Security
Crypto wallets: understand, choose and secure your wallet
Crypto wallets, seed phrases, hardware wallets, signatures and scams: a clear guide to choosing and securing your wallet.

Securing a crypto wallet depends less on hacker-level knowledge than on a few decisions made at the right time.
Understanding where assets actually exist, protecting the recovery phrase, checking signatures and separating different uses can prevent a large proportion of incidents.
The danger does not always come from a vulnerability in a blockchain. It often comes from a fake adviser, a cloned website, a fraudulent application or a transaction approved without understanding its content.
In May 2026, the Ethereum ecosystem launched a “clear signing” initiative to make signature requests easier to understand. It addresses a very practical problem: many losses occur when users approve actions they cannot read clearly.
A wallet does not contain your crypto-assets
Assets are recorded on a blockchain. A wallet manages the keys that control an address and sign transactions.
A simple comparison is a transparent safe in a public room. Everyone can see the safe and its contents. Only the person with the key can open it or move what it contains.
A wallet is therefore less like a purse full of coins and more like a key and permission manager.
This distinction is fundamental. It explains why deleting an application does not destroy the assets, provided the recovery phrase has been kept. It also explains why anyone who obtains that phrase can restore the wallet on another device and take control of the funds.
Custodial or non-custodial: who controls the keys?
Custodial wallet
A platform holds the keys on the user’s behalf. The user signs in with an identifier, a password and an additional authentication method.
Advantages:
- easier account recovery
- a familiar interface
- potential access to support
- less technical management
Risks:
- dependence on the platform
- account freezes or restrictions
- company failure
- hacking or a data leak
- no direct control over the keys
Non-custodial wallet
The user controls the keys. The recovery phrase can restore the wallet.
Advantages:
- direct control of assets
- access to decentralised applications
- less dependence on a single intermediary
Risks:
- permanent loss if the backup disappears
- asset theft if the phrase is disclosed
- transactions that are usually irreversible
- greater responsibility when signing
Neither model is perfect. The right choice depends on the amount involved, the frequency of use and the user’s ability to manage their own security.
Hot wallets, hardware wallets and other solutions
Hot wallet
It runs on a phone, browser or computer connected to the Internet. It is convenient for regular transactions and Web3 applications.
It is more exposed to fraudulent websites, malicious extensions and signing errors.
Hardware wallet
It keeps keys in a dedicated device and requires physical confirmation. In normal use, the private key should never leave the device.
This protection reduces certain risks, but does not make every transaction safe. A user can still approve a malicious contract on their screen if they fail to check the action.
Multisignature
A transaction requires several approvals from a set of keys. This approach is useful for a company, association or significant portfolio.
It reduces the risk attached to a single key, but requires clear organisation for backups, roles and recovery.
Smart accounts and social recovery
Some wallets use smart contracts to add limits, temporary keys, guardians or recovery mechanisms.
These features improve the experience while introducing a dependency on the wallet’s code and infrastructure.
The recovery phrase: the most important rule
The recovery phrase, also called a seed phrase, can recreate the wallet’s keys.
Anyone who has it can generally take control of the associated accounts. No legitimate support team, reputable platform or public service should ask you for it.
Essential rules:
- never send it by message, phone or form
- never enter it on a website
- do not photograph it
- do not store it in an email or cloud service
- do not copy it into a connected notes application
- prepare a durable and discreet physical backup
- check that the backup is readable before using the wallet for a significant amount
A hardware wallet bought directly from a manufacturer or trusted retailer should generate a new phrase during setup. A phrase already printed inside the box is a major warning sign.
The most common attacks
Fake support and fake advisers
A fraudster contacts a victim while claiming to represent an exchange, wallet provider, bank or anti-fraud service. Through a data leak, they may already know the victim’s name, telephone number or information about their portfolio.
In 2026, Cybermalveillance.gouv.fr reported an increase in contacts from fake employees linked to crypto operators. Their objective is to obtain the seed phrase, install software or persuade the victim to transfer funds to a supposedly “secure wallet” controlled by the scammer.
A genuine adviser will never ask you to move assets to an address provided over the phone.
Phishing
A website imitates the interface of a wallet or platform. The user enters their recovery phrase or connects their wallet, then approves a malicious action.
Sponsored adverts, direct messages and fake search results are common entry points.
Blind signing
The screen displays an incomprehensible string or message. The user signs without knowing which rights they are granting.
A signature can allow a contract to move a token, validate an order or act on several assets. The “Sign” button does not always mean “send a harmless transaction”.
Fake applications or extensions
An application with the correct logo can still have been published by a fraudulent actor. Use links from the official website and verify the publisher.
