Blockchain Security Best Practices: Protect Your Crypto Assets
Best practices for blockchain security

The best practices for blockchain security start with self-custody: keep your private keys offline in a hardware wallet, store your seed phrase physically in multiple secure locations, and layer on protections like a passphrase, strong 2FA, and phishing awareness. Users emphasize that controlling your own private keys matters most, and that security needs to go beyond software protections alone.
Device and account hygiene is the second pillar. Use a separate, clean machine for crypto activity, such as an air-gapped computer or a USB booted into Tails OS, so malware never touches your transactions. Turn on two-factor authentication everywhere, preferring authenticator apps over SMS because SMS is vulnerable to SIM-swapping attacks, and always double-check URLs before entering anything sensitive.
Maintenance keeps the whole setup reliable over time. Monitor your cold storage addresses so you get an early warning if unexpected activity hits the blockchain, and test wallet access once or twice a year while performing updates and verifying backups. Keep the system simple and redundant: losing one thing should never compromise everything.
Security checklist
- Hardware wallet cold storage Keeps your private key offline on secure hardware, making it far harder for hackers to reach.
- Offline seed phrase backups Written by hand on paper or engraved on metal, with copies kept in separate secure locations.
- Passphrase with a decoy wallet Leave small funds in the seed-only wallet and the rest in the passphrase-protected wallet.
- Dedicated secure device Use an air-gapped computer or boot Tails OS from a USB for all crypto activities.
- Authenticator app 2FA Enable 2FA on all crypto accounts with an authenticator app rather than SMS.
- Phishing vigilance Double-check URLs, avoid suspicious messages, and never click random airdrop links.
- Address monitoring Watch cold storage addresses and get notified if unexpected activity hits the blockchain.
- Periodic security reviews Test wallet access once or twice a year, perform updates, and verify backups.

Secure Your Wallet and Seed Phrase
Protect Your Devices and Online Activity
Ongoing Monitoring and Best Practices
Are you interested in learning more about specific hardware wallets or secure backup methods?
Bottom line
Prioritize self-custody with hardware wallets and secure offline storage of seed phrases to protect blockchain assets. Users emphasize the importance of controlling your private keys and implementing robust security measures beyond just software protections.
Community answers 25
What others in the community said:
Background: I currently work for a fortune 100 company's Computer Security Incident Response Team, I work specifically on detect and response which includes business email compromises, responding to phishing emails and malware within the organization, while documenting the process.
My last post on securing accounts got a lot of attention, and there was also a lot of feedback and recommendations to add and consider. After that post I set out to make the most complete guide yet on securing your account and listing the resources needed.
Email:
- Email Providers
- Any reputable email provider with 2FA will do
- If you want to get more into privacy and encrypting emails there is Protonmail or Preveil
- You can alternatively also hook up your current email with the Thunderbird email client (use to be managed by Mozilla Firefox) it is overseen by a volunteer board of contributors.
- 2FA - This is important, activating 2FA on your email is just as important as having it on exchanges. (Will cover more on 2FA further down)
- Create an email specifically for Crypto, but also avoid using crypto keywords / personal information in the email, treat your email address like its public information.
- Be on the lookout for Phishing emails, I made a post on how to identify phishing emails along with some useful tools here | How to spot a phishing email |
- Quick tips for emails:
- Don't trust email links
- Double check the address bar of login pages
- Know the levels of a domain
- Check to see if your crypto sites allow a anti-phish banner that displays a code with their emails that you set.
- Quick tips for emails:
- Tracking pixels are also a thing, there not malicious in themselves, but they can potentially let attackers know if you have open an email / let them know the email exist and is active.
- Furthermore You can check haveibeenpwned to see what data breaches your email has been apart of - If your email shows up and passwords are listed on the data that was compromised, ASSUME the worse and change the password and never use it again, along with any other accounts that use that password.
Passwords / PINs:
- Don't reuse them EVER
- Use strong secure passwords, passwords managers make these easy to manage and generate passwords.
- This includes your phone and 2FA app, if you have a weak pin (1234) for your phone and someone takes it, remember your 2FA app is then available (if same pin, or no pin/pass set), your email is automatically signed in (same for other accounts auto signed-in), and they can access your text messages.
