Kāinga Akademia Ngā Ārahi Aratohu Haumaru Crypto

Me pēhea te tiaki i tō Crypto: Aratohu Haumaru

Self-custody means you are responsible for your own security. This guide covers how to store your seed phrase, when to use a hardware wallet, how to spot scams and phishing, and what to do if something goes wrong.

12 meneti pānui Kua whakahoutia i te Mahuru 2026 Haumaru

He mea nui te Haumaru Crypto

I roto i te pūtea tuku iho, kei te pēke tō moni. Mēnā ka tāhaetia tō kāri, ka waea koe ki te pēke, ka whakahokia ngā utu. He rerekē te mahi a te Crypto. Ina pupuri koe i te crypto i roto i tētahi pukoro whakahaere-whaiaro, ko koe te pēke. Kāore he tari tinihanga, kāore he whakahokinga utu, kāore he tautuhi kupuhipa. Mēnā ka riro i tētahi atu ō kī tūmataiti, kua ngaro ngā moni mō ake tonu.

The scale of theft is large. According to the Chainalysis Crypto Crime Report, about $3.8 billion was stolen in crypto hacks in 2022, the worst year on record at the time, and about $1.7 billion in 2023. The Ronin bridge hack of March 2022 (about $625 million) and the Wormhole exploit of February 2022 (about $325 million) showed that even well-funded projects with professional teams can be breached. Chainalysis publishes updated yearly figures (see Sources).

Those figures cover protocol hacks. Individual losses from phishing, seed phrase theft, SIM swaps and social engineering come on top; the FBI Internet Crime Complaint Center (IC3) reports yearly totals for fraud complaints involving crypto (see Sources). The good news is that most attacks on individuals rely on a handful of mistakes, and this guide shows how to avoid them.

Ngā Mahi Phishing

Ngā paetukutuku rūpahu, ngā īmēra me ngā karere tika e whakapohehe ana i a koe ki te whakapuaki i tō rerenga kī, ki te haina rānei i tētahi whakawhitinga kino.

Ngā Whakamahinga Kaitono Atamai

Bugs in DeFi protocol code that let attackers drain funds. Bridges and lending protocols have been the most targeted.

Hangarau pāpori

Te whakatinana, ngā kaiāwhina tautoko rūpahu, ngā tinihanga aroha me te haumi e whakamahi ana i te whakawhirinaki, kaua ko te waehere.

Whakapūmautanga i tō Pukoro

Your wallet security starts with how you handle your seed phrase (also called a recovery phrase or mnemonic). This 12 or 24 word phrase is the master key to every account derived from it. Anyone who obtains it can empty every token on every chain linked to that wallet. There is no second factor, no verification and no recovery once it leaks.

1

Te Rohe Tiaki Rerenga Kākano: Te Ture Koura

Never store your seed phrase digitally. Not in a notes app, not in a screenshot, not in cloud storage, not in an email draft, not in a password manager. Anything digital can be reached remotely through malware, a cloud breach or a compromised account. Password managers and cloud services have suffered real breaches in which encrypted vaults were stolen and attacked offline afterwards.

Tuhia te rerenga kākano ki te pepa ka tiakina ki tētahi wāhi haumaru. Mō te rokiroki wā roa, whakamahia he tārua mētara (he pereti kua tāia, kua whakairohia rānei), ka ora i te ahi me te wai. Whakaarohia kia rua ngā tārua ki ngā wāhi haumaru motuhake, pērā i te pouaka haumaru o te kāinga me te pouaka haumaru o te pēke.

Never share your seed phrase with anyone. No legitimate service, support agent or developer will ever ask for it. If someone asks for it, it is a scam, every time.

2

Kupuhipa Pakari & Whakahaere Kupuhipa

Use a unique, long password for every crypto-related account (exchanges, email, wallet browser extensions). Length matters more than special characters: NIST guidance favours long passphrases over complex short ones (see Sources). Never reuse a password. When one service is breached, attackers try the leaked credentials on every exchange.

