Read this module twice. I mean that.
Every other module in this course is useful. This one is the difference between keeping what you bought and handing it to a stranger. Take your time here.
Not your keys, not your coins
There’s an old line in this space, blunt enough that it’s become a kind of scripture: not your keys, not your coins. Here’s what it means in plain terms. When you buy bitcoin on an exchange and just leave it sitting there, the exchange holds the actual keys, not you. You have a claim on the coins, the same way you have a claim on money sitting in a bank. Most of the time that’s fine. Sometimes it isn’t, and Mt. Gox and FTX are both real, documented examples of an exchange holding customer coins and then, one way or another, not being able to give them back.
Moving your bitcoin off an exchange and into a wallet you control is how you close that gap. It’s an extra step, and for a small first purchase it might not be worth the trouble yet. For anything you’d genuinely be upset to lose, learn this section before you get there.
What a wallet actually is
A wallet isn’t a place where your bitcoin sits, the way cash sits in a physical wallet. Your bitcoin always lives on the blockchain. A wallet is the tool that holds your keys and lets you prove you control certain coins on that ledger. There are two broad categories:
- Hot wallets are connected to the internet, usually an app on your phone or computer. Convenient for spending or trading. More exposed, because anything connected to the internet is a bigger target.
- Cold wallets, usually a small hardware device, keep your keys generated and stored somewhere that never touches the internet. Less convenient. Meaningfully harder to steal from remotely, because there’s nothing online to reach.
Neither category is a specific brand you should run out and buy on my word. Evaluate any hardware wallet the way you’d evaluate an exchange: an established track record, open documentation about how it actually works, and a reputation that’s held up under scrutiny, not just a slick ad.
The seed phrase is the whole ballgame
When you set up a wallet, it generates a seed phrase, usually twelve or twenty-four plain English words, shown to you exactly once. That phrase is not a password. It is not a recovery email. It is a complete, total, mathematical copy of every key that wallet will ever generate. Anyone who has those words has everything in that wallet, permanently, with no customer service line to call and no fraud department to appeal to. There is no undo.
So treat it like this:
- Write it down on paper, by hand, in the order given, and nowhere else. Not a photo. Not a screenshot. Not a note on your phone. Not an email to yourself “just for now.” Every one of those is a door into your wallet sitting on a device or a server you don’t fully control.
- Store it somewhere physical and private. A safe, a lockbox, somewhere fire and flood won’t take it and somewhere a stranger in your home wouldn’t stumble onto it.
- Never type it into a website, an app, or a chat, ever, for any reason. Not one. There is no legitimate reason on this entire earth for a website or a support agent to ask you for your seed phrase.
- Never say it out loud to anyone, including someone claiming to be support staff, a friend, or a fellow trader who “just wants to help you recover something.”
The scam patterns, so you can spot them the moment they show up
Almost every way people actually lose bitcoin isn’t a hack of the Bitcoin network itself. It’s a con aimed at getting you to hand over your seed phrase or send coins somewhere voluntarily. Learn these shapes and you’ll spot the next one, even in a form nobody’s invented yet:
- Fake support. Someone messages you, often after you post a public question somewhere, claiming to be from an exchange or wallet company, offering to help, and asking you to “verify your wallet” by entering your seed phrase into a form. Real support will never ask for it.
- The phishing site. A near-perfect copy of an exchange or wallet’s login page, one letter off in the web address, built purely to capture whatever you type into it.
- “Send one, get two back.” A message, sometimes appearing to come from someone with a recognizable name, promising to double any bitcoin you send them. It is always a lie. There is no version of this that isn’t a lie.
- The urgency play. “Your account will be suspended in ten minutes unless you verify now.” Real institutions do not create artificial ten-minute deadlines. Manufactured urgency is itself the tell.
- The romance or friendship long game. A relationship, often built slowly over weeks online, that eventually arrives at “I have this amazing investment opportunity” and asks you to move funds somewhere the other person controls.
The rule underneath every one of these: if a message asks for your seed phrase, or asks you to send bitcoin to “verify,” “unlock,” or “insure” something, it is a scam. No exception has ever existed. Not once, not for anyone.
What to do if you think you’ve been targeted
Stop responding. Don’t engage further, don’t try to negotiate, don’t send “just a little” to see what happens. If you haven’t shared your seed phrase, you’re very likely still safe; move your funds to a fresh wallet with a newly generated seed if you have any doubt at all. If you have shared it, move whatever funds you can to a new wallet immediately, because whoever has that phrase can move first. Report the attempt to the platform it happened on. There’s no shame in it. People far more careful than you have been caught by a good enough fake.
What you learned: Custody means controlling your own keys, your seed phrase is the single point of total failure, and nearly every real-world loss in this space comes from a scam asking you to hand it over, not from Bitcoin itself being broken.
Next: Module 4 covers where to keep learning, and how the cycles the book walked you through connect to keeping your guard up for good.