Don't get rekt
Almost every crypto loss is preventable. These are the rules that do the preventing, from the security channel this site grew out of.
Updated 2026-08-12.
Most people who lose crypto do not lose it to a market crash. They lose it to a mistake that took thirty seconds: a seed phrase typed into a fake site, savings left on an exchange that failed, a "support agent" who slid into their DMs. Every one of those mistakes is preventable, and preventing them costs almost nothing. That is what this page is for.
The threat model, honestly
Three things take people's coins, in this order:
- Scams. Phishing sites, fake support, investment-romance hybrids, guaranteed-yield schemes. The FBI logged over nine billion dollars in reported US crypto fraud losses in a single recent year, and reported losses undercount reality.
- Custodial failure. Mt. Gox, Celsius, FTX, Bittrex: exchanges and lenders that held customer coins and then could not give them back. Bankruptcy court is where crypto goes to wait for years.
- Self-inflicted key loss. Seed phrases in cloud photo albums (hacked), on a single piece of paper (burned, flooded, thrown out), or never backed up at all.
Notice what is missing: sophisticated hackers breaking cryptography. Bitcoin's cryptography has never been broken. Attackers go around it, through you. Which means your habits, not your technical skill, decide whether you keep your coins.
The ten rules
1. Not your keys, not your coins
An exchange balance is an IOU. It becomes your bitcoin only when you withdraw it to a wallet whose keys you hold. Keep on exchanges only what you are actively trading or about to spend. Everything you would mind losing belongs in self-custody.
2. Buy a hardware wallet from the manufacturer
A hardware wallet keeps your keys on a device that never exposes them to your computer. Buy it directly from the manufacturer, never from a marketplace reseller where tampered devices have turned up. When it arrives, the device generates a fresh seed phrase; nobody, including the manufacturer, should ever have seen it before you.
3. The seed phrase never goes digital
No photos. No cloud notes. No password manager. No typing it into any website, app, or "validation tool", ever. Write the words on paper or stamp them into steel, store the backup somewhere that survives fire and flood, and consider keeping a second copy in a different location. Every service that asks you to enter an existing seed phrase online is either a scam or about to be one.
4. Verification requests are attacks
No exchange, wallet maker, or influencer will ever DM you first. "Support" that contacts you is a scam. "Validation" of your wallet is a scam. Anyone asking you to move funds "to a safe address" is a scam. The correct response to unsolicited crypto help is silence and a block.
5. If the yield is guaranteed, the loss is too
Two percent per day, twenty percent per month, "risk-free arbitrage bot": these are not investments, they are countdown timers. Real yield in crypto is single-digit annual and comes with clearly explainable risk. Anything better than that is your own money being paid back to you until the operator leaves.
6. Slow down when money moves
Address poisoning attacks put lookalike addresses in your transaction history hoping you copy one. Check the first and last several characters of every address, send a small test amount first for large transfers, and treat urgency itself as a red flag. Nothing legitimate in crypto requires you to act in the next ten minutes.
7. Harden the accounts around your crypto
Your exchange account is only as strong as your email and phone number. Use a unique password and app-based or hardware-key two-factor authentication (never SMS, which falls to SIM swapping) on the exchange and on the email behind it. Ask your mobile carrier to add a port-out PIN.
8. Keep your setup boring
A browser full of random extensions, a computer full of cracked software, and a wallet full of airdropped mystery tokens is how people get drained. Do your crypto on a clean browser profile, ignore tokens and NFTs that appear uninvited, and never sign transactions you do not understand. Approval phishing, where a malicious site tricks you into granting spending permission, drains wallets months after the click.
When something goes wrong
Act fast and keep records. Move remaining funds to a fresh wallet immediately if you suspect key compromise. Revoke token approvals with a reputable revocation tool. Report to your local cybercrime unit and, in the US, the FBI's IC3. Then be warned: "recovery services" that promise to get your crypto back for an upfront fee are a second scam that targets fresh victims. Real recovery is rare and never sold via DM.
Where to go from here
Start with how to store crypto safely for the full storage walkthrough, check our hardware wallet reviews before buying a device, and read the VPN guide for what network privacy does and does not protect. Then set up your storage once, properly, and get on with your life. Boring is the goal.