Use a reputable password manager (such as 1Password or Bitwarden) to generate and store unique passwords. Protect the manager itself with a strong master password and a hardware key. Your email account matters most of all: whoever controls your email can reset the passwords on your exchange accounts.

3

Manatokanga Rua-Wāhanga (2FA)

Enable 2FA on every account that supports it. Not all 2FA methods are equal. From strongest to weakest:

1

Hardware security keys (FIDO2 or WebAuthn keys such as YubiKey or Google Titan): physical devices that must be plugged in or tapped. They resist phishing, SIM swaps and remote attacks because the key only answers the real domain.

2

Authenticator apps (Google Authenticator, Authy and similar): time-based codes generated on your phone. Much better than SMS, but a code can still be phished, and malware on the phone can read it.

3

SMS-based 2FA: the weakest option. It is vulnerable to SIM-swap attacks, where an attacker convinces your mobile carrier to move your number to their SIM, and NIST classes SMS as a restricted factor for this reason. Avoid SMS 2FA for crypto accounts.

If you use an authenticator app, save the recovery codes offline. Lose the phone without them and you may be locked out of your accounts for good.

Pukoro Rorohiko: Te Ārai Pai

A hardware wallet is a physical device that stores your private keys offline, isolated from your computer and the internet. Even if your computer is infected, the keys never leave the device. Every transaction must be confirmed on the device itself, so an attacker cannot sign remotely.

A hardware wallet is the single most effective step for protecting cryptocurrency. If you hold more than you could afford to lose, treat it as essential rather than optional.

Ledger

Ledger devices use a certified secure element chip, the same kind of chip found in bank cards and passports, to protect private keys. They pair with MetaMask, Rabby and most DeFi applications, and Ledger Live manages accounts and firmware. Current models, supported assets and prices are on ledger.com (see Sources).

Important: buy directly from the manufacturer or an authorised reseller listed on its site, never second-hand. Tampered devices shipped with a pre-written seed phrase have been used to steal funds. A genuine device arrives with no seed phrase; you generate it yourself during setup.

Trezor

Ka whāia e Trezor tētahi ara puna tuwhera: ka whakaputaina ōna waehere pūmanawa me ōna hoahoa pūmārō, nō reira ka taea e te hapori haumarutanga te tirotiro kei te mahi te pūrere i tāna e kī nei. Ka hono ngā pūrere Trezor ki a MetaMask me ngā tūāpapa DeFi rongonui. Kei trezor.io ngā tauira o nāianei me ngā rawa e tautokohia ana (tirohia ngā Puna).

Both Trezor and Ledger support a passphrase (sometimes called the "25th word"). It creates a hidden wallet that cannot be reached with the seed phrase alone, which adds a strong extra layer for high-value holdings. Lose the passphrase and that wallet is gone, so back it up as carefully as the seed phrase.

Me pēhea te whakarite i tētahi pūkete pūmau

1

Buy directly from the manufacturer (ledger.com or trezor.io). Check the packaging on arrival and follow the manufacturer's genuine-device check during setup.

2

Initialise the device and write the seed phrase on paper (or stamp it on metal). Check each word. The device asks you to confirm the words before it finishes.

3

Set a PIN on the device. It protects against physical access if the device is stolen. Ledger devices reset after three wrong attempts; Trezor devices add a growing delay after each wrong attempt (see the manufacturers' docs in Sources).

4

Connect the device to MetaMask or your preferred wallet interface. Send a small test amount first and confirm you can send it back out before moving larger holdings.

5

Puritia te kape o te rerenga kākano ki tētahi wāhi ā-tinana rerekē i te pūrere. Mēnā kei te pouaka kotahi e rua i te wā o te ahi, o te tāhae rānei, ka ngaro e rua.

Haumaru āu moni pūkete i te wā e whiwhi ana koe i te hua

Once your security basics are in place, put your USDC to work with Coinstancy. Earn 7.50% APY on USDC with Dollar Savings. Interest accrues every second and is automatically reinvested. No lock-up period, withdraw anytime.

