UTXOSUITE — home
Back to Academy
LEVEL 2 · Free

Wallet Security & Self-Custody

Protect keys, recovery material, destinations and devices using practical operational boundaries.

8 lessons · 8 Field exercise · 8 Practical scenarios · 20 question · 80% passing score
Start learning0% · 0/21
UTXO ACADEMY · SECURITY TRAINING · Wallet Security & Self-Custody
Self-custody working environment: hardware wallet, backup media and a review screen

What you will be able to do

Treat seed phrases and private keys as signing authority, not as support credentials or cloud data.

Recognize when a legitimate-looking interface is separated from the origin and authority it claims.

Defend against look-alike addresses, clipboard substitution and history poisoning before value leaves the wallet.

Reduce exposure by separating devices, roles, hot balances and recovery procedures.

Curriculum

1.1 · Never turn recovery material into a support credential20 min
1.2 · Backups need availability and confidentiality18 min
Lab · Protect the signing boundary

This course includes

  • 8 lessons · 14 guided hours
  • 4 Lab · Practical scenarios
  • 8 Applied case files · 8 Knowledge checks
  • 52 Item exam bank · 80% pass mark
  • Completion credential: UTXO Certified · Wallet Security Fundamentals

What this course expects of you

  • Recognize common wallet-compromise paths before funds move.
  • Passing score: 80%
  • Crypto & Blockchain Foundations
Course briefing

Training contract

Recognize common wallet-compromise paths before funds move.

01 · Target capabilityRecognize common wallet-compromise paths before funds move.
02 · Recommended prerequisiteCrypto & Blockchain Foundations
Practical deliverables
01

Secret material & recovery boundaries

Treat seed phrases and private keys as signing authority, not as support credentials or cloud data.

Evidence memo · KEY-BOUNDARY
02

Phishing, origins & social pressure

Recognize when a legitimate-looking interface is separated from the origin and authority it claims.

Evidence memo · PHISHING
03

Destination integrity

Defend against look-alike addresses, clipboard substitution and history poisoning before value leaves the wallet.

Evidence memo · ADDRESS-POISONING
04

Operational wallet security

Reduce exposure by separating devices, roles, hot balances and recovery procedures.

Evidence memo · KEY-BOUNDARY
Assessment contract
Lesson checks8
Module labs4
Final exam20
Mastery threshold80%
modules
Self-custody working environment: hardware wallet, backup media and a review screen
Complete syllabus

Wallet Security & Self-Custody

Review the full curriculum, competencies and assessment path before starting.

Guided study load14h
modules4
lessons8
01

Secret material & recovery boundaries

Treat seed phrases and private keys as signing authority, not as support credentials or cloud data.

1.1
Never turn recovery material into a support credential45 min · Deep technical lesson
1.2
Backups need availability and confidentiality45 min · Deep technical lesson
Module practical labProtect the signing boundary
02

Phishing, origins & social pressure

Recognize when a legitimate-looking interface is separated from the origin and authority it claims.

2.1
Read the origin, not the logo45 min · Deep technical lesson
2.2
Urgency is part of the exploit45 min · Deep technical lesson
Module practical labInspect the origin
03

Destination integrity

Defend against look-alike addresses, clipboard substitution and history poisoning before value leaves the wallet.

3.1
History is not an address book45 min · Deep technical lesson
3.2
Verify destinations before value becomes irreversible45 min · Deep technical lesson
Module practical labVerify the destination
04

Operational wallet security

Reduce exposure by separating devices, roles, hot balances and recovery procedures.

4.1
A secure wallet on an insecure device inherits risk45 min · Deep technical lesson
4.2
Good procedure reduces dependence on perfect software45 min · Deep technical lesson
Module practical labProtect the signing boundary
Competencies
  • Never type a seed phrase into a website presented as support.
  • A leaked seed cannot be made secret again.
  • Test recovery before an emergency.
  • Avoid single points of failure and single points of compromise.
  • Branding is not evidence of origin.
  • Verify domains independently before sensitive signing.
  • Time pressure should increase scrutiny, not reduce it.
  • Never let support channels dictate signing steps without independent verification.
  • Verify the full destination or a trusted address-book entry.
  • Do not copy destinations from transaction history blindly.
  • Re-check the final signer display when available.
  • Treat new destinations differently from established ones.
Assessment path
  1. Written field exercise × 8
  2. Knowledge checks × 8
  3. Module practical lab × 4
  4. Timed final exam · 20 · ≥ 80%
Guided study load
  1. Deep technical lesson · 360 min
  2. Written field exercise · 160 min
  3. Module practical lab · 140 min
  4. Specialist units · 105 min
  5. Timed final exam · 30 min
COURSE HANDBOOK

Scope, outcomes and study standard

14h
Who this is for

Protect keys, recovery material, destinations and devices using practical operational boundaries.

