# A Beginner's guide to How to Store your Crypto safely

By [Shanzson](https://paragraph.com/@shanzson) · 2023-02-21

---

First you need you understand that ultimately there are three ways to store your crypto-

1.  Centralized exchanges like Binance, Coinbase, Kucoin, etc.
    
2.  Wallet apps like Metamask, TrustWallet, WalletConnect, etc.
    
3.  Hardware wallets like Trezor, Ledger, etc.
    

As you might have guessed, I have listed the types above in increasing order of safety for storing your crypto. This means 1 < 2 < 3 in terms of the safety of storing your crypto. But again, each type comes with its own security risks, which cannot be overlooked if you really care for your crypto!

Let's look at them one by one:

1\. The Centralized Exchanges
-----------------------------

The centralized exchanges (or CEXs) are where most people buy their crypto. It's because these platforms make it as easy as possible to convert native currencies such as USD, INR, and JPY to cryptocurrency. But this convenience comes at a cost. And it comes at a cost that is quite massive. In the crypto world, there is a famous saying:

> "_Not your keys, not your crypto._"

The keys (specifically the private keys) which are like your computer generated passwords for your account, belong to the centralized exchanges and not you when you keep your crypto here. It gives the centralized exchanges the ultimate spending/transfer rights of your crypto. This means that they can transfer your crypto anywhere on the blockchain without your permission or without you even noticing.

This is what exactly happened in case of the [FTX exchange fraud](https://www.coindesk.com/layer2/2022/11/09/8-days-in-november-what-led-to-ftxs-sudden-collapse/). You can also checkout the [Quadriga CX scam](https://news.bitcoin.com/canadian-regulator-collapsed-crypto-exchange-quadrigacx/) which also has an exclusive Netflix documentary to its credit. Due to this, there is something called “_Proof of Solvency_” or “_Proof of Reserves_” which the CEXs have been under pressure to undergo lately, in order to prove their customers that their platform does have the amount of crypto that it claims to have.

Moreover there are other risks related to CEXs. Due to regulatory uncertainty in various countries, the [governments](https://beincrypto.com/centralized-exchanges-cannot-protect-customers-from-government-says-kraken-ceo/) can order the CEXs anytime to cease the assets of any customer. At times it can also happen that CEXs themselves [freeze](https://cryptoadventure.com/why-do-exchanges-freeze-users-crypto-funds/) the assets of unsuspecting customer who might or might not have done anything wrong or suspicious.

On top of it, there are mind numbing reveals from CEXs everyday, such as WazirX revealing that they they are actually storing everyone's crypto on Binance. This could mean that unlike a traditional CEX, there are two points of failures here due to which you can lose your crypto: first- WazirX itself and second- Binance. So you need to trust both these entities now for keeping your crypto safe. Which is a Halloween nightmare.

### Can CEXs be hacked?

Yes. There have been cases where the platforms of CEXs themselves were hacked which resulted in the CEXs losing user's crypto to attackers. Some exchanges do ensure to refund their users for the crypto hacked, but its not always guaranteed. Checkout the top 10 crypto exchange hacks in history.

[https://crystalblockchain.com/articles/the-10-biggest-crypto-exchange-hacks-in-history/](https://crystalblockchain.com/articles/the-10-biggest-crypto-exchange-hacks-in-history/)

### What are some of the best practices for CEX users?

Some of the best practices are-

1.  Keep a strong password for your CEX account as well as the email account associated with it.
    
2.  Enable Two-Factor authentication.
    
3.  Enable Biometric verification.
    
4.  Check if your exchange has undergone a foolproof Proof of Reserves or Proof of Solvency audit. If yes then it is a good sign otherwise it isn’t.
    
5.  Watch out for any red flags or report against the CEX operations or its reserves on [twitter](https://www.twitter.com), [coindesk](https://www.coindesk.com) or other news sources so that you can act before anything goes wrong.
    

2\. Enter the Wallet apps (aka Hot wallets)
-------------------------------------------

If you are a blockchain developer then you must have already used or interacted with one of these wallet apps. These wallet apps are the ones that give you true ownership of your crypto because now you really "_own_" or have the private keys of your crypto. This means that only you can spend and transfer your crypto on blockchain.