Whiwhi 7.50% APY i runga i te USDC

Aukati i ngā hēkē & te hākinakina hara

Phishing is the most common way individuals lose crypto. Unlike a protocol hack, which exploits code, phishing exploits you. Attackers build convincing fake websites, impersonate project staff, and use urgency and fear to get you to hand over your seed phrase or sign a malicious transaction. Here are the usual tactics and how to counter them.

Pae Tukutuku Rūpahu

Scammers build near-identical copies of popular DeFi sites (Uniswap, OpenSea, MetaMask) on domains that look almost right. Common tricks: swapping characters (un1swap), adding words (app-uniswap.org) or using a different top-level domain (.io instead of .org). Fake airdrop pages imitating well-known protocols have drained wallets by getting visitors to sign approval transactions.

Defence: bookmark the official URL of every protocol you use. Do not follow links from Discord, Telegram, social media ads or sponsored search results. Check the domain in the address bar before you connect a wallet or sign anything.

Discord & Telegram Karere Tūturu

Mēnā ka tuku karere mai tētahi ki a koe i runga Discord, Telegram rānei e tuku ana i te "tautoko", i tētahi "tuku koha", i tētahi "tuku airdrop" rānei, he tinihanga tērā. Kāore ngā kaupapa tūturu e tīmata ana i ngā kōrero tautoko mā te karere tika. Ka tāruatia e te hunga tinihanga ngā whakaahua kōtaha me ngā ingoa kaiwhakamahi o ngā kaiwhakahaere, ngā kaitiaki me ngā kaiwhakatū. Kua kahakina hoki ngā hongere ōkawa o ngā kaupapa ki te whakairi i ngā hononga mint rēhua, nō reira ahakoa he karere i te tūmau tika, me titiro anō.

Whakamarumaru: whakawetohia ngā karere tika mai i ngā mema tūmau i roto i ō tautuhinga tūmataiti Discord. Kaua e pāwhiri i ngā hononga ka tukuna mā te karere tika. Mēnā ka kī tētahi he kaitautoko ia, whakamanahia mā te hongere whaimana, mā te paetukutuku rānei o te kaupapa.

Ngā Matau Airdrop & Ngā Pāwhiri Puehu

Scammers send tokens you never asked for that appear to have value. When you try to swap or sell them, the token's smart contract may take your tokens through a hidden approval, or the token name points you to a phishing site. Some are built to be unsellable: they show a high value in explorers but every sell fails.

Defence: ignore unexpected tokens. Do not interact with them, do not try to sell them, and do not visit any website in the token name or description. If a token appeared without you buying it, treat it as malicious and hide it.

Whakaaetanga Phishing

This is the most technical common attack. A malicious site asks you to sign what looks like a normal transaction, but you are actually granting a smart contract permission to spend an unlimited amount of your tokens. The attacker then calls the contract and empties your wallet whenever they like. Losses from approval phishing and wallet drainers run to hundreds of millions of dollars a year according to Chainalysis (see Sources).

Defence: read what you are signing. If a site asks for an unlimited token approval, edit it down to the amount you need. Use a wallet or extension that simulates transactions before you sign, such as Rabby or MetaMask's built-in transaction insights, and stop if the preview shows an unexpected transfer or approval.

Haumaru Kaitātaritanga

Every time you use a DeFi protocol, you trust a smart contract with your funds. Once you approve a contract, it can move your tokens without asking again. Managing those permissions is a core part of crypto security.

1

Tirotiro & Whakakore Whakaaaetanga Tohu

Every DeFi action that spends your tokens (swapping, depositing, staking) needs a token approval. Over time a wallet collects dozens of them, each one a contract allowed to move your tokens. If any of those contracts is exploited or was malicious from the start, your funds are exposed.

Use revoke.cash to review approvals across chains. Connect your wallet, go through each active approval and revoke the ones you no longer use. Make it a monthly habit. Each revocation costs a small gas fee and removes one way in. Etherscan's Token Approval Checker does the same for Ethereum mainnet (see Sources).

