SAFU Basics

Crypto Safety Tips

How to stay safe in crypto and not get hacked, in plain English.

Last reviewed

The short answer: never share your seed phrase, never sign anything you don't understand, and only connect your wallet to sites you've checked yourself. Keep serious money in a hardware wallet, separate from the wallet you use for mints and games. If something feels urgent or too good to be true, stop. Most people who lose crypto aren't hacked by clever code; they're tricked into handing over access.

The five rules

  1. Never share your .
  2. Never sign something you don't understand.
  3. Never connect your wallet to a site you haven't checked yourself.
  4. Never keep serious money in the wallet you use for mints and games.
  5. When in doubt, do nothing.
Our promise

HooTang Clan will never ask you to connect a wallet, sign anything or share your seed phrase. This site doesn't even have a connect button. Anyone who says otherwise is scamming you.

Scam or safe?

Ten situations. Is each one a red flag, or safe?

How SAFU are you?

Be honest; nobody sees your answers. They stay on this device.

My seed phrase is written down offline, not on my phone or in the cloud.

I've never typed my seed phrase into a website.

Any serious money I have is in a hardware wallet.

I use a separate wallet for mints and games.

I open crypto sites from bookmarks, not search results or DMs.

I reject signatures I don't understand.

I've checked and revoked old approvals in the last few months.

I ignore DMs from "support", founders and mods.

My email and exchange accounts use an authenticator app or passkey, not text codes.

I check the whole address before sending, and never copy it from my history.

Crypto safety tips, topic by topic

Tap a topic, then tap any tip for the why. Words with a dotted line explain themselves when you tap them.

How do I keep my seed phrase safe?

Your seed phrase, 5 tips
Never share it.

Not with a founder, a moderator, "support", a friend or anyone offering to help. Whoever has it controls the wallet.

Never type it into a website.

Real apps never need it to connect. The only place it ever goes is your own wallet app, when you restore it.

Support will never ask for it.

Anyone who does is trying to take your wallet.

Write it on paper.

Never screenshot it or keep it in Notes, email, iCloud, Google Drive or Discord. For bigger holdings, consider a metal backup.

Store the backup safely.

Somewhere safe from fire, water and prying eyes. Don't split the words across places unless you really know what you're doing; done badly, it makes you less safe.

Read the guide: How to protect your seed phrase →

Which wallet should I keep my crypto in?

Your wallets, 4 tips
Keep serious money in a .

Your everyday is for everyday amounts.

Buy hardware wallets direct from the maker.

Never second-hand, and never use one that arrives with a seed phrase already written down. That's a known scam.

Use a separate wallet for mints and games.

Your main wallet should never connect to new sites. Keep a with small amounts for that. Think savings account, current account and cash in your pocket.

Leave strange tokens and NFTs alone.

Scammers send them to your wallet. Don't try to sell them and don't visit the sites they mention. Just hide them.

Read the guide: Hot vs cold wallets →

What should I check before signing anything?

Signing and approvals, 4 tips
If you don't understand it, don't sign it.

Reject it and find out first. You lose nothing by cancelling.

A signature can be as dangerous as a transaction.

A signature can hand over your tokens without any on-chain approval. Many work this way.

Be wary of .

Especially "SetApprovalForAll" and unlimited allowances. They let a contract move your tokens or NFTs for you.

Revoke old approvals regularly.

A tool like revoke.cash shows what you've approved; bookmark the real one, as fakes exist. Revoking costs a little .

Read the guide: Wallet drainers explained →Read the guide: How to revoke token approvals →

How do I spot a crypto scammer?

People and messages, 8 tips
Assume every DM is a scam until you've checked it.

Founders, mods and support staff don't message you first.

Be wary of "open a ticket" links and verification bots

that ask you to connect or sign anything.

Even official accounts get hacked.

Be most suspicious of a surprise "mint now" or "claim now" link, even from a real channel.

Urgency is a tactic.

"Your wallet is compromised, verify now", "claim before it expires", "you've won": all classics.

Nobody can reverse a blockchain transaction.

After a loss, "recovery experts" come calling. They're the second scam.

Guaranteed returns don't exist.

Fixed profits, "mentors", trading bots and groups promising gains are scams.

Knowing a lot doesn't make someone trustworthy.

Scammers are often the most knowledgeable people in the room.

Don't advertise your net worth.

Online or in person. It makes you a target.

Read the guide: Crypto recovery scams →

How do I secure my accounts and devices?

Accounts and devices, 4 tips
Use strong, unique passwords.

A password manager makes this easy.

Use an authenticator app or passkeys, not text codes.

SIM swaps make text codes easy to steal. Ask your mobile provider to put a PIN on your account.

Protect your email like your wallet.

Whoever controls it can reset your exchange and social accounts.

Keep everything updated.

Phone, computer, browser and wallet apps. Security updates matter.

How do I send crypto safely?

Sending crypto, 5 tips
Transactions are final.

There's no bank to call.

Check the whole address.

Not just the first and last few characters.

Never copy an address from your history.

Scammers send tiny transfers from lookalike addresses so they show up there. It's called .

Check what you pasted.

Some malware swaps the address on your clipboard.

For big transfers, send a small test first.

If the test arrives, send the rest.

Read the guide: Address poisoning →

How do I avoid losing money on tokens and NFTs?

