Security Center · Homepage
Crypto Security — What Actually Protects You
Most security advice is a list of rules. This pillar explains where the rules come from, because that is what helps in situations no list covers.
Direct answer
Cryptocurrency security follows from three properties: transactions are irreversible, private keys are the sole authority over funds, and there is no administrator to appeal to. Prevention is therefore the only control that works. Nearly all real losses come from authorisation mistakes and social engineering — not from broken cryptography.
Start here
| If you want to… | Read |
|---|---|
| Understand the foundations | Crypto Security Basics |
| Set up wallets properly | How to Protect Your Wallet |
| Check a token before buying | How to Verify a Smart Contract |
| Recognise a fraud in progress | Common Crypto Scams |
| Secure your CoinDock account | How to Set Up 2FA |
| Act after something went wrong | How to Report Phishing |
The two habits that matter most
Both are structural — they work without requiring you to correctly identify a threat. That matters, because correct identification is exactly what attackers spend their effort defeating.
1. Separate wallets by purpose
A vault that never touches contracts, a trading wallet, and a burner holding almost nothing for anything unfamiliar.
A malicious approval signed from a burner costs you a burner's contents. The identical signature from a vault costs you everything. You will eventually sign something you should not have; this decides what it costs.
2. Always initiate contact yourself
Type domains. Never follow links about your account, never respond to approaches, never reach a financial site from a search result.
This single habit defeats fake support, phishing, listing fraud, and recovery fraud simultaneously — four separate fraud categories, one behaviour.
Where losses actually come from
In rough order of frequency:
- Authorisation mistakes — a malicious token approval, or a transaction signed without reading it. No key theft; permission was granted.
- Social engineering — fake support, impersonated staff, urgent opportunities, recovery fraud after an earlier loss.
- Key handling — a seed phrase stored somewhere convenient and later accessed, or lost with no backup.
- Wrong destination — right amount, wrong address or wrong network.
Broken cryptography does not appear. Defensive effort belongs where the losses are.
The rule with no exceptions
No legitimate service ever needs your seed phrase.
Not support, not an administrator, not a verification tool, not a migration process, not CoinDock. A seed phrase grants complete control of a wallet, so anyone asking for it is attempting theft. There is no scenario in which providing it helps you.
What CoinDock will never do
- Ask for your seed phrase or private keys.
- Contact you first requesting a payment, an approval, or a credential.
- Send an invoice as an address in a message — invoices appear in your authenticated account.
- Guarantee a price, a return, or a performance outcome.
If something claiming to be CoinDock does any of these, it is not CoinDock. Report it via coindock.online/about, reached by typing the domain.
Account controls CoinDock provides
Two-factor authentication and passkeys (which cannot be phished, being bound to the domain), email verification, password confirmation before security changes, trusted-device management, scoped API keys separating read, trade, and withdraw, and a withdrawal address allowlist with a cooldown — so momentary account access cannot be turned straight into a withdrawal.
Details in account protection.
Note the boundary: these protect your CoinDock account. They have no bearing on a self-custody wallet.
Guides in this pillar
Concepts
- Crypto Security Basics
- Token Listing Safety
- Wallet Safety Guide
- Smart Contract Review Basics
- Common Crypto Scams
How-to
- How to Protect Your Wallet
- How to Spot a Rug Pull
- How to Verify a Smart Contract
- How to Set Up Two-Factor Authentication
- How to Report Phishing
Questions
Related pillars
- Listings — listing review and the fraud around it.
- Liquidity — liquidity traps and whether you can actually exit.
Educational content. Not financial, investment, or legal advice. Cryptocurrency trading carries risk of total loss, and no security practice eliminates that risk.
Related on Security Center
-
Wallet Safety Guide
A wallet stores keys, not coins. Once that is clear, most wallet security advice stops being arbitrary rules and starts...
-
How to Protect Your Wallet
A setup that limits the damage of mistakes rather than trying to prevent all of them.
-
Common Crypto Scams
Each scam here has a mechanism and a specific check that defeats it. Knowing the mechanism matters more than memorising...
-
Wallet Security FAQ
The wallet questions that come up most, answered from how wallets actually work.
-
Account Protection FAQ
The account-level controls CoinDock provides, what each one actually stops, and how to configure them.
Review CoinDock Security Standards
Continue your CoinDock journey.
Go