Skip to content
Actuator

Security

Protect your crypto like it matters β€” because it does.

In crypto, you are your own bank.  That means security is entirely your responsibility. This page ranks the security risks most likely to cause fund loss β€” in order of likelihood β€” then covers additional layered practices that further reduce your risk.

Walk Through Security Checklist β†’

Verify You’re on the Real Site β€” Before You Connect Anything

Five habits that stop lookalike sites before you connect a wallet

Phishing is one of the most common ways people lose crypto.  Attackers copy real sites pixel-for-pixel on lookalike domains, then wait for you to connect a wallet or type a seed phrase.  A few habits stop nearly all of it.

  1. Know what each site is.  This is an independent educational site (hexbonds.com).  The official app is actuator.finance and the official docs are docs.actuator.finance.  Reach them by typing the address or using your own bookmark β€” never through search ads, a Google result, or a link someone sent you.
  2. Read the domain letter-for-letter.  Phishers register near-identical names β€” actuat0r, actuator-finance.app, extra words, swapped letters.  The padlock icon only means the connection is encrypted; it does not mean the site is genuine.  Bookmark the websites and dapps you use regularly, and open them only from those bookmarks.
  3. A seed phrase typed into a website is a seed phrase given away.  No legitimate site, wallet, or app will ever ask for your seed phrase or private key β€” not this site, not Actuator, not "support."  Anyone who asks is trying to rob you.
  4. Confirm contract addresses before you approve.  Check any token or contract against the official list at docs.actuator.finance/contracts.  Read every wallet prompt and reject anything you don't fully understand.
  5. Ignore unsolicited DMs.  Real teams and admins do not message you first offering "support," giveaways, or help recovering funds.  On Telegram and X, assume a first-contact DM is a scam.

Bookmark the real sites now, and from then on only open them from your bookmarks.

1. Seed Phrase β€” Highest Risk

The master key: why most losses start here, and how to store it on metal

Your seed phrase (also called a recovery phrase or mnemonic) is the master key to your wallet. Anyone who has it can steal all your funds β€” across every account, every chain, forever.  Storing it safely is the single most important security decision you will make in crypto.

This is the #1 risk.  Most crypto losses start with seed phrase exposure β€” a photo on a phone, a text file on a laptop, a piece of paper found by the wrong person, a house fire that destroys paper.  If your seed phrase is compromised, you lose everything instantly and irreversibly.

The Problem with Most Storage Methods:

β–ͺ

Paper β€” burns at 233Β°C (451Β°F).  House fires reach 800Β°C+.  Floods destroy paper.  Paper is the usual reason people lose crypto to disasters

β–ͺ

Digital storage β€” photos, cloud drives, password managers, text files.  Any device connected to the internet can be hacked β€” a digitally stored phrase is only as safe as the least safe machine that has ever touched it

β–ͺ

Single copy β€” one backup in one location is a single point of failure.  Fire, theft, or loss at that location = total loss

The Solution β€” Layered Physical Storage:

β–ͺ

Metal stamping β€” engrave your seed phrase into stainless steel or titanium.  Survives fire (1,400Β°C+ for steel, 1,668Β°C for titanium), water, and corrosion.  Products: Trezor Keep Metal ($99), Cryptosteel ($80–$120), Billfodl ($99), or DIY steel plate + letter stamps ($10–$25)

β–ͺ

Shamir's Secret Sharing (SLIP-39) β€” split your seed into multiple cryptographic shares (20-word shares for 128-bit seeds, 33-word for 256-bit).  Excellent for distributing trust (e.g. 3-of-5 to family).  No single share reveals anything, and a threshold of shares is required to recover the wallet.

β–ͺ

Split-location strategy β€” distribute backups across 2–3 geographic locations (home safe, bank deposit box, a family member you choose to trust β€” a choice, not a default)

Quantum Resistance Note (2026)

The realistic quantum risk is Shor's algorithm deriving private keys from public keys revealed when you spend β€” a risk no backup format changes (see Section 8).  Seed-length choice (12 vs 24 words) is a minor factor by comparison; pick your backup method for theft and disaster resistance, not quantum resistance. Recommendation: Use one of the two standards, each with a passphrase: 24-word BIP-39 (256-bit, restores anywhere) or SLIP-39 multi-share (threshold shares across locations β€” no single point of failure).  The expert tier combines both strengths β€” 33-word SLIP-39 shares (256-bit and split), command-line only: the backup guide.

Full details: See the Seed Phrase page for complete implementation guides on all 7 storage methods, product comparison tables, and step-by-step directions.

Critical: a digitally stored seed phrase inherits every device's risk

No cloud drives, no password managers, no photos, no text files.  A phrase typed into any computer or phone lives on a machine you do not control β€” a hardware wallet device with a secure screen is the one entry surface that keeps it offline.  Paper burns; metal survives.  Shamir's Secret Sharing eliminates single points of failure.  And plan for the day you are not there to explain any of it: a seed dies with its holder unless the estate plan exists β€” Crypto Inheritance is the plan your heirs can actually execute.

β€’Hardware Wallet β€” Protects the Seed Phrase

Keeps your keys offline β€” set it up yourself, alone

A hardware wallet is the best defense for your seed phrase.  It keeps your private keys offline and never exposes them to the browser, keyboard, or camera.

Why it matters:

β–ͺ

Set it up yourself, alone β€” whoever is in the room when the words appear has them, however kind and however technical the helper.  A seed that was ever seen cannot be un-shared (If You Think You’re Compromised).

β–ͺ

Keys stay on the device β€” never touch your computer or phone.

β–ͺ

Physical confirmation β€” every transaction requires a button press on the device.

β–ͺ

Secure screen β€” you verify details directly on the hardware.

β–ͺ

Prevents browser-based attacks β€” clipboard swaps, malicious extensions, keyloggers.

Highly Rated

Trezor (Safe 3, Safe 5, Safe 7) β€” open-source, strong Secure Element protection, native Shamir Backup.  Buy only from trezor.io.  Full reviews on the Wallets page.

