HomeLearning CentreRisk and SafetyCryptocurrency Security Basics

Cryptocurrency security comes down to a handful of habits: protecting your passwords, controlling access to your devices, understanding who actually holds your funds, and slowing down before you click anything. Most losses in this area do not come from clever hacking of the technology itself, but from someone persuading a person to hand over access.

This article explains those habits in plain terms. It is general educational material, and none of it is personal advice.

Passwords: the first lock on the door

A password is only useful if it is hard to guess and used in one place. Reusing the same password across several accounts means that a single leak anywhere can open all of them.

Long is better than complicated. A phrase of four or five unrelated words is easier for you to remember and harder for a machine to work out than a short word with a few symbols bolted on.

Avoid anything that could be found out about you: a pet’s name, a birth year, a street, a football team. Password manager software (a program that stores and fills your passwords behind one master password) is a common approach, and if you prefer a written notebook kept somewhere private, that is far better than reusing one password everywhere.

Two-factor authentication, explained simply

Two-factor authentication, often shortened to 2FA, means an account asks for two different kinds of proof before letting you in. The first is something you know, such as your password. The second is something you have, such as a code from an app on your phone or a small physical key.

The point is that a stolen password on its own is not enough. Someone would also need the second item, which is usually in your pocket.

Codes sent by text message are better than nothing, but they are the weakest common form, because phone numbers can be moved to another handset by someone impersonating you to a telco. Codes generated by an authenticator app, or a physical security key, are generally considered stronger.

One rule matters more than the rest: a genuine organisation will never ring you and ask you to read out a 2FA code. Those codes exist to keep other people out, including people claiming to be staff.

Wallets: who is actually holding the keys?

A digital asset “wallet” does not hold coins the way a leather wallet holds notes. It holds the keys that let you move assets recorded on a network. There are two broad categories, and the difference matters.

Custodial

A custodial arrangement means a third party holds the keys on your behalf, much as a bank holds your cash. It is convenient, and if you forget your password there is usually a recovery process. The trade-off is that you depend entirely on that organisation’s security, solvency and conduct.

Non-custodial

A non-custodial wallet means you hold the keys yourself, on your own device or on a dedicated hardware device. Nobody can freeze your access, but equally nobody can restore it. If the keys are lost, the assets are generally unrecoverable. Understanding which category you are dealing with is part of a wider due diligence habit, and it sits alongside the practical checks set out in our guide to evaluating a trading provider.

Seed phrases

A seed phrase (sometimes called a recovery phrase) is a list of ordinary words, usually twelve or twenty-four, that can rebuild a non-custodial wallet from scratch. Anyone who reads those words can take everything in the wallet, immediately and permanently.

Treat it like the deed to a house. Write it on paper, store it somewhere private, and consider a second copy in a separate secure location in case of fire or flood.

Never photograph it, never type it into a website, never email it to yourself, and never store it in a notes app or cloud drive. No support desk, no wallet developer and no government agency has any legitimate reason to ask for it.

Phishing and suspicious links

Phishing is a message designed to look like it came from an organisation you trust, in order to collect your login details. It arrives by email, text, phone call, social media or messaging app, and modern versions are well written and convincingly branded.

The reliable defence is not recognising a fake, it is refusing to use the path you were given. Do not click the link in the message. Instead, open a browser yourself and type the address you already know, or use a bookmark you saved earlier.

Before clicking any link, hover your mouse over it to see where it really goes. Look closely at the spelling of the domain, since a single swapped letter or an extra word is a common trick. Be especially careful with shortened links that hide the destination entirely.

Impersonation of brands and staff

Impersonation is one of the most common tactics used against people in your position, and it works because it is patient and polite rather than obviously aggressive.

A caller may know your name, your suburb and which platforms you have looked at, all gathered from data breaches or social media. They may claim to be from a support team, a compliance department, a bank’s fraud unit or a government body. Some scams are two-stage: one party takes money, then months later another calls offering to recover it for a fee.

Adopt a simple standing rule. Hang up, then ring back on a number you found yourself from an official source. A legitimate organisation will have no problem with this. Applying the same scepticism to money is sensible too, and our list of questions worth asking before depositing funds covers that ground.

Device protection

Your phone and computer are the doors to your accounts, so they deserve the same care as the accounts themselves.

Account recovery

Sort out recovery before you need it, not during a crisis. Check that the email address and phone number attached to each account are current, and that you still control that email.

Your email account is the master key to most other accounts, so it deserves your strongest password and its own two-factor authentication. If backup or recovery codes are offered, save them somewhere physical and separate from your devices.

If you believe an account has been compromised, act in order: change the password, sign out all active sessions, check that no forwarding rules or new devices have been added, then contact the organisation through its official channel and report the matter to the relevant Australian authorities.

Warning signs to recognise

Most attempts share the same fingerprints. Any one of these is reason enough to stop and verify independently.

Technology is not a substitute for judgement. Automated tools carry their own failure modes, as explained in our article on the risks of automated trading signals, and you can find further background material in the learning centre.

Summary