A wallet security audit is not a hunt for the most advanced device. It is a search for the one event that can still cost you everything. Thirty focused minutes can find most of those events before an attacker, a fire or your future self does.
This checklist asks for no address, balance, seed phrase, private key or passphrase. No legitimate audit tool needs any of them.
Minutes 0–3: write down what actually controls the funds
- Exchange account: the provider controls the keys; your email, password, second factor and its withdrawal process control your access.
- Software wallet: keys live on the phone or computer; the recovery phrase can recreate them.
- Hardware wallet: keys sign on the device; the recovery backup can recreate them elsewhere.
- Seedless card: the physical backup devices and their access-code policy are the recovery system.
- Multisig: a threshold of independent keys plus the wallet configuration controls recovery.
If you cannot say which row applies, stop there. A product name is not a custody model. Coinbase.com and a self-custody wallet, for example, can sit under one brand while having completely different recovery rules.
Minutes 3–8: audit the backup
- Confirm it exists. Do not expose it; verify the object or sealed package is where your plan says it is.
- Confirm it is offline. Search your own habits: no photo, cloud note, email draft, messaging app, scanner folder or password-manager attachment.
- Confirm it is readable and ordered. Words need clear spelling and row numbers. Metal dots or tiles need decoding instructions.
- Confirm the passphrase is separate. A BIP-39 passphrase engraved beside the phrase is not a second factor.
- Confirm there is geographic redundancy. Two copies in one safe are one fire, one theft and one access problem.
Never type the phrase into a website to “check” it. Use the wallet’s on-device backup check or perform a controlled restore on a spare device. Our backup testing guide orders the methods from strongest to weakest.
Minutes 8–12: verify the signing boundary
Open the wallet you normally use and answer three questions:
- Does a separate device show the full destination and amount?
- Do you read that display, or click through from muscle memory?
- Can the wallet explain the transaction in human-readable terms, or are you blind-signing opaque data?
A hardware wallet protects keys from the computer. It does not protect you from approving the wrong transaction. Ledger calls readable device confirmation “clear signing”; the principle applies to every signer. If the trusted display cannot tell you what will happen, move the task to a separate low-value wallet rather than training yourself to approve unreadable requests.
Minutes 12–16: separate savings from activity
One wallet should not receive long-term savings, connect to experimental dApps, mint tokens, sign messages from strangers and travel in your pocket. Compartmentalisation limits the blast radius.
| Wallet | Purpose | What never happens there |
|---|---|---|
| Vault | Long-term holdings | No unknown contracts, no routine browsing, no airdrops |
| Working wallet | Known dApps and ordinary payments | No life-changing balance |
| Burner | New or untrusted interactions | No link to the vault beyond a limited transfer |
This is not anonymity. On-chain transfers may link the wallets. It is security containment.
Minutes 16–20: secure the accounts around the wallet
- Email: unique password, passkey or hardware security key, recovery methods reviewed.
- Mobile number: carrier PIN where available; do not treat SMS as the strongest second factor.
- Password manager: unique master password and a recovery method that does not depend on the same phone.
- Wallet app: downloaded from the official source, current version, no unexpected browser extensions.
- Hardware device: current official firmware, with the update initiated from the official app—not an email link.
These accounts may not hold the private key, but they reveal that you own crypto, reset a service relationship, deliver malicious software or help an attacker impersonate you.
Minutes 20–23: review approvals and address habits
- Revoke token approvals you no longer need using the chain’s trusted explorer or the wallet’s documented tool.
- For a new destination, verify the full address on the signer and send a small test first.
- For a repeated destination, do not copy from transaction history. Address poisoning exists to exploit that habit.
- Keep an allow-list or signed address book for important recipients, and verify changes out of band.
Minutes 23–26: check physical and privacy exposure
- Does a delivery record connect your home address to a hardware-wallet purchase?
- Can a visitor, cleaner, landlord or camera see the backup?
- Are every key and backup stored in one building?
- Does social media reveal your balance, device, travel or storage habits?
- Would a stolen wallet open after a short guessed PIN, or does the device enforce delays and wipes?
Do not answer coercion risk with bravado. A hidden wallet or duress feature is an uncertain technical layer, not a personal-safety plan. The best privacy measure is usually not advertising that the target exists.
Minutes 26–29: test recovery without improvising
For a single-signature wallet, confirm the official backup-check feature succeeds. For multisig, export and copy the descriptor or wallet configuration to every recovery location, then reconstruct a watch-only copy in independent software. For Tangem, confirm the backup cards still scan and decide whether access-code recovery should remain enabled.
Use a trivial test wallet if you are learning. The audit is not the moment to experiment with the only copy of a valuable secret.
Minute 29–30: leave one instruction for another person
Write where an executor or trusted person should begin—not the secret itself. Name the wallet type, the device or service, where the separate access map is kept, and whom to contact. If nobody else can discover the plan, loss of capacity is a total wallet failure even when every key survives.
Finish by running the custody risk scorecard. It turns the answers into a short remediation list and stores nothing.
Sources checked
- MetaMask security guidance
- Ledger explanation of clear signing and trusted displays
- Trezor backup handling guidance
- BlueWallet multisig configuration-backup guidance
- Unchained wallet-configuration recovery guidance
Get the SteelPhrase Self-Custody Brief
Email me SteelPhrase about twice a month: security changes, practical checklists, and carefully reviewed wallet guides. Unsubscribe anytime.