- Don't use words relating to crypto or personal information in your passwords (or email), if they are compromised in a breach, assume they will search for these terms to target crypto users and try the same combo against crypto sites or figure who you based on the information (email & password) and pivot to finding public information that could lead to them answering challenge questions for password resets. (Your first pet, is it posted on Facebook? How about your car? Your first girlfriend/boyfriend?)
- Password Managers: These work wonders when managing passwords securely. They generate random strong passwords which can be adjusted, and its all kept in an encrypted database file, so even if a attacker gets access to it, they won't be able to access it without the password.
- Password Managers trusted by the community:
- KeePass
- BitWarden
- LastPass
- 1Password
- Password Managers trusted by the community:
- Don't save passwords in your browser
- Does it require verification for you to use the password? Also I tend to find extensions being more buggy as they have to interact with more 'moving' parts and changing configurations, and generally more people try to target and exploit browsers.
2 Factor Authentications (2FA):
- Enable on everything possible (Email, Exchanges, Banks, Robinhood, even Users to protect your moons)
- Use 2FA Apps instead of SMS whenever possible, SIM Swap attacks are real, and more common than you think.
- 2FA Apps
- Authy (Linux | Windows | macOS | Iphone | Android)
- Google Authenticator (iOS | Android)
- Microsoft Authenticator ( iOS | Android)
- LastPass Authenticator (Browser Extension | iOS | Android | Windows Phone)
- 2FA Apps
- Hardware Keys
- These are physical 2FA device (I chose this list as I think it does a good job explaining them with pros and cons, I did NOT vet the sellers that are listed on the amazon links. Always research and buy from a reliable source)
- Backup codes:
- When you activate 2FA on any account you should have the ability to generate backup codes, these are used incase you lose access to your authenticator, TREAT these like your seed phrases. Use them by logging in with your user and pass, and use these backup codes in place of the 2FA code you usually enter.
- DO NOT take pictures of your QR codes, if you screenshot it, might end up syncing somewhere you don't want it to and if it ever gets compromised they have the ability to continually receive your 2FA code.
- Also, DO NOT sign up for your 2FA app or any crypto service for that matter using your work or school email address. You lose access to that email, then consider all accounts gone as you won't be able to access the codes if you switch devices.
Wallets
- Learn the difference between the different wallets, I think this article is REALLY good at going in depth about the differences and pros vs cons of them at a beginner level.
- Cold wallets will always be more secure than any hot wallets as they aren't connected to the internet
- Top trusted hardware wallets from the community:
- Ledger
- Trezor
- Top trusted hardware wallets from the community:
- Verify the details you are confirming on your hardware wallet device. the wallet app interacting with your cold wallet device could be compromised, but you would still be safe using it, as long as you verify each action on the cold wallet device, and reject the transaction if anything seems off. (Thanks keeri)
Seed Phrases: Treat these as they are the keys to the kingdom (Keep offline and out of your notes app)
Less Secure:
- Write down on paper and either break up the phrase and place in separate secure locations or hide them like the the FBI is going to come search your house
- Secure on USB
- Get a file shredder (securely deletes data, and overwrites it)
- Download password manager (optional)
- Disconnect device from internet
- Enter seed phrase into password manager / create encrypted file
- Put on a freshly reformatted USB / datalocker (Worms like to spread by USB)
- Save to USB, and shred the original using the file shredder software
- Hide USB
- Another device / old phone
- Factory reset
- Set Pin / Pass
- Download 2FA app and password manager / file encryption tool
- Disconnect from internet FOR GOOD (Treat this like a cold wallet)
- Back up 2FA and seed phrases
- Hide device
More secure (more expensive):
- BlockPlate
- CryptoSteel
- Have a copy saved in a safety deposit box / split between two banks.
NOTE: Each method is going to its pros and cons: Getting robbed, fading ink, the elements, data retention (USB ~10 years), ever being on a digital machine. Pick which ones benefits you the most, and correlates with your budget and what your willing to risk.
VPNs / TOR:
- Privacy vs Anonymity
- Privacy is the ability to keep your data and information about yourself exclusive to you (They know who you are, but not what you do).
