Public blockchain data only — we never ask for seed phrases, private keys or upfront fees.
No wallet data stored Runs in your browser
All prevention tutorials
Prevention Tutorial 20 2026-09-15 · 10 min read
Wallet Security Crypto Safety Audit Checklist: Twenty Minutes, Every Quarter

Nobody Hacks You. They Audit You First — and You Passed.

The quarterly audit that closes the doors you forgot were open.

Safety note: we never guarantee recovery and never ask for seed phrases, private keys, crypto payments or upfront unlocking fees. Anyone who does is running a second scam.
The short version

What this tutorial says in five lines

  • Most losses come from things that were left open months earlier, not from a clever attack today.
  • Approvals are permanent until revoked. A permission granted a year ago is still live.
  • Seed phrase exposure is binary. There is no partially safe way to have photographed it.
  • Two-factor authentication by SMS is a speed bump, not a control.
  • Twenty minutes a quarter closes the categories that account for most reported losses.

Why this matters

There is no single dramatic moment in most crypto losses. There is a permission granted a year ago, a screenshot taken for convenience, a reuse of the same address across experiments, an old session never signed out. A quarterly audit is worth more than any amount of daily caution, because it addresses what caution cannot: the state you left things in and then forgot about. Here is the full checklist, in the order that closes the most exposure per minute spent.

Why an audit beats vigilance

Vigilance is a continuous tax on attention, and attention is finite. It also fails predictably: it is lowest when you are tired, busy or excited, which is exactly when a decision matters most.

An audit is discrete. Twenty minutes, four times a year, reviewing a fixed list. It addresses the categories where risk actually accumulates — standing permissions, digital copies, hoarded address reuse, and credential hygiene — none of which are visible unless you go looking.

The audit does not require you to become more careful. It requires you to reverse four bad defaults once a quarter.

The checklist

Run top to bottom. The rows are ordered by how much exposure each item typically closes, and the first three account for the majority of avoidable loss.

If you only ever do three of these, do the first three.

Quarterly crypto safety audit — what to check and what a pass looks like
#CheckHowPass conditionTypical exposure closed
1Active token approvalsApproval checker, on every chain usedNo approval you cannot name the owner ofVery high
2Seed phrase digital copiesSearch your own devices, photos, notes, mail, cloudNo digital copy exists anywhereVery high
3Wallet separationConfirm a burner wallet is used for new sitesLarge balances never touch unverified pagesHigh
4Two-factor authenticationAuthenticator app, not SMS, on every money-adjacent accountNo SMS-only accounts remainHigh
5Password reuseCheck the same password against critical accountsEvery critical account has a unique passwordHigh
6Browser extensionsReview the full extension list and their permissionsNothing installed you cannot explainModerate
7Address reuseStop reusing any address previously exposedA fresh address per counterpartyModerate
8Backup of critical dataConfirm recovery material is offline and readableA restore test has actually been doneModerate
9Unsolicited assetsReview unexpected tokens or NFTs receivedNone in a wallet holding real valueModerate
10Contact surfaceReview what you have published about holdingsNo public balances, amounts or addressesModerate
11Device hygieneOS and browser updates installedAutomatic updates enabledModerate
12Recovery planWritten steps for a loss, stored offlineYou know the first three actions by heartLow but compound
Quarterly crypto safety audit — what to check and what a pass looks like

Where the exposure actually sits

Not every checklist item carries equal weight. This chart shows the relative contribution of each category to reported avoidable losses, which is the basis for the ordering above.

The distribution explains why the audit fits in twenty minutes: two categories dominate, and both are quick to inspect once you know where to look.

Data

Which categories account for avoidable loss

Relative share of avoidable unauthorised loss, by category

Standing token approvals 41
Seed phrase exposure 27
Account credentials / 2FA 12
Malicious extension or app 8
Address poisoning 6
Unsolicited token contracts 3
Device malware 3

Reading: Approvals and seed exposure together account for roughly two thirds of avoidable loss — and both are inspectable in under five minutes each. That ratio is why this audit is worth doing rather than merely reading.

The four defaults worth reversing permanently

An audit is a periodic action. These four changes are one-time, and each removes a class of risk rather than an instance of it.