Warning: Pre-2023 Trezor Models Lack the Secure Element Chip

Only Trezor Safe 3, Safe 5, and Safe 7 include a dedicated Secure Element chip (EAL6+ certified).  The older Model One (2014) and Model T (2018) do not have a Secure Element β€” they are more vulnerable to advanced physical attacks if stolen.  For new purchases, always choose a Safe series model.  One disclosure to know: on 2026-06-03 Trezor reported that Ledger's security lab had laser-glitched the Safe 7's TROPIC01 chip in a laboratory in January 2026 and extracted secrets from that one component β€” physical possession and lab equipment required, one of three layers beaten, no funds at risk.  A Secure Element raises the bar for a thief holding the device; it is not a wall.  See the Wallets page for the full model comparison.

2. Wallets β€” Second Highest Risk

Why software wallets are the second most likely way to lose crypto

A wallet stores your private keys and signs transactions.  The type of wallet you use determines your attack surface. Software wallets are the second most likely way people lose crypto β€” because your private keys live inside the browser environment, exposed to malicious extensions, clipboard swap attacks, and phishing.

Software Wallet Risks:

β–ͺ

Malicious extensions β€” browser extensions have been caught injecting code into wallet pages, swapping recipient addresses, and exfiltrating seed phrases

β–ͺ

Clipboard swap attacks β€” malware monitors your clipboard.  You copy a PulseChain address, malware replaces it with an attacker's address.  You paste, funds are gone

β–ͺ

Phishing β€” fake wallet websites trick you into entering your seed phrase.  Bookmark the real sites

β–ͺ

Key exposure β€” in a software wallet, your private keys exist in browser memory.  Any compromise of the browser = compromise of your keys

The Solution β€” Hardware Wallet:

A hardware wallet is a physical device that stores your private keys offline.  Your keys never touch a computer or phone connected to the internet.  Every transaction must be physically confirmed by pressing a button on the device.  Even if your browser is compromised with malware, an attacker cannot steal your keys.

β–ͺ

Keys stay offline β€” never exposed to the browser, OS, or any internet-connected device

β–ͺ

Physical confirmation β€” every transaction requires a button press on the device

β–ͺ

Secure screen β€” the device displays transaction details on its own screen, so you can verify the recipient address isn't being swapped

β–ͺ

Works with PulseChain β€” Ledger and Trezor both work with MetaMask and Internet Money Wallet for PulseChain interactions

Preferred Software Wallet

If you must use a software wallet, Internet Money Wallet is Highly Rated on our site β€” non-custodial, no data collection, two security audits of the wallet itself, and connects to Ledger and Trezor hardware wallets.  See the Wallet Comparison for the full breakdown.

A Passphrase (Hidden Wallet) Makes a Stolen Seed Phrase Not Enough

A passphrase — sometimes called the “25th word” — is an extra word or phrase added to your seed phrase.  It opens a completely separate, hidden wallet.  The seed phrase on its own opens only the standard wallet.

β–ͺ

Each different passphrase opens a different wallet with its own addresses.  A typo opens a different, empty wallet, with no error message.

β–ͺ

If someone finds your seed phrase only:  they open the standard wallet.  The hidden wallet stays shut.

β–ͺ

If someone finds your seed phrase and your passphrase:  they open the hidden wallet and can remove everything in it.

β–ͺ

If someone finds only the passphrase:  it opens nothing without the seed phrase.

β–ͺ

If you forget your passphrase:  reloading the seed phrase brings back only the standard wallet.  The hidden wallet cannot be reset or recovered, and its funds are lost — Trezor: “Passphrases cannot be changed, removed, or recovered.”

β–ͺ

The standard wallet still opens with the seed phrase alone; some holders keep a small amount there as a decoy.

See the Trezor Multi-Wallet Guide for step-by-step passphrase setup instructions.

Highly Rated Hardware Wallets:

β–ͺ

Trezor (Safe 3, Safe 5, Safe 7) β€” open-source firmware, native SLIP-39 Shamir Backup, strong security track record.  The gold standard for seed phrase security

β–ͺ

Ledger (Nano S Plus, Nano X) β€” widely supported, works with MetaMask for PulseChain

β–ͺ

GridPlus (Lattice1) β€” advanced features; open-source developer tools, device firmware not published

About Ledger:  Ledger devices do not support SLIP-39 (Shamir) backups, so a Ledger restores only from a standard 12- or 24-word seed phrase.  Ledger Recover is an optional paid subscription: the device encrypts your seed phrase, splits it into three pieces and sends them to three companies (Ledger, Coincover and EscrowTech), and getting it back requires an ID check.  It stays off unless you sign up.  Part of the code on Ledger’s secure chip is closed-source; Ledger says it belongs to the chip maker and cannot be published.

Important: A hardware wallet bought from eBay, an Amazon reseller, or second-hand can arrive tampered β€” and tampered devices have been used to steal funds.  The manufacturer's official website is the one source that rules this out.

Full wallet reviews: See the Wallets page for detailed reviews of Trezor, Internet Money, ZKX, MetaMask, and other PulseChain-compatible wallets.

β€’Transaction & Signing Hygiene β€” the Last Ten Seconds

Address poisoning, clipboard swaps, and signatures that steal

A safe wallet does not make a safe transaction.  The attacks below all live in the ten seconds between β€œI’m ready to send” and β€œConfirm” β€” and every one is defeated by habits, not tools.