These are safer than CEXs. And no government can cease this crypto by ordering the wallet company because ultimately it is indeed you who is in [control](https://ethereum.stackexchange.com/questions/39954/does-metamask-store-private-key-on-server-or-anywhere-else) of the private keys and not the wallet apps. But their downside is that they are not very easy to use and understand for a new user. It requires a basic level of technical understanding, such as the gas amount you need to pay for transactions and the networks of blockchains to send and receive crypto on.

If you lose your private key, or if it gets leaked due to some reason, or if you succumb to a phishing attack- you can still lose all of your crypto on wallet apps.

Note: You can always withdraw your tokens from a CEX to a wallet app.

### Can Wallet apps be hacked?

Yes. There have been cases where people lost their crypto from wallet apps even if they were dead sure that they had not given their private keys to anyone nor they were a victim of a phishing attack.

Such as in the case of Phantom wallet on Solana blockchain which was the most popular wallet on that blockchain which lost [4 Million dollars](https://www.coindesk.com/business/2022/08/10/phantom-says-its-systems-were-not-compromised-in-4m-hack/) in its hack (which is still way lesser and rarer than CEXs hacks!) The cause of these attacks was not fully discovered but some of the experts claimed that it involved storing the user's private keys in a database and that the database was compromised in an attack.

Ideally, it is not expected that a wallet app stores your private key. It is known and given only to you. But you never know!

In another incident, the wallet apps that used the Profanity tool to generate the wallet address were insecure due to a bug in the tool. This resulted in about [3.3 Million dollars](https://cointelegraph.com/news/profanity-tool-vulnerability-drains-3-3m-despite-1inch-warning) getting hacked.

### What are the best security practices for wallet apps?

1.  Write the seed phrase of your wallet on a paper and store it in a safe place. It is even better if you remember it instead. This is because the seed phrase is equivalent to getting access to your wallet and its private key.
    
2.  Do not store the backup of the seed phrase of your wallet nor its private key in your computer or phone. This is because a virus or malware is all an attacker needs to access them.
    
3.  Do not connect your wallet to websites you do not trust.
    
4.  Do not sign any transaction or messages with your wallet apps if you do not understand the message or find it suspicious. This is because signing a malicious transaction can give approval to an attacker to steal all the funds in your wallet.
    
5.  Keep rotating your wallet apps and accounts by moving your funds to avoid any chance of private key leaks threatening your crypto.
    

3\. The Hardware wallets (aka the cold storage)
-----------------------------------------------

These wallets are hardware devices specifically made to store your crypto. These are considered by far the safest way to store your crypto. But it is not always very easy to get your hands on a good hardware wallet in your country such as Trezor and these usually are quite expensive for an average user.

If you have to store a large amount of crypto then hardware wallets should be the go to solution for storing your crypto. But again, there are good security practices that you must follow, such as buying a hardware wallet from the official company website and not from platforms like Amazon.

### Can Hardware wallets be hacked?

It's tough, but [not impossible](https://www.wired.com/story/cryptocurrency-hardware-wallets-can-get-hacked-too/). Usually, it requires physical access to these wallets in order to hack them. Some of these wallets offer an anti-thief feature that they claim disallows such attacks.

There were some concerns when the Ledger database was [hacked](https://www.cryptovantage.com/news/is-ledger-still-safe-everything-we-learned-from-last-years-hack/), which is considered one of the safest hardware wallets (although no crypto was lost or hacked).

### What are the best security practices for Hardware wallets?

1.  Make sure that the hardware wallet is a standard one and has been stress tested by many.
    
2.  Enable all the security features offered by your hardware wallet such as biometric verification.
    
3.  Do not sign any unknown or suspicious transactions from your hardware wallet as it can result in you losing your crypto.
    
4.  Keep your hardware wallet in the safest place possible so that it’s quite impossible for attackers access it physically.
    
5.  Ensure that your hardware wallet was ordered from a trusted source and that its seed phrase or private key was not compromised in its journey from source to the destination address.
    

### Final Thoughts

Ufff. That’s a lot to digest for a newbie. Always do your own research. Or hire someone good to do that research. Still, you can check [this](https://officercia.mirror.xyz/p1ieZdxQWH4yHCNOXNPHyT8So1cY0X_wMGKwdmavi7s) out to dive deeper.

At the end of the day, it’s you who have to control and store the red chakra safely, or the Nine Tailed Fox can leak out and cause havoc :)

---

*Originally published on [Shanzson](https://paragraph.com/@shanzson/a-beginner-s-guide-to-how-to-store-your-crypto-safely)*
