Securing a crypto account isn't a single action—it's a layered process that combines device hygiene, credential management, and behavioral discipline. This checklist walks you through the essential steps to reduce your attack surface, from enabling two-factor authentication to verifying withdrawal addresses. Use it as a recurring audit, not a one-time setup.
1. Fortify Your Login Credentials
Your first line of defense is the strength and uniqueness of your passwords and recovery phrases. Weak or reused credentials are the leading cause of account compromise.
Password and Passphrase Hygiene
- Use a unique, randomly generated password for every exchange, wallet, and email account. A password manager is non-negotiable here.
- For your primary crypto email (the one linked to withdrawals), enable a separate, long passphrase—at least 16 characters—that you never reuse elsewhere.
- Never store passwords in browser autofill or in plain-text notes on your phone or computer.
Recovery Phrase Protection
- Your 12 or 24-word seed phrase is the master key to your funds. Never enter it into any website, app, or pop-up, even if it looks official.
- Write it on a metal or fireproof backup and store it in a physical safe. Avoid photographing or scanning it.
- If you use a hardware wallet like Ledger, treat the device PIN as a secondary secret—never share it with anyone, including "support" staff.
2. Enable and Layer Two-Factor Authentication
Passwords can be phished; a hardware security key or authenticator app cannot. This is the single highest-impact upgrade you can make.
Choose the Right 2FA Method
- Prefer hardware security keys (FIDO2/WebAuthn) over SMS or authenticator apps for your email and exchange accounts. They resist phishing and man-in-the-middle attacks.
- If hardware keys aren't available, use an authenticator app (like Google Authenticator or Authy) with a backup code stored offline. Never use SMS-only 2FA for financial accounts.
- For your Ledger device, the PIN itself acts as a form of 2FA—but pair it with a strong device passphrase (BIP39) for an extra layer of obfuscation.
Backup Codes and Recovery
- Store 2FA backup codes in a password manager or printed copy in your safe. Losing access to your authenticator app without codes can lock you out permanently.
- Review which accounts have 2FA enabled quarterly. Many exchanges allow you to disable it after a security review—don't let that lapse.
3. Segment Your Accounts and Devices
Don't put all your eggs in one basket. A single compromised device or email can cascade into total loss.
Email Segmentation
- Use a dedicated email address solely for crypto exchanges and wallet registrations. Keep it separate from your personal or work email.
- Enable login alerts and 2FA on that email first—it's the recovery vector for every other account.
Device Isolation
- Use a dedicated browser profile or even a separate device (like an old phone or laptop) exclusively for crypto transactions. This limits exposure to malware from casual browsing.
- Never install unknown browser extensions or mobile apps on the device that holds your 2FA codes or hardware wallet software.
4. Verify Withdrawal and Address Integrity
Many hacks succeed not by stealing your password, but by tricking you into sending funds to the wrong address.
Address Whitelisting and Verification
- On exchanges, enable address whitelisting (allowlisting) so withdrawals only go to pre-approved addresses. This blocks most malware that swaps clipboard addresses.
- Before every large transaction, verify the full address on the device itself—not just the first and last few characters. Compare it against a previously saved copy.
Transaction Signing Habits
- On a Ledger, always confirm the amount and address on the device's physical screen before pressing "approve." If the screen shows a different address than your computer, stop immediately.
- Avoid signing transactions while on public Wi-Fi or a VPN you don't control. Use a trusted, wired connection for high-value moves.
5. Conduct a Monthly Security Audit
Security is a moving target. A monthly 15-minute review catches drift before it becomes a breach.
Checklist for Your Audit
- Review active sessions on all exchanges and wallets. Log out of any device you don't recognize.
- Confirm that your 2FA methods are still active and that backup codes are accessible.
- Update your Ledger firmware and any wallet software to the latest version—patches often fix critical vulnerabilities.
- Search your name or email on a breach notification service to see if any linked accounts have been exposed.
Incident Response Prep
- Write down a step-by-step plan: which account to freeze first (email, then exchange), how to contact support, and where your hardware wallet is stored in an emergency.
- Keep a small "emergency kit" with printed backup codes and a list of your exchange support URLs—avoid clicking links from emails during a crisis.
Quick Reference: The 12-Point Checklist
| Category |
Action |
| Passwords |
Unique, random, manager-stored |
| Recovery phrase |
Offline, metal backup, never typed |
| 2FA |
Hardware key or authenticator app |
| Backup codes |
Printed and stored in a safe |
| Email |
Dedicated crypto-only address |
| Device |
Isolated browser or dedicated device |
| Address whitelist |
Enabled on all exchanges |
| Transaction review |
Confirm on hardware screen |
| Firmware |
Updated monthly |
| Sessions |
Cleared and reviewed |
| Breach alerts |
Monitored for linked accounts |
| Incident plan |
Written and tested |
Run this checklist quarterly, not just once. The crypto landscape changes fast—your security posture should evolve with it. When in doubt, prioritize the hardware wallet and the 2FA method you can physically control.