Protection
Protecting a crypto wallet: measures that actually hold
English version for the United States.
Protection that requires constant attention fails at the moment it is needed. The measures below are configured once, work without supervision, and hold even when an attacker has already reached the account.
01Decide custody before anything else
Funds on an exchange are subject to that platform's decisions and can be frozen, delayed or lost with the platform. Funds in a self custody wallet depend entirely on the recovery phrase, which nobody can restore.
Most people arrive at a split: the exchange holds what is actively traded, self custody holds what is not. The split is a decision, and making it deliberately is itself a protection.
02The recovery phrase is the whole asset
The phrase is written on something that does not sync, does not photograph itself and does not sit in a note application. Anyone who reads it owns the funds.
It is stored in a place that survives the ordinary failures: not one copy that a fire ends, not a cloud backup that an account takeover reaches. And it is never typed into a page that asks for it, because no genuine service ever asks.
| Measure | Time to set up | What it covers |
|---|---|---|
| Custody split | One evening | Platform failure and freezes |
| Offline recovery phrase | Fifteen minutes | Device loss, malware, cloud takeover |
| Withdrawal whitelist | Ten minutes | Withdrawal after account takeover |
| Delay window on new addresses | Two minutes | Gives time to intervene |
| Hardware key | Twenty minutes | Phishing pages and code interception |
| Backup codes stored apart | Ten minutes | Loss of the phone and the number |
| Annual review | Fifteen minutes a year | Configuration drift |
03The pair that changes outcomes: whitelist and delay
Where a platform allows a list of approved withdrawal addresses and a waiting period on new additions, both are enabled together.
This is the configuration that holds after the account is already compromised. An attacker with full access can add an address and still has to wait, and the waiting period is when the owner receives the notification and intervenes.
04The last line
Backup codes stored away from the device, because they work without a phone and without a network. A hardware key, because it cannot be phished by a page. An annual review that confirms the contact number, the recovery mailbox, the codes and the list of trusted devices.
None of these require vigilance. They are arranged once and then work on their own, which is the only kind of measure that survives a real incident.
05Questions and answers
Where should a recovery phrase be stored?
Somewhere offline that does not synchronise and is not photographed, in more than one place, so that a single fire or a single theft does not end it. Never in a note application, a message to yourself or a cloud folder.
Does a withdrawal whitelist help if my account is already taken over?
Yes, and that is its purpose. The attacker has to add a new address and wait out the delay, and the delay is the window in which the owner sees the notification and reacts.
Is a hardware wallet enough on its own?
It removes the key from an online device and does not remove the decision. A hardware wallet signs whatever the owner approves, so an approved malicious permission still moves funds.