Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileself-custody failures

Building a Personal Security Checklist

Everything on this site, reduced to a list you can work through in an evening and review annually.

Priya Raman · 2 min read

Eighteen months of writing up losses, reduced to the actions that would have prevented them.

Accounts

  • Two-factor set to an authenticator application or a hardware key, not SMS
  • Phone number removed as a recovery option where possible
  • Carrier port-out PIN enabled
  • Withdrawal address allowlist enabled, with a delay on additions
  • Dedicated email address for financial accounts, not published, protected by a hardware key
  • Active sessions reviewed, unused ones revoked
  • API keys reviewed, anything with trading or withdrawal permission removed

Wallets

  • Long-term holdings on a hardware wallet bought from the manufacturer
  • Recovery phrase written by hand, verified word by word
  • Restore tested before funding, confirming the address matches
  • First receiving address recorded alongside the phrase
  • Whether a passphrase exists documented, separately from the phrase
  • Backup stored away from the device, ideally in two locations
  • Separate wallet for connecting to websites, holding a small balance
  • Long-term wallet has never connected to any site

Approvals

  • Token approvals reviewed on a block explorer
  • Unlimited approvals revoked where not actively needed
  • Monthly reminder set for the review

Browser and device

  • Extensions audited, unused ones removed
  • Separate browser profile for crypto, with only the wallet extension
  • Wallet with transaction simulation, enabled

Habits

  • Address book entries used, never copying from transaction history
  • Test transaction sent before every large transfer
  • Addresses verified on the hardware wallet screen, checking the middle characters
  • Sites reached by typing the address or a personal bookmark, never a search result or a link
  • Unsolicited contact treated as fraudulent, without exception
  • Recovery phrase never typed anywhere except into a wallet you opened yourself

Documentation

  • Inheritance note written: what exists, where the backup is, step-by-step instructions
  • A named person who understands it and has walked through the first steps
  • Transaction records kept at the time, with local currency values

Annual review

  • Restore test repeated
  • Backup legibility checked, ink fades
  • Inheritance note still accurate
  • Venue fee schedule and security options rechecked

The five that matter most

If you do nothing else on this list:

  1. Hardware two-factor, never SMS
  2. Restore test before funding
  3. A separate wallet for connecting to sites
  4. A test transaction before every large transfer
  5. Never type a recovery phrase anywhere you did not navigate to yourself

Those five would have prevented the large majority of the losses documented on this site.

The working balance sits at an exchange you can actually contact with the account section of this list applied to it, and it is sized so that even a complete failure of everything above would be recoverable.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

checklistsecuritypractice

Related cases