Security — the mechanisms, ranked

How wallets actually get drained

The cryptography essentially never breaks. What breaks is the human loop around it. Here are the six mechanisms that account for nearly all real losses, in order of how often they happen, with the specific defence for each.

  • ~0% Losses caused by broken cryptography
  • #1 Recovery phrase given away voluntarily
  • 171 Phishing sites Ledger shut in two months after its 2020 leak
  • 2 habits Prevent the large majority of losses

The right way to think about this

Read enough loss reports and a clear pattern emerges: the private key is essentially never broken. The mathematics holds. The secure elements hold. Even the genuinely impressive hardware attacks — like the laser fault-injection technique Ledger's research lab published against Tangem's cards in July 2026, which needed physical possession and roughly US$250,000 of laboratory equipment — are vanishingly rare in the real world.

What gets broken is the loop around the key: the person, the interface, the supply chain, the backup. Someone types twelve words into a page that looked like support. Someone approves an allowance they did not read. Someone photographs a recovery phrase and the photo syncs to a cloud account protected by a password that leaked from an unrelated site in 2019. Someone buys a "sealed" device from a marketplace listing.

This matters for how you allocate attention. Spending a fortnight comparing EAL6+ certifications while keeping your recovery phrase in a note app is optimising the part that was never going to fail. The six sections below are ordered by frequency, and the first two account for the large majority of everything.

1 — Recovery phrase phishing

The single largest category, and it works because it does not require any technical compromise at all. The attacker simply asks, in a context where asking seems normal.

Fake support. You post a problem in a public forum, a Discord server or a social media reply, and within minutes receive a direct message from someone presenting as support for your wallet. They are helpful, patient and plausible. Then they ask you to "validate", "sync", "restore" or "migrate" your wallet by entering your recovery phrase into a form, or to send it directly. No wallet company has direct message support. Nobody legitimate will ever ask for your phrase.

Wallet validation pages. A site claiming your wallet needs to be verified against a new protocol version, an airdrop eligibility check, a security audit. All of them want the twelve or twenty-four words.

Migration notices. Particularly effective in New Zealand in 2026, because a genuine migration actually happened — Easy Crypto's customers really were moved to Swyftx after trading ceased on 30 March 2026. When real migration emails circulate, fake ones travel alongside them and look more credible than usual.

The defence is absolute and simple. Your recovery phrase goes into the wallet device or app itself, during initial setup or during a recovery you initiated, and nowhere else, ever. Not a website, not a chat, not a form, not a spreadsheet, not a person. If something is asking, it is stealing. There are no exceptions and there is no legitimate scenario. Internalise that one rule and you have eliminated the biggest category on this page.

2 — Token approval drains

The second largest category, and the one people find hardest to accept because nothing was hacked. You signed it.

On smart-contract chains — Ethereum, Solana, BNB Chain, Base and the rest — letting an application move your tokens requires granting it a spending allowance. This is a normal, necessary operation that every legitimate decentralised exchange needs. A malicious contract asks for an unlimited allowance, and the request looks indistinguishable from the legitimate ones: a contract address, a function name, a hexadecimal blob.

You approve it, because approving things is what using these applications involves. Nothing happens. Then days, weeks or months later, the contract exercises the allowance and that token leaves your wallet entirely. Your hardware wallet, if you used one, signed the original approval perfectly — it did exactly what you told it to.

Four defences, in order of effectiveness.

Use a wallet that simulates transactions. Phantom shows you what a signature will do to your balances before you approve it, turning "interact with contract 0x7a3f…" into "this will allow all of your USDC to be moved". That is a completely different decision. It is the best single defence available and we consider its absence from MetaMask and Trust Wallet a genuine weakness.

Use a burner wallet for anything unfamiliar. A separate wallet funded with only what the interaction needs. A malicious signature then costs you the burner's balance rather than your holdings. See how many wallets you need.

Audit and revoke your approvals. If you have used any smart-contract wallet for months, you almost certainly have active allowances to contracts you cannot name. Go and look. Remove anything unfamiliar and any unlimited approval you are not actively using. It takes five minutes.

Hold Bitcoin in a Bitcoin-only wallet. Bitcoin has no approval mechanism, so this entire category cannot happen. BlueWallet, Coldcard and Blockstream Jade are immune by construction, not by effort.

