The Golden Rule: You Are Your Own Bank
In traditional banking, if you forget your password, you can reset it. If someone steals your credit card, the bank can reverse the charges. With Ethereum, there's no customer service to call.
You control your crypto with a private key or seed phrase (12-24 words). Anyone with these words controls your funds. If you lose them, your crypto is gone forever. If someone steals them, your crypto is gone forever.
This isn't meant to scare you, it's meant to help you take security seriously from day one. Follow these guidelines and you'll be fine.
Hot Wallets vs. Cold Wallets
Not all wallets carry the same risk. A hot wallet (like MetaMask or Coinbase Wallet) stays connected to the internet, making it convenient for everyday transactions but more exposed to phishing sites, malware, and browser exploits. A cold wallet (like a Ledger or Trezor hardware device) stores your private key completely offline, only connecting briefly when you actually sign a transaction.
A simple rule most experienced holders follow: keep small, spendable amounts in a hot wallet for daily use, and move anything you'd genuinely hate to lose into cold storage. Treat your hot wallet like the cash in your pocket, and your cold wallet like a safe deposit box.
Common Scams to Watch For
Most crypto theft doesn't come from some genius hacker cracking your encryption. It comes from someone simply tricking you into handing over access. Here are the patterns that show up again and again:
Phishing sites. A fake website that looks identical to a real exchange or wallet interface, designed purely to capture your seed phrase or private key the moment you type it in. Always double check the URL before connecting a wallet, and bookmark the sites you use often instead of clicking links from search results or social media.
Fake support accounts. Scammers impersonate customer support on Discord, Telegram, or X, reaching out first and offering to "help" with a wallet issue. No legitimate support team will ever ask for your seed phrase. Ever. Full stop.
Malicious smart contract approvals. Some scam dApps ask you to "approve" a token permission that quietly grants unlimited access to drain a specific token from your wallet later. Always read what you're approving, and periodically review and revoke old permissions using a tool like Etherscan's token approval checker.
Too-good-to-be-true giveaways. "Send 1 ETH, get 2 ETH back" has drained wallets for years and somehow still works on new users. If it sounds like free money, it's not.
A Basic Security Checklist
Write your seed phrase on paper, never store it as a screenshot, text file, or cloud note. Use a hardware wallet for anything beyond spending money. Enable two-factor authentication on every exchange account, using an authenticator app rather than SMS. Never share your seed phrase with anyone, no matter how official they sound. Double check every URL before connecting a wallet. Revoke old token approvals periodically. And when something feels rushed or urgent, that's usually the scam working exactly as intended, slow down before you click anything.
Explore These Topics
Want to go deeper on staying safe? Start with any of the guides below.
Blockchain Explained: Ethereum Crypto Scams and the Wild West of Web3
A closer look at how crypto scams actually work.
Can Quantum Computers Break Ethereum?
What the real quantum computing timeline looks like.
Account Abstraction Explained
How social recovery could make wallet loss less permanent.