  • Address poisoning.  Thieves dust your wallet with tiny transactions from lookalike addresses engineered to match the first and last four characters of ones you actually use β€” betting you will copy from your transaction history.  Rule: never copy an address from history; keep a verified address book, and when checking, compare middle characters too.
  • Clipboard hijackers.  A common malware class silently swaps the address on your clipboard as you paste.  Rule: after every paste, re-read the address β€” and treat the hardware wallet’s screen as the only truth: what it displays is what will happen, whatever the computer shows.
  • The test-transaction habit.  First send to any new address is a small one β€” then confirm receipt at the destination, not on the explorer: the counterparty tells you they got it, or you see it in the receiving wallet you control.  A test that merely β€œlands” proves only that you sent somewhere β€” a poisoned address receives test transactions just as smoothly as real ones.  Only after independent confirmation, send the rest β€” to the address copied fresh from your verified address book, not from the test transaction in your history.
  • No blind signing.  If the device asks you to approve data it cannot render meaningfully, it is asking for faith, not confirmation.  Keep blind signing disabled unless a specific, verified interaction requires it β€” then re-disable it.
  • A signature can be a theft.  Modern drainer kits don’t ask you to send β€” they ask you to sign: a message (a β€œPermit” or approval) that lets them pull your tokens later, gas paid by them.  If a site you didn’t reach by bookmark asks for any signature β€” especially one mentioning β€œPermit”, β€œapprove”, β€œsetApprovalForAll”, or an unlimited amount β€” stop.  Nothing moving at signing time is not evidence of safety; it is the design of the attack.
  • No safety net on PulseChain.  On Ethereum, wallets like MetaMask scan a transaction before you sign it and warn about known drainers.  MetaMask’s security alerts do not cover PulseChain — chain 369 is not on its supported-network list (checked September 27, 2026) — so on PulseChain nothing checks the transaction for you.  The habits on this card are the check.
  • Approval hygiene.  Every token approval you have ever granted stays live until revoked β€” sweep them on a schedule (see the Wallets guide).  On PulseChain that includes approvals you never granted there: the May 2023 launch copied Ethereum’s full state, so every approval you had made on Ethereum before then is live on PulseChain too.  Revoke.cash lists and revokes PulseChain approvals.
  • “Upgrade your wallet” on Ethereum.  Ethereum’s 2025 upgrade added EIP-7702: one signature can hand an address’s control to a contract.  PulseChain has not adopted it, but the same seed opens the same address on Ethereum, where eHEX sits.  A “smart account upgrade” request from a site you didn’t reach by bookmark is the same theft as a Permit.

β€’A Spending Wallet and a Vault

What you use, kept apart from what you keep

Two wallets do what one cannot.  The spending wallet — a hot wallet — holds what you trade, farm, mint and connect to new sites with.  The vault holds everything else: it lives on the hardware wallet, connects to nothing new, and signs rarely.  A phishing site, a drainer approval or a stolen phone reaches only the wallet it touched.

  • Top up, sweep back.  When the spending wallet runs low it is refilled from the vault; when it grows, the surplus goes back.  A spending wallet left to grow becomes a second vault with none of the vault’s protection.
  • A throwaway address for the unknown.  A new dApp, a mint, or an airdrop claim can be tried from an address that holds only what that one interaction needs, so its approvals never sit on anything that matters.
  • The vault’s approvals stay empty.  A vault that never approves a contract has nothing for a drainer to pull.  Staking from the vault on go.hex.com, reached by bookmark, is a transaction, not an approval.

β€’Multisig β€” More Than One Key to Move Funds (Advanced)

One stolen key moves nothing on its own

A multisig wallet is a smart contract that needs signatures from several keys — say 2 of 3, each on its own hardware wallet — before it moves anything.  One stolen key, one phished signature or one lost device moves nothing by itself.  The cost is more devices, more steps on every transaction, and a backup plan for every key.

  • The contracts are on PulseChain; the official app is not.  Safe, the most widely used multisig, has its contracts on PulseChain — copied from Ethereum at the May 2023 launch.  Safe’s own app does not support PulseChain: a December 2024 request on Safe’s forum was answered with Safe’s policy of leaving each network to run its own.
  • The interface is the weak point.  Any PulseChain Safe website is someone else’s, and a multisig is only as safe as the page it signs through.  Each signer’s hardware-wallet screen is still the only truth.
  • Worth it at size.  For most holders the spending-wallet-and-vault split above does the same job with less to go wrong.  A multisig earns its complexity when one key is too much trust for the amount it guards.

3. Browsers β€” Third Risk (Attack Surface)

Brave for signing, hardened Firefox for research

Your browser is the front door to your crypto.  Every DeFi interaction β€” connecting your wallet, signing transactions, browsing PulseChain apps β€” happens through your browser.  A compromised browser is an attack surface that enables both wallet compromise and seed phrase theft.

This is the #3 risk β€” not because browser compromise directly steals your funds, but because it's the entry point for attacks on your wallet and seed phrase.  A malicious extension can swap addresses.  A tracking script can profile your activity.  A phishing page can harvest your credentials.

Browser Security Risks:

β–ͺ

Malicious extensions β€” every extension store has them.  In 2025 more than 150 fake wallet extensions were found on Firefox's own add-on store (the "GreedyBear" campaign, over $1 million stolen), and Chrome's store has carried the same.  A wallet extension is installed once, from the link on the vendor's own site β€” never from a store search

β–ͺ

Account-linked browsing β€” signed into a Google account (or any vendor's), your browsing is tied to your identity, and that identity marks you as a holder

β–ͺ

Tracking and fingerprinting β€” scripts that profile which sites you visit build a picture of what you hold and where

β–ͺ

No isolation β€” without a separate profile, your crypto session shares cookies and state with every other site you visit

β–ͺ

No path to the hardware wallet β€” a browser that cannot talk to a Trezor or Ledger pushes you back toward a software wallet, which is risk #2

The Solution β€” Two Browsers, Two Jobs:

No single browser wins both contests.  The one that signs transactions must reach your hardware wallet; the one you research in should be the hardest to track.  Use one of each.

β–ͺ

For signing β€” Brave.  Its Chromium engine connects to Trezor and Ledger over WebHID / WebUSB; Firefox has neither, Ledger's own documentation lists it as unsupported, and the Rabby wallet dropped its Firefox extension in 2025 partly for this reason.  Brave's ad and tracker blocking (Shields) is compiled into the browser, so Google's Manifest V3 change that crippled Chrome's extension blockers did not touch it; fingerprint randomization is on by default; and no Google account is involved

β–ͺ

Brave's baggage, handled in one settings pane β€” Brave has its own token (BAT), a built-in wallet, and a news feed.  Switch off Rewards, Wallet, and News; you will use none of them, and each is one more surface

β–ͺ

For research β€” Firefox + arkenfox.  Among the strongest fingerprinting resistance in a daily-use browser, container tabs, and an engine that is not Chromium.  It cannot connect a hardware wallet β€” which is the point: nothing signs here

β–ͺ

Open-source, both β€” Brave and Firefox are fully auditable codebases

Other Browser Options:

β–ͺ

Chrome β€” the same engine as Brave, so the hardware wallet works; but it invites a Google sign-in and its extension blockers are crippled by Manifest V3.  A fair choice if you prefer it; not a better one

β–ͺ

LibreWolf β€” a hardened Firefox fork with maximum privacy settings out of the box (research side only)

β–ͺ

Mullvad Browser β€” Tor Browser without the Tor network, built by the Tor Project with Mullvad; every user presents the same fingerprint (research side only)

Full browser analysis: See the Browsers page for the detailed comparison, the Firefox hardening walkthrough, and Techlore recommendations.

