Everything from the safety guide, gathered in the order it should be done. Do it once.
Your keys
- Recovery phrase written on paper, never photographed, never typed into a site.
- Stored somewhere only you can reach; split in two places is better than one.
- Each significant holding on a separate address, so one compromise is contained.
- Backed-up device, and the backup is not in the same place as the original.
Your accounts
- Two-factor on everything that can move money, including your email.
- An authenticator app or a hardware key — not SMS.
- A different, strong password for anything connected to money.
- Recovery codes saved offline.
Your device
- Operating system and browser updated.
- Nothing installed from a link in a message.
- Screen lock, disk encryption, and no one else using the device.
Every transaction
- Address copied, never typed; first and last six characters compared afterwards.
- Network checked, every time, from the page you are logged in to.
- A small test before a first send to any new address — the full method.
- No send to an address that arrived in a message.
Your habits
- Nothing on a request that arrived by message; reach the company yourself.
- Updates installed without delay.
- No borrowed money anywhere in the chain — see how much to deposit.
Then the part that is not security
None of this changes the market. It removes the ways you lose money by mistake rather than by price. The price risk is separate, and it is handled by sizing — the risk checklist. Both are necessary, and neither replaces the other.
