Download Trust Wallet
Home  >  Blog  >  Security  >  Crypto Self-Custody Security Checklist: 10 Rules
Security

Crypto Self-Custody Security Checklist: 10 Rules

Published on: Aug 13, 2026
Share post
In Brief

Ten practical rules that address the most common ways self-custody funds are lost: protecting your recovery phrase, verifying addresses, reviewing what you sign, revoking approvals, and the habits that stop scammers cold.

Crypto Self-Custody Security Checklist: 10 Rules

Ten rules address the most common ways self-custody funds are lost: write your recovery phrase on paper (never a screenshot), never type it into any website, verify addresses beyond the first characters, use the address book instead of copy-paste, review what you sign, revoke unused token approvals, avoid links from DMs and ads, keep long-term funds in a wallet that never touches dApps, enable app-level security, and treat "support" that asks for your phrase as a scam — always.

Why a Checklist?

Crypto theft rarely involves broken cryptography. It involves a phrase typed into a fake site, a look-alike address pasted from history, or a malicious transaction signed in a hurry. Each rule below closes one specific, real attack path.

The 10 Rules

  1. Write your recovery phrase on paper — never a screenshot. Screenshots sync to clouds and get scanned by malware. Paper (or metal) kept offline can't be hacked remotely. Your recovery phrase is the master key to everything.

  2. Never type your phrase into any website. No legitimate service — not Trust Wallet, not any dApp, not "support" — ever needs it on a webpage. Every site that asks is a phishing site, without exception.

  3. Verify addresses beyond the first characters. Scammers generate look-alike addresses matching the start and end of ones you use. Check a chunk from the middle too — especially before large transfers. This defeats address poisoning.

  4. Use the address book, not copy-paste. Saved, verified recipients remove the two classic failure points: clipboard-hijacking malware and poisoned transaction history.

  5. Review what you sign. If you can't say in one sentence what a transaction does, reject it. The Security Scanner's preview shows the real effect — read it.

  6. Revoke approvals you no longer use. Old token approvals stay active forever until you revoke them. A periodic cleanup limits what any single bad contract could ever touch.

  7. Don't follow links from DMs, ads, or comments. Type known URLs yourself or use bookmarks. Nearly every drainer campaign starts with an unsolicited link.

  8. Separate spending from savings. Keep long-term holdings in a wallet that never connects to dApps. One bad signature can only reach what's in the wallet that signed it.

  9. Enable app-level security. A passcode plus biometrics makes a lost or borrowed phone far less dangerous.

  10. Anyone who asks for your phrase is a scammer. Not sometimes — always. Real support never asks. This single rule defeats the most common scam in crypto.

How Many of These Do You Need?

All ten — but they take minutes, not hours. Rules 1, 2 and 10 (phrase hygiene) guard against total loss. Rules 3–7 (transaction hygiene) prevent the everyday scams. Rules 8–9 limit the damage if something slips through anyway. Defense in layers, none of them complicated.

Self-Custody Is a Habit, Not a Product

A good wallet gives you the tools — on-device keys, a transaction scanner, an address book, optional Encrypted Cloud Backup. The habits above are what turn those tools into safety. For the threats these rules defend against, see our guide to spotting wallet scams and the security overview at trustwallet.com/security.

Disclaimer: Content is for informational purposes and not investment, financial, or tax advice. Web3 and crypto come with risk. Please do your own research with respect to interacting with any Web3 applications or crypto assets. View our terms of service.

Simple and convenient
to use, seamless to explore

Download Trust Wallet