How to Store Bitcoin and Crypto Safely
Self-custody with a hardware wallet and an offline seed phrase is the safest way to store crypto. Learn custody tradeoffs, passphrases, today's scam patterns, and inheritance basics.
9 min read. Updated 2026-08-12.
The safest way to store bitcoin and crypto is self-custody: a hardware wallet, a seed phrase written on paper or stamped in steel and never photographed or typed into anything, and a deliberate habit of verifying addresses before you send. Keeping coins on a regulated exchange is a reasonable choice for small balances you trade often, but it means trusting someone else's security and solvency with your money. Everything else in crypto security is detail layered on top of those two decisions. This guide covers both custody models honestly, then works through the practical layers: choosing a hardware wallet, handling your seed phrase, adding a passphrase, recognizing the scams that actually empty wallets today, and making sure your coins do not die with you.
Not your keys, not your coins
Every bitcoin address is controlled by a private key, and modern wallets derive all of their keys from a single master secret called a seed phrase. Whoever holds that secret controls the coins. There is no account recovery department for the blockchain itself.
That leads to the two custody models:
Exchange custody means the platform holds the keys and you hold an IOU. The upside is convenience: you can log in from anywhere, reset a forgotten password, and trade instantly. The downside is counterparty risk. When FTX collapsed in November 2022, customers who thought they held bitcoin discovered they actually held unsecured claims in a bankruptcy. Hacks, withdrawal freezes, and sudden compliance holds are rarer on large regulated platforms, but the structural fact never changes: coins on an exchange are the exchange's coins, with a promise attached.
Self-custody means you hold the keys, usually through a hardware wallet. Nobody can freeze, seize, or lose your coins on your behalf. In exchange, you accept full responsibility. If you lose the seed phrase and the device, the coins are gone. If you get tricked into signing a malicious transaction, no one reverses it.
A sensible split for most people: keep only what you are actively trading on a reputable exchange, and move long-term holdings into self-custody. The more the balance matters to your life, the stronger the case for holding your own keys.
Hardware wallets: the self-custody standard
A hardware wallet is a small device that generates and stores your keys inside a dedicated chip and signs transactions internally, so the keys never touch your computer or phone. Even if your laptop is riddled with malware, the malware cannot extract keys from the device. Just as important, the device has its own screen: it shows you the real destination address and amount before you approve, which defeats software that silently rewrites transactions.
Three rules when buying and using one:
- Buy directly from the manufacturer. Devices bought from marketplace resellers or second-hand can be tampered with before they reach you. A legitimate device generates a fresh seed on first use; if one arrives with a seed phrase already filled in, it is a scam designed to let the seller drain it later.
- Verify on the device screen, every time. Trust the address shown on the hardware wallet, not the one on your computer, whenever you send or receive.
- Set a PIN so a thief who steals the device cannot use it before you restore your funds elsewhere.
Software wallets on a phone or desktop are fine for small spending balances, the same way a physical wallet holds pocket cash and not your savings. Compare current hardware options on our wallets page.
Seed phrases: one rule above all others
When you set up a wallet, it shows you a seed phrase of 12 or 24 common words. Those words are the wallet. Anyone who reads them can recreate your wallet on their own device and take everything, from anywhere in the world, without touching your hardware.
The rule that matters more than any other: the seed phrase never becomes digital. No photo, no cloud note, no email draft, no password manager, no encrypted file, no typing it into a website or app. Photos sync to clouds, clouds get breached, clipboards get read by malware, and phishing sites exist purely to harvest typed seed phrases. A legitimate wallet will only ever ask for the seed on the hardware device itself during recovery, never in a browser and never in a pop-up.
Practical handling:
- Write it by hand on the card provided, or better, stamp or engrave it into a steel plate that survives fire and flood.
- Store copies in two separate secure locations, such as a home safe and a bank deposit box.
- Do not get clever with splitting the words across locations in ways you might misremember. Complexity is how people lock themselves out.
- Never read it aloud on a call or show it on a screen share, no matter who is asking. That request is the scam.
Passphrase wallets: an optional 25th word
Most hardware wallets support an extra passphrase on top of the seed, sometimes called the 25th word. Adding a passphrase creates an entirely separate hidden wallet: the same seed with a different passphrase opens a different, empty wallet. This protects you if someone physically finds your written seed, because the words alone no longer unlock your main funds. It also enables a decoy setup, where the bare seed opens a small balance and the passphrase opens the real one.
