Inicio Academia Guías Guía de seguridad cripto

Cómo proteger tu cripto: Guía de seguridad

Self-custody means you are responsible for your own security. This guide covers how to store your seed phrase, when to use a hardware wallet, how to spot scams and phishing, and what to do if something goes wrong.

12 min de lectura Actualizado en septiembre de 2026 Seguridad

Por qué la seguridad de criptomonedas es importante

En las finanzas tradicionales, un banco custodia tu dinero. Si te roban la tarjeta, llamas al banco y los cargos se revierten. Las criptomonedas funcionan de manera diferente. Cuando tienes criptomonedas en una cartera de autocustodia, tú eres el banco. No hay departamento antifraude, ni contracargo, ni restablecimiento de contraseña. Si alguien obtiene tus claves privadas, los fondos se pierden para siempre.

The scale of theft is large. According to the Chainalysis Crypto Crime Report, about $3.8 billion was stolen in crypto hacks in 2022, the worst year on record at the time, and about $1.7 billion in 2023. The Ronin bridge hack of March 2022 (about $625 million) and the Wormhole exploit of February 2022 (about $325 million) showed that even well-funded projects with professional teams can be breached. Chainalysis publishes updated yearly figures (see Sources).

Those figures cover protocol hacks. Individual losses from phishing, seed phrase theft, SIM swaps and social engineering come on top; the FBI Internet Crime Complaint Center (IC3) reports yearly totals for fraud complaints involving crypto (see Sources). The good news is that most attacks on individuals rely on a handful of mistakes, and this guide shows how to avoid them.

Ataques de phishing

Fake websites, emails and direct messages that trick you into revealing your seed phrase or signing a malicious transaction.

Exploits de contratos inteligentes

Bugs in DeFi protocol code that let attackers drain funds. Bridges and lending protocols have been the most targeted.

Ingeniería social

Impersonation, fake support agents, romance and investment scams that exploit trust rather than code.

Asegurando su billetera

Your wallet security starts with how you handle your seed phrase (also called a recovery phrase or mnemonic). This 12 or 24 word phrase is the master key to every account derived from it. Anyone who obtains it can empty every token on every chain linked to that wallet. There is no second factor, no verification and no recovery once it leaks.

1

Almacenamiento de la frase semilla: la regla de oro

Nunca almacene su frase semilla de forma digital. Ni en una aplicación de notas, ni en una captura de pantalla, ni en el almacenamiento en la nube, ni en un borrador de correo electrónico, ni en un gestor de contraseñas. Cualquier cosa digital puede ser accedida de forma remota mediante malware, una brecha en la nube o una cuenta comprometida. Los gestores de contraseñas y los servicios en la nube han sufrido brechas reales en las que se robaron bóvedas cifradas y se atacaron posteriormente sin conexión.

Write the seed phrase on paper and keep it somewhere secure. For long-term storage, use a metal backup (stamped or engraved plates), which survives fire and water. Consider keeping two copies in separate secure places, such as a home safe and a bank safety deposit box.

Never share your seed phrase with anyone. No legitimate service, support agent or developer will ever ask for it. If someone asks for it, it is a scam, every time.

2

Contraseñas fuertes & gestión de contraseñas

Use a unique, long password for every crypto-related account (exchanges, email, wallet browser extensions). Length matters more than special characters: NIST guidance favours long passphrases over complex short ones (see Sources). Never reuse a password. When one service is breached, attackers try the leaked credentials on every exchange.

Use a reputable password manager (such as 1Password or Bitwarden) to generate and store unique passwords. Protect the manager itself with a strong master password and a hardware key. Your email account matters most of all: whoever controls your email can reset the passwords on your exchange accounts.

3

Autenticación de dos factores (2FA)

Active la 2FA en todas las cuentas que la admitan. No todos los métodos de 2FA son iguales. De mayor a menor seguridad:

1

Hardware security keys (FIDO2 or WebAuthn keys such as YubiKey or Google Titan): physical devices that must be plugged in or tapped. They resist phishing, SIM swaps and remote attacks because the key only answers the real domain.

2

Authenticator apps (Google Authenticator, Authy and similar): time-based codes generated on your phone. Much better than SMS, but a code can still be phished, and malware on the phone can read it.

3

SMS-based 2FA: the weakest option. It is vulnerable to SIM-swap attacks, where an attacker convinces your mobile carrier to move your number to their SIM, and NIST classes SMS as a restricted factor for this reason. Avoid SMS 2FA for crypto accounts.

Si utilizas una aplicación de autenticación, guarda los códigos de recuperación sin conexión. Si pierdes el teléfono sin ellos, podrías quedar bloqueado de tus cuentas de forma permanente.

Carteras de hardware: su mejor defensa

A hardware wallet is a physical device that stores your private keys offline, isolated from your computer and the internet. Even if your computer is infected, the keys never leave the device. Every transaction must be confirmed on the device itself, so an attacker cannot sign remotely.

A hardware wallet is the single most effective step for protecting cryptocurrency. If you hold more than you could afford to lose, treat it as essential rather than optional.

