Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › How to secure a warm wallet

How to secure a warm wallet

By Golan Ben Moshe · Co-founder, Chain Pursuit · 11 min · Last updated 1 October 2026

A warm wallet is a browser, mobile or desktop wallet that stays connected so you can use it. That convenience is the whole point, and it is also the exposure. The single most effective habit is separation: keep a small operational wallet for anything that touches an unfamiliar site, and keep long-term holdings somewhere that never connects to one.

Who this is for

You use a wallet regularly. MetaMask, Rabby, Phantom, Trust Wallet, Coinbase Wallet or something similar. You connect to applications, swap tokens, mint things, and you would rather not stop doing any of that.

If funds have already gone, start with what to do in the first 48 hours instead.

Start with separation

Before any other advice, this one. Most of the damage in warm wallet theft comes from holding everything in the wallet you use for everything.

Run at least two wallets.

An operational wallet holds what you are willing to lose in a bad week. It connects to new applications, claims things, tries things. If it is drained, the loss is bounded and annoying rather than catastrophic.

A long-term wallet holds the rest, and the comparison between the two covers what each protects. It connects to nothing it has not connected to before, ideally nothing at all. A hardware wallet is the natural home for this, and our cold wallet guide covers setting one up.

Move funds from long-term to operational when you need them, not the reverse. The friction is the feature.

This costs you a few minutes and removes most of the worst outcomes. Nothing else on this page is as effective.

What goes wrong

Scam Sniffer's 2025 report found signature-phishing losses across EVM chains of $83.85 million across 106,106 victims. That was down 83% in value and 68% in victims from 2024, when $494 million was taken from more than 332,000 wallets.

Two things are worth reading into that, and most coverage reads only the first.

The decline is real. Wallet interfaces improved, warning systems became common, and some drainer operations shut down.

It does not mean your risk fell. Average loss per victim dropped to around $790, which points to high-volume retail targeting rather than fewer attacks. Scam Sniffer note the decline may partly reflect a shift toward vectors their data does not capture, including private key compromise and targeted social engineering. A number going down in one dataset is not the same as a problem going away.

Of losses exceeding $1 million, Permit and Permit2 signatures accounted for 38%. The largest single incident was around $6.5 million in September 2025, from one malicious Permit signature.

That tells you where to concentrate. Not on exotic exploits. On what you approve.

Understanding what you are approving

Wallet prompts look similar and mean different things. This is the section worth reading twice.

A transaction moves something now. You can see the amount and the destination. It executes once.

A signature proves you control the address. Most are harmless, such as logging into a site. Some are not.

An approval lets a contract move a specific token on your behalf, later, without asking again. Many default to unlimited.

A Permit signature is an approval that costs no gas and produces no on-chain transaction at the moment you sign. Nothing appears in your history. This is why it is favoured by attackers: there is no visible event to alarm you, and the permission is live.

Permit2 extends the same idea across multiple tokens through a single contract. Convenient when legitimate. Broad when not.

EIP-7702 signatures emerged after the Pectra upgrade and allow an ordinary wallet address to temporarily behave like a smart contract. Scam Sniffer recorded malicious use of these in 2025. The category is new enough that wallet warnings are still catching up.

The practical rule: a request to sign something that is not a transaction, on a site you reached today, deserves more suspicion than a transaction does. A transaction shows you what it moves. A signature often does not.

Six prompts that look alike
TransactionMoves something now. You see theamount and destination. Executes once.SignatureProves you control the address. Mostare harmless. Some are not.ApprovalLets a contract move a token later,without asking again.PermitAn approval costing no gas. Nothingappears in your history.Permit2The same across many tokens throughone contract.EIP-7702Lets your address behave like acontract. New, warnings still catchingup.Permit and Permit2 accounted for 38% of losses above $1M in 2025 (Scam Sniffer).
A request to sign something that is not a transaction, on a site you reached today, deserves more suspicion than a transaction does.

Before you sign

Declining costs nothing. There is no penalty for closing a prompt and looking into it.

Approval hygiene

Approvals persist until revoked. An approval granted two years ago to a site that no longer exists is still live.

Check yours periodically, and see how to revoke token approvals for the full process. Use Revoke.cash or Etherscan's Token Approval Checker. Type the address rather than following a link. Fake revocation tools exist and are drainers.

Look for anything you do not recognise and anything marked unlimited. Each revocation is a transaction and costs gas.

Approvals are per-chain. Revoking on Ethereum does nothing on BNB Chain, Polygon, Arbitrum or Base. Check each chain you have used.

Revoking stops future transfers. It does not return anything already taken.

Browser and device

Use a separate browser profile for crypto. Not a separate tab. A profile, with only the extensions you need and none of your ordinary browsing. This limits what a compromised extension elsewhere can reach.

Audit your extensions. Remove anything you do not actively use. Extensions update themselves, and an extension that changes hands can become malicious without any action from you.

Install wallets from official sources only, reached by typing the address. Fake wallet extensions appear in stores regularly, and fake wallet apps are bought as search advertisements above the real result.

Keep the operating system and browser updated. Unglamorous, and it closes the vulnerabilities that malware relies on.

