Educational content, not investment advice. Crypto-asset values fluctuate.

Modulis 2 Β· Security and practice
1/8

Wallet security and your seed phrase

After this module

You'll manage your own keys, spot a scammer's message at a glance, and have a clear plan for any situation. Security in DeFi isn't a natural talent β€” it's a handful of skills you master once and use for the rest of your life.

Affiliate link

This is an affiliate link. It costs you nothing extra, but the platform pays us a commission. This helps keep the course free.

In DeFi, you are your own bank. That means you hold the keys yourself β€” with no intermediary who could freeze or seize them. In this lesson you'll master how crypto wallets work and how to protect your assets with simple, repeatable habits.


Custodial vs. non-custodial β€” who holds your money?

Two ways to hold your money

Picture two options:

  1. A bank holds your money β€” you just have a card and a password. Lose the card, and the bank issues a new one. But if the bank shuts down, your money gets stuck.

  2. You hold your money in a safe at home β€” only you have the key. No one can take it. But if you lose the key, no one can help you find it.

In the crypto world, the first option is called custodial, the second β€” non-custodial.

Custodial (someone else holds it)

When you keep money on an exchange (Nexo, Binance, Kraken), the exchange holds your money. You just have login credentials (email + password).

Non-custodial (you hold it yourself)

When you use a DeFi wallet (Jupiter Wallet, MetaMask), you hold your own money. No one else has access.

Not your keys, not your coins

This is the core rule of crypto. If the keys to your money belong to someone else (an exchange, a friend) β€” that money isn't truly yours. In 2022, one of the largest exchanges, FTX, collapsed, and customers lost billions. For DeFi strategies, we always use a non-custodial wallet β€” so that only you control your money.


Jupiter Wallet β€” the Solana wallet

SOL

Jupiter Wallet (recommended) is the official Jupiter Exchange wallet with built-in currency swapping. It works as a browser extension and a mobile app.

What can a Solana wallet do?

Installing Jupiter Wallet (recommended)

1

Download Jupiter Wallet

Go to the Chrome Web Store and search for 'Jupiter Wallet'. Or download Jupiter Mobile from the App Store / Google Play.

Use ONLY the official extension from the Chrome Web Store! Fake copies exist.

2

Create your wallet

You can sign in with Apple ID / email (simplest for beginners) or create a new wallet with a seed phrase.

3

Write down your seed phrase (if you chose that option)

If you chose the seed phrase option, write the 12 words ON PAPER. Not on your phone, not on your computer. Paper only.

This is the ONLY way to restore your wallet. If you lose these words, your money is lost FOREVER. There's no 'forgot password' button.

4

Set a password

Create a strong password for everyday use. You'll only need the seed phrase if you have to restore the wallet on a new device.


MetaMask β€” the Ethereum wallet

ETH

MetaMask is the most popular Ethereum wallet. It supports Ethereum, Arbitrum, and other similar networks.

What can MetaMask do?

Installing MetaMask

1

Download MetaMask

Go to metamask.io and download the browser extension. Works with Chrome, Firefox, Brave, Edge.

Use ONLY the official site, metamask.io. Fake sites look identical β€” but will steal your money.

2

Create a new wallet

Choose 'Create a new wallet'. MetaMask will generate a 12-word seed phrase.

3

Write down your seed phrase

Write the 12 words ON PAPER. Keep it somewhere safe. Best practice β€” two copies in two different places.

4

Add the Arbitrum network

Go to Settings β†’ Networks β†’ Add Network β†’ Arbitrum One. Or simply visit Aave β€” MetaMask will offer to add it automatically.

5

Set a password

For everyday use β€” a strong password. The seed phrase is only for restoring the wallet.


Seed phrase β€” the 12 words that control everything

Seed phrase β€” like a secret safe code

Imagine you have a safe holding all your money. The code to that safe is a sequence of 12 random words. Anyone who knows these 12 words can open the safe and take everything. And there's no backup protection β€” no bank, no police.