Ledger

Los dispositivos Ledger utilizan un chip de elemento seguro certificado, el mismo tipo de chip que se encuentra en tarjetas bancarias y pasaportes, para proteger las claves privadas. Se emparejan con MetaMask, Rabby y la mayoría de las aplicaciones DeFi , y Ledger Live gestiona cuentas y firmware. Los modelos actuales, los activos compatibles y los precios están en ledger.com (ver Fuentes).

Important: buy directly from the manufacturer or an authorised reseller listed on its site, never second-hand. Tampered devices shipped with a pre-written seed phrase have been used to steal funds. A genuine device arrives with no seed phrase; you generate it yourself during setup.

Trezor

Trezor adopta un enfoque de código abierto: sus diseños de firmware y hardware se publican, por lo que la comunidad de seguridad puede verificar que el dispositivo hace lo que afirma. Los dispositivos Trezor se emparejan con MetaMask y las interfaces DeFi populares. Los modelos actuales y los activos compatibles están en trezor.io (ver Fuentes).

Both Trezor and Ledger support a passphrase (sometimes called the "25th word"). It creates a hidden wallet that cannot be reached with the seed phrase alone, which adds a strong extra layer for high-value holdings. Lose the passphrase and that wallet is gone, so back it up as carefully as the seed phrase.

Cómo configurar una cartera de hardware

1

Buy directly from the manufacturer (ledger.com or trezor.io). Check the packaging on arrival and follow the manufacturer's genuine-device check during setup.

2

Initialise the device and write the seed phrase on paper (or stamp it on metal). Check each word. The device asks you to confirm the words before it finishes.

3

Configura un PIN en el dispositivo. Protege contra el acceso físico si te roban el dispositivo. Los dispositivos Ledger se restablecen tras tres intentos fallidos; los dispositivos Trezor añaden un retraso creciente tras cada intento fallido (consulta la documentación de los fabricantes en Fuentes).

4

Connect the device to MetaMask or your preferred wallet interface. Send a small test amount first and confirm you can send it back out before moving larger holdings.

5

Guarda la copia de seguridad de la frase semilla en un lugar físico diferente al del dispositivo. Si ambos están en el mismo cajón durante un incendio o un robo, pierdes los dos.

Asegure sus stablecoins mientras genera rendimiento

Once your security basics are in place, put your USDC to work with Coinstancy. Earn 7.50% APY on USDC with Dollar Savings. Interest accrues every second and is automatically reinvested. No lock-up period, withdraw anytime.

Gana 7.50% APY en USDC

Evitando estafas & phishing

Phishing is the most common way individuals lose crypto. Unlike a protocol hack, which exploits code, phishing exploits you. Attackers build convincing fake websites, impersonate project staff, and use urgency and fear to get you to hand over your seed phrase or sign a malicious transaction. Here are the usual tactics and how to counter them.

Sitios web falsos

Los estafadores crean copias casi idénticas de sitios DeFi populares (Uniswap, OpenSea, MetaMask) en dominios que parecen casi correctos. Trucos comunes: intercambiar caracteres (un1swap), añadir palabras (app-uniswap.org) o usar un dominio de nivel superior diferente (.io en lugar de .org). Las páginas falsas de airdrop que imitan protocolos conocidos han vaciado carteras al conseguir que los visitantes firmen transacciones de aprobación.

Defence: bookmark the official URL of every protocol you use. Do not follow links from Discord, Telegram, social media ads or sponsored search results. Check the domain in the address bar before you connect a wallet or sign anything.

Discord & Telegram MDs

Si alguien te envía un mensaje en Discord o Telegram ofreciendo "soporte", un "sorteo" o un "airdrop", es una estafa. Los proyectos legítimos no inician conversaciones de soporte por mensaje directo. Los estafadores copian las fotos de perfil y los nombres de usuario de administradores, moderadores y fundadores. También se han secuestrado canales oficiales de proyectos para publicar enlaces de mint falsos, por lo que incluso un mensaje en el servidor correcto merece una segunda mirada.

Defence: disable direct messages from server members in your Discord privacy settings. Do not click links sent by direct message. If someone claims to be support, verify through the project's official channel or website.

Estafas de Airdrop & Ataques de Dusting

Los estafadores envían tokens que nunca solicitaste y que parecen tener valor. Cuando intentas intercambiarlos o venderlos, el contrato inteligente del token puede tomar tus tokens mediante una aprobación oculta, o el nombre del token te dirige a un sitio de phishing. Algunos están diseñados para no poder venderse: muestran un valor alto en los exploradores, pero toda venta falla.

Defence: ignore unexpected tokens. Do not interact with them, do not try to sell them, and do not visit any website in the token name or description. If a token appeared without you buying it, treat it as malicious and hide it.

Phishing de aprobación

Este es el ataque común más técnico. Un sitio malicioso te pide que firmes lo que parece una transacción normal, pero en realidad estás otorgando a un contrato inteligente permiso para gastar una cantidad ilimitada de tus tokens. El atacante luego llama al contrato y vacía tu billetera cuando quiera. Las pérdidas por phishing de aprobación y drenadores de billeteras ascienden a cientos de millones de dólares al año según Chainalysis (ver Fuentes).