2

Tepe Whakaaetanga Tokana

He maha ngā mata o mua DeFi e tono whakaaetanga mutunga kore mā te taunoa. Mā tērā e āhei ai te kirimana ki te whakapau i tō toenga katoa o taua tohu i ngā wā katoa. Whakaaetia anake te nui e hiahia ana koe ki te whakamahi. Mā MetaMask koe e āhei ki te whakatika i te nui whakaaetanga i mua i tō whakaū (tirohia ngā tuhinga tautoko MetaMask i ngā Puna).

You will need to approve again next time, and each approval costs gas, but the trade-off is worth it. In December 2021, the Badger DAO front end was compromised: users who had granted approvals to the injected contract had their funds drained. Open-ended approvals are a standing liability.

3

Manatūhia ngā kirimana i ngā pūtirotiro poraka

Before using a new protocol, look up the contract address on Etherscan (or the explorer for that chain). Legitimate contracts have verified source code, so you can read what is deployed. Unverified code is a red flag. Check that the address matches the one in the project's official documentation.

Look for proxy patterns (upgradeable contracts). They are common in DeFi but add risk because the team can change the logic. Check whether upgrades sit behind a multisig or a timelock, which means changes need several signatures and a waiting period.

Rārangi Arotake Haumaru DeFi

I mua i te whakatakoto moni ki tētahi DeFi kawa, whakahaerehia tēnei rārangi arowhai. Ko te ahua tika ehara i te mea haumaru. Ka taea e ngā rukenga, ngā waehere hē me ngā mahi whakamahi ōhanga te mutunga ki te ngaronga katoa. Māu anō e mahi te tirotiro tika.

Tirotiro He mea e rapu ana Taumata mōrearea mēnā ngaro
Arotakenga Haumaru At least one audit by a recognised firm (for example Trail of Bits, OpenZeppelin, Spearbit or Cantina). Read the report and check that the findings were fixed. Kino
Utu Tapeke Katoa (TVL) Higher TVL usually means code that has been tested with real money for longer. Be careful with protocols that hold very little. Check TVL history on DefiLlama. Teitei
Team & Track Record A public team with verifiable identities. Anonymous teams are higher risk. Look at their prior projects and reputation. Teitei
Wā i te Mākete Ko te kawa e ora ana mō te neke atu i te tau kotahi me te kore aituā he iti ake te tūraru. Ko tētahi i whakarewahia i ētahi wiki kua hipa he nui ake te tūraru. Teitei
Waehere Tūwhera Verified source code on the block explorer. Unverified contracts can hide backdoors or fee mechanisms. Kino
Haumaru Oracle Uses reliable price oracles (Chainlink, Pyth). Protocols that rely on a single thin on-chain price source are exposed to price manipulation. Kino
Timata iti Deposit a small test amount first. Wait a few days. Check that you can withdraw before committing more. Mahi Pai

Haumaru Tauhokohoko

Centralized exchanges (Coinbase, Kraken, Binance) are convenient for buying, selling and trading. But, as the saying goes, "not your keys, not your crypto". Funds on an exchange depend on that company's security and solvency. Mt. Gox (hacked, 2014), QuadrigaCX (collapsed in 2019 after its founder died holding sole access to the wallets) and FTX (bankrupt in November 2022 with customer funds missing) are reminders of that risk.

Mēnā ka pupuri moni koe i runga i tētahi whakawhitinga mō te hokohoko, whakapakarihia te pūkete ki ēnei tikanga.

Whakahohe Kī Pūmanawa 2FA

Use a FIDO2 or WebAuthn hardware key (YubiKey, Google Titan) for login and withdrawal confirmation. It removes the SIM-swap and code-phishing risks. Most major exchanges support hardware keys; check your exchange's security settings.

Rārangi Whitelist Tārewa

Enable address whitelisting so withdrawals can only go to addresses you approved in advance. Most exchanges apply a waiting period before a new address becomes active, which gives you time to react if your account is compromised.

Waehere ārai hara

Set up an anti-phishing code where the exchange offers one. Every genuine email from the exchange then includes your code. An email without it is a phishing attempt.

Whakaiti i ngā taonga whakawhitinga

Keep on the exchange only what you need for active trading. Move long-term holdings to a hardware wallet. Treat exchanges as on-ramps and off-ramps, not storage.

