Most security advice is a list of rules. This pillar explains where the rules come from, because that is what helps in situations no list covers.
Direct answer
Cryptocurrency security follows from three properties: transactions are irreversible, private keys are the sole authority over funds, and there is no administrator to appeal to. Prevention is therefore the only control that works. Nearly all real losses come from authorisation mistakes and social engineering — not from broken cryptography.
Start here
| If you want to… | Read |
|---|---|
| Understand the foundations | Crypto Security Basics |
| Set up wallets properly | How to Protect Your Wallet |
| Check a token before buying | How to Verify a Smart Contract |
| Recognise a fraud in progress | Common Crypto Scams |
| Secure your CoinDock account | How to Set Up 2FA |
| Act after something went wrong | How to Report Phishing |
The two habits that matter most
Both are structural — they work without requiring you to correctly identify a threat. That matters, because correct identification is exactly what attackers spend their effort defeating.
1. Separate wallets by purpose
A vault that never touches contracts, a trading wallet, and a burner holding almost nothing for anything unfamiliar.
A malicious approval signed from a burner costs you a burner's contents. The identical signature from a vault costs you everything. You will eventually sign something you should not have; this decides what it costs.
2. Always initiate contact yourself
Type domains. Never follow links about your account, never respond to approaches, never reach a financial site from a search result.
This single habit defeats fake support, phishing, listing fraud, and recovery fraud simultaneously — four separate fraud categories, one behaviour.
Where losses actually come from
In rough order of frequency:
- Authorisation mistakes — a malicious token approval, or a transaction signed without reading it. No key theft; permission was granted.
- Social engineering — fake support, impersonated staff, urgent opportunities, recovery fraud after an earlier loss.
- Key handling — a seed phrase stored somewhere convenient and later accessed, or lost with no backup.
- Wrong destination — right amount, wrong address or wrong network.
Broken cryptography does not appear. Defensive effort belongs where the losses are.
The rule with no exceptions
No legitimate service ever needs your seed phrase.
Not support, not an administrator, not a verification tool, not a migration process, not CoinDock. A seed phrase grants complete control of a wallet, so anyone asking for it is attempting theft. There is no scenario in which providing it helps you.
What CoinDock will never do
- Ask for your seed phrase or private keys.
- Contact you first requesting a payment, an approval, or a credential.
- Send an invoice as an address in a message — invoices appear in your authenticated account.
- Guarantee a price, a return, or a performance outcome.
If something claiming to be CoinDock does any of these, it is not CoinDock. Report it via coindock.online/about, reached by typing the domain.
Account controls CoinDock provides
Two-factor authentication and passkeys (which cannot be phished, being bound to the domain), email verification, password confirmation before security changes, trusted-device management, scoped API keys separating read, trade, and withdraw, and a withdrawal address allowlist with a cooldown — so momentary account access cannot be turned straight into a withdrawal.
Details in account protection.
Note the boundary: these protect your CoinDock account. They have no bearing on a self-custody wallet.
Guides in this pillar
Concepts
- Crypto Security Basics
- Token Listing Safety
- Wallet Safety Guide
- Smart Contract Review Basics
- Common Crypto Scams
How-to
- How to Protect Your Wallet
- How to Spot a Rug Pull
- How to Verify a Smart Contract
- How to Set Up Two-Factor Authentication
- How to Report Phishing
Questions
Related pillars
- Listings — listing review and the fraud around it.
- Liquidity — liquidity traps and whether you can actually exit.
Educational content. Not financial, investment, or legal advice. Cryptocurrency trading carries risk of total loss, and no security practice eliminates that risk.
Core Topics
Crypto Security Basics
Most crypto security advice is a list of rules. This is where the rules come from — which is what lets you handle situations no list covers.
Token Listing Safety
A listing attracts attention, and attention attracts fraud aimed at both the project and its buyers.
Wallet Safety Guide
A wallet stores keys, not coins. Once that is clear, most wallet security advice stops being arbitrary rules and starts being obvious.
Smart Contract Review Basics
Contract review is not a search for a contract with no powers. It is an assessment of whether the powers are known and controlled.
Common Crypto Scams
Each scam here has a mechanism and a specific check that defeats it. Knowing the mechanism matters more than memorising the warning signs.
How-To Guides
Frequently Asked Questions
How do I keep my wallet safe?
Use a hardware wallet, never share your seed phrase, and verify every contract before signing.
What is a rug pull?
A rug pull is when a token team removes liquidity or abandons a project after taking user funds.
How does CoinDock screen tokens?
CoinDock performs documentation, contract, and identity checks during listing review.
Is a smart contract audit a guarantee?
No — audits reduce risk but do not eliminate it. Always combine audit findings with team and community signals.
What is phishing?
Phishing tricks users into signing harmful transactions or revealing credentials via fake sites and messages.
Should I share my seed phrase?
Never. No legitimate service will ever ask for your seed phrase.
What is 2FA?
Two-factor authentication adds a second credential to login, typically via an authenticator app.
Can a token be delisted for safety?
Yes — CoinDock may delist a token if safety, liquidity, or compliance issues arise.
Glossary
Approval
A permission given to a contract to spend tokens on your behalf — review carefully.
Cold Storage
Holding keys offline to reduce attack surface.
Hardware Wallet
A device that keeps private keys offline and signs transactions securely.
Honeypot
A contract that lets users buy but blocks sells, trapping funds.
KYT
Know-Your-Transaction — analysis of on-chain flows for risk indicators.
Phishing
Social engineering that tricks users into revealing credentials or signing malicious approvals.
Rug Pull
A scam where the team drains liquidity or abandons a project.
Sanctions Screening
Checking addresses against sanctioned-entity lists.
Seed Phrase
A human-readable backup of a wallet private key. Never share it.
Smart Contract Risk
Risk that a contract contains bugs, backdoors, or misuse vectors.
Sybil Attack
An attack where one party operates many fake identities to game a system.
Two-Factor Authentication
An additional login factor beyond a password, typically a time-based code.
Review CoinDock Security Standards
Trust starts with security. Learn the standards CoinDock applies to listings and the simple steps every trader and project should follow to stay safe.
Review CoinDock Security Standards