Why you should know this
Security is easiest before a deposit. After funds arrive, urgency, price movement and fear of missing out can persuade us to postpone setup or skip a test.
This is a coworker beside us asking, “Have we protected the next step?”
This checklist is not a badge or guarantee. It is a decision gate for one specific provider, wallet, route, device and amount at one point in time. Complete it with evidence, not confidence alone.
Define the action before scoring
Write one sentence: “I plan to use [provider or wallet] to [buy, hold, transfer, pay or trade] [asset] over [network] for [amount and purpose].” If the sentence contains several actions, score each critical route separately.
A secure login does not prove a receiving network is compatible. A correct transfer route does not prove the amount is affordable. The sections remain separate so one green area cannot hide another red one.
How to score the checklist

- Green: verified and recorded.
- Yellow: uncertain or incomplete; pause and resolve it.
- Red: secret exposure, unverified provider, incompatible transfer route, unaffordable risk or active compromise; do not deposit or trade.
One red item is enough to stop. A high score cannot cancel a critical failure.
Do not turn green, yellow and red into percentages. Twenty-four green checks and one exposed seed phrase is still a stop. For a yellow item, write the evidence needed to turn it green—for example, “current deposit page confirms Network Y,” not “I think it worked before.”
Add “not applicable” only with a reason. A self-custody wallet may not require KYC, but it still needs source verification, recovery and transaction checks.
1. Provider and purpose
- I can name the exact activity I need: custody, exchange, transfer, payment or self-custody.
- I verified the provider and relevant regulated category through an official source where applicable.
- I opened the genuine domain or app and checked the publisher.
- I read current fees, limits, withdrawal rules, risk disclosures and complaint route.
- I know that provider registration does not guarantee a token or return.
Evidence: legal entity, regulator or official-directory result where applicable, verified domain/app publisher, current terms, risk disclosure and complaint channel. Do not store login secrets in this record.
2. Account and recovery
- My primary email uses unique authentication and MFA.
- The crypto account uses a unique password or supported passkey and strong MFA.
- Recovery codes and backup authenticators are protected separately.
- I reviewed active sessions, devices and recovery details.
- Nobody else knows my password, OTP, private key or recovery phrase.
Evidence: current session review, MFA method, number of protected recovery methods and date tested. Record the existence of a recovery code, never its value.
3. Device, browser and SIM
- The operating system, browser and financial apps are current.
- The device has a strong screen lock and trusted recovery setup.
- Unknown apps, remote-access tools and unnecessary extensions are removed.
- Sensitive notification previews are limited.
- I understand my carrier’s SIM and port-out protections.
Evidence: software-update date, installed-app and extension review, lost-device status, carrier security control and a separate recovery route.
4. Wallet and custody
- I know whether the wallet is custodial or self-custodial.
- I can name who controls transaction keys and who controls login recovery.
- A self-custody recovery phrase is offline, private and recoverable.
- I understand the greatest provider, key, device and human-error risks.
- I am not relying on an untested screenshot or chat backup.
Evidence: custody map naming the key controller, login controller, recovery path and greatest failure dependency. For self-custody, demonstrate recovery planning without exposing or entering the real phrase in a website.
5. Transfer route
- The exact asset and network match on both sides.
- I compared the full current destination address.
- The memo or destination tag is included when required.
- Minimums, network fee, withdrawal fee and expected credit are understood.
- A valid test transaction was confirmed by the actual recipient or account.
- I will recheck every field before the main transfer.
Evidence: current receiving instructions, exact asset/network/address/tag, minimums and fees, test transaction hash, network result and recipient credit. The test record should not contain a seed phrase or password.
6. Financial and behavior boundary
- Essential money, bills, debt payments and emergency reserves remain separate.
- I can afford the planned loss without harming daily life.
- I am not acting because of a threat, guarantee, impersonator or countdown.
- I know what would make me stop, contact support or postpone trading.
- I recorded official support contacts before an emergency.
Evidence: written maximum affordable exposure, purpose, stop conditions, official contact sheet and a statement that essential money remains outside the plan.
Philippine scenario: one yellow and one red

Arvin completes most of the list. His phone and account are secure, but he cannot verify whether the receiving service supports the selected stablecoin network: yellow. A community contact also asks him to send the test to a different “activation address”: red.
Arvin stops. He checks the deposit route inside the official receiving account and ignores the activation request. The checklist did its job even though no transaction occurred.
After verifying the correct network, Arvin does not simply turn every item green. He confirms that the test amount meets the receiving minimum, secures the address from the genuine deposit page and asks the actual recipient to verify credit. If the community contact returns as a “recovery officer,” Arvin reports the account without opening the new link.
The success is not a profitable trade. It is preventing an avoidable operational loss before market risk even begins.
Your pre-funding decision

Go: no red items; all relevant items are green; the amount remains affordable.
Pause: one or more yellow items; collect evidence, update security or ask the verified provider.
Stop and respond: active compromise, exposed secret, impersonation, incompatible network, unverified provider or unaffordable risk.
The decision can change. A green check from last month should be reviewed after a new device, password reset, provider notice, policy change or long period of inactivity.
Keep a pre-funding record
Use a one-page record with:
- action, purpose and affordable amount;
- date and timezone of review;
- provider legal entity and verified access route;
- custody and recovery model;
- authentication and device review date;
- asset, network, address source and memo/tag requirement;
- test transaction result;
- yellow items, owner and resolution evidence;
- final go, pause or stop decision.
The record supports learning and later investigation without collecting secrets. Store it according to the project’s privacy rules and delete unnecessary identity screenshots.
Refresh after events, not only on a calendar

Repeat the relevant checks after a lost or replaced phone, changed SIM, email recovery change, new passkey, new browser extension, provider notice, address change, new network, new recipient, unusually large amount, long inactivity or suspected phishing.
A monthly review is useful for sessions, software and recovery. Transaction fields need a fresh review immediately before the transfer. Regulation, provider status, fees and supported networks are time-sensitive; check current primary sources during editorial review and in real use.
Academy 2 self-assessment
You are ready to continue when you can do these without revealing a real secret:
- Explain custodial and self-custody risk in your own words.
- Point to the recovery path for email, account and wallet.
- Rank the available authentication methods and explain the remaining dependency.
- Apply PAUSE to a convincing support impersonation.
- Match asset, network, address and memo/tag from current instructions.
- Design a valid test transfer and name what it does not prove.
- Build an incident timeline and official contact route.
- Explain why a final on-chain transaction and a provider credit are different.
If one answer is unclear, return to that lesson. Repetition is not failure; it is how professionals turn a checklist into habit.
How this connects to market mastery
Mastery is not faster clicking. It is knowing which conditions must be true before exposure begins. Later trading plans add liquidity, position size, invalidation and loss limits to the same gate-based method.
The connection matters because security losses and trading losses feel different but both consume risk capital. A correct market view cannot rescue funds sent to the wrong network, and flawless custody cannot make a poor trade profitable. Market survival requires both operational safety and analytical discipline.
Key takeaways and completion check
- Security includes provider, account, device, custody, transfer and behavior.
- A critical red flag outweighs many green checks.
- Evidence should be current; old deposit instructions can expire.
- The safest trade is sometimes the one that waits.
Academy completion check: Explain your custody model, demonstrate account recovery without revealing a secret, reject one phishing scenario and design a test transfer with the correct asset, network, address and tag.
This lesson combines provider, login, recovery and device checks before money enters an account.
*Cryptocurrency and virtual asset transactions are highly volatile and irreversible, may result in significant losses, and do not guarantee returns; customers should trade only after understanding the risks involved.