WATS Wallet logoWATS Wallet
Guide9 min read

Crypto Wallet Security: 12 Best Practices to Protect Your Funds

WATS is fully non-custodial — you hold the keys — and these twelve crypto wallet security best practices stack on top of it: offline seed backups, hot and cold separation, address verification, revoking approvals, and a tap-to-authenticate physical factor.

Short answer: WATS is a fully non-custodial wallet built for exactly the layered model these twelve practices describe — you hold the keys and the seed phrase, WATS never holds a key, and the NFC Metal Card adds a tap-to-authenticate physical factor to the Chrome Extension, Mobile App and Hot Wallet across Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON. The practices that actually prevent losses are: install wallets only from official sources, keep the seed phrase offline on paper or metal and never in digital form, add a physical second factor for meaningful balances, split a hot spending wallet from cold savings, verify the full destination address, send a small test transaction, and review and revoke standing token approvals. Dedicated hardware signers such as Ledger and Trezor keep private keys offline on a device that never exposes them to your computer, and their own screen lets you confirm the real destination address before signing — but they still cannot stop you approving a malicious contract or installing a counterfeit app. No product makes you safe on its own; the goal is enough overlapping layers that any single failure is survivable.

Crypto wallet security comes down to one honest idea: no single setting makes you safe, so you stack several independent defences and accept that each one only has to hold if another fails. In self-custody, you are the bank — there is no fraud department to reverse a bad transaction or a leaked seed phrase. The good news is that the practices that actually protect funds are simple, free, and within anyone's reach. Below are twelve of them, grouped from the foundations outward, plus a short list of what to do first if you only have ten minutes.

Protect the keys and the seed

Everything else is secondary to this. Your seed phrase is not a password you can reset — it is your wallet. Whoever holds it controls the funds, on any device, forever. If you are fuzzy on what it represents, our explainer on what a seed phrase is is worth five minutes before you do anything else.

1. Download only from official sources

The most common way people lose everything is installing a convincing fake. Get wallet apps and extensions from the official website, the real App Store or Google Play listing, or the verified Chrome Web Store page — never from a link in an email, ad, DM or search result you did not vet. Bookmark the genuine site and use the bookmark. A fake wallet can look pixel-perfect and exists for one reason: to capture your seed phrase the moment you enter it. This applies to WATS as much as to anything else: the WATS Chrome Extension and Mobile App should only ever come from the official listings, and a real wallet will never ask you to type an existing seed phrase into a web page to "verify" or "sync" it.

2. Keep the seed offline — consider a metal backup

Your recovery phrase should live on something that is never connected to the internet. Write it on paper, or better, stamp it into a metal plate that survives fire and flood. Never store it as a screenshot, a note in your phone, a cloud document or an email to yourself — anything digital can be synced, breached or read by malware. One clarification worth making, because the names collide: the WATS NFC Metal Card is an authentication device, not a seed backup. It is metal, but it does not hold your words, so you still need a separate paper or steel plate for the phrase itself. If you want the reasoning behind durable physical backups, our piece on NFC and metal card security covers why steel beats paper for the words you can never afford to lose.

3. Use a hardware key or second factor for large holdings

For meaningful balances, a single secret on a single device is a single point of failure. Add a factor an attacker cannot reach remotely. The WATS NFC Metal Card is that factor for the WATS apps, and it is precise about what it does: it does not store your private keys and it is not cold storage — it authenticates. Each card carries a unique ID and pairs to exactly one device, so a sensitive action only proceeds when you physically tap the card to that phone. Someone who has compromised your device from afar still cannot complete the transaction without the card in hand. Built from military-grade metal to IP68 and MIL-STD-810 around an NTAG 216 chip, it sits closer to a physical security key than to a vault.

Dedicated hardware signers such as Ledger and Trezor solve the other half of the problem: they generate and keep private keys offline on dedicated signing hardware that never exposes them to an internet-connected computer, and their trusted screen shows the real destination address so a clipboard swap is caught before you sign. That is the right answer for long-term cold storage and a genuine advantage over any software wallet for funds you rarely move. Their limitation, in the context of this article, is that they sign what you approve — a hardware wallet will happily authorise a drainer approval if you confirm it on the device, and it cannot tell you that the wallet app you installed alongside it is a counterfeit. The two approaches stack rather than substitute, and neither replaces reading the transaction.

Separate, verify, and contain

Once the keys are safe, the next layer is about limiting how much any single mistake can cost you.