Do This: Set Up the Signing Browser in 6 Steps

1

Install Brave from brave.com β€” nowhere else

2

Turn off Brave Rewards, Brave Wallet, and Brave News in Settings

3

Create a dedicated Crypto profile (isolates crypto activity from everyday browsing)

4

Install exactly one wallet extension, from the link on the vendor's own site, plus Bitwarden β€” nothing else

5

Bookmark the official sites and navigate by bookmark only

6

Keep everyday browsing and research in Firefox + arkenfox β€” the hardening walkthrough is on the Browsers page

β€’Social Engineering β€” the Human Attack Surface

Five scams that work by conversation, and the one tell they share

Everything above defends machines and accounts.  The most successful crypto attacks defeat neither β€” they are conversations, and they work on smart people because they are built by teams who do nothing else all day.  Learn the five scripts and the one tell they share.

  • The β€œsupport agent.”  Appears in your DMs minutes after you post a question anywhere public, helpful and patient, and eventually needs your seed phrase or a β€œvalidation” transaction to fix your issue.  The rule that ends it: nobody legitimate DMs first β€” no protocol, no wallet vendor, no exchange, ever.
  • The recruiter.  A generous job offer, a friendly interview process, then a β€œtake-home assignment” or β€œassessment tool” to install.  The installer is the payload β€” this is the playbook of state-level groups, aimed precisely at people known to hold crypto.  Career talk never requires installing anything.
  • The long con (β€œpig butchering”).  Months of genuine-feeling friendship or romance, then an investment opportunity on a slick platform where deposits show gorgeous returns β€” and withdrawals need β€œtaxes,” then β€œfees,” then silence.  The platform was theater from the first day.  The tell: any relationship that ends up steering where your money goes.
  • The giveaway / impersonation.  A famous account promises to double what you send, or a β€œprotocol migration” needs you to move funds β€œto stay eligible.”  Sending crypto to receive crypto is the whole scam, every time.
  • The fake authority.  A badge at your door, or a call from the β€œFBI,” β€œIRS,” or β€œEuropol”: your funds are β€œpart of an investigation” and must move to a β€œsecure government wallet” for safekeeping.  No agency, anywhere, takes custody by having you send crypto β€” that request is the entire scam, and it especially hunts older holders.  Comply physically and never lie, but verify the badge like a URL: call the office yourself, at a number you look up β€” a real agent expects verification and waits; only an impostor pressures against it.  Real seizures arrive as paperwork through lawyers, not surprises on a sidewalk β€” and β€œI want to speak with a lawyer” costs a real case nothing.

The shared tell is urgency.  Every script manufactures a deadline, because pressure is what turns careful people careless.  The universal defense costs nothing: sleep on it.  No legitimate opportunity in an ecosystem of immutable contracts expires overnight.

4. Password Manager

Unique passwords everywhere β€” seed phrases never go in it

A good password manager (e.g., Bitwarden, KeePassXC, 1Password) is one of the most valuable tools for crypto users β€” as long as you never store your seed phrases, recovery keys, or hardware wallet PINs in it.

How a Password Manager Helps in Crypto

1

Managing Exchange, Wallet, and dApp Accounts β€” Strong, unique passwords for every exchange (Binance, Coinbase, Kraken), PulseChain explorers, Actuator, PulseX, and email accounts used for 2FA.  Prevents password reuse attacks β€” one compromised site doesn't give attackers access to everything.

2

2FA / MFA Management β€” Store backup codes and TOTP seeds for exchanges and wallets (not your main seed phrases).  Many managers have built-in authenticator functionality.

3

API Keys and Developer Access β€” Secure storage for read-only API keys used with trading bots, portfolio trackers, on-chain tools, private RPC endpoints, or GitHub tokens.

4

dApp Logins & Software-Wallet Recovery β€” Passwords for the few dApps and tools that have accounts.  Recovery or backup codes for software wallets (if not using hardware).

5

Financial & Tax Records β€” Passwords for tax software, KYC portals, accounting tools, and bank accounts or fiat on-ramps used for crypto purchases.

6

Domain & Infrastructure Security β€” Passwords for domain registrars (protecting project websites or ENS names), hosting accounts, VPS, or node servers.

7

Team / Multisig / Shared Access (Advanced) β€” Secure sharing of non-seed credentials with trusted team members.  Emergency recovery codes or secondary access methods.

8

General Operational Security β€” Passwords for browser profiles, VPN accounts, dedicated crypto computers, license keys for security software.

Best Practices When Using a Password Manager for Crypto

β–ͺ

Use a strong master password + enable 2FA on the password manager itself.

β–ͺ

Prefer open-source options like Bitwarden or KeePassXC for transparency.

β–ͺ

Self-host or cloud β€” Bitwarden self-hosted is ideal for maximum control.

β–ͺ

Separate vaults β€” create a dedicated "Crypto" folder or vault.

Stored in a Password Manager, These Live on Machines You Do Not Control:

βœ—

Seed phrases

βœ—

Hardware wallet PINs

βœ—

Passphrases for hidden wallets

βœ—

Private keys

Recommended Setup

βœ“

Bitwarden (or KeePassXC) as primary manager.

βœ“

Hardware wallet (Trezor) for actual funds.

βœ“

Brave (Rewards, Wallet, and News off) for signing; hardened Firefox + arkenfox for everything else.

βœ“

Password manager 2FA via hardware key (YubiKey) if possible.

A password manager turns "weak password reuse" into "unique strong passwords everywhere" β€” one of the highest-ROI security improvements you can make.

