101 · Foundations · lesson 1 of 4

Twelve rules. That’s the whole thing.

Everything on this site compresses into the rules below. Follow them and your Bitcoin is safe — genuinely, that is the entire deal. You don’t have to understand all of them yet. That’s what the rest of the course is for: every rule below gets a lesson of its own, in full.


A few words before you start

Your Bitcoin is controlled by a secret key. That key is written down as a list of 12 or 24 ordinary words — your seed phrase, and whoever has those words has the money. A hardware wallet is a small dedicated gadget that keeps the key offline and signs payments without ever handing it over. That’s enough vocabulary for every rule below.

  1. 01

    Not your keys, not your coins.

    Bitcoin sitting on an exchange isn’t really your Bitcoin. It’s a promise from a company to give you some later — and companies go bankrupt, get hacked, and freeze accounts. Mt. Gox lost roughly 850,000 coins. FTX vaporised about $8 billion. Move your coins off the exchange after you buy. That one step is what this whole guide is about.

    In full: 101 · Not your keys, not your coins

  2. 02

    Protect your Bitcoin with at least two independent things, so no single one of them failing can lose it.

    One seed, in one drawer, is one thing: a fire, a flood, a burglary or a single miscopied word takes all of it, and nothing else has to go wrong first. The floor is two independent things — a seed plus a passphrase the device never saw, keys from two different makers, two complete backups that can’t burn together. Independent is the word doing the work: three keys from one manufacturer, made the same way in the same batch, are one thing bought three times. Count what has to fail, not how many pieces you own.

    In full: 101 · How people lose Bitcoin

  3. 03

    Never keep long-term savings on an internet-connected device.

    A wallet is hot when its keys sit on something that goes online, and cold when they don’t. Phone and desktop wallets are hot: fine for walking-around money, wrong for savings. Anything you are actually saving belongs on a device that stays offline — and writing your words into a note, a photo or a password manager puts them straight back online.

    In full: 102 · Hot and cold — where savings belong

  4. 04

    The more you’re protecting, the more it takes to protect it.

    A setup isn’t secure or insecure in the abstract — it’s secure enough, or not, for what it’s holding. What is entirely sensible for money you’re learning with stops being sensible once the same arrangement is carrying years of savings, and the arrangement will not notice; you have to. So the question is never “is this secure?” but “is this secure enough for what it holds now?” We ask what losing it would actually do to you, never how much you have — because consequence is what should set the shape of a setup.

    In full: 102 · The wallet configuration ladder

  5. 05

    Choose the simplest setup that covers you.

    Not the most impressive one, and not the one a vendor is selling — the simplest one that defends against risks you can name out loud. No setup is simply “right”: every choice here trades one risk for another. What makes it harder for a thief to reach your Bitcoin usually makes it easier for you to lock yourself out, and what makes recovery easy for you makes it easier for someone else too. There is no arrangement without a downside — only the one whose downsides you chose on purpose.

    And the thing you are mostly defending against is yourself. The mental picture is a hacker; the reality is a house fire, a single backup nobody copied, a word miscopied and never checked, or an owner who died leaving no instructions. Far more Bitcoin has gone that way than was ever taken — which is why complexity you don’t fully control is itself a threat, and why every extra key, device and clever scheme is one more thing you have to keep right for years, on your worst day. Simplicity is still the target. It just never means leaving one thing whose failure takes everything.

    In full: 102 · The wallet configuration ladder

  6. 06

    Buy your hardware wallet new, direct from the maker, and set it up yourself.

    A device bought second-hand, or from a marketplace reseller, can reach you already loaded with someone else’s keys — and you would not find out until your coins left. Order from the manufacturer’s own website, check the tamper seal when it arrives, and make the device generate a brand-new seed phrase in front of you. If one ever arrives already showing you a seed phrase, it is compromised. Don’t use it.

    In full: 102 · Choosing a hardware wallet

  7. 07

    Never let your seed words touch anything digital.

    No photo. No cloud note. No password manager. No typing them into a phone or a computer, not even for a second, not even to “check” them. A digital copy of your words is a hot wallet holding everything you own, and it can leak years later when some account you forgot about gets breached. Paper, or better, metal.

    In full: 103 · Backing up a seed phrase

  8. 08

    Fully test your backup before you send any significant Bitcoin to your wallet.

    One miscopied word makes a backup worthless, and you find that out on the day you need it — the worst possible day there is. Wipe the device and restore from your written words with a trivial amount first. Only once you have watched it work should real money go in. Then prove it again about once a year.

    In full: 103 · Testing a backup

  9. 09

    If someone requires your seed words for any reason, they’re trying to steal your Bitcoin.

    Not your wallet maker, not your exchange, not support, not a “migration,” not a security check, not an urgent message about suspicious activity. No legitimate service ever needs those words — so there is no judgement call to make and no story to weigh up. The demand itself is the proof. The only time your words are ever typed anywhere is a recovery you started, on a device you chose, at a moment you picked. Anything else is theft in progress. Phishing is the number-one real-world attack, and this one rule defeats nearly all of it.

    In full: 104 · Phishing and everyday safety

  10. 10

    Talk about Bitcoin. Never talk about your Bitcoin.

    Physical attacks are almost never random. They start with a leaked customer list, get cross-referenced against anything you have said publicly about owning Bitcoin, and end at your door. So talk about Bitcoin the idea as loudly as you like — the technology, the economics, the freedom. Just never attach your own name to the fact that you hold it, and never attach a number. That includes people you trust: they have people they trust too, and you don’t control the third telling.

    In full: 104 · Privacy / OpSec

  11. 11

    Every time you receive Bitcoin, generate a new address.

    Reusing one address publishes your whole financial history to anyone who looks — the ledger is public, and every payment to that address is permanently linked to every other. Your wallet makes fresh addresses for free, endlessly, and usually offers a new one by default. Let it. This single free habit does most of the privacy work there is.

    In full: 104 · Privacy / OpSec

  12. 12

    Leave your family a plan they can actually follow.

    Most Bitcoin that vanishes forever wasn’t stolen — it was left behind with no instructions. Your family finds a metal plate and a strange gadget, has no idea what either is, and bins them. Write down what you have, where it is, and how to reach it, in language a grieving non-technical person can follow. Then rehearse it with them while you still can.

    In full: 104 · Why Bitcoin doesn’t inherit like money

And the one that contains all twelve

Verify. Don’t trust.

Check your backup instead of assuming it. Check the address on the screen instead of trusting the computer. Check the rules yourself, with your own node, instead of taking a company’s word for what’s yours.

In full: 104 · Running your own node — the last lesson of the course.

What to do with this page

Don’t try to memorise it. Read it once now so the shape of the thing is in your head, then carry on to the next lesson — the rules will make far more sense once you’ve met the ideas behind them. Come back here whenever you want the whole guide in two minutes, and use it as a checklist before you move any meaningful amount of Bitcoin.

And don’t take them on trust — that would be an odd way to begin a course whose last rule is the one above. There is nothing you can buy that makes you safe; what keeps Bitcoin is somebody who understands their own setup and has practised it. So every lesson ahead shows you the mechanism rather than handing you the instruction, and the bar it is written to is whether you finish able to explain the rule to somebody else. That is the only version of a rule you can still apply on a bad day.

Each lesson that teaches a rule opens by naming it, so you always know which of the twelve you’re working on.

Last verified: August 4, 2026