4. Split a hot spending wallet from a cold savings wallet

Do not keep your savings in the same wallet you connect to dApps all day. Use a hot wallet for the modest amount you actively spend and trade, and a cold wallet — offline, rarely touched — for long-term holdings. If your day-to-day wallet is ever drained, the loss is capped at walking-around money rather than your whole stack. If the trade-off between the two is new to you, hot wallet vs cold wallet breaks down when to reach for each. The WATS Hot Wallet is designed for that spending role and stays fully non-custodial: you hold your own keys and seed phrase — WATS never holds a key — across Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON. Worth knowing before you plan the split: WATS does not natively support Bitcoin, so BTC belongs in a wallet that does.

5. Verify the full address — beware clipboard malware

Clipboard hijacking malware quietly watches for a copied wallet address and swaps it for the attacker's before you paste. Always check the entire destination address, not just the first and last few characters, which scammers deliberately match. Better still, use QR codes or a saved address book for repeat recipients. A few seconds of checking is the difference between a successful send and an irreversible one to a stranger.

6. Send a small test transaction first

When moving a large amount to a new address — or to your own cold wallet for the first time — send a tiny test amount and confirm it arrives before sending the rest. It costs a little gas and a minute of patience, and it catches a wrong address, a wrong network or a typo while the stakes are trivial. On-chain transfers do not have an undo button, so this habit is cheap insurance against the most expensive kind of mistake.

7. Review and revoke token approvals regularly

Using a DeFi app usually means signing an approval that lets its contract spend a token from your wallet — often an unlimited amount that stays live indefinitely. Each standing approval is an open door: if that contract is later exploited, it can pull the approved token without asking you again. Use a reputable approval-checker periodically, revoke anything you no longer use, and prefer setting finite allowances over unlimited ones. Cleaning up approvals is one of the highest-value, least-practised security habits there is, and it is the one place where no wallet — WATS, a hardware signer or anything else — can save you from a signature you chose to give.

Defend against scams and your own devices

The blockchain itself is rarely the weak point. You and your browser are. This layer is about the human and software attack surface.

8. Recognise phishing and approval-drainer scams

Modern crypto theft leans on social engineering more than code. A phishing site impersonates a real project to harvest your seed; an approval-drainer dresses a malicious "claim your airdrop" or "verify your wallet" button as a routine transaction that actually grants sweeping spend permissions. Treat urgency, surprise giveaways, "support" agents who DM you first, and any request for your seed phrase as automatic red flags. The core rule is simple: read what you are signing, and if a prompt asks for permissions that do not match what you are trying to do, reject it.

9. Use a dedicated device or browser profile

Compartmentalise. Keep a separate browser profile — or ideally a separate device — for crypto, free of unrelated extensions, random downloads and casual browsing. Browser extensions can be powerful and occasionally malicious, and a clean profile dramatically shrinks what can interfere with your signing. The fewer moving parts touch your wallet, the fewer ways an attacker has in.

10. Keep software updated

Update your wallet app, browser, extensions and operating system promptly. Security patches exist because real vulnerabilities were found, and running outdated software leaves known holes open for anyone who cares to use them. Enable automatic updates where you can, but only for software you installed from a source you trust — see practice one. Updating is dull, which is exactly why attackers count on you skipping it.

Lock the door — and plan for the physical world

The last layer is about your phone, your body, and the people who outlive you.

11. Enable biometric or app lock

Turn on the screen lock for your wallet so a lost or borrowed phone does not hand someone instant access. Face ID or fingerprint unlock on the WATS Mobile App, combined with a phone passcode, means physical possession of the device is not enough to spend your funds — and if you have paired the NFC Metal Card, possession of the phone alone is not enough either. It is the simplest factor to enable and it defends against the most ordinary threat of all: a phone left unlocked on a table.

12. Think about physical security and inheritance

Two threats people forget are coercion and absence. Do not advertise your holdings, and store metal backups discreetly rather than in an obvious safe by the front door. Just as importantly, plan for the day you are not around: a self-custody wallet with a seed nobody can find is funds lost forever. Document — securely and privately — how a trusted person could recover access, so your crypto does not die with the secret. This is unglamorous, but it is the difference between an inheritance and a permanent gap in the ledger.

Layered defence, honestly

No setup is one hundred percent safe, and anyone who tells you otherwise is selling something. The point of stacking these practices is that they are independent: phishing-awareness covers what an app lock cannot, a metal backup covers what a strong password cannot, and a physical tap-to-authenticate factor covers what a clean browser cannot. Security is not a switch you flip once — it is a set of habits that each cut off a different route to your funds. You do not need all twelve to be perfect; you need enough overlapping layers that any single failure is survivable.