3 — Digitally stored phrases

This one has a long fuse. The wallet is compromised weeks or years after the mistake, when something entirely unrelated fails.

The pattern: someone photographs their recovery phrase during setup because it is faster than writing it out. The photo syncs to iCloud or Google Photos. Years later that cloud account is accessed — usually because the password was reused on a site that suffered a breach, and credential-stuffing tools work through leaked combinations methodically. The attacker finds a photograph of twelve words and empties the wallet.

Variants include a password manager entry, a note app, an encrypted archive on a desktop, a draft email, and a text message to oneself. All of them share the same flaw: the phrase now exists somewhere reachable over a network, and its security depends on a credential rather than on physical possession.

The defence is pen and paper, two copies, two buildings, and never a photograph. For larger holdings, steel. Full detail in the backup guide.

4 — Clipboard swapping and address poisoning

Two related attacks on the moment you paste a destination.

Clipboard hijacking is malware that watches for something resembling a cryptocurrency address to be copied and substitutes the attacker's — chosen to share the first and last few characters, because that is all anyone checks. You paste, glance, and the four characters at each end match. You send.

Address poisoning needs no malware at all. The attacker sends you a dust transaction from an address resembling one you use often. Later you copy a recipient from your transaction history — and copy theirs.

Three defences. Get the address fresh from the destination wallet, never from a transaction history. Verify it on your hardware wallet's own screen, which is driven by firmware your computer cannot alter — this is the specific attack that trusted display exists to defeat, and it is why we mark down devices with tiny screens. And send a small test amount first, so that if the address was altered you lose ten dollars instead of everything.

5 — Fake apps and cloned sites

A mature criminal business, and the download step is where nearly all of it happens.

Fake wallet applications appear on both major app stores regularly, and paid search results for terms like "trust wallet download" or "metamask download" have repeatedly been used to distribute modified software. On desktop, cloned distribution sites for Electrum and other wallets have circulated for years. The fake app looks and behaves like the real one, generates a recovery phrase the attacker already knows, and waits for you to fund it.

The defence is one extra step: type the project's domain directly, and follow the link from their own site to the store listing or download. Never click an advert. Where a project publishes checksums or signatures — Electrum and Sparrow both do — verify them. And on macOS, treat any wallet that asks you to bypass Gatekeeper as hostile.

Cryptocurrency tokens beside a device, representing the security boundary around wallet keys
Nothing on this page is an attack on cryptography. Every one is an attack on the person, the interface or the supply chain.

Recovery scams

If you have just lost funds, you will be approached by people offering to recover them — "blockchain forensics specialists", "certified recovery agents", accounts replying to your public post about the loss. Essentially all of them are secondary fraud. On-chain transactions are not reversible by any private party. Anyone claiming otherwise, for an upfront fee, is stealing from you a second time.

6 — Tampered and second-hand devices

Less common than the above and the most effective attack that exists against a careful person, because every visible signal is correct.

A device bought second-hand, from a marketplace listing, or from an unauthorised reseller can arrive pre-initialised with a recovery phrase the seller retains. The packaging looks right. The boot screen looks right. The setup flow looks right. You are shown a phrase and told to write it down — and the seller already has it. You fund the wallet, and at some point of their choosing, they empty it. A more elaborate variant supplies a "replacement recovery card" with words for you to enter.

The defence is procurement plus one test. Buy only from the manufacturer or an authorised reseller — in New Zealand that means GROOV in Christchurch for Ledger, The Bitcoin Shop in Tauranga for Bitcoin-focused devices, or PB Tech and Mighty Ape for Ledger entry models. See our buying guide. And then let the device generate its own recovery phrase in front of you. A genuine, uncompromised device creates a new random seed at setup and shows you the words for the first time. If a phrase arrives pre-written, or someone supplies words for you to type, the wallet is not yours and never was.

The New Zealand angle: leaked addresses

There is one loss vector that is specific to hardware wallet owners and that no chip protects against, and New Zealanders were affected by it alongside everyone else.

In July 2020, Ledger suffered a breach of its e-commerce and marketing database through a third-party API. Roughly 270,000 customers had names, email addresses, phone numbers and physical postal addresses exposed, along with over a million email addresses. The data was sold and then dumped publicly in December 2020.