That's why you must guard these words better than anything else you own.

Seed phrase (recovery phrase) β€” a sequence of 12 random English words that is the "master key" to your money.

How does it work?

  1. Your private key (a secret code) is mathematically derived from the 12 words
  2. Your public address is derived from the private key (like an account number β€” safe to share)
  3. Anyone who has the 12 words can restore your wallet on any device
  4. You don't need Jupiter Wallet or MetaMask specifically β€” a seed phrase works with any compatible wallet

Seed phrase example

abandon ability able about above absent absorb abstract absurd abuse access accident

This is 12 words from a standardized list of 2048 words. Each word encodes part of your secret code.

NEVER do these things with your seed phrase

  • Don't photograph it with your phone (photos can sync to the cloud)
  • Don't store it on your computer or in any app
  • Don't send it via Telegram, WhatsApp, or any messenger
  • Don't type it into any website (not "Jupiter support," not "airdrop," not "verification")
  • Don't tell anyone β€” not even "official support" (real support NEVER asks for your seed phrase)
  • Don't store it in Google Drive, Dropbox, iCloud, or any cloud service

How to store your seed phrase safely

1

Write it on paper

Write the 12 words on paper by hand. Use a pen, not a pencil (pencil marks fade or smudge).

2

Make 2 copies

Keep them in two separate places. For example: in a home safe + with a trusted family member.

3

Consider a metal plate

For larger amounts, engrave your seed phrase onto a stainless-steel plate. It protects against fire and water.

Popular products: Cryptosteel, Billfodl, SeedPlate.

4

Consider an extra passphrase

Think of it as a 13th word. Even if someone found your 12 words, they couldn't reach your money without this extra password.

No one can recover this password for you β€” write it on paper SEPARATELY from the 12 words. Lose it, and you won't be able to restore the wallet even with all 12 words.


Hardware wallets β€” maximum security

A hardware wallet β€” like an extra safe

Imagine that, besides your seed phrase (the master key), you also have a physical device β€” like a spare key. Even if someone hacked your computer, they couldn't reach your money without this physical device.

For large amounts, a hardware wallet is recommended β€” a small physical device that stores your keys separately from your computer.

How it works: the private key is stored in a physical chip. When you want to carry out an operation, you press a button on the device. Even if your computer is infected with a virus, a hacker can't reach the key.

When is it worth using a hardware wallet?


Jupiter Wallet vs. MetaMask β€” comparison

What mattersJupiter Wallet SOLMetaMask ETH
Main networkSolanaEthereum + Arbitrum
Transaction costUnder $0.01$0.01–$0.30
SpeedUnder 1 sec.2–12 sec.
DeFi protocolsKamino, Orca, Meteora, JupiterAave, Uniswap
Hardware walletLedgerLedger, Trezor
Mobile appYes (iOS, Android)Yes (iOS, Android)
Browser extensionsChrome, Firefox, Brave, EdgeChrome, Firefox, Brave, Edge
Built-in currency swapYesYes
In our strategyPrimary (SOL collateral)Alternative (ETH collateral)

Ethereum transaction costs change with network load β€” during congestion they can temporarily jump several times over. Before a larger operation, check the current price at etherscan.io/gastracker.


Security rules β€” what NEVER to do

1. Never share your seed phrase

Even if you get a message from "Jupiter support," "MetaMask support," or "Kamino team." Real projects NEVER ask for your seed phrase. It's 100% a scam.

2. Never sign unclear transactions

When a DeFi site asks you to confirm a transaction β€” read what you're confirming. If you see "Approve unlimited" or an unfamiliar smart contract β€” reject it.

3. Use a separate browser for DeFi

Keep a separate browser profile just for DeFi. Don't install random extensions. Don't visit untrusted sites.

