Tool · check
Security check
How well protected is your bitcoin? Question 1 asks where it is kept – after that you only see the questions that apply to you. You get a traffic light and your next steps, the most urgent first.
In the learning pathStage 6 · Protect & stay the course
- Runs
- locally, in your browser
- Inputs
- stay on your device
- Sources
- 8 · as of 27/09/2026
- Advice
- none – education, not recommendations
After the check
Your next steps
As soon as you answer, your recommendations appear here – the most urgent first.
No open recommendations – well done.
01 Where is your bitcoin kept?
A balance with a provider is legally a claim against that provider – not bitcoin in your own hands. MiCA requires client assets to be held separately, but there is no deposit guarantee like for a bank account. Get to know your own wallet, at the latest once the amount matters to you.
Read more: Understanding custody Setting up your first wallet
02 Have you checked yourself that your provider is authorised in the EU (MiCA)?
Check the authorisation yourself – in the ESMA register or with your national regulator (in Germany: BaFin). All MiCA transition periods ended on 1 July 2026: anyone offering crypto services in the EU needs authorisation. Advertising, follower counts and a slick design say nothing about it.
Read more: Choosing a provider MiCA & regulation
03 What protects the login at your provider besides the password?
Turn on two-factor login – ideally with an authenticator app or a security key (also as a passkey) rather than SMS, as Germany’s BSI also recommends. SMS codes can be intercepted through SIM swapping, where criminals get your number moved to their SIM card. Protect withdrawals and address-book changes with 2FA too.
Read more: Security checklist Buying Bitcoin
04 Does your provider account have a password you use nowhere else – and is your email account protected with two-factor login too?
Use a long password for your provider account that you use nowhere else – a password manager helps. Protect your email account with two-factor login too, as many accounts can be reset through it.
Read more: Security checklist
05 How do you open your provider’s website or app?
Only open your provider via a saved bookmark or the official app. Phishing sites look deceptively like real exchanges, often with a slightly altered address – and sometimes even appear as search ads. Don’t click links in messages urging you to log in.
Read more: Spotting scams
06 How have you backed up your wallet’s seed phrase (recovery words)?
Write your seed phrase by hand on paper and, for the long term, on metal – never as a photo, screenshot, in the cloud, by email or in an app. Whoever has these words has your bitcoin. Losing them means losing access for good; no support can restore them. If it was ever stored digitally, move your bitcoin to a newly generated wallet.
Read more: Backing up your seed phrase Setting up your first wallet
07 How many copies of your seed backup exist?
Keep at least two copies in separate, safe places so your backup survives fire, water or a move. Don’t split the words into halves; that weakens security. If you need more protection, look into multisig.
Read more: Backing up your seed phrase Multisig
08 Have you ever tested your backup – with a trial restore or your device’s backup check?
Do a trial restore while only a small amount is in the wallet. If more is already in it, use your hardware wallet’s backup check or restore on a second device without wiping the first. That way you find out in time if a word was written down wrongly.
Read more: Testing recovery
09 Where does your hardware wallet come from – and who generated the seed phrase?
Only buy hardware wallets new from the manufacturer or official resellers and always generate the seed phrase on the device yourself. A ready-made “recovery card” in the box is a scam: move your bitcoin to a newly generated wallet right away. A second-hand device may have been tampered with – replace it with a new one. Only update firmware from official sources.
Read more: Setting up a hardware wallet Hardware wallets compared
10 How do you check a receiving address before you send bitcoin?
Compare addresses in full and never copy them from your transaction history: scammers send tiny amounts from addresses that match yours at the beginning and end (“address poisoning”). Malware can swap copied addresses. Send a small test amount the first time.
Read more: First withdrawal Keys & addresses
11 Do you keep your phone, computer and wallet apps up to date and install apps only from official sources?
Install updates promptly and download wallet apps only from the official app store or the developer’s website – check the developer name. Fake wallet apps and “updates” via link or QR code are a common scam.
