Securing Guarda with Best Practices
As a non-custodial wallet, Guarda gives you complete control over your assets. That also means you're responsible for protecting them. Fortunately, keeping your wallet secure doesn't call for advanced technical knowledge. You are able to use Guarda safely right from the start. Following simple habits goes a long way toward protecting your crypto. You'll find all of them in this guide.
Protecting Your Recovery Information
Your recovery information is the most important part of your wallet.
- A backup is the easiest way to restore your entire Guarda Wallet. It contains all supported wallets, recovery phrases, and private keys that existed when the backup was created.
- A mnemonic (recovery phrase) is the master key that restores every wallet created from it.
- A private key restores and controls one individual wallet and is used to sign its transactions.
All of these credentials are a green light to your wallet. This is a good thing, as long as it’s only you. Store this information offline whenever possible and keep more than one secure copy in different locations.
For example, keep backups and private keys in an encrypted folder on the hard drive. To secure a mnemonic, write it on several pieces of paper and store it in several locations, including a safe. Those are just a couple scenarios. You can find different methods on the internet and choose the best one for you.
Never share your backup, recovery phrase, or private keys with anyone.
Guarda Support will never ask you for your backup, recovery phrase, or private key. If anyone does, you're dealing with a scam and not even an elegant one.
Keeping Your Backup Up to Date
A backup in Guarda doesn’t save itself automatically. At the same time, it is only useful if it reflects your current wallet. To download a new backup, you only need to take a few seconds. But it will save you from losing access to wallets that weren't included in the previous version.
Whenever you create a new wallet, import an existing one, or delete a wallet on any platform, Guarda sends you a reminder to download a fresh backup. An older backup won't include those changes, which can make recovery more difficult later.
Password and Device Security
Your password protects access to Guarda on your current device. While it doesn't replace your recovery phrase or backup, it's another important layer that makes the whole Guarda Wallet recovery possible. You won’t be able to restore your backup without the password. The same thing applies to mnemonics.
Create a long, unique password that you don't reuse anywhere else. Encrypted offline password managers are very helpful to generate passwords. But there is a risk of your password manager being hacked. It's up to you to decide your risk tolerance to store your password there. Cloud notes or messaging apps for storage are a definite no.
For even stronger protection, enable full disk encryption on your computer. If your device is lost or stolen, encryption's got your back and prevents anyone from accessing its contents, including your Guarda data, saved passwords, banking information, and other sensitive files.
Operating systems typically have this feature. You can find the exact software here:
- macOS: FileVault
- Windows: BitLocker
- Linux: LUKS
Sending Crypto Safely
Unlike bank transfers, blockchain transactions cannot be reversed after they're confirmed. Spending a few extra seconds reviewing your transaction prevents costly mistakes.
Before sending cryptocurrency, always verify:
- the recipient's wallet address;
- the selected blockchain network;
- the Memo (destination tag), if required for particular assets;
- the amount you're sending;
- the estimated network fee.
Tip: When you think about it, checking the address digit by digit sounds overwhelming and anxiety-inducing. But mistyped addresses are one of the easiest ways to lose funds permanently. Pay attention to the first four digits and the last four digits of the address. Comparing them is often enough to spot a mistake.
Recognizing Scams and Phishing
Crypto scammers don't target the blockchain itself. They are more interested in people. Scammers rely on urgency, excitement, or fear. All to convince victims to send money or reveal sensitive info. And most of the time they try to act very helpful.
The first rule is no legitimate person or service will ever ask for your backup, recovery phrase, or private keys. Scammers often impersonate support teams, create fake websites, promote giveaway campaigns, or promise guaranteed and stable investment returns. The goal is usually the same: convince you to reveal your recovery details or approve a malicious transaction.
The second rule is there is no stability or guarantee in crypto. The assets are volatile, and the market is often hype-driven. If someone genuinely discovered a 100% guaranteed way to make money in crypto, they won’t message you via Telegram and invite you to join them.
Understanding Unexpected Transactions
You may notice spam tokens, unsolicited NFTs, or tiny cryptocurrency transfers known as dusting attacks appearing in your wallet. In most cases, receiving these assets doesn't mean your wallet has been compromised.
The safest approach is usually to ignore and avoid. Just ignore unknown assets and avoid interacting with them unless you're certain they're legitimate. After all, receiving cryptocurrency you weren't expecting is surprisingly common. If you are simply receiving them, they do not put your wallet or your funds at risk.
Using Web3 Safely
Connecting your wallet to decentralized applications unlocks many blockchain services, but it also requires extra caution. Here is the quick checklist:
- Only connect your wallet to applications you trust. A blogger's recommendation is not enough of a source. Do your research.
- Always read signature requests before approving them.
- When a dApp asks for permission to use your tokens, review exactly what you're approving.
- If you no longer use an application, consider disconnecting it or revoking unnecessary token approvals.
If you don't understand what a transaction or signature request does, don't approve it until you are sure of its purpose.
Keeping Your Device Secure
Your wallet is only as secure as the device it's running on. Here’s a quick checklist for that too:
- Keep both your operating system and Guarda updated to the latest version so you receive the newest security improvements.
- Protect your device with a password, PIN, or biometric authentication.
- Avoid installing software from untrusted sources.
- Never access your wallet from public computers.
- Public Wi-Fi networks should also be treated with caution, especially when managing your crypto assets.
Cold Storage
If you've built a sizable crypto portfolio and don't plan to use it regularly, consider storing it in cold storage.
Cold storage means keeping your private keys completely offline, isolated from internet-connected devices. Because the keys are never exposed to the internet, they're much harder for malware, hackers, or phishing attacks to compromise. The trade-off is that you’ll need access to your cold storage device whenever you want to send funds.
The most common type of cold storage is a hardware wallet. These dedicated devices are designed to generate and store private keys securely and sign transactions without exposing the keys to your computer or the internet.
Guarda supports hardware wallets through its built-in Ledger integration. This lets you manage your assets using Guarda's interface while your private keys remain securely stored on your Ledger device.
If you're planning to hold crypto for months or years rather than trade it frequently, a hardware wallet is one of the most secure ways to protect your assets. You can learn how to connect and use Ledger with Guarda in our dedicated guide.