The single biggest cause of lost crypto isn't sophisticated hacking — it's simple, preventable mistakes.
Your seed phrase is the master key
If you hold crypto in a self-custody wallet, your 12-24 word seed phrase is the only thing standing between you and total loss. Anyone who has it can move your funds — no password, no ID, no second step required. Never type it into a website, never store it in a photo, email, or cloud note, and never share it with "support staff" — no legitimate support agent will ever ask for it.
Two-factor authentication (2FA)
Turn on 2FA everywhere it's offered — ideally using an authenticator app rather than SMS, since phone numbers can be hijacked ("SIM swapped"). This adds a second barrier even if your password leaks in an unrelated data breach.
Common attack patterns to watch for
- Fake browser extensions or wallet apps that mimic real ones
- Phishing emails or texts that link to a lookalike login page
- Unsolicited "support" contacts asking you to share your screen or seed phrase
A healthy dose of suspicion toward anything urging you to act immediately — "verify now or lose access" — will filter out most of these attempts before they succeed.