Prerequisites

Recommended prior study

  • Crypto & Blockchain Foundations
Learning outcomes
  • Never type a seed phrase into a website presented as support.
  • A leaked seed cannot be made secret again.
  • Move assets to new keys after suspected disclosure.
  • Test recovery before an emergency.
  • Avoid single points of failure and single points of compromise.
  • Document inheritance or emergency access deliberately.
  • Branding is not evidence of origin.
  • Verify domains independently before sensitive signing.
  • A wallet request inherits risk from the context that initiated it.
  • Time pressure should increase scrutiny, not reduce it.
Study method
  1. 01

    Read the six-part technical chapter

  2. 02

    Inspect the unique visual and protocol model

  3. 03

    Work through the case file and evidence map

  4. 04

    Submit the written field exercise

  5. 05

    Pass the knowledge check and module lab

  6. 06

    Complete the timed final assessment

Evidence standard

Claims should be tied to observable fields, protocol behavior, primary references or clearly stated assumptions. Unknowns must remain explicit instead of being silently treated as safe.

Completion standard

Completion requires the written work, knowledge checks, all module labs and a final exam score of at least 80%. Professional level also requires the capstone.

Core glossary
Never turn recovery material into a support credential
A recovery phrase or private key is not a password reset token. Anyone who receives it can usually reconstruct signing authority. Legitimate support workflows should never require it, and security processes should assume any disclosed recovery material is permanently compromised.
Backups need availability and confidentiality
A recovery strategy must survive device loss without creating an easy theft path. One cloud note or a photo roll backup may improve availability while destroying confidentiality. Strong recovery separates copies, locations and access mechanisms according to the value at risk.
Read the origin, not the logo
Phishing sites can reproduce a brand perfectly while using a different origin. Unicode look-alikes, subdomain tricks and sponsored search results exploit visual trust. The authoritative question is which origin requested the wallet connection and whether that origin matches a known, independently verified destination.
Urgency is part of the exploit
Attackers combine technical payloads with emotional pressure: expiring claims, account freezes, emergency migrations or support impersonation. Security controls should deliberately slow high-risk operations so urgency cannot bypass verification.
History is not an address book
Address-poisoning attacks send tiny or crafted transactions from look-alike addresses so a user copies the wrong destination from recent history. Prefix and suffix similarity is not sufficient verification when meaningful value is moving.
Verify destinations before value becomes irreversible
Destination integrity can be attacked through clipboard malware, poisoned history, compromised QR codes or incorrect ENS-style resolution. A robust workflow verifies the resolved destination at the signing boundary and escalates new high-value addresses.
A secure wallet on an insecure device inherits risk
Malware can alter clipboard data, inject browser content, steal sessions or replace installers. Self-custody therefore requires device hygiene, software provenance and separation between everyday browsing and high-value signing.
Good procedure reduces dependence on perfect software
No single product can eliminate every failure mode. Procedures such as transaction limits, role separation, allowlisted destinations and dry runs make one compromised component less likely to become a catastrophic loss.
SPECIALIST EXTENSIONS

Modern protocol and operational topics

These extensions broaden the core curriculum with current standards and security boundaries that practitioners are expected to recognize.

RPC and provider trust boundaries
Specialist study unit01
EXT / 01

RPC and provider trust boundaries

A provider transports requests and chain state but should not become an invisible source of truth. Model chain/account changes, stale or adversarial RPC responses, and the difference between connectivity and authorization correctness.

Security focusEIP-1193 · RPC integrity · chain changes · account exposure · fail-visible behavior
Study taskRead the primary material, identify the trust boundary, and explain how the mechanism changes the authorization or execution model.
Required outputProduce a concise analyst note containing assumptions, material evidence, failure conditions and a justified security decision.
Primary referencesEIP-1193
Wallet software supply-chain security
Specialist study unit02
EXT / 02

Wallet software supply-chain security

Treat dependencies, build systems, registries and release artifacts as part of the signing threat model. Provenance and reproducibility reduce the chance that a trusted frontend or extension becomes the delivery path for malicious request code.

Security focusSource provenance · dependencies · build integrity · releases · update trust
Study taskRead the primary material, identify the trust boundary, and explain how the mechanism changes the authorization or execution model.
Required outputProduce a concise analyst note containing assumptions, material evidence, failure conditions and a justified security decision.
Primary referencesSLSA v1.2
Hardware-backed key management
Specialist study unit03
EXT / 03

Hardware-backed key management

Separate key generation, storage, use, backup, rotation and destruction as distinct lifecycle operations. Hardware isolation reduces extraction risk but does not automatically make an incorrect transaction safe to authorize.

