← back to blog

Wallet hygiene: the habits that stop you losing everything

wallet-security token-approvals seed-phrase hardware-wallet wallet-ops

I run mobile proxy lines and a rack of Android phones for a living, so most of my week goes on one question. When this fails, how far does the failure reach. A dead SIM should cost one customer one port for an hour. It should never cost me the rack.

Wallets are that same question with a worse ending, because there is nobody to escalate to.

Almost nothing is lost to cryptography. The key does not get broken. What happens is that a permission gets granted, usually in about four seconds, usually months before anything visible happens, and then it sits there being valid.

So wallet hygiene is maintenance work. Same category as swapping a powered hub out before it starts dropping ports.

Separate by purpose, or the rest is decoration

The wallet holding anything you would be upset to lose does not connect to websites. Not for a balance check, not for a claim, not once.

A wallet that has never signed anything has no live permissions on it. Nothing to abuse, nothing to audit. That is the entire argument.

In practice that is three roles. A storage address that only ever receives and sends by hand. Working addresses that do the daily clicking, the swaps and the quests. And a fresh address for anything you have not touched before.

The third one is free and it is the one that gets skipped. Creating a new account inside a wallet you already have takes seconds and costs nothing until you fund it. Set that against the effort farmers put into a new browser profile with its own fingerprint and proxy. The address is the cheaper half of that job.

There is a genuine cost. A brand new address carries no history, and history is frequently what gets counted. So the fresh address is for prodding at things you do not trust yet, and the identity you build over months is a different wallet doing a different job.

The approval is the thing that moves the funds

When you swap a token, you do not send the contract your tokens. You give it permission to take them, in a separate transaction that most people sign without registering it.

Most interfaces request an unlimited allowance by default. Reasonable from their side, since you pay for it once and every later trade is cheaper. It is also why an active wallet accumulates a long tail of live permissions belonging to interfaces nobody has opened since 2024.

The permission has no expiry. It is not scoped to the trade you made. It survives closing the tab, deleting the bookmark and forgetting the project existed.

So the question worth asking is whether that contract still deserves standing permission every day from here on. After the team disperses. After the admin keys end up on an old laptop. After an upgradeable contract gets pointed somewhere new.

You granted an address. Addresses carry on working long after the people behind them stop paying attention.

A revoke routine you will actually run

Revoking is its own transaction. You set the allowance back to zero and pay gas for it. On a cheap chain that is small change. On Ethereum mainnet at a busy hour it can cost more than the tokens the approval covers, which is the honest reason stale approvals sit for a year.

Put it on a fixed day each month and run it like any other dull recurring job.

  1. Pull up your full address list, including the ones you are certain are clean.
  2. Run each through an approval checker, once per chain. Approvals are per token, per spender, per chain, so a wallet used across six chains has six lists, and clearing one tells you nothing about the other five.
  3. Revoke anything you have not used this month. Cheap chains first, where most of the list lives and the gas is trivial.
  4. Write down what you deliberately kept and why.

That last step matters. Skip it and you re derive the same decisions every month until you get bored and stop.

Signing a message is not free

This mechanism has moved fastest, and it catches people who are careful everywhere else.

A transaction costs gas and lands in your history where you can find it. A signature costs nothing, leaves no record you will ever go looking for, and shows up as a dialog you dismiss on the way to something else.

And a signature can create a permission on its own. Permit style signing exists so that approving a token can happen without its own onchain transaction. A real feature, and it saves everybody money. It also means an approval can now be granted by clicking sign on a message.

So a page asking you to sign to log in, sign to verify ownership, or sign to continue, while your wallet displays a block of hex, is asking for a blank cheque with the amount already filled in.

One line covers it. If the wallet cannot render it as a sentence you understand, do not sign. There is no exception for being in a hurry, and hurry is exactly when these arrive. Which is the other habit worth naming: never make a first time interaction under time pressure. Fake claim pages go live in the same hour as the real ones and buy ads against them, because that is the hour people click without reading.

The collection wide version for NFTs is the same mechanism with a wider blast radius, granted during a marketplace listing, which feels like admin rather than a decision.

Seed phrases, where there is no grey area

Paper. Two copies. Two locations.

Never a photo, because photos sync, and the account they sync into is guarded by a password and an SMS code. That is a far softer target than the wallet was.

Never typed into anything except the wallet application itself, during a restore that you started on purpose. Not a website. Not a form. Not a chat window. Not a support tool. Not a page telling you your wallet must be validated or migrated before you can claim.

There is no legitimate use for your seed phrase by anybody else. Developers cannot act on your behalf with it. Support cannot. The phrase is the wallet.

Which hands you one rule that needs no judgement at all, and those are rare. Every person who asks for your seed phrase is an attacker. Every one.

The loss I have watched most often has nothing to do with attackers. A house move. A leak. Somebody tidying a drawer who had no idea what the card was. A restore test proves the copies work: take a wallet with nothing in it, wipe it, restore from the card, check the same address comes back. An untested backup is a belief.

What a hardware wallet covers

One problem, and it covers it properly. The key is generated inside the device and never leaves. Transactions go in, signatures come out.

So a fully compromised computer, keylogger running, clipboard being swapped underneath you, a browser extension that updated itself overnight, still cannot extract the key. Nothing on the machine to take. Since a compromised machine is where most losses start, that removes a large slice of the problem.

Here is what it does not do.

It will sign a malicious transaction without hesitating. Connect it to a phishing page, press confirm, and the device has performed as designed. The press is the authorisation.

It does not solve blind signing. The screens are small, a complex transaction gets compressed into a summary that tells you very little, and confirming a truncated summary is the same leap of faith it would be in a browser.

It does not protect the phrase, which is still on paper somewhere and is still the whole wallet.

And it does nothing if you bought it used, or through a marketplace listing rather than the manufacturer. A device that arrives with a recovery phrase already printed on a card in the box is a mailbox for whoever printed it.

What I got wrong

I described a wallet as cold for about two years.

It had been connected to a site exactly once, early on, for a small claim. I remembered doing it and had filed it as a one off.

What I never considered was the residue. That single connection left a live approval on the wallet I had decided was untouchable, and it sat there for roughly a year while I carried on calling that wallet offline.

I found it because I finally ran a sweep across every address I own rather than the ones I expected to be dirty. Twenty minutes for the whole set. I had avoided it for a year assuming it was an afternoon.

Nothing came of it. That is luck, and luck is not a control.

The real failure sat one level up. I had a label in my head that had stopped describing the behaviour, and the label kept winning. Cold is a measurement of what a wallet has done, and I had been using it as a name.

Where all of this stops working

None of it recovers anything.

Once a transaction confirms, that is the end of the process. No reversal, no chargeback, nobody to escalate to, no realistic path back for an individual. Tracing is real work that real people do, and it is still a long way from getting funds returned.

So every habit above is worth precisely what it prevents. It stays unrewarding right up until the day it turns out to be the only thing that mattered.

One more follows directly. Anybody who contacts you after a loss offering to recover the funds is the second theft. The first took the wallet. This one takes whatever is left while you are still panicking.

More wallet ops guides and tested tool picks are on the site.

Get new guides and videos first — join the Telegram channel.

need infra for this today?