Keys are everything
A crypto wallet does not actually hold coins. The coins stay on the blockchain. What a wallet holds is the private key that lets you authorise moving them. Anyone who obtains that key can move the funds, and there is usually no bank to call and no chargeback to request. Good security is therefore mostly about protecting keys and the things that unlock them.
Custodial and self-custody wallets
When you keep funds in an exchange account, the exchange manages the keys on your behalf. This is custodial storage: your job is to protect the account login. When you use your own wallet app or device, you hold the keys yourself. This is self-custody: your job is to protect the keys directly. Both approaches have trade-offs, and many people use a mix.
Hot and cold wallets
| Hot wallet | Cold wallet | |
|---|---|---|
| Connection | Keys live on an internet-connected device | Keys stay offline, for example on a hardware device |
| Convenience | Quick for everyday transfers | Slower; needs the device to sign |
| Exposure | More exposed to malware and phishing | Much less exposed to remote attacks |
| Typical use | Small, frequently used balances | Longer-term holdings |
Seed phrases
Most self-custody wallets give you a seed phrase (also called a recovery phrase) of 12 or 24 words. It can recreate all of the wallet's keys on any compatible device. Treat it as the master key.
- Write it down on paper or stamp it into metal. Store it somewhere private and protected from fire and water.
- Never type it into a website, chat, email or form. No legitimate support team will ask for it.
- Avoid photos, screenshots, cloud notes and password managers that sync by default, unless you fully understand the trade-offs.
- Consider keeping a second copy in a separate secure location.
Protecting your exchange account
- Use a unique, long password. A password manager makes this practical.
- Turn on two-factor authentication (2FA). An authenticator app or hardware security key is generally stronger than SMS codes, which can be intercepted through SIM-swap attacks.
- Enable a withdrawal address allowlist where available, so funds can only be sent to addresses you have approved in advance.
- Review active sessions and devices and sign out of any you do not recognise.
- Protect your email. Your email account can often reset your exchange password, so give it the same care.
The account protections Zenvorika offers are described on the security page.
Recognising phishing
Most losses come from being tricked rather than from broken cryptography. Warning signs include:
- a message creating urgency, such as "your account will be closed in one hour";
- a link to a login page whose address is slightly misspelled;
- someone offering to "double" your crypto or asking you to send funds to receive a reward;
- a "support agent" who contacts you first and asks for your 2FA code, password or seed phrase;
- a browser extension or app downloaded from an unofficial source.
When in doubt, stop, close the message and navigate to the site yourself by typing the address you already know.
Safe withdrawal habits
- Copy and paste addresses, then check them. Some malware swaps a copied address for the attacker's. Compare the first and last several characters.
- Match the network. The receiving wallet must support the network you choose. A mismatch can mean lost funds.
- Send a small test first when using a new address, then send the rest once it arrives.
- Include a memo or tag if required. Some assets need one to credit the right account.
Build habits before balances
It is easier to learn good routines while little is at stake. The practice account on the trading terminal at /trade/ uses virtual funds only, so while little is at stake it is a good time to set up 2FA and a withdrawal allowlist on any other exchange accounts you already hold.
Crypto assets are highly volatile and you may lose all the capital you invest.
Practise without risk to real funds
The practice account trades live prices with virtual USDT.