They are the highest-leverage things in this tutorial, because they keep working when nobody is paying attention.

  • 01Stop digitising recovery material. Written offline, in one place you control, never photographed, never in a cloud note, never sent to yourself.
  • 02Stop approving unlimited allowances. Approve a specific amount, and approve it again next time. The extra click is the entire cost.
  • 03Stop reusing one wallet for everything. A burner for experiments and a cold wallet for value, permanently separated.
  • 04Stop treating an inbound message as an opportunity. Anything about your holdings that arrives unsolicited is a probe or a fraud.

These four changes take about an hour in total and remove the two largest categories in the chart above. Nothing else in this tutorial comes close on return.

Testing the plan before you need it

A recovery plan you have never tested is a plan you do not have. The two exercises below surface the problems while they are inconvenient rather than while they are fatal.

Neither requires any money or any risk, and both take ten minutes.

  • 01Restore test: on a spare device, restore a small wallet from your written backup. If you cannot, your backup has failed — and better to learn that today than during an emergency.
  • 02First-hour drill: write down the first five actions you would take after discovering a drain, from memory. Then check them against this site’s first-hour tutorial. Most people miss the revocation step and the card dispute.
  • 03Contact test: confirm you can reach your bank’s fraud line and your exchange’s compliance contact without searching for them under pressure.
  • 04Evidence test: confirm your evidence folder exists and is on a second device, so that a compromised machine does not take your records with it.

The restore test is the one people skip and the one that matters most. A seed phrase you cannot read, or a backup you cannot actually restore from, provides exactly no protection.

Scheduling it

The audit only works if it recurs. Put it in the same category as a financial review rather than in the category of things you will get to.

Four dates a year, tied to something you already track — quarter ends, tax dates, or a repeating calendar entry — and run the table top to bottom each time.

  • 01Set a recurring reminder for the same four dates every year, and treat it as a commitment rather than an intention.
  • 02Run rows 1 to 3 first, every time. They are the ones with the highest exposure and they take under five minutes.
  • 03Do it on a device you trust, and never follow links from an email or a message while auditing.
  • 04Keep a short written log of what you revoked and when. It is useful evidence if something happens, and it takes one line per quarter.
  • 05If you make a mistake during a quarter — approved something unfamiliar, entered a phrase somewhere — run the audit immediately rather than waiting for the scheduled date.

The visual summary

Everything above, reduced to the four stages that matter for this topic. If you only look at one thing on this page, look at this.

Infographic supporting Crypto Safety Audit Checklist: Twenty Minutes, Every Quarter
Crypto Safety Audit Checklist: Twenty Minutes, Every Quarter — supporting infographic
Stage map

Where this fits in the pattern

01

Before contact

Nothing has happened yet. This is when every tutorial here is most useful and costs you nothing but reading.

02

During the approach

The script is running. The verification tests in this tutorial are designed to be run here, neutrally, without confrontation.

03

At the money request

The decisive moment. Any request for funds, fees, taxes or unlock deposits is the end of the script, not a stage of it.

04

After a loss

Prevention is over; evidence work begins. Preserve, report, and never pay a second fee to recover the first.

Common questions

Quarterly is enough for the full checklist, with an immediate run whenever something out of the ordinary happens — approving an unfamiliar contract, entering a seed phrase anywhere, or receiving an unsolicited token. The approval and seed-phrase checks in particular should not wait for the scheduled date.
Active token approvals, on every chain you have used. They are permanent until revoked, they are the largest category of avoidable loss, and checking them takes a few minutes. Seed phrase exposure is the close second — and unlike approvals, it cannot be undone once it has happened.
No. SMS codes can be intercepted or obtained through SIM-swap attacks, which is why the checklist places authenticator apps ahead of them. SMS is a meaningful improvement over nothing, but it should be treated as a speed bump rather than a control.
Next step

Audit the address itself, not just the habits

Run your address through the tracer to see every outgoing flow, contract interaction and approval exposure the public ledger already records for it.

Primary sources and further reading

External links open in a new tab so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.

Share this tutorial

Prevention only works if it reaches people before the contact does.

Disclaimer: this tutorial is general information, not legal, financial or recovery advice, and is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.