The tradeoff is severe: there is no reset. A passphrase you forget, or write down with one wrong character, destroys access as completely as a lost seed. If you use one, choose something you can store or remember reliably, and always send a small test amount and practice a full recovery before moving serious funds behind it.
The attacks that actually work now
Most crypto losses today do not come from someone breaking bitcoin's cryptography. They come from people being talked or tricked into handing value over. The FBI's Internet Crime Complaint Center recorded 9.3 billion dollars in reported crypto fraud losses from Americans in 2024 alone, up 66 percent from the year before, with long-con investment scams (often called pig butchering) causing the largest losses. Four patterns are worth knowing in detail.
Approval phishing
On networks like Ethereum, tokens support approvals: you can authorize an app to spend tokens on your behalf. Scam sites imitate airdrops, mints, or trading tools and ask you to sign what looks like a routine confirmation but is actually an unlimited spending approval. The attacker can then drain the approved tokens at any later time, without another signature from you. Researchers at Chainalysis have tied more than a billion dollars in losses to this technique since May 2021. Defenses: read what you are signing on your hardware wallet screen, be ruthless about unknown sites, and periodically revoke old approvals with a reputable revocation tool.
Address poisoning
Attackers send tiny transfers to your wallet from addresses crafted to look like ones you have used, matching the first and last characters. Later, when you copy an address from your transaction history, you copy theirs. In May 2024 a single victim sent 1,155 wrapped bitcoin, worth about 68 million dollars, to a poisoned address; the funds were returned only after investigators identified the attacker, an outcome nobody should count on. Defenses: never copy addresses from transaction history, verify more than the first and last four characters, keep an address book of verified destinations, and send a small test amount before any large transfer.
SIM swaps
An attacker convinces or bribes a mobile carrier employee to move your phone number to their SIM, then intercepts your text-message codes and resets your exchange and email accounts. US carriers have been required since mid-2024 to use stronger authentication and to notify you of SIM change requests, but the attack has not disappeared. Defenses: remove SMS as a second factor wherever possible, use an authenticator app or a hardware security key for exchanges and email, and set a PIN or port-freeze with your carrier.
Fake support
No legitimate exchange, wallet company, or blockchain project will ever contact you first to fix a problem, and none will ever need your seed phrase. Scammers run fake support accounts on social platforms, buy search ads pointing at cloned websites, and send urgent emails about breaches or mandatory wallet updates. Leaked customer lists make this worse: buyers of hardware wallets have received convincing phishing for years after vendor data leaks, such as the Ledger customer database breach in 2020. Defenses: bookmark the real sites, type addresses yourself, treat every unsolicited contact about your crypto as hostile, and remember that keeping your holdings private is itself a defense. Our guide to what a VPN protects and what it does not covers the network privacy side.
Inheritance: make your coins survivable
Self-custody done perfectly can still fail your family. If you are the only person on earth who can find and use your seed phrase, your coins are lost the day you are gone. The opposite failure is just as real: instructions so accessible that a relative, roommate, or burglar can drain the wallet early.
A workable basic plan:
- Keep a plain-language inventory of what exists and where it lives (which device, which locations), stored with your will or attorney. The inventory contains no secrets.
- Keep the seed itself sealed in a separate secure location the executor can access only through the estate process.
- Never put the seed phrase in the will itself; wills can become public records in probate.
- If you use a passphrase, make sure it is recoverable through the same process, or the seed is useless.
- Walk your intended heir through a practice recovery once. A plan that has never been tested is a hope, not a plan.
Larger holdings can justify multisignature setups or splitting material between an attorney and a family member, but a simple tested plan beats a sophisticated untested one.
The closing checklist
- Long-term holdings sit in a hardware wallet bought directly from the manufacturer.
- The seed phrase exists only on paper or steel, in two secure locations, with zero digital copies.
- A passphrase protects large balances, and it is both memorable and recoverable.
- Exchange accounts use an authenticator app or hardware security key, never SMS codes.
- Every send is verified on the device screen, with a test transaction before large amounts.
- Addresses are never copied from transaction history, and old token approvals get revoked.
- Anyone who contacts you first about your crypto is treated as a scammer, because they almost certainly are.
- A written, tested inheritance plan exists, with no secrets in the will.
- You review the whole setup once a year.
None of this requires technical brilliance. It requires accepting that in crypto you are the bank, and banks have procedures.