- Anonymity is about hiding and concealing your identity, but not your actions. (They know what you do, but not who you are)
- Think about what your goal is, I commonly associate privacy with VPN and anonymity with TOR
- Both encrypt your data before leaving your device, then routes it through proxy servers to mask your IP/Location. VPNs you have to trust the provider (ensure they state there is a no log policy) while TOR runs through servers ran by volunteers (don't think governments don't run their own) and lets you access the dark web. Here is a more in-depth comparison on VPN vs TOR.
- Personally Its worth paying the few bucks a month for a paid tier of the VPN service.
- VPN Providers - Zero log VPN services:
- ProtonVPN
- Nord
- Mullvad
- TOR
- Brave offers TOR, but I would treat this more like a VPN
- If being anonymous is your goal the only real way to achieve this is running Tails off a USB.
NOTE: Some exchanges and websites blacklist IP ranges associated with VPN and most commonly TOR for security reasons. Some people on this community stated that this can lead to them freezing your account.
Browsers (Excluding TOR):
- Top 3 Browsers built for privacy
- Firefox
- Epic
- Brave (I know Brave draws criticism but I made a technical post showing how the trackers didn't show up within the metamask extension through brave compared to Google Chrome.)
- Learn to harden your browser to make it even more secure
- Search Engine for privacy: DuckDuckGo
- Extensions
- One of the most dangerous threats I think that aren't taken seriously are extensions. These can start out legitimate, then through an update turn malicious. These will then be removed from the webstore, but not your browser.
- Some will be removed the store due to not being supported anymore which = no more updates, and no more updates = vulnerabilities that won't be fixed
- If you have Google Sync activated, these extensions will also sync to all those devices
- Remove any extensions you don't need, check to see there still available on the store, and even search them to see if some security article like this pops up about it.
- Check the privacy practice tab of the extension to see what data it collects.
- One of the most dangerous threats I think that aren't taken seriously are extensions. These can start out legitimate, then through an update turn malicious. These will then be removed from the webstore, but not your browser.
Checking and verifying hashes of a download:
Hashes are the fingerprint of a file, even if you change the name of the file the hash will be the same. This is similar to how wallets work, its a string of characters and numbers, yet represents data (aka your holdings)
- How to get hash:
- Go to the search bar in windows and enter ‘cmd’ this should bring up the command prompt (open terminal on Linux / MAC)
- type “Certutil -hashfile Desktop\example.txt sha256” for windows
- type "Sha256sum Desktop\example.txt" for Linux
- type “shasum -a 256 Desktop\example.txt” for MAC
- (Remove quotes, and replace 'Desktop\example.txt" with the path to the file you want to check)
- Go to the search bar in windows and enter ‘cmd’ this should bring up the command prompt (open terminal on Linux / MAC)
- this should give you the sha256 hash you can copy and paste into VirusTotal to check to see if its known as malicious by many security vendors. Here is the hash and VirusTotal link for the shredder download I previously mentioned in the seed back up step. 72714927de74b97c524c5fa8bc1a0dec83f038dbbed80b93b5e6280ca1317f41/detection
NOTE: You can also just submit the file to VirusTotal, but if it potentially contains personal information, it will upload the file and allow other people to download it, searching the hash will not do this.
Other General Safety Tips:
- Harden your PC (Guide is for Windows 10, but can translate to other OS)
- Update OS and any software // turn on automatic updates - Everything you download is an attack vector
- Set firewall rules - Default deny, open only p855orts you need, disable rules you don't need
- disable remote access
- Install AV // Malwarebytes for removing malware
- Turn on encryption
- Setup user accounts // privileges'
- Strong password
- Whitelist addresses if possible (Some exchanges allow you to designate a address as 'safe' any other transactions besides those won't go through)
- If you use a encrypted messaging service, I highly recommend Signal, if you haven't seen their reply regarding a subpoena you should
- Lock down your social media accounts (go to security settings, turn off being able to be found via search engine, ad related settings, change who can view your posts, etc)
- Don't disclose your holdings and earnings
- Don't access your crypto on your work computer
- Don't answer PMs about winning some contest or some amazing opportunity
Phone:
Many users asked about security regarding people who mainly use their phones. Many of these tips can translate to phones as well, but here's a quick rundown.
- Unique pin / password for the phone
- download a password manager
- email account purely for crypto
- pin / password (different than getting into your phone) for your 2FA app.