Money basics, 6 tips
Only use money you can afford to lose.

If losing it would hurt, it's too much.

Most new tokens go to zero.

Plenty of NFTs do too.

Check before you buy.

Is the locked? How much do the dev and top wallets hold? Has anyone managed to sell? That's Owl Eyes in owl.fun, in real life. Skip those checks and you're one or away from zero.

The house keeps an edge.

Real casinos, and plenty of "yield" schemes, are built so that over time you lose.

FOMO is a scammer's best friend.

If you feel rushed to , stop.

In the UK, selling or swapping crypto can be taxable.

Keep records of every trade.

Read the guide: How to spot a rug pull →Read the guide: Honeypot tokens →

In-depth guides

Scam or safe? Worked examples

Show all 16 situations and answers (spoilers for the quiz)
  1. A Discord DM from “HooTang Support”: your wallet has been flagged, and you must verify your seed phrase within 30 minutes.

    Red flag. Support never DMs first and never needs your seed phrase. The countdown is the tell.

  2. The mint link goes to magiceden-claim.io. The site looks exactly like Magic Eden.

    Red flag. Lookalike domains copy real sites pixel for pixel. Use your bookmark, not the link.

  3. Your new hardware wallet arrives with a card showing a seed phrase already filled in, “for your convenience”.

    Red flag. A real one makes you create your own. Whoever wrote that card can empty it.

  4. A free-mint site asks you to sign SetApprovalForAll for your whole NFT collection.

    Red flag. That lets the contract move every NFT in that collection. A free mint doesn’t need it.

  5. You open the marketplace from your own bookmark, check the URL, and connect your mint-only wallet.

    Safe. Bookmark, check, separate wallet. That’s the routine.

  6. A mystery NFT turns up in your wallet with a link to “claim your reward”.

    Red flag. Scam NFTs are bait. Don’t click, don’t try to sell. Just hide it.

  7. After a hack, a “recovery expert” offers to get your ETH back for a small fee upfront.

    Red flag. Nobody can reverse a blockchain transaction. This is the second scam.

  8. Before moving a large amount to your new wallet, you send a tiny test transaction first.

    Safe. If the test lands, the address is right. Cheap insurance.

  9. A trading group promises 3% a day, guaranteed, if you send ETH to their bot.

    Red flag. Guaranteed returns don’t exist. That’s over 4,000% a year; nobody real offers that.

  10. You copy an address from your transaction history because the first and last four characters match.

    Red flag. That’s address poisoning. Lookalikes match the ends. Check the whole address, from a trusted source.

  11. You write your seed phrase on paper and keep it hidden at home, with no photo of it anywhere.

    Safe. Offline, private and yours. Exactly right.

  12. The project’s official X account posts a surprise “claim now, one hour only” link.

    Red flag. Official accounts get hacked, and surprise claim links are how it pays. Check with the team elsewhere first.

  13. You switch your exchange login from text-message codes to an authenticator app.

    Safe. Text codes can be stolen with a SIM swap. An app is much safer.

  14. A site asks you to sign a “permit” message. There’s no gas fee, so it must be harmless.

    Red flag. Free doesn’t mean safe. Permit signatures can hand over your tokens.

  15. Once a month you check your old approvals and revoke the ones you no longer need.

    Safe. Good hygiene. Old approvals are open doors.

  16. You connect your main savings wallet to a brand-new mint because the art looks great.

    Red flag. New sites get your mint wallet, never your savings. Great art proves nothing.

Crypto safety glossary

Show all 13 terms
Seed phrase
The 12 or 24 words that are your wallet. Anyone who has them owns it.
Hot wallet
A wallet that lives on your phone or in your browser. Handy, and more exposed.
Hardware (cold) wallet
A small device that keeps your keys offline, so a hacked computer can’t sign for you.
Degen wallet
A separate wallet with small amounts in it, used for risky mints and new sites.
Approval
Permission you give a contract to move your tokens or NFTs. Useful, and dangerous if the contract is malicious.
Permit signature
A free, off-chain signature that can approve spending of your tokens. Drainers love them.
Wallet drainer
A scam site or contract that empties your wallet once you connect and sign.
Gas
The small fee you pay to get a transaction onto the blockchain.
Address poisoning
Scammers send tiny transfers from lookalike addresses, hoping you copy the wrong one from your history.
Liquidity pool
The pot of money a token trades against. If it’s thin or unlocked, it’s easy to move, or to empty.
Rug pull
When the people behind a token or project take the money and run. Holders are left with the bag.
Honeypot
A token you can buy but can’t sell, or can only sell at a huge loss.
Ape in
Buying fast without checking. Usually how people get hurt.

Where to get help in the UK

  • FCA ScamSmart: check whether an investment offer is a known scam.
  • Action Fraud: report fraud in England, Wales and Northern Ireland. In Scotland, call Police Scotland on 101.
  • National Cyber Security Centre: guidance on passwords, two-step verification and securing your devices.

A transaction showing up in your wallet doesn't mean it's safe. A website looking professional doesn't mean it's legitimate. Someone knowing a lot about crypto doesn't mean they're trustworthy.

Self-custody gives you control, but it also means you are the final security layer.

General safety information, not financial or legal advice. HooTang Clan has no token, and nothing on this page is a reason to buy anything.