Criminals are increasingly using AI to help them steal other people's crypto, and it's an emerging threat vector that investors need to defend themselves against. In April, two major hacks, one against an exchange on Solana (SOL -3.42%) and one against a staking protocol on Ethereum (ETH -3.26%), stole $577 million in total. And based on the blockchain intelligence company TRM Labs' 2026 AI-in-Crime Adoption Index, criminal adoption of AI tools rose by 40% over the past 12 months.
You can keep your crypto safe from attackers, whether they're using AI or not, without becoming a computer security professional. Here are four very quick and easy solutions that you should take today, if you haven't already.
Image source: Getty Images.
1. Let a regulated U.S. exchange hold your coins
The highest-ROI move you can make to safeguard your crypto is to only buy and hold it using a large, regulated, and domestic exchange like Coinbase Global (COIN -6.01%) rather than using an offshore venue or a wallet app you run yourself.
Major exchanges have the money to pay for large and competent security teams and extensive third-party security audits. Protecting their reputation from the damage a major hack would do is a pretty powerful incentive for the exchanges to have good security practices. What's more, they usually hold most of their customer funds offline.

NASDAQ: COIN
Key Data Points
And most of the time, holding assets on an exchange isn't meaningfully less convenient than holding them in a wallet app anyway.
2. Hold ETF shares instead of coins
Holding your crypto via a spot crypto exchange-traded fund (ETF) is another great move that instantly confers a very high degree of security.
When you hold crypto via an ETF rather than directly or via a reputable domestic exchange, the asset manager that issues the ETF shares appoints a specialist custodian to hold the underlying assets.
The advantage of this is that the custodian is responsible for managing the private keys that control the fund's own coin holdings, which sit in accounts that are not commingled with the sponsor's assets or with those of other clients. They do that using a cold storage system, which is run on computers that never touch the internet.

CRYPTO: SOL
Key Data Points
So, you get to use their security in exchange for paying the expense fees on the ETF, which are usually minimal.
3. Limit the possible damage from a breach
Holding coins yourself in a wallet application is fine, and possible to do safely, but you should never keep all your eggs in one basket.
One quick and widely used trick is to have two different wallets: a "hot" wallet and a "cold" wallet.
Use the hot wallet for daily transactions and spending, as well as for minting non-fungible tokens (NFTs), interacting with smart contracts and decentralized finance (DeFi) protocols, and generally for connecting to applications or services. The cold wallet, on the other hand, should only ever be used to send and receive bulk funds from that hot wallet, and it should be managed using a separate computer system that you know to be secure, if possible.

CRYPTO: ETH
Key Data Points
The risk of getting hacked will end up being concentrated almost entirely in the hot wallet, where you keep far fewer funds.
4. Do not give your credentials to anyone, ever, and especially not if they ask
There is no security scheme that will protect your crypto if you give someone else the information they need to transfer it out of your exchange account or your wallet.
No customer support agent will ever need it or ask for it. No exchange employee will ever request it. Nobody has a legitimate reason to hear or see your account password or your wallet's private key.
And Coinbase, like most other exchanges, states that its crime policy excludes the recouping of customer losses from an attacker that accesses your account using your credentials -- so if you let a hacker's social engineering skills get the better of you, it could be a total loss.
In one particularly shocking incident in April, hackers affiliated with the government of North Korea spent months building rapport with Drift Protocol's employees in person before they were able to obtain the signatures that allowed them to steal $285 million in 12 minutes. More realistically for most investors, the risk is that you'll be facing the cheaper and AI-enabled version of this attack, made from a cloned voice or cloned face of someone you trust on a video call, or a patient chat agent.
But there's an easy solution: Just don't tell anyone your critical information.





