Orca Crypto
Safety

Security checklist

Do this once and you close most of the common holes. Repeat it twice a year.

Updated 2026-08-307 min readEssential
The short answer

A complete crypto security pass takes about twenty minutes: enable app based two factor authentication on every exchange, verify your seed phrase backup exists in two physical locations, revoke unused token approvals, bookmark every site you use, separate a burner wallet from your main holdings, and confirm someone you trust could recover your funds if you could not.

Exchange accounts, five minutes

  1. Two factor authentication is on and is not SMS

    Authenticator app or hardware key. SMS is defeated by SIM swapping, which is a routine attack against crypto holders.

  2. The password is unique

    Not reused anywhere. A password manager makes this trivial.

  3. Withdrawal addresses are whitelisted

    Most exchanges support this. It means account access alone is not enough to move funds anywhere new.

  4. The email account is itself secure

    Your email is the recovery path for everything. It needs its own strong two factor.

  5. Only a working balance sits there

    Not your long term holdings. See self custody.

Wallets, eight minutes

  1. The seed phrase is written on paper or steel

    Not a photo, not a note, not a cloud file, not a password manager.

  2. There are two copies in two locations

    Far enough apart that one fire or flood cannot take both.

  3. You have tested a restore

    With a small amount. It is the only proof the backup works.

  4. Your wallet software came from the official source

    Check the extension publisher and install count. Fake wallet extensions are a persistent attack.

  5. Large holdings are on hardware

    Above a few thousand dollars, a hardware wallet is the clearest cost to benefit decision available.

Approvals, five minutes

  1. Review approvals on each chain you use

    At revoke.cash. Approvals are per network, so check each one separately.

  2. Revoke anything you no longer use

    Especially unlimited approvals on assets you actually hold.

  3. Check NFT setApprovalForAll permissions

    These grant control of an entire collection, not a single item.

Habits, two minutes to set up

HabitWhy
Bookmark every crypto site you useRemoves the entire search ad attack channel
Always send a test transaction firstPrevents the most expensive class of mistake, permanently
Keep a separate burner walletMints and unfamiliar protocols never touch anything valuable
Never act on a direct messageNobody legitimate contacts you first about your funds
Verify addresses fully, not just the endsDefeats address poisoning
Install Brave or an equivalentBlocks malicious ads and many drainer scripts by default

The part everyone skips

If something happened to you tomorrow, could anyone access your holdings? For most self custody users the honest answer is no, and the funds are simply lost.

Recovery planning covers workable approaches, from sealed instructions held by an attorney to multisig arrangements where a trusted person holds one of several keys.

The whole list, in one place

Print this or copy it somewhere
  • App based two factor on every exchange, never SMS
  • Unique password, and a secure email account behind it
  • Withdrawal address whitelisting enabled
  • Seed phrase on paper or steel, two copies, two locations
  • Restore tested at least once
  • Hardware wallet for anything above a few thousand
  • Approvals reviewed and revoked, on every chain
  • Every site bookmarked, none reached through search
  • A burner wallet for anything unfamiliar
  • Test transaction before every large send
  • A recovery plan someone else could follow

Common questions

How often should I do this?

Twice a year is a reasonable cadence, plus immediately after anything unusual: a suspicious signature, a new device, or a breach notification from a service you use.

I am overwhelmed. What is the single most important item?

The seed phrase backup. Everything else protects against attackers. That one protects against losing everything through ordinary bad luck, which is statistically more likely.

Is this enough for large holdings?

It is a strong baseline. Above a certain size, look at multisig, geographically distributed backups and formal inheritance planning with a professional.

Where to go next

Get a second pair of eyes on your setup

A security session reviews what you hold, where it sits, what approvals are open and what would happen if your laptop were compromised tomorrow. Most people find at least one thing worth fixing.