4. Check the URL

5. Revoke old approvals

Periodically check and revoke old token approvals (permissions to use your tokens):

The most common scam schemes


How to prepare for our strategy

1

Install Jupiter Wallet + MetaMask

Both browser extensions β€” Jupiter Wallet for Solana operations, MetaMask for Ethereum/Arbitrum operations.

2

Write down and safely store your seed phrases

A separate seed phrase for each wallet. 2 paper copies, 2 different places.

3

Buy a hardware wallet (if your portfolio is over $5k)

Ledger Nano S Plus β€” the best price-to-quality ratio. Connect it to Jupiter Wallet and MetaMask.

4

Create a separate DeFi browser profile

A separate Chrome profile just for DeFi. No extra extensions β€” just Jupiter Wallet and MetaMask.

5

Save your bookmarks

app.kamino.finance, orca.so, app.aave.com, deribit.com β€” use ONLY bookmarks, not Google search.


Summary


Security rules and the most common mistakes


NEVER rules

NEVER β€” absolute rules

These eight rules are your personal protection. Learn them once, and no scam scheme will ever get close to your money.

  1. NEVER share your seed phrase with anyone β€” no "employee," no friend, no website
  2. NEVER type your seed phrase into any website (only into the wallet itself when restoring it)
  3. NEVER store your seed phrase on your phone, in email, or in the cloud
  4. NEVER click on unknown tokens that appear in your wallet
  5. NEVER connect to DeFi through links from Discord, Telegram, or email
  6. NEVER confirm a transaction you don't understand
  7. NEVER keep all your assets in one place
  8. NEVER send large amounts without a test transfer

ALWAYS rules

ALWAYS β€” required actions

  1. ALWAYS check the website URL before logging in
  2. ALWAYS use 2FA (Google Authenticator, NOT SMS)
  3. ALWAYS send a small test amount the first time
  4. ALWAYS check the network (Solana, Ethereum, Arbitrum) before sending
  5. ALWAYS read what the wallet shows before confirming
  6. ALWAYS keep your seed phrase on paper in a safe (2 copies)
  7. ALWAYS have enough SOL/ETH for fees (0.05 SOL, 0.01 ETH)
  8. ALWAYS use a different password for each exchange
  9. ALWAYS disconnect your wallet from sites you no longer use
  10. ALWAYS regularly check "Connected Sites" in your wallet

The 9 most common mistakes β€” and how to recognize each one

Below are real situations where people lost money. The good news: each one has a clear tell that you'll spot instantly once you've read this lesson. These are teaching examples β€” your "training ground" for recognizing danger before it reaches you.

1. Handing over your seed phrase to an "employee"

What happens: You get a message on Discord or Telegram: "Hi, I'm a Jupiter support employee. We found a problem. Please provide your seed phrase."

How to recognize it: No real project will EVER ask for your seed phrase. That request alone is 100% proof it's a scammer. See it, and you know what to do: ignore it.


2. Fake website (phishing)

What happens: You search Google for "Orca swap" and click the first result. The URL is 0rca.so (a zero instead of "o"). You connect your wallet and lose everything.

How to recognize a fake website

  • Check the URL letter by letter!
  • Use bookmarks for real sites
  • Official addresses: jup.ag, orca.so, app.kamino.finance, app.aave.com
  • Google ads can show FAKE sites above the real ones!
  • Never click links from Discord or Telegram

3. Wrong network when sending

What happens: You send SOL from Binance, but instead of the Solana network you pick a different one.

Result: The SOL is lost. It can sometimes be recovered, but it's very difficult.

Rule: ALWAYS check the network three times before sending.


4. Scam tokens in your wallet

What happens: A new token, "FREE-SOL" or "CLAIM-1000-USDC," appears in your wallet. You click on it β€” and everything disappears.

Result: You sign a transaction that lets the scammers take all your tokens.

Rule: Ignore ALL unknown tokens. Don't click on them.