What followed was not digital. Ledger reported shutting down 171 phishing sites in the following two months. Customers received physical extortion letters demanding US$700 to US$1,000 in Bitcoin under threat of doxxing or physical harm. In 2021, some owners received unsolicited counterfeit Ledger devices in the post, modified so that connecting one installed malware. And on 5 January 2026, Ledger disclosed a further exposure of names, emails, postal addresses and phone numbers through its payment processor Global-e, caused by a misconfigured API key.

A list of verified home addresses belonging to people known to hold cryptocurrency is a uniquely valuable asset to a certain kind of criminal. Three practical responses: buy hardware from a New Zealand reseller so your address stays in a local company's records; use a parcel locker or collection point rather than your home; and if your details were in that data, enable a passphrase so that anyone who reaches your written seed words finds a decoy wallet. See the backup guide.

What to do if it happens to you

Move fast, and assume the compromise is total rather than partial.

Create a new wallet on a clean device and move what remains. Not a new account in the same wallet — a new wallet with a new recovery phrase, generated on a device you have reason to trust. If your phrase leaked, revoking approvals achieves nothing, because the attacker can sign anything at any time.

Record everything. Transaction hashes, timestamps, addresses, screenshots, and how the contact or site reached you. You may need it for police, for an insurance claim, or to explain to Inland Revenue why assets left your wallet without a corresponding sale.

Report it. Netsafe handles online harm reports in New Zealand, and police take reports of fraud. If a registered platform was involved, its dispute resolution scheme may be relevant — another reason to check the FSPR before you deposit anywhere.

Do not engage with recovery offers. See the warning above. The transaction cannot be reversed by any private party.

Then work out which mechanism it was, because that determines what else is exposed. If your phrase leaked, every wallet derived from it is gone. If you approved a malicious contract, only the approved token was at risk. If the machine was compromised, treat every credential entered on it as public.

The two habits, again

We will end where we began, because these two sentences cover the large majority of everything above. Your recovery phrase goes into the wallet device or app during setup and recovery, and nowhere else, ever. And every time you approve a transaction, read what the device is actually showing you rather than what you assume it says. Those two habits are worth more than any amount of hardware.

Frequently asked

Questions on this topic

How do crypto wallets get hacked?

Almost never through the cryptography. In the incident reports we have read, the loss mechanisms in order of frequency are: the owner typed their recovery phrase into a fake site or gave it to a fake support agent; the owner approved a malicious token allowance; the phrase was stored digitally and the cloud account was compromised; the destination address was swapped by clipboard malware; or the device was bought second-hand and pre-loaded with someone else's seed. Every one of those involves the human loop around the key, not the key itself.

What should I do if my crypto wallet is hacked?

Assume the key is fully compromised, not partially. Create a brand new wallet with a new recovery phrase on a clean device and move anything remaining immediately — do not just revoke approvals and keep using the same key, because if the phrase leaked the attacker can return any time. Record transaction hashes and timestamps. Report to Netsafe and to police. Be extremely wary of anyone offering to recover your funds; recovery scams target people who have just been victimised. On-chain transactions are not reversible.

Can someone steal crypto with just my wallet address?

No. A public address lets someone send you funds and see your balance and transaction history on a block explorer — nothing more. Spending requires the private key. What an address does expose is information: your holdings, your transaction patterns, and potentially links to other addresses you control. That is a privacy issue rather than a theft risk, and it is covered in our tracking and traceability guide.

What is a token approval drain?

On smart-contract chains, letting an application move your tokens requires granting it a spending allowance. A malicious contract asks for an unlimited one, you approve it because approving things is what using these applications involves, and at some later point — days or months — the contract exercises the allowance and empties that token from your wallet. Nothing was hacked; you authorised it, and a hardware wallet signs it just as faithfully as a phone wallet. Bitcoin-only wallets are structurally immune because Bitcoin has no approval mechanism.

How do I know if a crypto website is fake?

Type the domain yourself rather than clicking a search result or an advert — paid results for wallet downloads have repeatedly been used to distribute malicious software. Check the URL character by character, since look-alike domains use substituted letters. Be suspicious of any urgency, any request for your recovery phrase, and any support contact that initiated the conversation. And remember that a legitimate-looking site reached from an untrusted link is still an untrusted site.

Next in this cluster

Keep reading