Start with the wallet’s actual boundaries
A non-custodial wallet generally gives the holder direct authority to sign transactions. That control is useful, but it also means there may be no support desk capable of reversing a transfer. Before using any wallet, identify who controls recovery, which networks it supports, whether its software is open to inspection, and how updates are authenticated.
Protect recovery material offline
A recovery phrase can recreate the wallet. Anyone who obtains it may obtain the assets. Do not photograph it, paste it into cloud notes, email it, or enter it into a website reached through an advertisement or direct message. Store recovery material in a form that is physically durable and inaccessible to casual visitors.
- Write down the words accurately and verify the order while offline.
- Do not label the storage location with a public wallet name or balance.
- Think through fire, water, theft, and inheritance risks.
- Test the documented recovery process with an empty or low-value wallet before depending on it.
Treat token approvals as spending authority
A token approval can grant a smart contract permission to move an asset. Read the asset, network, contract, spender, amount, and expiration when available. An unlimited approval may exceed the task you intended. Reject unclear requests and inspect existing approvals through a reputable network-specific explorer or established revocation tool reached independently.
Use a deliberate transfer pause
- Confirm the destination through a second trusted channel.
- Match the asset and network on both sides.
- Check whether a memo, destination tag, or reference is required.
- Compare more than the first and last few address characters.
- Review the amount and fee in the wallet’s final signing view.
- When practical, send a small test and verify receipt before sending more.
Address-poisoning attacks can place look-alike addresses in transaction history. Never select a destination solely because it resembles a previously used address.
Separate high-risk browsing from signing
Keep wallet software, browsers, extensions, and the operating system updated from official sources. Remove extensions you no longer use. A dedicated browser profile—or for higher-value use, a dedicated device—reduces exposure to unrelated extensions and daily browsing. Hardware wallets can isolate keys, but the device screen still needs careful review.
Prepare for loss before it happens
Document which assets and networks exist without recording private keys in the same document. Decide who should know that the plan exists, how they can authenticate instructions, and what should happen if you are unavailable. Revisit the plan after changing devices, wallets, networks, or storage locations.