5. "Unlimited" approval (token approval)

What happens: You use a DeFi protocol and it asks for permission to use your USDC. You approve an "Unlimited" allowance. Later, the protocol gets hacked.

Result: Hackers can take all your USDC, even if you haven't used that protocol in a long time.


6. Not enough SOL/ETH for fees

What happens: You swapped ALL your SOL into USDC. Now you can't carry out any transaction β€” not even sending USDC.

A simple analogy

It's like a car without gas. Even with a truckload of gold, you're not going anywhere without gas. SOL and ETH are the "fuel" for your wallet.

Rule: Always keep 0.05 SOL or 0.01 ETH for fees.


7. SMS instead of Authenticator

What happens: You use SMS as your 2FA. Hackers hijack your phone number with a "SIM swap" attack.

Result: Hackers log in to the exchange and withdraw everything.

Rule: ALWAYS use Google Authenticator or Authy. NEVER SMS.


8. Public Wi-Fi

What happens: At a cafe, you connect to public Wi-Fi and carry out DeFi operations.

Result: Someone can intercept your login credentials.

Rule: Only carry out DeFi operations on a secure network (home Wi-Fi or mobile data).


9. All your assets in one place

What happens: You keep ALL your assets in one wallet. That wallet gets hacked.

Result: 100% lost.

Rule: Use several wallets: a "daily" wallet (small amount) and a "savings" wallet (large amounts).


Security checklist

Check this before you start doing DeFi operations:

Wallet security

Exchange security

Operation security

Asset allocation


Official URL addresses β€” save these!

Save these addresses in your browser bookmarks:

Bookmark strategy

Create a "DeFi" folder in your browser and add all the official sites. Connect to DeFi ONLY through your bookmarks. NEVER through Google, Discord, or email. It's the simplest protection against scammers.


What to do if something goes wrong?

You think your wallet's been hacked

  1. DON'T WAIT β€” every second counts
  2. Create a new wallet (new 12 words)
  3. Move all your tokens to the new wallet
  4. Revoke all approvals (revoke.cash)
  5. Never use the old wallet again

You lost your seed phrase

  1. If you still have access to the wallet β€” create a new one and move everything over
  2. If you don't have access β€” the money is lost forever (there's no "password reset")

You sent to the wrong address

  1. Blockchain transactions are irreversible
  2. If you sent it to an exchange address β€” contact that exchange's support
  3. If you sent it to a random address β€” the money is gone

Blockchain = final

Blockchain transactions can't be undone β€” there's no "Undo" button. That's exactly why one simple habit works so well: before a large transfer, send a small test amount. Once you've confirmed it arrived where it should, you send the rest with confidence.


Hardware wallets β€” an extra layer of security

For large amounts (over $5,000), we recommend a physical security device:

What is a hardware wallet?

A hardware wallet is a small USB device that stores your keys. Even if your computer is hacked, hackers can't reach your money because the key lives on a physical device. It's like a safe you carry around with you.


Wrap-up

Security in DeFi is your personal responsibility. There's no bank, no insurance. But by following these rules, the risk is manageable. The essentials:

  1. Keep your seed phrase on paper
  2. Check the URL before every login
  3. Use 2FA (Authenticator, not SMS)
  4. Always test before sending large amounts
  5. Never keep everything in one place
Quick check
What's the difference between a custodial and a non-custodial wallet?
Practice task
0 / 5
Run a security audit on your seed phrase

This task is a security audit with no money moved (~15 min). Most losses don't happen because hackers are brilliant β€” they happen because of a bad backup. Check your weak spots NOW, while they haven't cost you anything.

During this audit, never type your seed phrase anywhere and never show it to anyone. You're only checking where it's stored β€” the actual text should never end up on any device.

This is learning, not investing β€” use only small amounts you treat as tuition.

You just completed a full security audit of your own keys and know how to recognize the most common scam schemes β€” most crypto users never do this.