Crypto Wallet Security Basics

My Wallet
Crypto Wallet Security Basics

Most wallet losses come from shared seeds, fake apps, and rushed signatures—not from “hacked blockchains.” Security for a non-custodial wallet is mostly habits you control.

Quick answer

Protect a wallet like My Wallet by treating the seed phrase as the real key, installing only from official links, enabling app password / biometrics / auto-lock, and reading every send or dApp prompt before you sign. My Wallet is non-custodial: the app does not store your seed. Official support never asks for it.

What “secure” means for non-custodial wallets

In a non-custodial wallet you hold the keys. That is the point—and the responsibility.

LayerWhat it protectsWhat it does not replace
Seed phrase (offline backup)Restoring the wallet on a new deviceNothing—this is the master key
App password / biometricsSomeone opening the app on your phoneA stolen seed still drains funds
Auto-lockCasual phone accessMalware or phishing you approve
Official download sourceFake apps that harvest seedsYour own confirmation mistakes

Face ID can feel like “2FA,” but for self-custody the seed still sits above every device lock. See Two-factor authentication for crypto wallets.

Habit 1: Guard the seed phrase

  1. Write the words offline when you create the wallet.
  2. Check order and spelling before you fund it.
  3. Store the backup where only you can reach it—paper or another offline medium beats a camera-roll screenshot.
  4. Never type the phrase into a website, “support” chat, or airdrop form.

If someone has the seed, they do not need your phone. Full primer: What Is a Seed Phrase? and How to Back Up Your Wallet.

Habit 2: Install only from official sources

Fake wallet apps clone brands (My Wallet, MetaMask, Trust Wallet, Phantom, Keeper, and others) and ask for your seed on first open.

  • Prefer links you typed or bookmarked: get.mywallet.io
  • Cross-check publisher names in app stores against official sources
  • Ignore DMs that send “urgent” download links

Details: How to Spot a Fake Wallet App.

Habit 3: Turn on in-app protections

Practical settings in My Wallet:

  • Strong password / passcode for access and confirmations
  • Biometrics (Face ID / fingerprint) when your device supports them
  • Auto-lock after inactivity
  • Optional Remember Passcode only when you understand the convenience trade-off (available when biometrics are off)

These settings stop a borrowed phone from casually sending funds. They do not replace an offline seed backup.

Habit 4: Read every signature

Phishing and drainers win when you approve a transfer or contract call you did not mean to start.

  • Confirm network, asset, amount, and recipient on the confirmation screen
  • Reject prompts you did not initiate
  • Disconnect dApps you no longer use
  • Prefer small test sends to new addresses

Connecting safely: How to Connect to a dApp. Scam patterns: How to Avoid Crypto Phishing Scams.

Habit 5: Size risk by how you store funds

A practical split many people use:

Security is not a product badge. It is how you download, back up, and confirm.

Common mistakes

  • Screenshotting the seed “just for tonight”
  • Trusting search ads for “[wallet] download”
  • Believing support can “look up” your phrase
  • Approving unlimited token allowances without reading
  • Keeping your only backup on the same phone as the wallet

Download My Wallet

Download My Wallet to hold the keys and build habits that match that power.

FAQ

Is a free wallet unsafe?

No. Safety comes from custody model, download source, and your habits—not the sticker price. Network fees still apply on-chain.

Does My Wallet store my seed on a server?

No. Non-custodial means the phrase stays with you. Anyone claiming they can retrieve it for you is lying.

What should I do first after installing?

Back up the seed offline, enable password/biometrics and auto-lock, then send a tiny test before moving sizeable funds.

Helpful My Wallet guides