Ilia Zavialov

Protection

Protecting a crypto wallet: measures that actually hold

English version for the United Kingdom.

Protection that requires constant attention fails at the moment it is needed. The measures below are configured once, work without supervision, and hold even when an attacker has already reached the account.

·3 min read·Ilia Zavialov

Diagram of layered crypto protection: custody split, whitelist, delay, last line
Diagram of layered crypto protection: custody split, whitelist, delay, last line

01Decide custody before anything else

Funds on an exchange are subject to that platform's decisions and can be frozen, delayed or lost with the platform. Funds in a self custody wallet depend entirely on the recovery phrase, which nobody can restore.

Most people arrive at a split: the exchange holds what is actively traded, self custody holds what is not. The split is a decision, and making it deliberately is itself a protection.

02The recovery phrase is the whole asset

The phrase is written on something that does not sync, does not photograph itself and does not sit in a note application. Anyone who reads it owns the funds.

It is stored in a place that survives the ordinary failures: not one copy that a fire ends, not a cloud backup that an account takeover reaches. And it is never typed into a page that asks for it, because no genuine service ever asks.

Protective measures ordered by what they cost and what they cover
MeasureTime to set upWhat it covers
Custody splitOne eveningPlatform failure and freezes
Offline recovery phraseFifteen minutesDevice loss, malware, cloud takeover
Withdrawal whitelistTen minutesWithdrawal after account takeover
Delay window on new addressesTwo minutesGives time to intervene
Hardware keyTwenty minutesPhishing pages and code interception
Backup codes stored apartTen minutesLoss of the phone and the number
Annual reviewFifteen minutes a yearConfiguration drift

03The pair that changes outcomes: whitelist and delay

Where a platform allows a list of approved withdrawal addresses and a waiting period on new additions, both are enabled together.

This is the configuration that holds after the account is already compromised. An attacker with full access can add an address and still has to wait, and the waiting period is when the owner receives the notification and intervenes.

04The last line

Backup codes stored away from the device, because they work without a phone and without a network. A hardware key, because it cannot be phished by a page. An annual review that confirms the contact number, the recovery mailbox, the codes and the list of trusted devices.

None of these require vigilance. They are arranged once and then work on their own, which is the only kind of measure that survives a real incident.

05Questions and answers

Where should a recovery phrase be stored?

Somewhere offline that does not synchronise and is not photographed, in more than one place, so that a single fire or a single theft does not end it. Never in a note application, a message to yourself or a cloud folder.

Does a withdrawal whitelist help if my account is already taken over?

Yes, and that is its purpose. The attacker has to add a new address and wait out the delay, and the delay is the window in which the owner sees the notification and reacts.

Is a hardware wallet enough on its own?

It removes the key from an online device and does not remove the decision. A hardware wallet signs whatever the owner approves, so an approved malicious permission still moves funds.

Monogram of Ilia Zavialov

Written by Ilia Zavialov, digital security consultant. Profile of Ilia Zavialov

06Read next

Back to the blog