People lose money in crypto in a small number of repeatable ways. The market itself is only one of them, and for most people it is not the one that does the real damage. The rest are operational: a key that was never backed up, a link that looked right, a platform that held the coins and then did not.
This guide takes each category in turn and describes it the way you would describe a fault in a machine — what it is, how it presents, and what actually removes it. There is no reassurance here, because the honest version of this subject does not have any.
Volatility is the risk everyone talks about. Custody and human error are the risks that empty accounts.
Market risk: the price does what it wants
Crypto assets move further and faster than most people expect, in both directions, and there is no floor guaranteed by anyone. A drawdown of more than half from a recent high is an ordinary event in this asset class, not an anomaly, and an asset that has fallen that far has no obligation to recover.
The only real protection is sizing. Not a stop-loss, not a thesis, not diversification across ten things that all move together — sizing. The amount you commit should be an amount whose total loss changes nothing important about your life. Everything else is a refinement of that one decision.
Smaller assets carry a second layer: liquidity. A token can be quoted at a price that exists only for tiny amounts, and discovering that during an exit is how a paper loss becomes a permanent one.
Custody risk: whose coins are they, really
If a company holds the keys, you hold a claim, not a coin. That claim is only as good as the company's solvency, its competence and its willingness to keep letting you withdraw. History in this industry is not short of platforms that were fine right up until the withdrawals stopped.
Self-custody removes that counterparty and hands you a different job: never losing the key. There is no reset link and no support desk that can restore a seed phrase. The practical answer is an offline written backup, stored somewhere safe from fire and water, and a tested restore before the wallet holds anything meaningful. The wallet setup walkthrough covers the drill; the wallet pillar covers choosing the software in the first place.
A non-custodial swap sidesteps the middle of this problem: coins leave your wallet and arrive in your wallet, and there is no balance parked with a third party waiting for a withdrawal to be approved.
Operational risk: the transfer that cannot be undone
Blockchain transactions are final. There is no chargeback, no reversal and, in most cases, no recovery. That turns ordinary clerical errors into permanent ones:
- Wrong network. The same token exists on several chains, and sending an ERC-20 balance to an address expecting the TRON version is one of the most common ways funds disappear. Our USDT network guide explains how the address formats differ and how to move between them deliberately.
- Missing memo or tag. Some networks route deposits by a memo field. Omit it and the transfer arrives somewhere that cannot attribute it to you.
- Clipboard tampering. Malware that swaps a copied address for its own is old, cheap and still effective. Check the first and last characters against the source every time, on the screen you are sending from.
- Untested amounts. A small first transfer costs a network fee. Skipping it can cost the whole balance.
Fraud: the attacks that actually work
The successful scams in crypto are rarely technical. They are patient, they are conversational, and they arrive at the moment you are already expecting a message.
- Fake support. Nobody legitimate needs your seed phrase, ever, for any reason. A request for it is proof of fraud with no further investigation required. This is true of us as well: Monivo support will never ask for a recovery phrase or a private key.
- Lookalike sites. Search ads and near-miss domains harvest wallet connections. Reach the site through a bookmark you created yourself, not through a link you were sent.
- Guaranteed returns. A yield that cannot fail is a story about where the next depositor's money goes. There is no version of this that ends differently.
- Romance and long-con investment platforms. Weeks of ordinary conversation, a small withdrawal that works, then a larger deposit that does not come back. The early successful withdrawal is the product.
- Malicious approvals. Signing a token approval can grant an open-ended right to move your balance later. Review what you are signing and revoke approvals you no longer use.
Exposure: the ledger remembers everything
Public chains publish your history permanently. A reused address links every payment ever made to it, and an address tied once to a verified account is tied to it forever. The risk is not abstract: a visible balance is a targeting signal, and the data outlives whichever service collected it.
Reducing exposure is a matter of habits — fresh addresses, wallets separated by purpose, and confidential assets such as Monero where privacy is the actual requirement. On crypto-to-crypto routes Monivo asks for no account and no ID, so there is no identity record to leak; fiat rails do require verification, because banks require it of anyone who touches them.
Provider and settlement risk
A swap involves a liquidity provider, and providers vary in what they quote, how fast they settle and how they behave when a network congests. A quote is an estimate until it is filled; floating-rate routes can land above or below the figure shown, and fixed-rate routes charge for that certainty in the rate itself.
The defence is visibility rather than trust. We publish the swap rate index precisely because the spread between providers on identical pairs is a real, measurable cost that most people never see, and the provider comparison shows how those routes differ before you commit to one. If a swap stalls, live support is available around the clock — not as a guarantee of outcome, but so a stuck transfer has somewhere to go.
The short version
- Commit only what a total loss would not change.
- Write the seed phrase down offline and test a restore.
- Verify the network and the first and last characters of the address.
- Send a small test transfer first.
- Never share a recovery phrase — no legitimate party asks.
- Reach sites through your own bookmark.
- Treat guaranteed returns as proof of fraud.
- Use fresh addresses; assume the ledger is public forever.
The companion to this page is the strategy guide: how people structure decisions once they understand what they are exposed to.