them. Agree in advance, with anyone who shares your finances, that no transfer request received by message will ever be actioned without a phone call to a number already in the contacts list. That single rule defeats a large class of impersonation fraud.
This guide is general information, not advice on your specific case
Every case turns on its own facts. If you have been defrauded, submit a report for a free assessment, and report the matter to your national fraud authority as well.
Been targeted by something like this?
Submit your case for a free assessment. If recovery is unlikely, we will say so.
