Self-Custody Security: A Practical Playbook by Portfolio Size
The price of self-custody is responsibility. There is no bank to reverse a mistake, so security is the asset. The good news: the necessary practices scale with how much you hold. You do not need everything on day one.
Level 0: rules for any amount
- Seed phrase offline, always. Paper or metal, stored physically. Photos, cloud notes, and message-to-self are the recurring leak paths in real incidents.
- Every request for your seed phrase is a scam. Wallet support desks, airdrop pages, "wallet sync" popups, no exceptions. Legitimate services never need it.
- Install from official sources only. Search-ad wallet sites can be phishing clones. Type the URL yourself or follow links from official docs.
Level 1: everyday amounts (hot wallet)
- Verify addresses at three points: first four characters, last four, and a slice of the middle. Address poisoning plants lookalike addresses in your transaction history to exploit copy-paste. Drop the habit of copying addresses from history at all.
- Make test transfers routine. Large amounts always move in two sends.
- Manage token approvals. Using DeFi accumulates grants that let contracts spend your tokens. An unlimited approval left on a later-hacked contract can drain the wallet. Review and revoke quarterly with an approval manager.
- Read what you sign. A "signature request" can be authority to move assets. If you cannot tell what a signature does, declining is the default.
Level 2: meaningful savings (cold wallet)
- Buy hardware wallets new, from the official store. Second-hand or marketplace units carry tampering risk.
- Generate the seed on the device yourself. Any "pre-written seed card" in the box means fraud, every time.
- Confirm large sends on the device screen. Malware can swap the address on your computer display; the hardware screen is far harder to fake.
- Separate vault and activity wallets. The cold wallet never connects to dapps. That separation is the point.
Level 3: serious holdings (security by structure)
- Passphrase (the 25th word): a hidden wallet that a leaked seed alone cannot open. The trade: losing the passphrase loses the funds, so it needs its own storage plan.
- Multisig / social recovery: split signing power to remove the single point of failure. Smart-wallet social recovery attacks the same problem from another angle.
- Inheritance planning: written procedure for family to locate and access assets if you cannot. The most commonly forgotten piece of self-custody.
Five things to check today
- Is your seed phrase stored anywhere online?
- Any unknown contracts in your recent approvals and signatures?
- Are you copying addresses out of transaction history?
- Are long-term holdings sitting in a dapp-connected wallet?
- Would your family even know these assets exist?
Summary
Security is a habit, not a product. As holdings grow, add structure to the habit: hardware, passphrase, multisig. Moving up just one level today already blocks most real-world attacks.
This content is educational information, not investment advice. Cryptoassets carry a high risk of loss. Investment decisions and their outcomes are your own responsibility.