He mea me mahia mēnā kua whakakāhorea koe

If you suspect your wallet is compromised, speed matters. The attacker may be draining it as you read. Follow these steps in order.

1

Whakakorehia ngā whakaaetanga tohu katoa ināianei

Go to revoke.cash, connect the wallet and revoke every active approval, starting with the tokens worth the most. This stops drains that rely on approvals. If the seed phrase itself leaked, skip straight to step 2: the attacker does not need approvals.

2

Tuku ngā moni toenga ki tētahi pūkete haumaru

Create a new wallet on a clean device (ideally a hardware wallet). Move everything left in the compromised wallet to the new one. If the seed phrase leaked, every address derived from it is compromised, on every chain.

3

Haumaru ō pūkete

Change the passwords on your email, exchange accounts and any service linked to the wallet. If you suspect malware, do not use that computer for any crypto account until it has been wiped and reinstalled.

4

Pūrongo & Tuhinga

File a report with the police, or with the FBI Internet Crime Complaint Center (IC3) in the United States (see Sources); you will need it for any legal action. Keep the transaction hashes and the attacker's addresses. If the funds went to a centralized exchange, contact that exchange's support or compliance team at once: it may be able to freeze the account.

5

Mātai Whaiwhakaata Blockchain

For a large loss, consider a blockchain analytics or investigation firm. They can trace stolen funds across chains, and some victims have recovered assets through legal action once the funds reached an identifiable exchange account. Be wary of anyone who contacts you promising recovery for an upfront fee: recovery scams target people who have just been robbed.

Mā te Haumaru Tuatahi te Pūtauki i te USDC

Whiwhi 7.50% APY i runga i te USDC me te Coinstancy Dollar Savings. Ka uru tuatahi ngā pūtea penapena ki tētahi pūkoro waitohu-maha e whakahaerehia ana e te rōpū a Coinstancy, kātahi ka tohatohaina ki te rautaki ā-poraka e hāngai ana. Ka whakaemihia te huamoni ia hēkona, ā, ka whakamoni aunoa. Kāore he here, ka taea te tango i ngā wā katoa.

Tīmata te whiwhi moni i te Coinstancy

Ngā Pātai Auau

He aha te ara haumaru rawa ki te penapena moni matihiko?
For most people, the safest way to store cryptocurrency is a hardware wallet (cold storage) such as a Ledger or Trezor device. A hardware wallet keeps your private keys offline, so malware on your computer cannot read them, and every transaction must be confirmed on the device screen. It does not protect you from signing a bad transaction yourself, so still read what you sign. Keep the seed phrase backup on paper or metal in a secure place such as a safe, never in a digital file.
Ka taea te whakahoki i te moni matihiko i tukua?
In most cases, stolen crypto cannot be recovered. Blockchain transactions are irreversible by design. If the stolen funds reach a centralized exchange, law enforcement can sometimes get the account frozen, so report the theft quickly (to the FBI IC3 in the United States, or your local police elsewhere) and to the exchange. Blockchain analytics firms can trace funds, and some victims have recovered assets through legal proceedings, but this is slow and uncertain. Prevention is the only reliable strategy.
He haumaru ki te pupuri crypto i runga i tētahi whakawhiti?
Keeping crypto on an exchange carries counterparty risk. Exchanges can be hacked (Mt. Gox, 2014), go bankrupt (FTX, November 2022) or freeze withdrawals. For small amounts you trade often, a reputable exchange with strong account security is acceptable. For long-term holdings, move the funds to a hardware wallet where you control the private keys.
He aha taku mahi mēnā i pāwhiri au i tētahi hononga mahi hara?
Mēnā i pāwhiritia e koe tētahi hononga whakapohehe engari kāore koe i haina i tētahi mea, kāore rānei i whakauru i tō kīanga kākano, ka noho haumaru pea ō pūtea. Momotu tō pākete mai i te pae. Mēnā i haina koe i tētahi whakawhitinga, tirohia ō whakaaetanga tohu i revoke.cash ā whakakāhoretia ngā mea kāore koe e mōhio. Mēnā i whakauru koe i tō kīanga kākano, hangaia he pākete hou i runga i tētahi pūrere mā, ā, nekehia ngā rawa katoa ki waho o te pākete kua raru i te wā poto rawa.
He aha te whakaaetanga tohu, ā, he aha te mōrearea?
A token approval is an on-chain permission you grant to a smart contract to spend your tokens on your behalf. If you approve a contract for unlimited spending, that contract can move your whole balance of that token at any time. Approval phishing tricks users into granting such an approval to a malicious contract. Limit approvals to the amount you need, and review and revoke unused approvals regularly at revoke.cash or the Etherscan token approval checker.
He nui te whakamana-rua ki te tiaki i taku crypto?
Two-factor authentication (2FA) improves exchange account security a lot, but it is not foolproof. SMS-based 2FA is vulnerable to SIM-swap attacks, where an attacker persuades your carrier to move your number to their phone. Authenticator apps are better, and hardware security keys (FIDO2, such as a YubiKey) are the strongest option. Combine 2FA with a unique password, a withdrawal address whitelist and an anti-phishing code.