Security focusKey lifecycle · cryptographic boundary · backup · rotation · signer display
Study taskRead the primary material, identify the trust boundary, and explain how the mechanism changes the authorization or execution model.
Required outputProduce a concise analyst note containing assumptions, material evidence, failure conditions and a justified security decision.
Primary referencesNIST SP 800-57 Pt1 Rev5
Practical scenarios
Self-custody working environment: hardware wallet, backup media and a review screen
Module 01

Secret material & recovery boundaries

Treat seed phrases and private keys as signing authority, not as support credentials or cloud data.

Technical environment related to this course module
Lesson 1.1

Never turn recovery material into a support credential

20 min
UTXO ACADEMY / CONCEPT MODELRECOVERY MATERIALCONTROLVISUAL AID · NOT A SECURITY VERDICT
Technical chapter

Never turn recovery material into a support credential

Deep technical lesson
01
Mental model

A recovery phrase or private key is not a password reset token. Anyone who receives it can usually reconstruct signing authority. Legitimate support workflows should never require it, and security processes should assume any disclosed recovery material is permanently compromised.

This concept matters because Never type a seed phrase into a website presented as support.

Seed phrases deterministically reconstruct signing authority and therefore cannot be scoped like a password reset token.

02
What actually happens

Identify whether the workflow requests recovery words or raw signing material.

At protocol and execution level, inspect seed phrase and derived key and signer and backup and compromise. Protocol identifiers remain untranslated because they are part of the technical payload.

seed phrase

root recovery secret

derived key

account-specific authority

signer

uses key without exposing it

backup

offline recovery copy

compromise

authority must be migrated

03
Failure surface

Entering a seed into a support portal gives the requester durable authority over all derived wallets.

The practical consequence is that A leaked seed cannot be made secret again. Unknown is not equivalent to safe.

  • seed typed into website
  • seed photographed/cloud-synced
  • support asks for recovery words
  • same seed used in insecure environment
  • suspected disclosure without migration
04
Decision standard

Never disclose; if already entered, migrate assets from a known-clean environment.

The practical consequence is that A leaked seed cannot be made secret again.

Escalate when evidence is contradictory, incomplete or the consequence exceeds routine policy.

05
Verification procedure

Verify the request through independent evidence before irreversible authorization.

  1. 01

    classify recovery material

  2. 02

    remove online copies

  3. 03

    verify signer never exports secrets

  4. 04

    design recovery test

  5. 05

    migrate assets after suspected exposure

06
Required analyst output

Record the facts, assumptions, unknowns and decision so another analyst can reproduce the review.

Never type a seed phrase into a website presented as support. and Move assets to new keys after suspected disclosure.

Required analyst outputsecret-material handling policy
Never turn recovery material into a support credential
LESSON VISUALNever turn recovery material into a support credentialseed private key boundary
Never turn recovery material into a support credential
REAL-WORLD CONTEXT · HARDWARE SIGNING ENVIRONMENTNever turn recovery material into a support credentialCONCEPT → REAL ENVIRONMENT → OPERATIONAL DECISION
VISUAL MODEL / KEY BOUNDARYseed-private-key-boundary
N01N02N03N04N05N06KEY BOUNDARYNever turn recovery material into a support credential
CONCEPT → EVIDENCE → FAILURE MODE → VERIFICATION
Technical workbook

Analyst objective

Never type a seed phrase into a website presented as support.

Mechanics
seed phraseroot recovery secret
derived keyaccount-specific authority
signeruses key without exposing it
backupoffline recovery copy
compromiseauthority must be migrated
Failure signals
  1. 01

