Library · Keeping it safe
The five ways people actually lose crypto
Not hacks of the blockchain — losses come from a short, boring, well-documented list, and each one has a specific defence.
Crypto losses are imagined as sophisticated attacks on cryptography. In practice the cryptography holds, and the money leaves through a short list of ordinary failures. Knowing the list is most of the defence, because each entry has a countermeasure that is neither expensive nor clever.
One: the backup is gone. No dramatic event, no attacker. A phrase written on a receipt that was thrown out, a laptop replaced, a phone lost with a wallet on it and the words never written down at all, a house move, a flood, a death in the family with no instructions left. This is almost certainly the largest category of permanently lost crypto, and it is entirely self-inflicted and entirely preventable. The defence: the recovery phrase on paper or stamped metal, in at least two places that will not burn or flood together, never in a photo, a cloud note, a password manager entry or an email. And test it — restore the wallet from the written words onto a clean device once, so that you know the backup works before you need it to.
Two: the phrase is given away. Fake wallet apps, lookalike sites, "validate your wallet" pop-ups, a support agent in a private message, a "migration" that needs your words, an airdrop that requires them. The tell is invariant and simple: any request for a seed phrase is theft, because no legitimate service has any use for it. The defence: those words are never typed into anything except the wallet itself, restoring the wallet, on a device you control. Not into a website, not into a form, not to a person, not to us. If a phrase has ever been typed anywhere else, treat it as compromised and move the funds to a new wallet today.
Three: a transaction was approved that should not have been. This is the modern version, and it does not require your phrase at all. Interacting with a token contract usually means granting it permission to move that token from your wallet, often in unlimited amount and often for as long as the wallet exists. Sign a malicious one — from a fake mint, a fake airdrop, a cloned site — and the drain happens later, at a time of the attacker's choosing, with no further action from you. Note that a hardware wallet does not prevent this: you approved it, so the device signed it, exactly as designed. The defence: read what the wallet says you are signing, be suspicious of any transaction whose purpose you cannot state in a sentence, review and revoke old approvals periodically, and keep a separate wallet with a small balance for anything experimental. What is not in the wallet cannot be drained from it.
Four: the company holding it failed. Not a technical loss at all. Exchanges and lenders have frozen withdrawals, collapsed, been hacked, and gone into administration — repeatedly, across every cycle, including several that were large, well-known and widely trusted right up to the week they stopped. If a company can reset your password, they hold the keys and you hold a claim against them, which is worth what the company is worth. The defence is not "never use an exchange" — custody has real advantages and self-custody has real risks. It is to hold on an exchange only what you are actively using or genuinely prepared to lose, to prefer regulated entities where a claim means something, and to keep the long-term balance somewhere a corporate failure cannot reach. What "not your keys, not your coins" means is the longer version.
Five: the funds went somewhere unrecoverable. Sent on the wrong network, pasted to a wrong or substituted address, sent to a contract that cannot return them. Clipboard-hijacking malware exists specifically for this — it watches for a copied address and silently swaps in the attacker's, which looks approximately the same at a glance. Blockchain transactions are final, and no one can reverse them. The defence: verify the first four and last four characters of the address on the screen where you will sign it, confirm the network matches on both ends, and send a small test amount first for any transfer large enough to hurt. The test fee is the cheapest insurance available anywhere in this industry.
What is not on the list. Nobody has broken the cryptography. There is no fault in Bitcoin's or Ethereum's ledger being exploited to take coins from ordinary holders. Essentially every loss you will read about traces back to one of the five above — usually to a backup, a signature, or a company.
Which means the security work is boring, and that is the good news. Write the phrase down properly and store it in two places. Never type it anywhere. Read what you sign, and keep a separate wallet for anything speculative. Do not leave more on a platform than you would accept losing. Test every large transfer with a small one first. That is the whole of it, and it costs an afternoon.
Where to go next
From our directory. Each entry has a full listing with what it is good for and what to watch out for.
Czech hardware wallet maker; its firmware and hardware designs are open source.
Free tool for reviewing and cancelling the token approvals you have granted to smart contracts — the permission most wallet drains actually rely on.
Educational content, not financial advice. We are not a broker, exchange, custodian or adviser, and we never take custody of your assets. We will never ask for a seed phrase or private key. See the full disclaimer.