Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.

Personal Security Checklist & Reporting

Build a practical operational-security framework, learn the proper reporting channels (IC3, FTC, SEC, ChainAbuse), and understand realistic recovery options.

15 min · beginner · part of Crypto Scams & How to Stay Safe

Operational Security: Hardware, Seed Phrases, and Authentication

Operational security ("opsec") is the practice of structuring your devices, accounts, and habits so that one mistake does not compromise everything. The core principles are simple. Implementing them takes a few hours and prevents most realistic attacks. Use a hardware wallet for any crypto holding worth more than a small spending budget. Ledger and Trezor are the established options. The hardware device signs transactions internally and never exposes the private key to your computer, so even if your laptop is fully compromised by malware, an attacker cannot move funds without physical access to the device and the PIN. Verify the device on first setup using the official manufacturer software, and buy directly from the manufacturer or an authorized reseller — never used, never from a third-party marketplace. Write your seed phrase on paper or stamp it into metal. Never type it into any computer. Never photograph it. Never store it in a cloud-synced note app. Do not enter it into any website or wallet recovery tool that asks for it — the only legitimate use of a seed phrase is restoring a wallet from scratch on a new hardware device or trusted software wallet, in your physical possession. Anyone asking for it through a website, chat, email, phone call, or video call is conducting a theft attempt. Use long, unique passwords for every crypto-related account, generated and stored by a password manager (1Password, Bitwarden, KeePassXC). The same password reused across two sites is a pre-authorized breach. Enable two-factor authentication on every exchange and email account, and use an authenticator app (Aegis, Authy, Ente Auth) or a hardware security key (YubiKey, SoloKey) — not SMS. SMS-based 2FA is vulnerable to SIM-swapping attacks where an attacker convinces your mobile carrier to port your number to their device, then receives the SMS codes. Use a YubiKey for the highest tier of accounts; phishing-resistant FIDO2 keys are an order of magnitude harder to defeat than authenticator apps. Keep two separate wallets at minimum: a "hot wallet" for daily DeFi activity holding limited funds, and a "cold wallet" (hardware-secured) holding long-term savings that rarely transacts. Compromise of the hot wallet should not cascade. Maintain a separate email address used only for crypto exchange accounts, with no other usage. This reduces the surface area for credential stuffing and targeted phishing.

Also in this lesson

  • Evaluating a New Project Before You Invest
  • Detection Tools You Should Have Installed
  • How to Report a Crypto Scam
  • Recovery Realities
  • Ongoing Vigilance: The Habit Stack

Key terms

Hardware wallet
A device (such as Ledger or Trezor) that signs transactions internally and never exposes the private key to the connected computer. The single highest-leverage security purchase for anyone holding meaningful crypto.
Seed phrase
A 12 or 24 word recovery phrase that controls a wallet. Must be written on paper or metal and never typed into a computer, photographed, or stored in cloud notes. No legitimate service ever asks for it.
SIM-swapping
An attack where the attacker convinces your mobile carrier to port your phone number to their device, capturing SMS-based 2FA codes. Use authenticator apps or YubiKeys instead.
Hot vs cold wallet
A separation strategy where daily-use funds live in a "hot" wallet exposed to dApp interactions and long-term savings live in a "cold" hardware-secured wallet that rarely transacts.
Revoke.cash
A free web tool at revoke.cash that lets you audit and revoke smart contract permissions to spend your tokens. Run monthly to close doors that future drainers might walk through.
ScamSniffer
A browser extension maintaining a real-time blocklist of known phishing domains and drainer signature patterns. One of the most effective single defenses against drainer attacks.
ChainAbuse
A community scam-reporting platform at chainabuse.com jointly operated by TRM Labs and Binance. Lets you search wallet addresses for prior reports and submit your own.
IC3 reporting (ic3.gov)
The FBI Internet Crime Complaint Center, the central federal portal for reporting crypto fraud. File within 24 hours with all transaction hashes, communications, and account details.
Recovery scam
A second scam targeting previous fraud victims with promises to recover stolen funds for an upfront fee. Legitimate U.S. law enforcement never charges fees. Refuse all unsolicited recovery offers.
YubiKey / FIDO2 hardware key
A physical security key that provides phishing-resistant two-factor authentication, an order of magnitude harder to defeat than authenticator apps and dramatically harder than SMS codes.

Continue this lesson — 5 more sections in the CryptoBipto app.

Open lesson

Educational only — not financial advice.