    seed typed into website

  2. 02

    seed photographed/cloud-synced

  3. 03

    support asks for recovery words

  4. 04

    same seed used in insecure environment

  5. 05

    suspected disclosure without migration

Verification procedure
  1. 01

    classify recovery material

  2. 02

    remove online copies

  3. 03

    verify signer never exports secrets

  4. 04

    design recovery test

  5. 05

    migrate assets after suspected exposure

Reasoning chain
  1. 01

    facts → material evidence

  2. 02

    evidence → consequence / authority

  3. 03

    consequence → explicit decision + next action

Required deliverablesecret-material handling policy
Protocol walkthrough

Follow the security decision path

seed / private / key / boundary
01Observe
  • seed phrase: root recovery secret
  • derived key: account-specific authority
02Trace
  • signer: uses key without exposing it
  • backup: offline recovery copy
  • compromise: authority must be migrated
03Challenge
  • seed typed into website
  • seed photographed/cloud-synced
  • support asks for recovery words
04Verify
  • classify recovery material
  • remove online copies
  • verify signer never exports secrets
05Output
  • secret-material handling policy
Authority surfaceseed phrase · derived key · signer
Failure conditionseed typed into website
Applied case file
recovery-phish
CASE / seed-private-key-boundary
requestenter 24 words
pagewallet recovery portal
originwallet-helpdesk.io
support Contactunsolicited
funds Movedno
required Actiontreat material as compromised if entered
Analyst task

Before answering the checkpoint, identify the authority being granted, the trust boundary that can fail, and the consequence that becomes irreversible.

Evidence map

Organize before you decide

Separate identity, authority, execution and context before reaching a security decision.

01
Identity

Who or what is requesting, receiving or representing authority?

originwallet-helpdesk.io
support Contactunsolicited
02
Authority

What capability can be granted, retained or exercised?

03
Execution

What will the payload, route or system actually do?

04
Context

Which surrounding facts can materially change the decision?

requestenter 24 words
pagewallet recovery portal
funds Movedno
required Actiontreat material as compromised if entered
Field exercise

Produce an analyst-ready finding

Local-only analyst record

Do not answer from memory. Use the case, protocol fields and verification procedure above to write a reproducible finding.

Focusseed phrase · derived key · signer
Failure signalseed typed into website
Verify firstclassify recovery material
Deliverablesecret-material handling policy
Completion criteria
  • Cites material evidence, not UI appearance.
  • Names the authority, state transition or consequence.
  • Provides a reproducible next action or decision.
Security notes
  1. 01

    Never type a seed phrase into a website presented as support.

  2. 02

    A leaked seed cannot be made secret again.

  3. 03

    Move assets to new keys after suspected disclosure.

Analyst notebook

Build your evidence memo

Local-only learning record

Record your reasoning before the checkpoint. Finish with an explicit decision or next action. Notes stay on this device.

LOCAL STORAGE
Field exercise

Develop all three sections before completion.

Lesson 1.2

Backups need availability and confidentiality

18 min
UTXO ACADEMY / CONCEPT MODELRECOVERY DESIGNAVAILABILITY / CONFIDENTIALITYVISUAL AID · NOT A SECURITY VERDICT
Technical chapter

Backups need availability and confidentiality

Deep technical lesson
01
Mental model

A recovery strategy must survive device loss without creating an easy theft path. One cloud note or a photo roll backup may improve availability while destroying confidentiality. Strong recovery separates copies, locations and access mechanisms according to the value at risk.

This concept matters because Test recovery before an emergency.

Recovery design balances availability against the creation of additional theft paths.

02
What actually happens

Map number of copies, storage media, physical locations and recovery testing.

At protocol and execution level, inspect availability and confidentiality and redundancy and separation and test. Protocol identifiers remain untranslated because they are part of the technical payload.

availability

can recover after loss

confidentiality

unauthorized recovery prevented

redundancy

no single physical failure

separation

copies not compromised together

test

recovery procedure validated

03
Failure surface

Cloud photos, single-site backups and untested procedures create either compromise or permanent loss.

The practical consequence is that Avoid single points of failure and single points of compromise. Unknown is not equivalent to safe.

  • single backup
  • all copies same location
  • cloud photo/note
  • backup never tested
  • inheritance/emergency path undefined
04
Decision standard

Use separated, tested recovery paths appropriate to asset value and threat model.

The practical consequence is that Avoid single points of failure and single points of compromise.

Escalate when evidence is contradictory, incomplete or the consequence exceeds routine policy.

05
Verification procedure

Verify the request through independent evidence before irreversible authorization.

  1. 01

    define loss scenarios

  2. 02

    choose independent backup locations

  3. 03

    protect access separately

  4. 04

    test recovery with non-production funds

  5. 05

    document emergency/inheritance procedure

06
Required analyst output

Record the facts, assumptions, unknowns and decision so another analyst can reproduce the review.

Test recovery before an emergency. and Document inheritance or emergency access deliberately.

Required analyst outputtested recovery runbook
Backups need availability and confidentiality
LESSON VISUALBackups need availability and confidentialitybackup recovery
Backups need availability and confidentiality
REAL-WORLD CONTEXT · HARDWARE SIGNING ENVIRONMENTBackups need availability and confidentialityCONCEPT → REAL ENVIRONMENT → OPERATIONAL DECISION
VISUAL MODEL / KEY BOUNDARYbackup-recovery
N01N02N03N04N05N06KEY BOUNDARYBackups need availability and confidentiality
CONCEPT → EVIDENCE → FAILURE MODE → VERIFICATION
Technical workbook

Analyst objective

Test recovery before an emergency.

