Cold storage reduces online exposure
A hardware wallet is one common approach: it stores private keys in a dedicated device and signs transactions there. You still need to verify what you are approving on the device screen.
A clear, independent checklist for anyone about to send crypto, swap tokens or connect a wallet. Know what to check before you approve a transaction.
Three short, realistic situations. Choose what you would do and get a practical explanation. This is a learning exercise, not a score or a guarantee.
A message claims your wallet will be frozen unless you act in ten minutes.
A DApp asks for unlimited token approval, but you expected a small swap.
After a loss, an “on-chain expert” guarantees recovery for an $80 advance fee and remote access to your device.
When something feels urgent or unclear, pause. Verify through a separate official route, read the exact transaction, and never share recovery words. This exercise does not inspect your wallet or determine whether a real message is safe.
Built from public consumer guidance: FBI Operation Level Up · FTC consumer advice · FBI IC3 cryptocurrency guidance.
Before confirming a transaction, understand where it goes, which network it uses and what permission you are granting. Your wallet is the signing tool; the transaction details still need your attention.
A hardware wallet is one common approach: it stores private keys in a dedicated device and signs transactions there. You still need to verify what you are approving on the device screen.
If a recovery phrase is lost, exposed or entered on a fake website, a device alone may not protect your funds. Anyone with the phrase can usually restore the wallet.
Every setup involves trade-offs between convenience, security and recovery. No wallet type removes risk.
Think about what you need to protect, how often you transact, and what you could safely recover if a device is lost.
Buy from the manufacturer or an explicitly authorized seller. Confirm setup instructions using the maker’s official website.
Follow the manufacturer’s guidance and confirm you understand the recovery process before storing meaningful value.
Small pauses can help prevent costly mistakes. Use this as a reminder, not a guarantee of safety.
Scammers impersonate real wallet brands and support teams. These examples are general warnings and do not imply wrongdoing by the named brands.
A stranger promises to trace or restore lost crypto, then asks for an upfront fee, remote access or your recovery phrase. Recovery-fee demands are a serious red flag.
Fake support accounts, sponsored search results and copycat apps can imitate MetaMask, Trust Wallet, Coinbase/Base, Bitget, OneKey and others.
An unsolicited airdrop or token may lure you to a malicious site or a transaction you do not understand. A token’s name or logo does not prove it is legitimate.
Choose a wallet to see common impersonation patterns and practical checks.
An impersonator may offer to “fix” a wallet issue, ask for an unlock fee, or send an airdrop link or form that requests your recovery phrase. They may also direct you to a phishing site.
Copycat apps may reuse a wallet’s name and icon to trick people into importing a wallet. Fake support may contact you by text, phone, or social media and claim you need an upgrade, verification, or recovery.
Imitation apps or tokens can use names similar to popular assets. A fake promotion may ask you to send USDT, connect to a DApp, or scan a QR code. Matching token names do not mean matching contract addresses.
A replaced or tampered device, or a card with a pre-written recovery phrase, could expose the wallet to someone else. Fake firmware pages may also imitate update instructions.
Fake sites, texts, QR codes, and support accounts use urgency to push you to log in, connect a wallet, or reveal sensitive information. Fake ads may lead to copycat download pages.
Scammers may pose as support on social platforms or direct you to fake extensions and websites. They may also ask you to sign an unfamiliar message or approve a broad token allowance.
Scammers may misuse Base or Coinbase branding to promote fake tokens, early access, or reward campaigns and then ask you to connect a wallet, sign, or reveal recovery information. An unsolicited token doesn’t require visiting its linked site.
Impersonators may claim your wallet needs syncing, verification, or recovery. A phishing DApp may ask you to connect and sign a transaction that moves assets.
The video is hosted with this site. Click play to watch the FBI media kit; it may take a moment to start.
Source: FBI, Operation Level Up · English and translated captions based on the video transcript; timing is approximate. The audio is in English.
No. Crypto assets are recorded on their respective blockchains. A wallet stores or protects the keys that let you authorize transactions.
No device is risk-free. Fake apps, unsafe backups, malicious approvals, compromised computers and physical attacks can all create risk. Keep firmware and setup steps tied to the manufacturer’s verified instructions.
Assume the wallet may be compromised. From a trusted device and a verified wallet, seek reputable official guidance to move remaining assets to a newly created wallet with a new recovery phrase. Never send the exposed phrase to anyone for help.