TECA — Further Reading
This page supports the Teca notebook. Use it to find account-security guidance, recovery resources and instructions for making a physical backup.
Updated
On this page
- Check for signs of account exposure
- Password managers and recovery planning
- Add another layer of account protection
- Recognize common crypto scams
- Paper and metal backups
- Sources and further reading
Check for signs of account exposure
Search your email address in known breaches
Have I Been Pwned can show whether an email address appears in breaches recorded by the service. Read the details: a listed breach does not always mean a password was exposed, and a clean result does not prove an account has never been compromised. Its FAQ explains these limits.
If a password was exposed, replace it on the affected account and anywhere you reused it. Open the service through its official app or a known address to make the change.
Review account activity
For a Google account, open Google Security Checkup. Review unfamiliar devices, connected apps and recovery details. For other services, use their official security settings.
Unexpected sign-in notices, reset emails or verification codes deserve investigation, but they do not by themselves prove someone has your password. Check the activity from within the account rather than following an unexpected message's links.
Password managers and recovery planning
A password manager can generate and store a different long password for each account. Protect the manager itself with a strong, unique account password and the additional authentication options it supports. NIST's password-manager guidance explains the benefits and the importance of protecting the vault.
Compare the features you will use
- Password generation and autofill on your devices.
- Clear documentation about encryption and independent security assessments.
- Support for additional authentication, secure exports and account recovery.
Read the recovery instructions before you need them. Recovery options depend on the provider, account type and settings you have already enabled. For example, 1Password documents recovery codes and family or team recovery, while Bitwarden documents emergency access, organization recovery and other possible routes. These options must not be assumed to exist for every account.
If you record an account password or recovery information in the notebook, treat the notebook as sensitive. Store it securely and keep the information current. A wallet's recovery words, a password manager's recovery kit and a website's backup codes are different things; label records clearly.
Add another layer of account protection
Use a passkey or security key where supported for phishing-resistant sign-in. An authenticator app is another useful option, but manually entered codes can still be captured by a phishing site. NIST explains this distinction in its authentication guidelines.
- Open the account's security settings through its official app or website.
- Find its passkey, security-key or two-factor authentication options and follow the provider's setup instructions.
- If using an authenticator app, complete the code-confirmation step.
- Save any recovery codes or other recovery information the service provides in a secure place you can access if your usual device is unavailable.
- Check that the new sign-in method works before removing an existing method.
For example, Google backup codes are single-use, and generating a new set invalidates the old one. Other services have their own rules. Backup codes are one possible recovery method, not necessarily the only one.
Recognize common crypto scams
Guidance reviewed . These are common patterns, not a complete list of active scams.
Fake support and recovery websites
Do not send recovery words to a person claiming to provide support. Be suspicious of unsolicited messages asking you to “validate” or “sync” a wallet. Restore a wallet only through the verified wallet provider's documented process. Ethereum's security guide explains common impersonation and recovery-phrase scams.
Counterfeit apps and devices
Use the wallet manufacturer's official website to find its software and authorized purchasing channels. Follow its device-authenticity and initialization checks. Stop if a purportedly new wallet arrives with recovery words already supplied for you to use.
Address poisoning
An attacker can place a lookalike address in transaction history and hope you copy it. Obtain the recipient's address from a trusted source and check the entire address, including on the hardware wallet's display when available. Checking only the start, middle or end is insufficient. Read Ledger's explanation of address poisoning.
Malicious approvals and signatures
A request to sign a message or approve token spending can give someone permission to move assets. The effect depends on the request, and theft may happen immediately or later. Read the permissions and spending limits; reject a request you do not understand. MetaMask explains signature phishing and how signed permissions can be misused.
Paper and metal backups
A written backup needs protection from loss, damage and unauthorized access. Choose storage suited to what you are recording and how you would recover it. Keep recovery words private, verify the record carefully and avoid keeping every necessary backup in one place. Our paper vs. metal guide explains the practical differences.
Crypto Seed Bank
Crypto Seed Bank is a physical backup for recovery words, used alongside your existing wallet. The kit includes two 304-grade stainless steel cards, integrated letter stencils and a tungsten tipped engraving pen. Wallet-size cards are 0.5 mm thick; Plus-size cards are 0.7 mm thick.
In our demonstrated blowtorch test, the engraved words remained readable after the card was heated until red hot. That observation is not a certified temperature rating or a guarantee for every fire. Physical durability also does not prevent someone from reading an exposed backup.
For the English BIP39 wordlist, the first four letters identify each word; record shorter words in full. Preserve word order and do not translate the phrase. Other backup formats need their own instructions. See the BIP39 specification and our engraving guide.
An optional wallet passphrase must be recorded exactly, including capitalization and spaces. It must not be abbreviated like recovery words. Check the storage format can preserve every character you need. Trezor's passphrase guide explains why the exact value matters.
Sources and further reading
- NIST authentication guidelines — password and authentication requirements.
- BIP39 specification — recovery phrases, wordlists and passphrases.
- Trezor's guide to wallet backup formats — why different formats are not interchangeable.
- Ethereum security and scam prevention — practical wallet-security guidance.
Password-cracking estimates depend on the password, the attack method, the hardware and how the service stores passwords. Treat a crack-time chart as an illustration of stated assumptions, not a guarantee for an individual account.
Our promise
Robins and Coleman will never ask you to share a recovery phrase, password, PIN or backup code. You do not need to connect a crypto wallet to use these guides. If someone claiming to represent us requests those secrets, do not provide them.
For product questions, contact contact@robinsandcoleman.com. Keep recovery words and other secrets out of your message and attachments.