Mechanics
availabilitycan recover after loss
confidentialityunauthorized recovery prevented
redundancyno single physical failure
separationcopies not compromised together
testrecovery procedure validated
Failure signals
  1. 01

    single backup

  2. 02

    all copies same location

  3. 03

    cloud photo/note

  4. 04

    backup never tested

  5. 05

    inheritance/emergency path undefined

Verification procedure
  1. 01

    define loss scenarios

  2. 02

    choose independent backup locations

  3. 03

    protect access separately

  4. 04

    test recovery with non-production funds

  5. 05

    document emergency/inheritance procedure

Reasoning chain
  1. 01

    facts → material evidence

  2. 02

    evidence → consequence / authority

  3. 03

    consequence → explicit decision + next action

Required deliverabletested recovery runbook
Protocol walkthrough

Follow the security decision path

backup / recovery
01Observe
  • availability: can recover after loss
  • confidentiality: unauthorized recovery prevented
02Trace
  • redundancy: no single physical failure
  • separation: copies not compromised together
  • test: recovery procedure validated
03Challenge
  • single backup
  • all copies same location
  • cloud photo/note
04Verify
  • define loss scenarios
  • choose independent backup locations
  • protect access separately
05Output
  • tested recovery runbook
Authority surfaceavailability · confidentiality · redundancy
Failure conditionsingle backup
Applied case file
backup-design
CASE / backup-recovery
copies2
copy Ahome safe
copy Bcloud photo
encryptionaccount password
inheritancenone
recovery Testnever
asset Value$95,000
Analyst task

Before answering the checkpoint, identify the authority being granted, the trust boundary that can fail, and the consequence that becomes irreversible.

Evidence map

Organize before you decide

Separate identity, authority, execution and context before reaching a security decision.

01
Identity

Who or what is requesting, receiving or representing authority?

02
Authority

What capability can be granted, retained or exercised?

03
Execution

What will the payload, route or system actually do?

asset Value$95,000
04
Context

Which surrounding facts can materially change the decision?

copies2
copy Ahome safe
copy Bcloud photo
encryptionaccount password
inheritancenone
recovery Testnever
Field exercise

Produce an analyst-ready finding

Local-only analyst record

Do not answer from memory. Use the case, protocol fields and verification procedure above to write a reproducible finding.

Focusavailability · confidentiality · redundancy
Failure signalsingle backup
Verify firstdefine loss scenarios
Deliverabletested recovery runbook
Completion criteria
  • Cites material evidence, not UI appearance.
  • Names the authority, state transition or consequence.
  • Provides a reproducible next action or decision.
Security notes
  1. 01

    Test recovery before an emergency.

  2. 02

    Avoid single points of failure and single points of compromise.

  3. 03

    Document inheritance or emergency access deliberately.

Analyst notebook

Build your evidence memo

Local-only learning record

Record your reasoning before the checkpoint. Finish with an explicit decision or next action. Notes stay on this device.

LOCAL STORAGE
Field exercise

Develop all three sections before completion.

Lab
Practical custody work: devices, backups and verification in progress
Practical lab locked

Pass both lesson knowledge checks in this module before attempting the practical lab.

Module 02

Phishing, origins & social pressure

Recognize when a legitimate-looking interface is separated from the origin and authority it claims.

Module locked

Complete the previous module, including its practical lab, before continuing.

Module 03

Destination integrity

Defend against look-alike addresses, clipboard substitution and history poisoning before value leaves the wallet.

Operational security environment related to this course module
Module locked

Complete the previous module, including its practical lab, before continuing.

Module 04

Operational wallet security

Reduce exposure by separating devices, roles, hot balances and recovery procedures.

Module locked

Complete the previous module, including its practical lab, before continuing.

Final examination
Assessment environment: a connected signing device and a review desk
Final examination

Final examination

This is a cumulative assessment. Questions are rebuilt from the course concepts and practical scenarios on every attempt.

You must score at least 80% to pass. Completing theory alone does not issue a credential.

Passing score80%
Best score0%
Bank52
Attempt20
Attempts0
Time limit30 min
Final examination
UTXO ACADEMY / FINAL EXAMINATION · self-custodyFinal examination
LOCKEDComplete every lesson checkpoint and every practical lab before the final examination unlocks.
Progress · 0%
Continue