Crypto topics

Wallet Security

Find practical guides to wallet keys, recovery, signatures and spending permissions. Read the request's scope before connecting, signing or approving.

← All topics

Read the coverage

9 sourced articles, with the mechanisms and limits explained.

Useful definitions

Self-custody →

A custody arrangement in which the user controls the keys or authorization needed to move assets.

Token approval →

An onchain permission allowing a specified spender to transfer up to an allowance of tokens.

Phishing →

A deception that tries to make someone reveal a secret or authorize an action they did not intend.

Blockchain bridge →

A system that communicates or represents assets and messages across otherwise separate networks.

Private key →

A secret value used to create digital signatures that authorize actions for a blockchain account or output.

Public address →

A network-specific identifier used as a destination or reference for blockchain activity.

Seed phrase →

A human-readable recovery representation commonly used to derive a wallet’s root secret and many keys.

Background & primary sources

This desk collects published explainers, not a list of approved wallets or a guarantee that a transaction is safe. Its introduction helps you choose the next useful question. Each linked article keeps its own sources and dates; this collection update does not claim a new independent review of every guide.

Start with your question

Your questionRead nextWhat it helps separate
Where are my assets recorded?Crypto wallets explainedWallet interface, account records, keys and custody
What must stay secret?Seed phrase vs private keyRecovery material versus an individual signing key
What does this wallet request permit?Connection, signature and token approvalAccount access, authentication, permits and delegation
Why can a contract still spend a token?Token approvals explainedStanding allowance, spender and revocation

For shorter definitions, use self-custody, token approval and phishing.

Protect recovery before troubleshooting a request

Ethereum.org explains the wallet/account distinction; Bitcoin.org covers backups, device security and keeping wallet software current. Recovery procedures differ by wallet. Keep secrets out of support chats, unsolicited forms and permission-checking sites. A recovery phrase is not something a legitimate sign-in needs.

Read the permission, not just the button

In the conventional ERC-20 allowance model, setting a spender's limit and using it are separate operations. A signed ERC-2612 permit can create an allowance when submitted later; a deadline for submitting it is not automatically an expiry for the allowance.

MetaMask's advanced permissions are a different, supported-app smart-account flow. Do not assume every wallet offers those limits or every permission appears after connection. The guide above compares the mechanisms rather than treating every Sign button as a login.

A pause that has a purpose

  1. Open the intended service through an independently checked route. Do not follow an unsolicited rescue message.
  2. Identify whether the request shares an address, authenticates a session, authorizes spending or delegates account capabilities.
  3. Check the network and relevant contracts, asset, spender or recipient, amount and time limits against what you intended.
  4. For an old permission, check its actual current state. Disconnecting does not remove an ERC-20 allowance; an onchain revoke needs a fee and confirmation.

This routine cannot eliminate protocol, device, custody or market risk. A token-approval list is not a complete account-security audit, and changing a permission cannot undo an already completed transfer.

Sources

Collection introduction researched 5 October 2026; individual linked guides retain their own research histories.