The short version
In a self-custody wallet, security is a shared effort: the product encrypts and stores your keys locally, and you decide what leaves the wallet. Almost every loss comes from one of three things — giving away the recovery phrase, approving a transaction that grants spending permission, or installing software that was never legitimate. Defend those three and the rest is detail.
How the security model works
Custodial accounts put a company between you and your assets. Self-custody removes that company — and that is both the protection and the responsibility.
When you set up the extension, keys are generated on your device and encrypted with your password. Transactions are signed locally, so approving a transfer never sends your key anywhere. Coinbase's servers are not in the signing path, and no one there can move the wallet's assets or reverse a transaction that has been mined.
| Security property | What it gives you | What it costs you |
|---|---|---|
| Keys on your device | No company can freeze, seize or lose your assets for you. | You are the recovery plan. A lost phrase means a lost wallet. |
| No account recovery | Nobody can socially-engineer support into handing over your funds. | Nobody can restore access on your behalf either. |
| Irreversible transfers | Approvals mean exactly what they say. | A mistake, or a signature you did not read, cannot be undone. |
| Open browser surface | Access to every Web3 app, without gatekeeping. | Malicious pages and extensions share the same browser as your wallet. |
What a wallet product can and cannot protect
Good wallet software encrypts keys properly, shows you what you are about to sign, and warns about known-bad domains. It cannot stop you from pasting a recovery phrase into a fake page, and it cannot tell that the address you copied has been swapped by malware. Those last two are human-layer problems, which is why the next sections matter more than any feature list.
Recovery phrase rules
The recovery phrase is the wallet. Everything else in this guide is secondary.
The single rule
Never enter your recovery phrase anywhere except the wallet's own restore screen. No website, pop-up, chat, phone call, "validation" form, migration tool or support agent has a legitimate reason to ask for it. A request for those words is the theft, whatever it claims to be fixing.
- Write it by hand, offline. Paper is acceptable; stamped metal survives fire and flood. Two copies in two places beats one careful copy.
- Never photograph it and never type it into a computer. Screenshots sync to cloud backups; clipboard content is readable by other software.
- Keep it out of cloud notes, email drafts and password-manager notes fields. Those are the first places an attacker with device access looks.
- Test the backup early. Restore the wallet on a second browser profile while it holds nothing important.
- Treat any exposure as total. If the phrase ever touched a website, a message or a camera, create a new wallet and move the assets yourself.
- Never split it in a clever way. Home-made schemes fail on inheritance and on your own memory. Use a documented method, or a hardware wallet's backup.
Approvals, signatures and permissions
Most long-term wallet losses do not happen at install. They happen later, through a permission the owner granted and forgot.
Two request types look similar on screen and are very different in effect:
| Request | What you are granting | Risk |
|---|---|---|
| Connect | Read access to your public address and balances. | Low. Privacy and clutter concerns, revocable at any time. |
| Sign message | Proof that you control the address. | Medium. Blind signing can authorise something you cannot see. |
| Approve token | A contract's permission to spend a token — sometimes unlimited. | High. The classic drainer path, and it persists after the site closes. |
| Send / swap / bridge | An immediate transfer or trade. | High. Irreversible once mined, and fee is lost even if the swap fails. |
- Read the approval amount. If a site asks for unlimited spending and the task does not need it, that is a signal.
- Review and revoke old approvals periodically using a reputable approval-management tool you reached by bookmark.
- Disconnect dApps you no longer use — connection alone is harmless, but a live session is one more place a request can arrive from.
- Treat unsolicited signature requests as hostile, even on a site you know.
Scams worth recognising on sight
Fake extensions in ads
Sponsored search results and ad-cloned pages offering wallet downloads. Install only from your browser's own gallery.
"Support" in DMs
Someone helpful, often with a logo in their avatar, offering to fix a wallet problem — then asking for the recovery phrase or for a remote screen session.
Migration and validation pages
Sites claiming wallets must be upgraded, verified or re-synced, with a form for your 12 words. There is no such process.
Airdrops that need a signature
Free tokens that require connecting and signing. The reward is bait; the signature is the payload.
Clipboard hijackers
Malware that swaps a copied address for the attacker's. Always compare the first and last characters after pasting.
"Unlock" or "claim" token traps
A fake token appears in your wallet; interacting with it to claim or unlock something drains the real assets.
One pattern connects all six: they need something from you. A phrase, a signature, a file, a moment of urgency. When a request combines urgency with authority — "your wallet will be blocked unless…" — the safe answer is always to stop and verify independently from an official source.
Browser hygiene
The wallet shares a browser with everything else you install and visit, so the browser is part of the wallet's security perimeter.
- Install fewer extensions. Every extension you add can read page content on the sites it is allowed to touch. Keep the list short and current.
- Keep the browser updated. Most exploited bugs are patched ones.
- Use a dedicated profile if you explore. A wallet profile that visits known dApps is a smaller target than one used for everything.
- Watch for conflicting wallet extensions. Several wallets fighting for the same provider slot is a reliability problem and a confusion risk — keep one active.
- Verify the hostname, not the design. Cloned sites copy branding perfectly. The address bar is the only part they get subtly wrong.
Hardware wallets
A hardware wallet keeps the signing key on a separate device. The extension sends it a request, and you physically confirm on the device. A malicious page, or a malicious extension, can then only ask — it cannot sign on its own.
That covers the case where the browser itself is compromised, which is the one case software-only protections struggle with. It does not cover approving a bad transaction by hand, so pair it with the habit of reading every confirmation.
A reasonable rule of thumb: if the balance would be painful to lose, it belongs on a hardware-backed wallet. Keep a small, software-only wallet for everyday connections and experiments.
Security checklist
- Recovery phrase written offline, in two locations, never photographed or typed into a computer.
- Wallet password long and unique to this device.
- Backup restoration actually tested at least once.
- dApps reached by bookmark, never by search result or ad.
- Token approvals reviewed, old ones revoked, funding amounts left to the minimum where possible.
- Small-balance wallet for experiments; hardware wallet for anything significant.
- Unsolicited messages, pop-ups and urgent-sounding pages treated as hostile by default.
- The phrase never shared with anyone, no matter how convincing their story is.
Keep reading
How to install safely
Verification checks and offline backup during setup.
Features explained
What the wallet does, and its limitations.
Troubleshooting
Stuck transactions, detection failures, wrong network.
Full FAQ
Direct answers on fees, browsers, networks and support.
This guide is educational and independent. It is not financial advice, and it is not an official support channel — for account or product issues, use the official Coinbase support routes.