Most stolen crypto is not taken from a wallet. It is taken from an account, and the break-in usually starts somewhere that has nothing to do with crypto at all: your email.

  • Most crypto theft never touches a seed phrase. It goes through email takeovers, reused passwords and hijacked phone numbers, and every step of it is preventable for free.
  • The order matters: secure your email first, then passwords, then switch two-factor codes off SMS. Twenty minutes, no spending.
  • SIM-swap fraud rose 38% in a year in the UK. Your phone number is a weaker lock than you think it is.

The theft that never touches your wallet

Here is how it usually goes. Somebody gets into your email. Not through anything clever: a password you also used somewhere else turned up in a breach, and they tried it. Once they are in, they do not read your messages. They go straight to your exchange, click forgot password, and the reset link lands in an inbox they now control. If your two-factor codes arrive by text, they may already have moved your phone number to their SIM, so those land with them too.

At no point did they touch your seed phrase, your hardware wallet or your PIN. Everything in our self-custody guide still held. They simply walked in through the front door of an account, using keys you left in other people’s buildings.

If you keep any crypto on an exchange, and most people keep at least some, then your real security is not the exchange’s vaults. It is your email password, your phone contract and whether you reuse passwords. Those three things decide whether the rest of this page ever matters to you.

Your email is the master key

Every account you hold can be reset from your email. That makes it worth more than any single account it unlocks, and it deserves better treatment than it usually gets: the average email password is old, reused and has been quietly sitting in a breach dump for years. You can check that last part right now at Have I Been Pwned, which is free and run by a security researcher, not a company selling you the cure.

Three things fix the email problem, in order of effort:

Give your email a password used nowhere else. Not a variation. Not the usual one with a different number on the end. A breach of one site should tell an attacker nothing about any other, and variations are the first thing the software they use tries.

Turn on two-factor for the email itself. People protect the exchange and forget the inbox that can reset it.

Consider a separate address that only your crypto accounts know. This is the quiet one, and it is more powerful than it sounds. The address that gets phished is the one that is everywhere: in old forum signups, marketing lists and breach dumps. An address that exists only for your exchange has never leaked anywhere, receives no phishing because nobody knows it exists, and makes any “urgent security alert” arriving at your everyday address instantly identifiable as fake, because your exchange does not have that address.

You can do the third one with any provider, including a second free Gmail. We point at Proton below because the encrypted inbox and the alias tool do this job with the least friction, and it is what we use ourselves. The advice stands either way, and the free tiers cover everything this page asks of them.

The separate inbox
Proton MailAd

A separate encrypted inbox for your crypto accounts, so a leak of your everyday address never reaches them.

Aliases built in
Proton PassAd

A password manager that also makes throwaway email aliases, one different address per exchange.

The free option
Bitwarden

The open-source password manager. Does the one job that matters here, and the free tier is not a trial.

Links marked Ad earn us a commission. It costs you nothing extra, and we chose what to recommend before we chose who to sign up with. How we make money

Passwords, without the lecture

You already know passwords should be long and unique, and you already know nobody can memorise forty of them. The gap between those two facts is the entire reason password managers exist. One strong password protects the manager; the manager generates and remembers a different random one for every site. Which manager matters far less than using one at all: Proton Pass and Bitwarden above are both good, both free, and both a large upgrade on the browser asking if you would like to save that password again.

If you do nothing else from this section, make the email password unique today and let the rest follow when it follows.

Two-factor: the kind that works and the kind that doesn’t

Two-factor authentication by text message has a flaw that has nothing to do with your phone: the number itself can be moved. A fraudster who convinces your network to port your number, or to issue a replacement SIM, receives every code meant for you. Cifas, the UK’s fraud prevention service, recorded a 38% rise in SIM-swap fraud in a year in its 2026 Fraudscape report. It is not an exotic attack. It is a phone call to a call centre by someone who has rehearsed.

The fix costs nothing: an authenticator app. It generates the six-digit codes on the device itself, so there is no text to intercept and nothing a ported number can receive. Any of them will do the job, and every serious exchange supports them. Better again, most large exchanges now accept passkeys or a physical security key, which resist phishing too, because they simply will not sign in to a fake site however convincing it looks.

While you are at it, ring your mobile network and ask what protection they offer against SIM swapping. There is no single UK-wide answer, which is itself worth knowing: EE can place accounts in a secure state where automated porting requests fail, Three lets you lock account access behind the app with biometrics, and Vodafone can require the account PIN before a porting code is issued. Ten minutes on the phone, and the attack that grew 38% last year mostly stops applying to you.

The messages that open the door

Almost every account takeover begins with a message, and the message has one job: to make you act before you think. Your account is restricted. A withdrawal you did not make is being processed. Support has noticed suspicious activity, click here within 24 hours. The details change and the shape never does: urgency, plus a link, plus a login page that is not quite the real one.

The defence is a habit, not a product. Never log in through a link that arrived in a message. Go to the exchange the way you always do, through your own bookmark or by typing the address, and if something is genuinely wrong with your account it will say so there. No exchange minds you ignoring their email and logging in directly. Only the fake ones need the link clicked.

Two settings in your exchange’s security page quietly finish the job. An anti-phishing code makes the exchange include a word you chose in every genuine email, so a message without it exposes itself. A withdrawal address allowlist means that even someone inside your account cannot send coins anywhere new without a waiting period, which turns a theft into an alarm.

If it has already happened

Speed matters more than anything else in the first hour, and the order matters too.

Take back the email first. Reset its password from a device you trust, sign out all other sessions, and check two places attackers use to keep a foothold: forwarding rules and recovery details. If there is a forwarding rule you did not create, that is how they were planning to come back.

Then the exchange. Change the password, revoke active sessions, and contact support asking for a freeze on withdrawals. Exchanges deal with this daily and move faster than people expect when the word “compromised” is in the first line.

Report it to Action Fraud, which covers England, Wales and Northern Ireland (Police Scotland handle it directly in Scotland). You get a crime reference number, and if a bank transfer was involved, call your bank on 159, the anti-fraud line every major UK bank answers.

Be extremely wary of anyone offering to get the coins back. Search results and social media replies fill with “crypto recovery services” precisely when people are desperate, and nearly all of them are the second scam. Nobody legitimate asks for an upfront fee to recover stolen crypto, and nobody at all can reverse a confirmed transaction.

Common questions

Is SMS two-factor better than nothing?

Yes, clearly. It stops the attacker who only has your password, which is most of them. The point is not that SMS is worthless, it is that the free alternative also stops the attacker who has your phone number, so there is no reason to settle.

My coins are on a hardware wallet. Do I still need this?

The coins on the device are safe from all of it, and that is exactly what the device is for. But your exchange account still holds whatever you left there, your bank connection, and enough identity documents to be worth stealing on their own. moves the money out of the building. It does not un-build the building.

I got an email saying my details were in a breach. Panic?

No, act. Check the address at Have I Been Pwned to see what actually leaked, change the password anywhere that password was used, and treat it as the prompt to stop reusing passwords that it is. Breaches are constant background weather now. The people who get hurt by them are the ones for whom one password opened many doors.