Watch for clipboard hijackers. Some malware replaces a copied address with the attacker's. Verify the first and last characters after pasting, and ideally the middle too.

Do not store a recovery phrase on the device. Not in notes, not in a password manager, not in a screenshot. A warm wallet's phrase deserves the same treatment as a cold wallet's.

Connecting to applications

Reach sites by typing the address or using a bookmark. Search advertisements for major protocols are routinely bought by phishing operations, and the fake result sits above the real one.

Check the domain character by character before connecting. Look-alike domains differ by one letter, a hyphen, or a different ending.

Disconnect when finished. Most wallets list connected sites in settings. Review that list occasionally and remove what you no longer use.

Treat unsolicited links as hostile, including from people you know. Compromised accounts send links.

Social platforms

Most warm wallet theft begins on a social platform rather than in a wallet.

Nobody legitimate contacts you first about your wallet. Not support, not a project, not an investigator. If you post publicly about a problem, expect replies from accounts impersonating support within minutes. Open a ticket through the company's own site instead.

Verified badges prove very little. Accounts get compromised, and on some platforms verification can be purchased.

No legitimate airdrop or giveaway requires you to send crypto first, or to enter a recovery phrase. Our guide to giveaway scams and fake airdrops covers the pattern.

Unsolicited tokens in your wallet are bait. Do not interact with them, including trying to sell them.

Monitoring

Set transaction alerts where your wallet or a service supports them, so movement reaches you rather than waiting to be noticed.

Keep the operational wallet's balance low. A drained wallet holding $200 is a bad afternoon.

Review approvals quarterly. Put it in a calendar.

The first ten minutes after suspected compromise

Order matters. Attackers often run scripts that sweep anything arriving at a known-compromised address.

  1. Move remaining funds to a new wallet. One created fresh, with a phrase the attacker has never had a chance to see. Do this before anything else.
  2. Revoke approvals on the compromised address, on every chain you have used.
  3. If the recovery phrase may have been exposed, treat the wallet as permanently compromised. Revoking does not help; the phrase is the wallet.
  4. Secure your email, then your exchange accounts. Check for forwarding rules you did not create.
  5. Document it before anything disappears. Our evidence checklist covers what matters.
  6. Report it through the channel in your country that can lead to an investigation. Our country guides explain which one that is.

Red flags

What not to do

Warm wallet checklist

Setup

Habits

Maintenance

What this guide cannot do

Security controls reduce risk. They do not remove it. New attack types appear, software has flaws, and people under time pressure approve things they would not otherwise approve. Following everything here does not guarantee your funds are safe, and no honest guide would claim otherwise.

This is general information, not legal, tax or financial advice.

If you have been targeted

People who lose crypto are approached afterwards by others offering to recover it. They may present as investigators, lawyers, exchange staff or officials. Read how to spot a crypto recovery scam before replying to anyone.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

Scam Sniffer, 2025: Crypto Phishing Losses Fall 83% to $84 Million, January 2026. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/

FBI, Cryptocurrency and AI Scams Bilk Americans of Billions, April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions

Scam Sniffer figures reflect that firm's observed EVM wallet-drainer dataset. They are not a complete total across all blockchains or all forms of wallet theft.

Frequently asked questions

What is the difference between a warm wallet and a hot wallet?

The terms are used interchangeably. Both describe a wallet whose keys are held on an internet-connected device. Some people use warm for a wallet that connects occasionally and hot for one always online, but the security considerations are the same.

Is MetaMask safe to use?

Mainstream wallets including MetaMask, Rabby and Phantom are maintained software with active security work behind them. Most losses involving them come from what the user approved rather than a flaw in the wallet. The wallet cannot tell you whether a transaction is a good idea.

What is a Permit signature and why does it matter?

It is an approval that costs no gas and creates no on-chain transaction when you sign. Nothing appears in your history, so there is no visible event to alarm you, while the permission is live. Scam Sniffer found Permit and Permit2 accounted for 38% of losses above $1 million in 2025.

How often should I revoke token approvals?

Quarterly is a reasonable cadence, plus immediately after using anything unfamiliar. Approvals persist until revoked, and they are per-chain, so check each network you have used.

Someone sent unknown tokens to my wallet. Is that dangerous?

Receiving them is harmless. Interacting with them is the attack. Do not try to sell, approve or swap them, and do not visit any site named in the token. Hide it and move on.

Should I use a hardware wallet with my warm wallet?

Many browser wallets can be paired with a hardware device so signing happens on the device. That improves things considerably, because the destination is shown on a screen your computer does not control. It does not prevent you approving something malicious.

Does antivirus software protect my crypto?

It helps against some malware including clipboard hijackers and infostealers. It does nothing about approval and signature phishing, which is where most losses originate. Treat it as one layer, not a solution.

My wallet showed a warning but the site looked fine. Should I proceed?

No. Wallet warnings exist because the site looked fine to somebody else too. Close the prompt, leave the site, and verify independently. Declining costs nothing.

If something has already gone wrong

Ten questions showing which documentation and reporting steps are available in your case.

Recovery pathway assessment

Keep reading