β€’Two-Factor Authentication β€” Where It Helps, Where It Can’t

Hardware key first, authenticator app second, never SMS

First, the twist most newcomers miss: 2FA does nothing for your actual wallet.  A self-custody wallet is not an account β€” there is no login, no server, and nobody to show a second factor to.  The seed phrase is total authority, and no 2FA exists on-chain.  If you catch yourself thinking your crypto is β€œprotected by 2FA,” you are thinking of an exchange account, not your wallet.

Where 2FA is critical is the account perimeter around your crypto life β€” the four accounts and the one passcode that, if taken over, can reach your money or your machine:

  • Your email β€” the master key: it can password-reset everything else.  Give it the strongest 2FA you own.
  • Any exchange or on-ramp account β€” where fiat meets crypto is where account takeover pays a thief directly.
  • Your password manager β€” it holds the rest of the keys to the perimeter.
  • The Apple or Microsoft account controlling your crypto machine β€” remote takeover of the account can mean remote reach into the device.
  • Your phone's passcode β€” it unlocks the authenticator, the email, and every reset link on this list.  Nobody else's face or fingerprint belongs on it.

The type matters as much as having it:

  • Best: a hardware security key or passkey (FIDO2) β€” phishing-resistant by construction: an authenticator code can be typed into a pixel-perfect fake site, but a security key cryptographically checks the real domain before it answers β€” a perfect phish gets silence.  One catch: the key only protects logins that use it β€” remove weaker fallback methods (SMS, authenticator codes) from the account, or the phisher simply asks for those instead.  The canonical device is a YubiKey or Yubico's FIDO-only Security Key ($29–58 each); your Trezor can also serve as one, but separation of duties argues for a dedicated key β€” the money device stays in the drawer, the login key rides the keychain.  Buy two and register both everywhere β€” a lone key’s main guarantee is lockout when it’s lost.  And keep the jobs straight: a security key authenticates you to services; it is not a wallet and never signs a crypto transaction.
  • Good: an authenticator app (rotating six-digit codes) β€” solid, but the code can still be phished by a convincing fake page.
  • Last, or never: SMS codes.  SIM-swapping is the signature crypto attack β€” the thief social-engineers your carrier into porting your number, then resets your exchange and your email in one afternoon.  Remove SMS as a fallback wherever an account allows it, and set a port-freeze PIN with your mobile carrier.

For completeness: paid SIM-swap-protection carriers exist (Efani is the best-known name) β€” a boutique phone company whose product is that your number cannot be casually ported: verified account changes, port cooldowns, insurance, at a premium monthly price.  Our honest read: it solves the problem from the wrong end for most people.  The free discipline above β€” port-freeze PIN, and making SMS worthless by removing it from every account that touches money β€” protects you even if a carrier fails.  A middle path can cost nothing: give financial accounts a VoIP number (Google Voice–style β€” U.S.-only; other countries have equivalents) instead of your real cell.  No SIM exists to swap β€” though the number is only as strong as the email account behind it (the hardware key goes there too), and some banks and exchanges refuse VoIP numbers outright.  The paid service earns its keep for one profile only: the known target β€” publicly associated with large holdings, doxxed, or previously attacked (the full physical-world playbook is in Physical Security & OPSEC).  As always here: documented, not endorsed.

One habit ties it together: keep 2FA out of the same basket as the password β€” codes in a separate app or key, never stored beside the password they protect, or the β€œsecond” factor quietly becomes the first.

β€’Private Email β€” Break the Links, Not Just the Code

A separate address that breaks the SIM-swap chain

A private email provider (Proton Mail is the best-known; Tuta is another) helps crypto security in a way most people misname: the win is not mainly encryption β€” it is breaking the links that let attackers find, profile, and recover-attack you.

  • Sever identity from crypto activity.  A fresh address with no ties to your name means exchanges and wallet vendors know a persona, not a person β€” and breach dumps from those services cannot be correlated back to you.  Correlation is exactly how SIM-swap targets get selected.
  • Aliases as tripwires.  One unique address per service: a "Ledger" email arriving at your exchange-only alias is instantly exposed as phishing, a breach announces exactly who leaked, and a burned alias gets deleted without moving your real account.
  • Break the SIM-swap chain at the first link.  Signup without a phone number, recovery by phrase instead of SMS β€” the steal-number β†’ reset-email β†’ reset-everything chain from Two-Factor Authentication never starts.
  • Zero-access storage.  Your mailbox holds the keys to the whole account perimeter β€” KYC documents, statements, reset links.  Zero-access encryption means a provider breach leaks ciphertext.  Honest caveats: mail in transit to ordinary recipients is not end-to-end, and Swiss (Proton) or German (Tuta) privacy law shields you from thieves and profilers, not from lawful orders β€” which is fine, because thieves are the threat model.

The working structure: keep your identity email for real life; create one private address that exists only for crypto-adjacent accounts; never cross the streams.  And the same twist as 2FA applies: none of this protects the wallet itself (no login to protect), and the private mailbox is only as strong as its own second factor β€” the hardware key goes on it too.  As always: documented, not endorsed.

5. VPNs β€” What They Do and Don’t Do

A privacy choice, not a security shield

A Virtual Private Network (VPN) sends your traffic through another company’s server, so the sites you visit see that server’s address instead of your home’s.

What it does:

  • Hides your home IP β€” from sites, block explorers, and the RPC gateways your wallet talks to.  Without one, they see your IP next to every wallet address you look up.
  • Hides your browsing from your internet provider β€” it no longer sees which sites you visit.

What it doesn’t do:

  • Stop theft β€” phishing sites, wallet drainers, malware, and fake apps work the same with or without one.
  • Add much on public WiFi β€” HTTPS already encrypts what you send.

The trade:  the VPN company now sees what your internet provider used to see, so a VPN is only as private as the company running it.

One thing a VPN should not be used for: evading an exchange's regional block.  Exchanges detect this, and the usual result is a frozen account with your funds stuck inside β€” the block is a legal boundary, not a technical one.

If you choose one β€” highly rated providers:

  • ProtonVPN β€” open-source apps, strong privacy policy, free tier available
  • Mullvad β€” anonymous accounts (no email needed), flat pricing, open-source
  • IVPN β€” audited, open-source, no-logs verified

For deeper VPN research and comparisons: visit Techlore's VPN resources β€” they provide detailed, regularly-updated VPN rankings and security analysis.

