The single biggest cause of lost crypto isn't sophisticated hacking — it's simple, preventable mistakes.

Your seed phrase is the master key

If you hold crypto in a self-custody wallet, your 12-24 word seed phrase is the only thing standing between you and total loss. Anyone who has it can move your funds — no password, no ID, no second step required. Never type it into a website, never store it in a photo, email, or cloud note, and never share it with "support staff" — no legitimate support agent will ever ask for it.

Two-factor authentication (2FA)

Turn on 2FA everywhere it's offered — ideally using an authenticator app rather than SMS, since phone numbers can be hijacked ("SIM swapped"). This adds a second barrier even if your password leaks in an unrelated data breach.

Common attack patterns to watch for

  • Fake browser extensions or wallet apps that mimic real ones
  • Phishing emails or texts that link to a lookalike login page
  • Unsolicited "support" contacts asking you to share your screen or seed phrase

A healthy dose of suspicion toward anything urging you to act immediately — "verify now or lose access" — will filter out most of these attempts before they succeed.