
Most crypto losses aren’t from hacks—they’re from users skipping basic steps. In 2026, wallet security isn’t about paranoia. It’s about building habits that take 30 seconds and save you years of regret.
This checklist covers self-custody wallets (MetaMask, hardware wallets) and custodial platforms (MuseWallet, exchanges). Pick what’s relevant to your setup.
1. The Foundation: Your Recovery Phrase
What to Do
- Write it down on paper or metal plate. Never store digitally (photos, cloud, password managers).
- Make 2+ copies stored in separate physical locations (home + bank safe deposit box + trusted family).
- Test recovery once after setup. Delete the wallet, restore from phrase, confirm balance shows.
- Never share it. Support teams, “airdrop validators,” and YouTube tutorials asking for it are scams.
What Not to Do
- ❌ Screenshot your phrase
- ❌ Email it to yourself
- ❌ Store in Google Drive, iCloud, or any cloud service
- ❌ Split into parts and store digitally (defeats the purpose)
Reality check: If someone gets your 12 words, they get everything. No bank to call. No refunds.
2. Device & Access Security
For All Wallets
- Use a dedicated device for large transactions (old phone, fresh OS, no social apps).
- Enable biometric lock (Face ID / fingerprint) on wallet apps.
- Set auto-lock to 1 minute or less.
- Never install wallet apps from unofficial sources. Verify APK signatures on Android.
- Keep OS and apps updated. Security patches matter.
For Desktop/MetaMask Users
- Use a separate browser profile for crypto (no extensions except wallet).
- Remove unnecessary extensions. Fake PDF viewers and grammar tools have stolen millions.
- Bookmark official sites. Never Google “OpenSea” or “Uniswap”—phishing ads rank first.
- Enable hardware wallet integration (Ledger/Trezor) for any amount >$1,000.
3. Transaction Safety
Before Every Transaction
- Verify the address character by character. Malware replaces clipboard addresses.
- Check the network. Sending ERC-20 to TRC-20 = permanent loss.
- Start with a test amount. $10 first, then the rest.
- Read the transaction data. “Unlimited token approval” = they can drain your wallet.
Smart Contract Interactions
- Use revoke.cash monthly to check and remove old token approvals.
- Approve minimum amounts, not “unlimited.” Takes 10 seconds more, saves your stack.
- Verify contract addresses on Etherscan/BscScan. Fake Uniswap contracts are common.
4. Custodial Platform Security (MuseWallet, Exchanges)
Account Protection
- Enable 2FA on everything. App-based (Google Authenticator/Authy), not SMS.
- Use unique passwords. Password manager (Bitwarden, 1Password) is non-negotiable.
- Set withdrawal whitelist. Only pre-approved addresses can receive funds.
- Enable login notifications. Email + push for every new device/location.
- Set spending limits. Daily caps prevent total drain if compromised.
Platform Selection
- Verify licenses. VASP, EMI, MSB registrations should be publicly verifiable.
- Check insurance/ protection funds. What happens if the platform is breached?
- Review audit history. Has the platform published security audits?
- Test support responsiveness. Send a ticket before depositing large amounts.
5. Social Engineering Defense
Common Scams in 2026
| Scam Type | How It Works | Defense |
|---|---|---|
| Fake support | DM claiming “your wallet is compromised” | No legit support DMs first. Ignore. |
| Airdrop phishing | Free tokens requiring “wallet verification” | Real airdrops don’t need your phrase. |
| Fake apps | Cloned wallets in app stores | Only download from official sites. |
| Romance scams | “Help me invest” after 2 weeks chatting | No. Just no. |
| Job scams | “Payment processor” using your wallet | Legit jobs don’t need your crypto. |
| Clipboard malware | Replaces your pasted address | Verify last 4 characters every time. |
Communication Rules
- Never discuss holdings publicly (Twitter, Discord, Telegram).
- Never share screenshots with balances or addresses visible.
- Never click links in crypto DMs, even from “friends” (accounts get hijacked).
- Verify identities via secondary channel before large transfers.
6. Backup & Recovery Testing
Quarterly Routine (15 minutes)
- Check recovery phrase storage. Paper degraded? Metal plate rusted?
- Test restore on spare device. Confirm phrase still works.
- Update emergency contacts. Who knows where your backups are if something happens to you?
- Review active approvals on revoke.cash.
- Check platform health. Any news about your custodial platform?
Annual Routine (1 hour)
- Rotate passwords on exchanges and email.
- Verify 2FA backups. Save recovery codes for Google Authenticator.
- Update hardware wallet firmware.
- Review and prune old wallets, unused accounts, stale API keys.
7. Hardware Wallet Best Practices
Setup
- Buy directly from manufacturer. Amazon resellers have sold tampered devices.
- Verify packaging integrity. Holographic seals, no signs of opening.
- Initialize yourself. Never use a “pre-configured” device.
- Set a strong PIN. Not 1234, not your birthday.
- Write passphrase (25th word) separately if using advanced security.
Usage
- Connect only when signing. Unplug after transaction.
- Verify on device screen. Malware can show fake confirmations on your computer.
- Use passphrase for large holdings. Hidden wallet = plausible deniability.
8. Emergency Response Plan
If You Suspect Compromise
- Immediately transfer funds to a new, clean wallet (hardware wallet preferred).
- Revoke all token approvals via revoke.cash.
- Change passwords on all platforms.
- Check transaction history for unauthorized activity.
- Document everything for potential law enforcement report.
If You Lose Access
- Lost phrase, no backup: Funds are permanently inaccessible. Accept and move on.
- Lost phrase, has backup: Retrieve backup, restore wallet, verify balance.
- Forgotten PIN (hardware): Reset device, restore from phrase. Funds safe.
- Platform frozen account: Contact support with KYC documents. Be patient.
9. Security Level: Choose Your Paranoia
| Level | Setup | Best For |
|---|---|---|
| Basic | Strong password + 2FA + written phrase | <$1,000 holdings, casual users |
| Standard | Hardware wallet + dedicated device + quarterly checks | $1k–$50k, regular users |
| Advanced | Multi-sig + passphrase + geographic backup distribution | $50k+, long-term holders |
| Maximum | Air-gapped signing + Shamir backup + legal entity holding | $500k+, institutional |
Most users should aim for Standard. The cost ($100 hardware wallet + 2 hours setup) is trivial compared to potential loss.
10. Final Reminder: Security Is a Habit, Not a Product
No app, no hardware, no insurance replaces good habits:
- Slow down. Scammers exploit urgency.
- Verify everything. Addresses, URLs, identities.
- Assume compromise. What happens if this device is stolen?
- Test recovery. A backup you can’t use isn’t a backup.
The 30 seconds you spend double-checking an address beats the 30 days you’ll spend trying to recover stolen funds.