β€’DNS Lookup Protection β€” the Internet's Phonebook

Encrypted lookups, and filtering resolvers that block phishing names

Before any site loads, your device asks a DNS resolver β€” the internet's phonebook β€” to turn the name you typed into a numeric address.  Every site, every wallet, every RPC gateway starts with one of these lookups, and whoever answers it decides where your traffic actually goes.

Plain, out-of-the-box DNS has two weaknesses that matter for crypto:

  • Lookups travel unencrypted β€” on public WiFi or through your ISP, anyone on the path can read which crypto sites you visit, building a profile of what you hold and where
  • A wrong answer sends you to the attacker's server β€” a poisoned router or hostile network can answer a real name with a different address (DNS spoofing).  HTTPS usually objects loudly when this happens β€” which is why a sudden certificate warning is a stop sign, not something to click through

The Two Protections:

  • Encrypted DNS (DoH / DoT) β€” the lookup rides inside encryption, so nobody on the path can read it or rewrite the answer.  Built into modern systems: "DNS over HTTPS" in Firefox and Chrome, "Private DNS" on Android, encrypted-DNS profiles on Apple devices
  • Filtering resolvers β€” Quad9 (9.9.9.9), Cloudflare's 1.1.1.2, and NextDNS refuse to resolve names on known malware and phishing blocklists.  A phishing link that never resolves never loads β€” one settings change protects every app on the machine, and set at the router it covers every device in the house

A VPN (section 5) moves this problem rather than solving it: a good one carries your lookups inside the tunnel to its own resolver.  The failure mode to know is the DNS leak β€” lookups slipping outside the tunnel to your ISP while the VPN is on β€” and free leak-test sites exist to check for exactly that.

The trade-off filtering carries: blocklists make mistakes.  A legitimate service can land on a threat feed, and from then on β€” on your network only β€” that name simply stops existing, while the rest of the world reaches it fine.  Crypto infrastructure is especially prone: public RPC endpoints get swept into "drainer" lists because scam sites call the same free gateways real apps do.  If a site or gateway works for everyone but you, an over-eager DNS filter is a prime suspect.  Filtering still stops real phishing every day β€” the trade is yours to weigh.

6. Dedicated Computer & Environment

One machine used only for crypto shrinks the attack surface

For large crypto holdings, consider using a dedicated computer β€” a device used exclusively for crypto transactions.  No web browsing, no email, no games, no random software.  This dramatically reduces the attack surface.

It doesn't need to be expensive.  A cheap, clean laptop works perfectly.  The key is discipline: this machine only connects to known, trusted sites (PulseChain explorer, Actuator app, your hardware wallet software).

Dedicated Computer Best Practices:

  • Fresh OS install β€” wipe and reinstall the operating system from a verified image
  • No email client β€” email is a leading vector for phishing and malware
  • No social media β€” eliminates clicking malicious links
  • Only install wallet software and the password manager β€” the wallet extension, Ledger Wallet (formerly Ledger Live) or Trezor Suite, Bitwarden β€” nothing else
  • Keep it updated β€” install OS and security updates promptly
  • A VPN on this machine is optional β€” if one runs, it is the one install beyond the wallet software and password manager above, chosen from Use a VPN and downloaded by typing the vendor's own web address, and it stays on, even at home
  • Pick and harden the right OS β€” the full answer, for MacBooks and Windows PCs, is in The Operating System just below
  • Mask or disable cameras β€” cover webcams and phone cameras when handling seed phrases or sensitive operations.  Cameras can capture your screen, seed phrase cards, or hardware wallet displays

Lighter alternative: If a dedicated computer isn't feasible, use a dedicated browser profile or a separate user account on your existing machine for all crypto activity.  Install only crypto-related extensions, and never use that profile for general web browsing.

β€’The Operating System β€” Pick, Patch, Lock

Current macOS on Apple Silicon or Windows 11, patched and locked down

Start with the threat model this protocol already gives you: with a hardware wallet, the computer never holds keys that can move funds.  So the operating system’s job shrinks to three things β€” don’t get phished, don’t run malware that swaps addresses on your screen, and don’t leak your seed during setup.  That contest is won by a well-patched, locked-down appliance, not an exotic fortress β€” and the honest answer differs by machine.

On a MacBook: current macOS on Apple Silicon, hardened.

  • Why stock macOS wins here β€” Apple Silicon gives you a secure enclave, verified boot, and a cryptographically sealed system volume, so malware can’t quietly patch the OS underneath you; notarization plus rapid automatic updates beat any realistically-maintained alternative.
  • Turn on Lockdown Mode (Settings β†’ Privacy & Security) β€” a one-switch hardening built for exactly the "targeted individual holding assets" profile; it disables the attack surfaces real exploits use.
  • FileVault on, automatic updates on, non-admin daily account β€” three switches, most of the win.
  • Why not Linux or the privacy OSes on a Mac β€” Qubes OS (the genuine gold standard for compartmentalization) does not run on Apple Silicon at all; Tails is x86-only; Linux via Asahi is impressive but incomplete.  An unsupported OS on unsupported hardware means unpatched gaps β€” less secure, wearing a security costume.
  • Intel MacBook?  Check your support window β€” macOS 26 Tahoe is the last release that runs on Intel; macOS 27 (September 2026) is Apple silicon only, and Apple's pattern is about three more years of security patches for the final version.  A machine that stops receiving security patches matters more than any OS choice.  Plan the replacement.

On a Windows PC: current Windows 11, hardened β€” or a dedicated Linux appliance if you’ll maintain it.