Haere tonu ki te ako

Tirohia ētahi aratohu anō mō ngā pūkete, ngā kirimana atamai, me ngā mātāpono o te DeFi.

Tiaki tō Crypto, ā, whakapakari i tōna tipu

Inā kua tū te tūāpapa haumarutanga, whakamahia tō USDC. Whiwhi 7.50% APY i runga i te USDC me te Coinstancy Dollar Savings. Ka whiwhi huamoni ia hēkona, ka whakamahi anō aunoa. Kāore he wā maukati, ka taea te tango i ngā wā katoa.

Tīmata te whiwhi moni i te Coinstancy

Ngā puna me ngā pānuitanga atu anō

Ka whakawhirinaki ngā tatauranga me ngā kerēme o tēnei whārangi ki ngā tuhinga kei raro nei. Ka neke ngā tatauranga pā ki te wā (reiti, hua, utu, raraunga mākete): tirohia te uara ora i te puna i mua i te mahi.

  1. Ethereum.org, Security and scam preventionethereum.org

    Seed phrase handling, hardware wallets, common scam patterns and how to check what you sign.

  2. Ethereum.org, Walletsethereum.org

    What a self-custodial wallet is and how private keys and recovery phrases work.

  3. Ledger Supportsupport.ledger.com

    Device setup, the secure element, PIN behaviour after wrong attempts, passphrase and buying only from official channels.

  4. Trezor Learntrezor.io

    Open-source firmware, device setup, PIN protection and the passphrase (hidden wallet) feature.

  5. Tautoko MetaMasksupport.metamask.io

    Editing token approval amounts, hardware wallet pairing and phishing warnings in MetaMask.

  6. Revoke.cashrevoke.cash

    Viewing and revoking token approvals across chains.

  7. Etherscan, Token Approval Checkeretherscan.io

    Reviewing and revoking approvals on Ethereum mainnet.

  8. Chainalysis, Crypto Crime Reportchainalysis.com

    Ngā tatauranga ā-tau mō ngā moni i tāhaetia i roto i ngā hack, tae atu ki te tapeke o te tau 2022 tata ki te $3.8 piriona me te tapeke o te tau 2023 tata ki te $1.7 piriona.

  9. FBI Internet Crime Complaint Center (IC3)ic3.gov

    Yearly reports on cryptocurrency fraud losses reported by the public, and where US victims file a complaint.

  10. NIST SP 800-63B, Digital Identity Guidelinespages.nist.gov

    Password length over complexity, and the weakness of SMS as a second factor.

I arotakea whakamutunga: Mahuru 2026. Ka whakatuwheratia ngā hononga o waho ki tētahi tihopa hou; kāore a Coinstancy e whai kawenga mō ō rātou ihirangi.

Noho Haumaru, Whiwhi Māia

Inā kua tū ngā mahi haumarutanga kaha, whiwhi 7.50% APY i runga i te USDC me te Coinstancy Dollar Savings. Ka whiwhi huamoni ia hēkona, ka whakamahi anō aunoa, ā, ka taea te tango i ngā wā katoa.