- Don't lend phone out
- Avoid apps you don't need, read the 3 star reviews as they are the most honest)
- Download VPN / be aware of the wifi your connecting to
- Be aware of phishing
- Call your service provider and see if they can lock your SIM card and prevent SIM swapping.
NOTE: These are still just suggestions, these are methods that balance security and usability. One could use 2 password managers and split a password between both, but that would compromise usability / ease of use.
The ‘Bitcoin Security Consortium’ includes BlackRock….That’s all we need to know.
I am about to move for work and I was wondering how were safely transporting seed phrases? I have to move through EU and US customs.
I have multiple paper copies, unfortunately now in a single location now due to getting ready for this move. I cannot ship locked cases and high value items need to be reported to the shipper. Because of that I don't feel confident hiding a copy somewhere random in my shipment. I'd also like to move with my Trezors but I think that would heighten awareness? My important bag does have a passphrase but my others do not.
Taking any ideas for anyone who's been through something like this. Thanks.
I’m trying to understand the best ways to protect a Bitcoin wallet.
Some obvious techniques include: Backing up your seed phrase in multiple locations. Split the phrase and avoid storing all copies in the same place.
But what do experienced users do to feel confident their Bitcoin is safe? 1. Is the only sign of compromise is if funds are moved unexpectedly? No way to know someone "logged in" or "tried to login" to your wallet? 2. If I suspect something, the only way to secure my Bitcoin is moving everything to another wallet?
I’m not really into day trading or chasing quick profits. My plan is simple: buy crypto I believe in and hold it for the long term. Because of that, I want to make sure I’m doing things the right way from the start.
I often hear advice like “not your keys, not your coins,” but I’m still figuring out how far to take that. For long-term holding, is it better to move funds off exchanges into a wallet right away, or is it okay to keep some on a trusted exchange? I’m also curious about how people store their recovery phrases safely without risking loss or theft.
Another thing I wonder about is how often you actually check your holdings. Do you set things up and forget about them for months, or do you check in regularly just to make sure everything is secure? I don’t want to stress over prices every day, but I also don’t want to ignore things completely.
If you’ve been holding crypto long term, I’d really appreciate hearing what habits worked well for you and what you’d do differently if you were starting again.
In the past, I have gone as far as wiping and rebooting my computer before executing any transactions, even if I am using a hardware wallet.
I'm guessing that is being a bit too paranoid, but it is the only way I feel confident that my computer is clean.
I'm also terrified of using browser extentions like Metamask and worry about about losing crypto due to approving smart contracts (though I don't think I've ever approved one).
I've read a good bit about best practices for keeping crypto safe, but I haven't seen as much info about making sure the devices I'm using are secure.
Any words of wisdom?
Edit: Hard to keep up with all the comments below... I'm always impressed by this community!
This is a normal progression in security -
1) better education in security best practices -
2) Hardware wallet
3) Hardware wallet + metal backup seed
4) Hardware wallet + metal backup seed + extended passphrase
5) Hardware wallet + metal backup seed + extended passphrase and pairing your hardware wallet to your own bitcoin full node (example - sparrow with core backend)
6) More complicated security once you own millions of dollars in Bitcoin like multisig or SSS
Move to each higher level when you are ready
- Is the only sign of compromise is if funds are moved unexpectedly? No way to know someone "logged in" or "tried to login" to your wallet? 2. If I suspect something, the only way to secure my Bitcoin is moving everything to another wallet?
Using an extended passphrase can help here because you have a decoy balance secured by the pin of your hardware wallet or the seed words which acts as a honeypot. Thus if that balance moves you know one person found your seed words or has your hardware wallet and pin and most your savings is secure with an extended passphrase where you can investigate and move your account over to a new set of seed words(and extended passphrase) at your leisure with no panic of someone being able to take most your Bitcoin
Hi all
Given the current focus on AI review of wallet generators both hardware and software, by both white hats and criminals, I wondered what people are doing to monitor developments.
I myself don't visit this sub often or pay close attention to the news.
My holdings are stored in multiple addresses (not all eggs in same basket), and the private keys are never entered on anything but an airgapped computer creating transaction manually and saving on a usb stick to publish to blockchain network.