  • Windows 10 reached end of support on 2025-10-14 β€” unless the machine is enrolled in Microsoft's Extended Security Updates program (extended in June 2026 to October 2027), it has been unpatched for months β€” and even ESU is a countdown, not a fix.  Upgrade or retire it before it touches anything crypto.  This one line outranks everything else in this list.
  • Windows 11 done right β€” TPM 2.0 + Secure Boot (required by 11 anyway), BitLocker on, automatic updates on, Microsoft Defender left on (it is genuinely good now), Smart App Control on (Windows allows it only while S mode is off and optional diagnostic data is on), and a standard non-admin account for daily use.
  • Respect the ecosystem risk β€” the malware economy overwhelmingly targets Windows, and modern infostealers specifically hunt browser profiles and wallet extensions.  The dedicated-machine rule matters more on Windows, and pirated software is a leading way these infections arrive: a cracked installer runs with the owner's permission, and so does the infostealer it carries.
  • The Linux option is real on a PC (unlike a Mac) β€” a minimal, auto-updating distribution used only for crypto sidesteps the Windows malware ecosystem entirely; Qubes OS runs properly on many PCs and is the expert-tier answer.  The honest caveat: a poorly-maintained Linux box is weaker than a well-patched Windows 11 β€” choose it only if you’ll keep it current.

Either way, the checklist is the same: dedicated machine or at minimum a dedicated non-admin account; full-disk encryption on; automatic updates on; nothing installed beyond the browser, the wallet software, and the password manager; bookmarks-only navigation; verify every contract address against Appendix A.  That stack, plus the hardware wallet, beats any exotic OS with a distracted operator.  Step-by-step walkthroughs: set up your Mac Β· set up your Windows PC.

7. Additional Layered Security

Eight everyday habits that make you a hard target

Security is about layers.  No single measure is perfect, but together they make you a hard target:

  • Verify contract addresses β€” always double-check the contract address on docs.actuator.finance and scan.pulsechain.com before interacting with any protocol
  • Check URLs carefully β€” phishing sites use look-alike domains (actuator-finance.com vs actuator.finance).  Bookmark the real sites
  • A shared seed phrase is shared control β€” no legitimate support person, website, or app will ever ask for it
  • Use a password manager β€” unique, strong passwords for every account (Bitwarden, KeePassXC)
  • Enable 2FA everywhere β€” use an authenticator app (Aegis on Android; Ente Auth or 2FAS on iOS) or hardware key (YubiKey), not SMS β€” details and the type ranking in Two-Factor Authentication
  • Test with small amounts first β€” when using a new protocol or contract, send a small test transaction before moving larger amounts
  • Be Skeptical of DMs β€” anyone messaging you privately about crypto is likely trying to scam you.  Public Communication Is Always Best.  Get advice from several sources and make your own decisions.
  • Keep software updated β€” browser, OS, wallet apps, hardware wallet firmware

β€’If You Think You’re Compromised β€” the Runbook

Five steps, in order, for the bad hour

Read this section before you ever need it.  In the bad hour, order is everything β€” the thief is racing you, and most people run the steps backwards.  Signs you are in that hour: a transaction you did not make, an approval you do not recognize, a seed phrase that was ever photographed, typed, or seen β€” or a machine behaving strangely after you installed anything.

  1. Stop touching the suspect machine.  Do not log in anywhere β€œto check” β€” every keystroke on it may be watched.
  2. From a clean device, create a new wallet with a new seed on your hardware wallet, and move liquid funds to it β€” most valuable first.  Tokenized stakes move too: a tokenized HSI is an NFT β€” transfer it with the same urgency, because the thief can move it exactly as easily (an untokenized HSI must be tokenized first, from the same compromised address β€” two transactions, same race).  A native HEX stake cannot be transferred, but it can be ended β€” by you or by the thief, early with penalty or at maturity β€” and the HEX lands on the same compromised address, which the thief's bot is watching.  That is not "safe, note it"; it is a race: end and sweep in the same instant, or accept that at maturity the thief can.  Positions held inside a protocol (a delegated stake comes free only by retiring its HTTs first) are the same race, one step longer.
  3. Revoke every approval on the old addresses, still from the clean device β€” a live approval can drain a token later without another signature.
  4. Rotate the account perimeter β€” email first, then password manager, then exchanges β€” new passwords, hardware-key 2FA, all sessions signed out everywhere.
  5. Only now deal with the machine: full wipe and clean install (the Mac / Windows setup guides are the rebuild recipe).

One rule with no exceptions: a seed that was ever exposed β€” photographed, typed into a computer, stored in a cloud note, seen by anyone β€” is burned forever, even if nothing has been stolen yet.  Thieves warehouse seeds and wait.  Migrate at the next calm opportunity; never bet on β€œit’s been fine so far.”

8. Quantum Security (Future-Proofing)

The hedge is a habit: hold on addresses that have never signed

Quantum computers that can break today’s wallet cryptography don’t exist yet.  We expect it to become a real problem in 2 to 5 years, and there will be a way to handle it as that gets closer.  Stay aware of the situation.

What This Means for You:

  • The realistic attack is Shor's algorithm run against a public key.  On PulseChain and Ethereum an address reveals its public key the first time it signs an outgoing transaction; an address you have never spent from has revealed nothing.
  • "Harvest Now, Decrypt Later" here means collecting those exposed public keys and signatures today and attacking them once the machine exists.  The chain is public, so for every spent-from address the harvest is already done.
  • No backup format changes any of this.  Twelve words, 24 words, Shamir shares, metal plates β€” those are theft-and-fire decisions, not quantum ones (see the note in Section 1).

Practical Steps You Can Take Today:

  • Hold long-term on receive-only addresses β€” an address that has never signed has never shown its public key, and there is nothing on-chain for Shor to attack.
  • When a vault must spend, sweep it whole β€” move the entire balance to a fresh address in one transaction.  From that first signature the old address is exposed forever; leaving a remainder on it is the mistake.
  • Know what cannot hide β€” a native HEX stake ends at the address that started it, and any active position (staking, farming, delegating) requires signing.  The quantum hedge covers passive holdings only.
  • Keep the ordinary defenses for the ordinary thieves β€” hardware wallet, passphrase, metal backup.  They do nothing against Shor, and they are what stops the theft that is actually happening today.
  • Stay informed.  The major chains are researching post-quantum signatures; when a migration path exists, holdings on never-spent addresses are expected to be the easiest to migrate.

Bottom line: No panic required.  The quantum hedge is a behavior, not a product: hold on addresses that have never signed, and when one must sign, sweep everything at once.  Everything else on this page defends against the thieves who exist now.