Old approvals
A DeFi application can retain permission to spend certain tokens after it is no longer being used. If the contract or website is compromised, that permission can become dangerous.
Personal data theft
A leaked address, telephone number or financial information can enable highly targeted attacks. Keeping the value of one’s holdings private is part of good security.
A simple method for each type of use
For learning with a small amount
- use an authorised platform and strong authentication
- create a separate wallet for testing
- keep only a small amount in the wallet connected to applications
- learn to read a transaction in a blockchain explorer
For regular DeFi use
- use a hardware wallet
- separate the main wallet from the interaction wallet
- limit approvals
- verify the contract address
- keep a dedicated browser or browser profile
- test with a small amount first
For holding a significant portfolio
- favour a cold-storage architecture
- consider several keys or a multisignature setup
- document the recovery process
- plan for transmission or inheritance
- avoid concentrating all value behind a single seed phrase
- test the procedure without exposing the secrets
Security should be proportionate. A system so complex that its owner can no longer use it becomes a risk in its own right.
Ten habits to adopt
- Never share the seed phrase or private key.
- Enable strong authentication on platforms.
- Use unique passwords.
- Download applications from their official source.
- Check the website address before connecting a wallet.
- Read the network, amount and action before signing.
- Test new addresses with a small amount.
- Separate long-term holding from Web3 interaction.
- Revoke approvals that are no longer needed.
- Keep holdings and storage arrangements private.
How to check a transaction before signing
Before approving anything, take a few seconds to examine:
- the network being used
- the recipient address
- the token and amount
- the fees
- the contract being called
- the nature of the approval
- the source of the link or request
If the interface does not make the action understandable, stop and verify. A legitimate transaction can wait a few minutes. A malicious one often relies on urgency.
What should you do if a wallet appears compromised?
If the seed phrase has been disclosed
Treat the wallet as permanently compromised.
- create a new wallet on a trusted device
- generate a new recovery phrase
- transfer any remaining assets to the new address
- do not reuse the old seed phrase
- check associated accounts and networks
- retain evidence and transaction identifiers
Act carefully. An attacker may be monitoring the address and automatically withdrawing incoming funds.
If a malicious approval was signed
- disconnect the wallet from the website
- check active approvals
- revoke suspicious approvals
- move significant assets if doubt remains
- check the device and extensions used
Disconnecting from a website does not necessarily revoke permissions already recorded on the blockchain.
If a platform account has been compromised
- contact the platform through its official website
- change the password from a clean device
- revoke sessions and API keys
- secure the associated email address
- check recovery methods and strong authentication
- report the incident to the authorities when necessary
Checking a platform’s regulatory status
Since 2 July 2026, crypto-asset service providers operating in France must come under the MiCA regime.
The AMF publishes a whitelist of authorised firms as well as lists of unauthorised websites. On 8 July 2026, it stated that 38 names had been added to its crypto blacklist since the start of the year.
Appearing on a whitelist does not remove market risks or user error. It does at least confirm that the provider has a status that permits it to supply the services concerned.
Understanding remains the most useful expertise
In wallet training, technical handling is generally not the main obstacle. The difficulty lies in vocabulary and mental models: confusing a wallet with an account, an address with a key, or a signature with a password.
Once these distinctions are understood, security rules become more logical and easier to remember.
The objective is not to frighten users. It is to give them enough understanding to recognise an abnormal request and stop before approving it.
In summary
A wallet protects the keys that control assets recorded on a blockchain. The recovery phrase generally gives access to all associated accounts and must never be shared.
The level of security should depend on the intended use and the amount involved. An interaction wallet may hold very little, while a significant portfolio deserves a dedicated solution, carefully designed backups and a recovery procedure.
The best reflex is simple: when a request is urgent, incomprehensible or asks for a secret, do not sign or send anything.
Learn to use a wallet without unnecessary risk
A guided demonstration can explain wallet creation, networks, transactions, signatures and the main scams without using significant funds.
Take action
Learn the right habits in a guided setting
A practical educational format adapted to your level and context.
Discover the wallet and security workshopFrequently asked questions
Where are crypto-assets stored?
They are recorded on the blockchain. The wallet manages the keys that control the associated addresses.
What is the difference between a private key and a seed phrase?
A private key controls an account. A seed phrase generally generates and restores several keys and accounts within a wallet.
Can a hardware wallet be hacked?
No device is invulnerable. It significantly reduces certain risks, but a user can still sign a malicious transaction or disclose their recovery phrase.
Should you keep assets on an exchange?
It depends on the amount, the intended use and your ability to manage keys yourself. Self-custody provides more control, but also more responsibility.
Does disconnecting from a website remove its permissions?
No. Approvals recorded on a blockchain may remain active. They need to be checked and revoked separately when appropriate.