What this tutorial says in five lines
- Most losses come from things that were left open months earlier, not from a clever attack today.
- Approvals are permanent until revoked. A permission granted a year ago is still live.
- Seed phrase exposure is binary. There is no partially safe way to have photographed it.
- Two-factor authentication by SMS is a speed bump, not a control.
- Twenty minutes a quarter closes the categories that account for most reported losses.
Why this matters
There is no single dramatic moment in most crypto losses. There is a permission granted a year ago, a screenshot taken for convenience, a reuse of the same address across experiments, an old session never signed out. A quarterly audit is worth more than any amount of daily caution, because it addresses what caution cannot: the state you left things in and then forgot about. Here is the full checklist, in the order that closes the most exposure per minute spent.
Why an audit beats vigilance
Vigilance is a continuous tax on attention, and attention is finite. It also fails predictably: it is lowest when you are tired, busy or excited, which is exactly when a decision matters most.
An audit is discrete. Twenty minutes, four times a year, reviewing a fixed list. It addresses the categories where risk actually accumulates — standing permissions, digital copies, hoarded address reuse, and credential hygiene — none of which are visible unless you go looking.
The audit does not require you to become more careful. It requires you to reverse four bad defaults once a quarter.
The checklist
Run top to bottom. The rows are ordered by how much exposure each item typically closes, and the first three account for the majority of avoidable loss.
If you only ever do three of these, do the first three.
| # | Check | How | Pass condition | Typical exposure closed |
|---|---|---|---|---|
| 1 | Active token approvals | Approval checker, on every chain used | No approval you cannot name the owner of | Very high |
| 2 | Seed phrase digital copies | Search your own devices, photos, notes, mail, cloud | No digital copy exists anywhere | Very high |
| 3 | Wallet separation | Confirm a burner wallet is used for new sites | Large balances never touch unverified pages | High |
| 4 | Two-factor authentication | Authenticator app, not SMS, on every money-adjacent account | No SMS-only accounts remain | High |
| 5 | Password reuse | Check the same password against critical accounts | Every critical account has a unique password | High |
| 6 | Browser extensions | Review the full extension list and their permissions | Nothing installed you cannot explain | Moderate |
| 7 | Address reuse | Stop reusing any address previously exposed | A fresh address per counterparty | Moderate |
| 8 | Backup of critical data | Confirm recovery material is offline and readable | A restore test has actually been done | Moderate |
| 9 | Unsolicited assets | Review unexpected tokens or NFTs received | None in a wallet holding real value | Moderate |
| 10 | Contact surface | Review what you have published about holdings | No public balances, amounts or addresses | Moderate |
| 11 | Device hygiene | OS and browser updates installed | Automatic updates enabled | Moderate |
| 12 | Recovery plan | Written steps for a loss, stored offline | You know the first three actions by heart | Low but compound |
Where the exposure actually sits
Not every checklist item carries equal weight. This chart shows the relative contribution of each category to reported avoidable losses, which is the basis for the ordering above.
The distribution explains why the audit fits in twenty minutes: two categories dominate, and both are quick to inspect once you know where to look.
Which categories account for avoidable loss
Relative share of avoidable unauthorised loss, by category
Reading: Approvals and seed exposure together account for roughly two thirds of avoidable loss — and both are inspectable in under five minutes each. That ratio is why this audit is worth doing rather than merely reading.
The four defaults worth reversing permanently
An audit is a periodic action. These four changes are one-time, and each removes a class of risk rather than an instance of it.
They are the highest-leverage things in this tutorial, because they keep working when nobody is paying attention.
- 01Stop digitising recovery material. Written offline, in one place you control, never photographed, never in a cloud note, never sent to yourself.
- 02Stop approving unlimited allowances. Approve a specific amount, and approve it again next time. The extra click is the entire cost.
- 03Stop reusing one wallet for everything. A burner for experiments and a cold wallet for value, permanently separated.
- 04Stop treating an inbound message as an opportunity. Anything about your holdings that arrives unsolicited is a probe or a fraud.
These four changes take about an hour in total and remove the two largest categories in the chart above. Nothing else in this tutorial comes close on return.
Testing the plan before you need it
A recovery plan you have never tested is a plan you do not have. The two exercises below surface the problems while they are inconvenient rather than while they are fatal.
Neither requires any money or any risk, and both take ten minutes.
- 01Restore test: on a spare device, restore a small wallet from your written backup. If you cannot, your backup has failed — and better to learn that today than during an emergency.
- 02First-hour drill: write down the first five actions you would take after discovering a drain, from memory. Then check them against this site’s first-hour tutorial. Most people miss the revocation step and the card dispute.
- 03Contact test: confirm you can reach your bank’s fraud line and your exchange’s compliance contact without searching for them under pressure.
- 04Evidence test: confirm your evidence folder exists and is on a second device, so that a compromised machine does not take your records with it.
The restore test is the one people skip and the one that matters most. A seed phrase you cannot read, or a backup you cannot actually restore from, provides exactly no protection.
Scheduling it
The audit only works if it recurs. Put it in the same category as a financial review rather than in the category of things you will get to.
Four dates a year, tied to something you already track — quarter ends, tax dates, or a repeating calendar entry — and run the table top to bottom each time.
- 01Set a recurring reminder for the same four dates every year, and treat it as a commitment rather than an intention.
- 02Run rows 1 to 3 first, every time. They are the ones with the highest exposure and they take under five minutes.
- 03Do it on a device you trust, and never follow links from an email or a message while auditing.
- 04Keep a short written log of what you revoked and when. It is useful evidence if something happens, and it takes one line per quarter.
- 05If you make a mistake during a quarter — approved something unfamiliar, entered a phrase somewhere — run the audit immediately rather than waiting for the scheduled date.
The visual summary
Everything above, reduced to the four stages that matter for this topic. If you only look at one thing on this page, look at this.
Where this fits in the pattern
Before contact
Nothing has happened yet. This is when every tutorial here is most useful and costs you nothing but reading.
During the approach
The script is running. The verification tests in this tutorial are designed to be run here, neutrally, without confrontation.
At the money request
The decisive moment. Any request for funds, fees, taxes or unlock deposits is the end of the script, not a stage of it.
After a loss
Prevention is over; evidence work begins. Preserve, report, and never pay a second fee to recover the first.
Common questions
Audit the address itself, not just the habits
Run your address through the tracer to see every outgoing flow, contract interaction and approval exposure the public ledger already records for it.
Primary sources and further reading
- CISA — Cybersecurity Best Practices www.cisa.gov
- FTC — Protecting Your Accounts consumer.ftc.gov
External links open in a new tab so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.
Prevention only works if it reaches people before the contact does.
Disclaimer: this tutorial is general information, not legal, financial or recovery advice, and is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.