I've had a solution to monitor my cold storage BTC addresses and notify me if anything mentioning them hits the blockchain for years now. Too late for that address but at least I can then consider the remaining holdings unsafe and move them promptly.
I've created some google alerts to tell me if anything potentially relevant regarding vulnerabilities and the like is published.
As this is a particularly active period for these issues, what are others doing?
Have a crypto only computer, or learn about a virtual machine it’s a virtual computer inside of your normal pc, that you can isolate and keep separate, disable and don’t click links on it etc.
After you are done using it you can disconnect the virtual machine internet, shut it down etc and it will have no access to the internet.
Or I have a friend who uses his old phone as crypto wallet, after he stakes or does a smart contract, he goes in the settings and disables all connections or shuts it down. It’s kind of like a hot/cold storage, he only has a small amount so it wasn’t worth the hard wallet yet.
But a cheap old physical laptop will work as a crypto only pc. Also remember to really secure it you can have bios password and hard drive password and don't connect it to wifi, uses a physical cable.
But you have to remember drives do get corrupted or go bad so backup your crypto files or clone the drive. And there's not much redundancy in having your backup in the same location as your PC.
In the IT world we like to have redundancy and it's not really a backup unless you have a few backups, in different media forms, in different locations, and you've tested the restore. Pretend you lost that PC and try to restore you crpyto.
1.Holding your coins on an exchange is the least secure. Not your keys not your coins
1.1.Do not store your seed phrase on anything electronic. Preferable store it on a metal plate.
Read about the safest metal seed storages here:
2.Software wallet. More secure than 1. but your private key is stored on your phone/pc etc.
3.Hardware wallet. The most secure way to store your coins. Your private key is stored safely on secure hardware.
4.F2A is a must have as it is additional layer of defense against hackers.
5.SMS F2A is the least secure because of recent increase of sim swapping attacks
6.Authenticator F2A like Google Authenticator are the most secure.
If you back up your seed phrase onto anything besides a steel plate, you're a moron.
1 Generally speaking, yes. From the PoV of the blockchain, which is how you see what's happening, there is no such thing as "logging in to a wallet."
2 Correct.
ledger breach wasn't so bad unless you're vulnerable to phishing and scams. scams are easy to detect with a little bit of knowledge, like for instance NEVER give your mnemonic phrase or private keys or passwords or logins to ANYONE, no matter who they claim to be. if you're worried about the people knowing you own bitcoin, then you should never spend your bitcoin anywhere online unless you can do it anonymously. so ledger's breach isn't special in that regard.
your data is safe with nobody, whether or not you have heard about a breach. there are 2 kinds of companies: those who have been hacked; and those who WILL be hacked.
primary phone is fine if you're using either a hardware wallet or a 2fa from another physical device. primary phone is also fine without either of those things if you're just storing what you consider a small amount. a phone is more secure than a desktop computer.
If using a hardwallet, you shouldn't directly connect it to your computer. For example, if you have a cold card, you should only insert the sd card to your computer for transactions. The safest method is always to avoid direct connection to your internet connected PC.
2FA on a reboot old cellphone with no internet connection.
Not what you asked but thats what u want
Seems like a good idea. Are you saying you get an alert as soon as a transaction for one of those addresses hits the mempool? I wouldn’t want to wait for google crawlers to find your address.
The address monitor is useful as an incident alarm, but it's downstream: it tells you after a key was used. I'd pair your Google alerts with a written migration trigger for the exact generator/version you used. For example: a confirmed RNG or key-extraction flaw affecting that implementation means generate fresh keys elsewhere and sweep; an unverified claim means wait and investigate. The hard part is deciding in advance which alert justifies touching cold storage. Also, if those multiple addresses came from the same seed or generator, they aren't separate security baskets.
So, I know Im late, but just learning more about the ledger breach and why its so bad even if the wallets themselves are fine.
Learning I should get off my primary phone and my primary email and Im wondering what are some other good security practices to avoid such things and if someone can or know of some place that can explain these things at a ELI5 level. Like Im still trying to wrap my head around sim hacks.
I find it interesting and would like to implement myself. Can you explain in more detail how you monitor and what code?
Replies (0)
No replies yet. Be the first to reply.