Skip to content
BeginnerLearn the steps

How to secure a mobile wallet

Author
CRYPTO PORT Editorial
Published
Updated
Reading time
5 min

In short

Securing a phone wallet starts with securing the phone. Keep the OS and apps current, set a screen lock and biometrics, and install nothing outside official channels. Then keep only everyday amounts on it, so that losing the device limits the damage rather than ending it.

Key points

  • Keep the OS and apps updated — that is where most of the defence lives
  • Lock the device and lock the wallet app itself, both
  • Install only from the official store, and do not use a modified device
  • Keep only everyday amounts on the phone and hold long-term assets elsewhere

Definition

Configuring protections at both the device and app level for a wallet that stores keys on a phone, so loss or unauthorised access does limited harm.

Start from the fact that a phone wallet is a hot wallet, permanently online. Convenience comes at the price that a compromised device puts the keys at risk. So the order of thinking is the state of the device first, the wallet's own settings second.

Three things are the minimum on the device. First, do not let OS and app updates pile up — that is the only way known weaknesses get closed. Second, set a screen lock with a passcode that is hard to guess; biometrics are convenient, but a passcode is still required after a restart, so its strength is the foundation. Third, do not modify the device — jailbreaking or rooting weakens the separation between apps, and the wallet's protections lose the assumptions they rest on.

In the app, enable its own lock. Separately from the device lock, wallets generally offer an authentication prompt when opening the app. Setting a short auto-lock delay shrinks the window if you put the phone down somewhere. Turning off balance and transaction detail in notifications also stops information leaking onto the lock screen. Names and locations vary by app.

In daily use, mind what you connect through. Avoid operating over public Wi-Fi and use mobile data instead. When connecting to a dApp from a browser, open it from a bookmark you saved rather than from a search result or an advert. And if a signature request appears that you did nothing to trigger, do not approve it without reading it. 'How to review a transaction before signing' sets out how to judge.

Finally, decide your own ceiling on losses. Phones get dropped, stolen and broken. Do not keep everything on one: hold long-term assets on the cold side, as described in 'How to separate hot and cold wallets'. With that in place, losing the device costs you only what you were using day to day. If a phone does go missing, lock or wipe it remotely, and if you suspect the seed phrase has been exposed, move the assets to a new wallet.

Watch out for

  • · Never store the seed phrase on the phone — notes apps, photos and cloud sync are all leak paths
  • · Do not run a wallet on a jailbroken or rooted device, or one carrying apps of unknown origin
  • · Do not send or sign over public Wi-Fi or on a device you borrowed from someone else

Frequently asked questions

  • What should I do when I change phones?

    Install the app on the new device through official channels and restore it on the wallet app's own restore screen. Do not rely solely on the phone's bulk transfer feature, and proceed only with your seed phrase backup to hand. Factory reset the old device once you have confirmed the new one works.

Read next

Crypto quizzes

Answer a few questions and get your result instantly.

Start