Read more: Spotting scams Types of wallet
12 A friendly “support agent” asks you to enter your seed phrase to fix a problem. What do you do?
No legitimate company ever asks for your seed phrase or private keys – not by email, phone, chat or form. Anyone who asks wants to rob you. Only contact support yourself via the official app or website.
Read more: Spotting scams
13 Has someone you only know from a chat, a phone call or social media ever got you to pay money into an investment platform?
This is the typical pattern of investment fraud: build trust, show fake profits, then demand “fees” or “taxes” for a withdrawal. Pay in nothing more, end the contact, check the platform against your financial regulator’s warning list (in Germany: BaFin) and report it to the police. Beware of “recovery services” that want payment upfront.
Read more: Spotting scams
14 Do you talk publicly or among acquaintances about how much bitcoin you have?
Keep how much bitcoin you own to yourself. Bragging makes you a target – for phishing, extortion and in the worst case robbery. Such attacks have increased recently.
Read more: Spotting scams Privacy
15 Would a trusted person know how to reach your bitcoin in an emergency – without knowing your seed phrase today?
Write an emergency letter: which accounts and wallets exist, where the backups are and who can help technically – but without the seed phrase or passwords in the letter. Without this, even heirs cannot get to your bitcoin.
Read more: Inheritance & emergency plan
Open calculationHow we calculate
Assumptions, formulas and limits – click to expand
How the traffic light works
- Question 1 asks where your bitcoin is kept. It does not count, but it hides questions that don’t apply to you – for example about the seed phrase if your bitcoin is only with a provider.
- Every other answer scores 2 points (good), 1 point (could be better) or 0 points (risk). “Not applicable” does not count.
- Red means: at least one answer is an acute risk – login with a password only, a seed phrase stored digitally or not at all, a seed phrase that came in the box, handing the seed phrase to “support”, or money paid into a platform that an online or phone contact led you to. It is also red if you reach less than half of the points.
- Amber means: no acute risk, but at least one answer with 0 points or less than 85% of the points.
- Green means: at least 85% of the points and no answer with 0 points.
- While questions are still open, the light shows an interim result. An acute risk turns it red immediately.
What the questions are based on
- Two-factor login: Germany’s BSI rates authenticator apps and hardware tokens (FIDO) as more secure than SMS codes.[1]
- Seed phrase: the recovery words generate your keys – whoever knows them controls the bitcoin.[4] Metal backups have been stress-tested against heat, corrosion and crushing – the simpler the design, the fewer the points of failure.[5]
- Scams: European supervisors warn about phishing, fake support, fake apps and investment fraud – legitimate companies never ask for passwords or seed phrases.[2] Consumer advocates currently warn about investment groups in messengers.[7][8]
- Providers: in the EU, crypto service providers need MiCA authorisation; all transition periods ended on 1 July 2026. ESMA keeps the register.[3]
- Discretion: robberies and extortion against known bitcoin holders are documented and have increased.[6]
What the check cannot do
It does not replace security advice and does not know your devices. Never enter your seed phrase, passwords or balances anywhere – not here either. Your answers never leave your browser.
Sources8 sources · 6 publishers
The superscript numbers in the text refer to these sources.
- Zwei-Faktor-Authentisierung – Bundesamt für Sicherheit in der Informationstechnik (BSI) (accessed 27/09/2026)
- Factsheet: Krypto-Betrug und -Täuschung (deutsche Fassung) – EBA, EIOPA und ESMA, 2026 (accessed 27/09/2026)
- Markets in Crypto-Assets Regulation (MiCA) – ESMA (accessed 27/09/2026)
- BIP 39: Mnemonic code for generating deterministic keys – Bitcoin Improvement Proposals (accessed 27/09/2026)
- Metal Bitcoin Seed Storage Stress Test Reviews – Jameson Lopp (accessed 27/09/2026)
- Known Physical Bitcoin Attacks – Jameson Lopp (accessed 27/09/2026)
- Anlagebetrug über WhatsApp-Gruppen: Vorsicht vor diesen Maschen – Verbraucherzentrale, 17.09.2026 (accessed 27/09/2026)
- Anlagebetrug erkennen – BaFin (accessed 27/09/2026)
Source
All sources ↓