Hot wallet hygiene checklist
Device hygiene, test sends, address book habits, and official URLs for browser/mobile wallets—plain-English checklist drawn from public security guidance.
A hot wallet keeps keys on an internet-connected phone or browser extension. Convenience is the point; the tradeoff is a larger attack surface than offline cold storage. ethereum.org security pages and major wallet vendors stress operational habits over “secret tips.” This checklist is education about process—not advice to buy, sell, or hold any asset.
Device & browser hygiene
- Keep OS and browser updated. Many compromises start with malware, not cryptography.
- Separate browsing when you can. A dedicated browser profile (or device) for wallet use reduces drive-by extension risk. Only install extensions you verified from official sources.
- Lock the wallet when idle; use a strong device passcode/biometrics. Wallet password ≠ seed phrase—know both concepts (see wallet basics).
- Beware “wallet helper” downloads and cracked software. CISA-style phishing guidance applies: unexpected installers and urgent “security updates” from DMs are hostile until proven otherwise.
Official URLs only
- Create bookmarks from official documentation the first time—not from search ads, Discord pins, or Telegram “support.”
- Re-check the domain character-by-character before connecting (homoglyph / lookalike domains are common).
- App stores: confirm publisher name against the project’s published guidance; fake apps recycle brand names.
Address book & test sends
- Save trusted addresses in your wallet’s contacts / address book after you have verified them once via an independent channel (not a DM).
- Send a tiny test to a new destination before a large transfer. Confirm receipt on a public explorer you navigated to yourself.
- Watch address poisoning: dust from lookalike addresses in your history. Copy from your address book, not from a random inbound transfer.
- Double-check network (Ethereum mainnet vs another EVM chain) before confirming.
Seed & backup (hot wallets still have seeds)
- Write the recovery phrase offline; never store it in screenshots, email, or cloud notes.
- No support agent needs your seed. Ever. See the seed-phrase safety checklist.
- Practice restore on a throwaway wallet before you depend on the backup for real funds.
Approvals & prompts
- Read every prompt: connect vs send vs approve vs permit (prompt decoder doc).
- Prefer limited allowances when the UI allows; review and revoke unused approvals with tools you verified yourself (literacy topic—not a product endorsement).
- Decline anything you do not understand. Urgency is a scam feature.
TakeawayHot wallets fail more often from phishing, bad extensions, and rushed confirms than from “someone hacked the blockchain.” Hygiene is process: official URLs, test sends, address book, and reading prompts.
Related free docs & worksheets
- Seed phrase safety checklist · free printable: seed-phrase safety checklist (product)
- Address-book & send-test worksheet pack (teaser) — soft overview; no payment link on this page
- What is a token approval?
- Common crypto scams to recognize
Sources
- ethereum.org — Security and scam prevention
- ethereum.org — Wallets
- MetaMask Support — Basic safety and security tips (vendor education; not an endorsement)
- CISA — Secure Our World (device updates, phishing recognition)
- FTC — Cryptocurrency and scams
Educational content only — not investment advice. This checklist is about operational safety of hot wallets, not about which assets to acquire or which products to buy.