For a deeper technical breakdown β€” Shor's algorithm timelines, why spent addresses are more exposed, and how "Harvest Now, Decrypt Later" works β€” see our deep dive on quantum threats to seed phrases and ECDSA.  For the latest developments, we recommend following reputable sources such as the Ethereum Foundation, Bitcoin developers, and post-quantum cryptography research.

9. Learn More: Techlore

Where to keep learning about privacy and security

Techlore is an educational organization focused on privacy and security.  They produce high-quality, accessible content about VPNs, threat modeling, password management, browser security, and more β€” all directly applicable to protecting your crypto.

We highly recommend their content for anyone serious about operational security.  Their VPN rankings, in particular, are the most thorough and regularly-updated resource available.

IPFS: Decentralized Access

How to reach HEX and Actuator if the main websites go down

What happens if the main website goes down?  The smart contracts live on-chain forever, but traditional frontends can be censored or taken offline.  IPFS hosts the full interface on a decentralized network.

HEX IPFS

HEX publishes an official frontend CID via go.hex.com β€” the app served as a content-addressed IPFS file rather than a website.  The rule for any CID, this one included: verify it against the official channel before connecting a wallet.

The HEX frontend IPFS hash (as published by go.hex.com) is:bafybeigxypck6aqtgt2wrvt2kd4ixy3ipxr7lhaafvg3j3ucdu4w3vumbm

Actuator IPFS

Actuator provides a complete IPFS-hosted version of its dApp that replicates all functions of the main site.

Benefits

β–ͺ

Censorship resistance.

β–ͺ

High availability via any gateway.

β–ͺ

Immutability verified by CID/hash.

β–ͺ

Reduced phishing risk.

Check actuator.finance for the current IPFS link/CID.

For a full walkthrough β€” including the IPFS hash, gateway links, desktop app downloads, community frontends, and security considerations β€” read our guide: IPFS: Decentralized Access to HEX

Frequently Asked Questions

Short answers on SLIP-39, backups and quantum risk

What is SLIP-39 and how does it differ from BIP-39?

SLIP-39 (Shamir's Secret Sharing) splits your wallet backup into multiple 20- or 33-word shares.Β  Unlike BIP-39 (a single 12 or 24-word seed), SLIP-39 requires a threshold number of shares to recover your wallet.Β  This eliminates the single point of failure β€” one lost or stolen share alone cannot compromise your wallet.

Is SLIP-39 more secure than BIP-39?

When configured with multiple shares, SLIP-39 is generally more secure than standard BIP-39 because it removes the single point of failure.Β  Both provide the same base entropy (128–256 bits).Β  However, BIP-39 has universal compatibility while SLIP-39 is limited to Trezor, Keystone, and select devices.

How does Shor's algorithm affect seed phrases?

Shor's algorithm does not directly break seed phrases.Β  The risk is indirect: when you spend from an address, your public key is revealed on the blockchain.Β  A quantum computer running Shor's algorithm could then derive your private key from that public key.Β  Addresses you have never spent from remain safer.

What is the best seed phrase backup method in 2026?

The strongest approach combines: (1) a hardware wallet with a Secure Element chip, (2) one of the two backup standards β€” 24-word BIP-39, or SLIP-39 multi-share stored in separate geographic locations β€” and (3) metal stamping for fire/water resistance.Β  A passphrase (the "25th word") adds a hidden wallet: the seed alone opens only the standard wallet, and a forgotten passphrase takes the hidden wallet with it.Β  For most users, a hardware wallet with a metal backup is excellent; the expert tier is 33-word SLIP-39 shares (256-bit and multi-share, created via Trezor's command line β€” see our backup guide).

Are quantum computers a threat to my crypto today?

No.Β  Cryptographically relevant quantum computers are estimated to be years away (late 2020s to mid-2030s).Β  The hedge is a behavior, not a product: hold long-term on addresses that have never signed a transaction, and when one must sign, sweep the whole balance to a fresh address at once.Β  Hardware wallets, passphrases, and metal backups defend against today's thieves; they do nothing against Shor.

If quantum computers crack 128-bit seeds, do 256-bit seeds fall next?

No β€” quantum search (Grover's algorithm) only square-roots brute-force work, so each extra bit multiplies the effort by about 1.41, and two extra bits double it.Β  If a quantum computer cracked a 128-bit seed in one second, a 256-bit seed would take roughly 585 billion years.Β  But seed-cracking is the wrong door anyway: the realistic quantum attack is Shor's algorithm against public keys already exposed on-chain, and Shor ignores seed length entirely.Β  Behavior (keeping funds on never-spent-from addresses) matters more than word count.

Does a cold wallet protect against Shor's algorithm?

Only for a precise reason β€” and it is not the coldness.Β  On PulseChain and Ethereum, an account's public key is revealed the first time it signs an outgoing transaction.Β  A receive-only cold vault has never signed, so there is nothing on-chain for Shor to attack.Β  A cold wallet you have spent from even once is exposed forever (its signature can be harvested now and attacked later), and active positions like staking or farming require sending β€” the quantum hedge covers passive holdings only.Β  In a quantum era, a vault's first spend should sweep the entire balance to a fresh address in one transaction.

Custody vs. Price β€” Why This Information Is Universal

Why securing yourself also protects everyone's price

Security’s promise is narrow and absolute: no one can take your claim.  It never promised what the claim is worth β€” price also depends on the market’s security, not just yours: every drained holder is forced selling and burned confidence, so a market where many skip these practices taxes everyone’s price, including the perfectly secured.  The asymmetry is the whole argument for the discipline: a drawdown is temporary for those still holding; a drained wallet is permanent.  Security converts your worst case from terminal to temporal β€” the market can give you back a decline; it can never give you back custody.

That is why the information this website provides is universal and free of any pitch: every person who secures themselves also defends the market you hold.  Point people to the source β€” an address they type once, verify, and bookmark β€” rather than forwarding copies: files passed around are exactly the vector this page warns about, and information accessed safely at the source stays canonical and current.

Facts last reviewed: September 23, 2026

Suggest or Correct

Spotted an error?  Have an idea?  Found something missing?
Let us know.  This site is community-built and your input is welcome.

Anything sent here arrives as an email that a person reads.  A Seed Phrase sent here gives its wallet to whoever reads it.