Skip to content
ISO Coins

Guide 1

Guide 1 - Prepare your digital security before you touch any coin

A dedicated email, a password manager, safer 2FA, a hardened phone and computer, and a plan for where the seed phrase lives, before you open an exchange account.

8 min readLast updated: October 11, 2026

Goal

By the end of this guide you will have a small, boring, well-protected set of accounts and devices that you will use only for crypto. You will also have decided, in advance, where the most sensitive secret of all, your , will and will not be kept.

Most losses in crypto do not come from clever attacks on the blockchain. They come from a reused password, a hijacked phone number or a fake website. Fixing those takes an afternoon, and it is far easier before there is money at stake.

Nothing here is investment advice. It is preparation.

Time needed

  • Dedicated email and password manager: 30-45 minutes.
  • Authenticator app or security key: 15-20 minutes.
  • Phone and computer review: 30 minutes.
  • Deciding on the seed phrase plan: 15 minutes of thinking, no purchases yet.

Plan on about two hours, once.

Before you start

  • A computer and a phone that you control, and that are not shared or managed by an employer.
  • About 30 minutes of quiet. Rushing is how people skip the recovery step.
  • A pen and paper for the recovery codes you will generate. You will not photograph them.

Steps

Step 1 - Create an email address used only for crypto

Your email is the master key to every account that says "forgot password". If an attacker controls it, every other protection falls back to that one door. Kraken, for example, strongly recommends a dedicated email address that you use only for the exchange. [3]

Open a new address with a mainstream provider, protect it with a strong password and the strongest 2FA it offers, and do not use it for newsletters, shopping or social networks. Do not publish it. Over time, a spam-free inbox also makes real security alerts easier to notice.

Step 2 - Install a password manager

A password manager creates and stores a different long password for every site, so one leak cannot unlock the others. CISA's guidance is to use at least 16 characters, a unique password for each account, and a password manager to remember them. [1]

Choose a well-known manager, set a long master passphrase that you have never used anywhere else, and write that master passphrase on paper kept at home. Add the new crypto email first. Let the manager generate every future password.

Step 3 - Choose your second factor

asks for something beyond the password. Not all second factors are equal:

OptionProtects against password theftProtects against fake sitesNotes
SMS codeYesNoMessages are not encrypted and can be intercepted or redirected through your phone number. [2]
Authenticator app (time-based code)YesNoYou can still be tricked into typing the code on a fake site.
Security key or passkey (FIDO)YesYesPhishing-resistant: CISA calls FIDO the only widely available phishing-resistant authentication. [2][4]

CISA's mobile guidance recommends enabling FIDO authentication where possible and turning off weaker forms, and states that SMS is not phishing-resistant. [2] Kraken also recommends a passkey for sign-in 2FA over an authenticator app, because passkeys resist phishing while authenticator codes can be stolen. [3]

A practical plan: a hardware security key or passkey if the service supports it, an authenticator app otherwise, and no SMS. Many people keep two keys, one in use and one stored elsewhere, so a lost key is an inconvenience and not a lockout. When an app shows backup codes, print or write them and store them with your other paper records.

Step 4 - Harden your phone

  • Set a SIM PIN with your mobile carrier, and ask the carrier whether it offers a port-out lock or a "no SIM change without in-person ID" option. A SIM swap is how SMS codes get stolen. [2]
  • Update the operating system and apps and turn on automatic updates.
  • Use a strong device passcode, not four digits, and enable biometric unlock only as a convenience.
  • Install apps only from the official store, and remove ones you do not use.
  • Be suspicious of links in messages claiming to be from an exchange or wallet. Open the app or type the address yourself.

Step 5 - Clean up your computer

  • Keep the operating system and browser updated.
  • Use a separate browser profile, or a separate browser, for crypto only, with few extensions. Extensions can read what you see on a page.
  • Do not install cracked software or "free" tools. Do not run attachments from people you do not know.
  • Run the built-in antivirus, and lock the screen when you step away.

If you can afford it, a separate computer used only for money is the cleanest solution. If not, the dedicated browser profile is a reasonable compromise.

Step 6 - Decide where the seed phrase will live (and where it will not)

When you set up a in guide 5, it will show you a list of words. Anyone who has them controls the funds, and nobody can reset them. Ledger tells users that it will never provide or ask for a secret recovery phrase. [5]

Where it can live:

  • On paper or metal that you wrote yourself, made at home from the device screen.
  • Kept in a place you can reach but strangers cannot, such as a home safe, and ideally with a second copy in another location.

Where it must never live:

  • A photo, screenshot, email, chat message, cloud note or text file.
  • A password manager or any website form.
  • A device that is online, or a "recovery tool" someone sent you.
  • A sheet that came pre-written in the box. A new device should come with a blank recovery sheet. [5]

Decide now: which room, which container, and who, if anyone, will know it exists. Guide 5 covers paper versus metal in detail.

Step 7 - Run a short fire drill

Before any money moves, rehearse one bad day. Log out of your dedicated email and sign back in using only the second factor. Open the password manager on a second device. Find your written backup codes without searching for more than a minute. If any step fails, fix it now, while the cost of failure is a few minutes and not a locked account.

Then write a one-page note for yourself, kept on paper with your other records: which accounts exist, which second factor protects each, and where the backup codes are. Do not include passwords or the seed phrase. The goal is that a calm version of you, a year from now, can recover access without guessing.

Common mistakes

  • Using your personal email for the exchange. A breach of a shopping site then becomes a route into your crypto.
  • Reusing a password "just for the small account".
  • Keeping SMS 2FA because it is convenient. It is the first thing criminals target. [2]
  • Photographing the seed phrase "just as a backup". Photos sync to the cloud automatically.
  • Entering the phrase into a website that asks for it. No legitimate wallet or support team ever needs it. [5]
  • Storing recovery codes in the same manager as the password they protect.

If something goes wrong

You lost your authenticator or key. Use the backup codes you saved, or the second key. If neither exists, the service's recovery process may take days and ask for ID. This is why recovery codes are part of the setup, not an extra.

Your phone stopped working or lost signal unexpectedly. Contact your carrier from another phone and check whether your number was moved. Then change the passwords on your dedicated email first.

You think a device is infected. Disconnect it, change passwords from a clean device, and do not enter a seed phrase on the suspect device.

You already photographed or typed the seed phrase somewhere. Treat that phrase as compromised. Create a new wallet with a new phrase and move the funds. See guide 10.

Official help articles

  • CISA - Use strong passwords [1]
  • CISA - Mobile communications best practice guidance [2]
  • CISA - Next level MFA: FIDO authentication [4]
  • Kraken - Securing your account and digital life [3]
  • Ledger - Scams targeting crypto holders [5]
  • Trezor - Scams and phishing (background reading) [6]

Sources

  1. Use strong passwords - CISA Secure Our World - https://www.cisa.gov/secure-our-world/use-strong-passwords
  2. Mobile Communications Best Practice Guidance (December 2025) - CISA - https://www.cisa.gov/sites/default/files/2025-12/guidance-mobile-communications-best-practices_508c.pdf
  3. Securing your Kraken account and digital life - Kraken Support - https://support.kraken.com/articles/201396837-securing-your-kraken-account-and-digital-life
  4. Next Level MFA: FIDO Authentication - CISA - https://www.cisa.gov/news-events/news/next-level-mfa-fido-authentication
  5. Scams Targeting Crypto Holders - Ledger Support - https://support.ledger.com/article/scams-targeting-crypto-holders
  6. Scams and phishing - Trezor Learn - https://trezor.io/learn/security-privacy/personal-security-standards/scams-and-phishing