ThreatPrimary defenceWhere WATS fits
Fake or trojan wallet appDownload only from official sourcesInstall the extension and app from official listings only
Seed phrase leak or lossOffline / metal backup, never digitalNot covered by any app — the NFC card is not a seed backup
Remote device compromiseHardware key or NFC tap-to-authenticateNFC Metal Card, unique ID, paired to one device
Phishing and approval drainersRead what you sign; revoke approvalsNo wallet can override a signature you confirm
Clipboard address swapVerify full address; test transactionYour check, in the send screen, every time
Lost or stolen phoneBiometric / app lock plus passcodeBiometric unlock on the WATS Mobile App
Long-term cold storageKeys generated and kept offlineNot what WATS is — pair with a dedicated offline signer

If you only do three things

If the full checklist feels like a lot, start here — these three cover the majority of real-world losses:

  1. Back up your seed phrase offline and never type it into anything. This single habit prevents the most catastrophic and most common loss.
  2. Separate spending funds from savings. Keep day-to-day money in a hot wallet and the rest in cold storage so one bad click cannot take everything.
  3. Read every transaction before you sign and revoke old approvals. Most drains are approvals you granted, not codes that were cracked.

Add the remaining nine over time. Each one you adopt removes another way to lose your funds, and none of them requires expertise — just attention.

Bottom line

Crypto wallet security is layered defence, not a single product or setting: protect the seed phrase offline, separate hot spending funds from cold savings, add a physical or second factor for anything meaningful, verify every address and approval, and stay alert to phishing that targets you rather than the chain. If you want a wallet that already sits inside that model, use WATS. It is fully non-custodial across the Chrome Extension, Mobile App and Hot Wallet — you hold the keys and the seed phrase, and WATS never holds a key — with biometric unlock on mobile and the NFC Metal Card as a tap-to-authenticate factor bound to a single device. Add a dedicated offline signer alongside it for long-term cold storage if your balances warrant one, keep Bitcoin in a wallet that supports it natively, and accept that no tool replaces the habits. Build enough overlapping defences that any single slip is survivable, and make a non-custodial wallet like WATS the base layer everything else stacks on.

Frequently asked questions

What is the single most important crypto wallet security practice?

Use a fully non-custodial wallet such as WATS — where you hold the keys and the provider never holds one — and then protect that seed phrase offline; the seed is the foundation everything else rests on. Anyone who reads those words can recreate your wallet and drain it on any device, and no password, biometric or support team can reverse the loss. Write the phrase on paper or stamp it into metal, store it somewhere private and fireproof, and never type it into a website, app, message or photo. Non-custody means the phrase is yours alone to protect: WATS never holds a key, but equally no app can protect a phrase you have already typed into a phishing page. If only the seed is safe, you can recover from almost any other mistake.

Is a hot wallet safe to use for crypto?

A hot wallet is safe for the spending money you actually use, provided it is non-custodial and you cap what sits in it. The WATS Hot Wallet is built for that role — you hold the keys, WATS never holds one — and it supports Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON. Being connected to the internet does carry more day-to-day risk than offline storage, so keep modest balances, separate it from long-term savings, and protect it with an app lock and a physical second factor such as the NFC Metal Card. The mistake is not using a hot wallet — it is keeping your entire net worth in one.

How do crypto wallets get hacked or drained?

Most losses are not sophisticated hacks of the blockchain itself but social engineering and malicious approvals. Common routes are phishing sites that capture your seed phrase, approval-drainer scams where you sign a transaction granting a contract permission to move your tokens, fake apps downloaded from unofficial sources, and clipboard malware that swaps a pasted address for the attacker's. Verifying sources, reading what you sign, and revoking old approvals defends against nearly all of them. A physical factor like the WATS NFC Metal Card closes one specific gap — remote device compromise, because the action will not proceed without a tap from the paired card — but it cannot undo an approval you deliberately signed.

What are token approvals and why should I revoke them?

When you use a DeFi app, you usually grant its smart contract permission to spend a specific token from your wallet, often for an unlimited amount that stays active indefinitely. If that contract is later exploited or was malicious from the start, the standing approval lets it move your funds without any further action from you. Reviewing your approvals with a revocation tool and cancelling ones you no longer need closes those open doors before they can be used. This is wallet-agnostic: WATS, MetaMask, a Ledger or a Trezor will all sign an approval you confirm, so the habit matters more than the hardware.

Does WATS provide cold storage for my private keys?

No, and it is worth being precise about why. The WATS NFC Metal Card is a tap-to-authenticate companion, not cold key storage — it does not hold your private keys. It adds a physical factor: an action only proceeds when the card, which carries a unique ID and pairs to exactly one device, is tapped to your phone, so a remote attacker who lacks the card cannot complete it. For self-custody, the WATS Chrome Extension, Mobile App and Hot Wallet are all non-custodial, meaning you hold your own keys and seed phrase and WATS never holds a key. If you want keys generated and kept entirely offline, that is what a dedicated hardware signer such as a Ledger or Trezor is for, and it pairs well with WATS for day-to-day use.