Defence: read what you are signing. If a site asks for an unlimited token approval, edit it down to the amount you need. Use a wallet or extension that simulates transactions before you sign, such as Rabby or MetaMask's built-in transaction insights, and stop if the preview shows an unexpected transfer or approval.

Seguridad de contratos inteligentes

Cada vez que usas un protocolo DeFi , confías tus fondos a un contrato inteligente . Una vez que apruebas un contrato, este puede mover tus tokens sin volver a pedir permiso. Gestionar esos permisos es una parte fundamental de la seguridad en cripto.

1

Verificar & revocar aprobaciones de tokens

Every DeFi action that spends your tokens (swapping, depositing, staking) needs a token approval. Over time a wallet collects dozens of them, each one a contract allowed to move your tokens. If any of those contracts is exploited or was malicious from the start, your funds are exposed.

Use revoke.cash to review approvals across chains. Connect your wallet, go through each active approval and revoke the ones you no longer use. Make it a monthly habit. Each revocation costs a small gas fee and removes one way in. Etherscan's Token Approval Checker does the same for Ethereum mainnet (see Sources).

2

Limitar Cantidades de Aprobación de Tokens

Muchas interfaces de DeFi solicitan una aprobación ilimitada de forma predeterminada. Esto permite que el contrato gaste todo tu saldo de ese token en cualquier momento. En su lugar, aprueba solo la cantidad que pretendes usar. MetaMask te permite editar la cantidad de aprobación antes de confirmar (consulta la documentación de soporte de MetaMask en Fuentes).

You will need to approve again next time, and each approval costs gas, but the trade-off is worth it. In December 2021, the Badger DAO front end was compromised: users who had granted approvals to the injected contract had their funds drained. Open-ended approvals are a standing liability.

3

Verificar contratos en exploradores de bloques

Antes de usar un nuevo protocolo, busca la dirección del contrato en Etherscan (o en el explorador de esa cadena). Los contratos legítimos tienen el código fuente verificado, por lo que puedes leer lo que está desplegado. El código no verificado es una señal de alerta. Comprueba que la dirección coincida con la de la documentación oficial del proyecto.

Busque patrones de proxy (contratos actualizables). Son comunes en DeFi, pero añaden riesgo porque el equipo puede cambiar la lógica. Compruebe si las actualizaciones están detrás de una multifirma o un timelock, lo que significa que los cambios requieren varias firmas y un periodo de espera.

Lista de verificación de seguridad DeFi

Antes de depositar en cualquier protocolo DeFi , repasa esta lista de verificación. Parecer legítimo no es lo mismo que ser seguro. Los rug pulls, el código mal escrito y los exploits económicos pueden acabar en una pérdida total. La diligencia debida es tu responsabilidad.

Verificar Qué buscar Nivel de riesgo si falta
Auditorías de seguridad At least one audit by a recognised firm (for example Trail of Bits, OpenZeppelin, Spearbit or Cantina). Read the report and check that the findings were fixed. Crítico
Valor total bloqueado (TVL) Un TVL más alto generalmente significa que el código ha sido probado con dinero real durante más tiempo. Ten cuidado con los protocolos que retienen muy poco. Consulta el historial de TVL en DefiLlama. Alto
Equipo & Historial A public team with verifiable identities. Anonymous teams are higher risk. Look at their prior projects and reputation. Alto
Tiempo en el mercado Un protocolo activo durante más de un año sin incidentes tiene menor riesgo. Uno lanzado hace unas semanas conlleva un riesgo mucho mayor. Alto
Código abierto Código fuente verificado en el explorador de bloques. Los contratos no verificados pueden ocultar puertas traseras o mecanismos de comisiones. Crítico
Seguridad de Oráculos Uses reliable price oracles (Chainlink, Pyth). Protocols that rely on a single thin on-chain price source are exposed to price manipulation. Crítico
Comienza pequeño Deposit a small test amount first. Wait a few days. Check that you can withdraw before committing more. Mejor práctica

Seguridad de intercambio

Centralized exchanges (Coinbase, Kraken, Binance) are convenient for buying, selling and trading. But, as the saying goes, "not your keys, not your crypto". Funds on an exchange depend on that company's security and solvency. Mt. Gox (hacked, 2014), QuadrigaCX (collapsed in 2019 after its founder died holding sole access to the wallets) and FTX (bankrupt in November 2022 with customer funds missing) are reminders of that risk.

Si mantiene fondos en un exchange para operar, refuerce la seguridad de la cuenta con estas medidas.

Activar 2FA con llave de hardware

Utilice una clave de hardware FIDO2 o WebAuthn (YubiKey, Google Titan) para el inicio de sesión y la confirmación de retiros. Elimina los riesgos de SIM-swap y phishing de códigos. La mayoría de los principales exchanges admiten claves de hardware; consulte la configuración de seguridad de su exchange.

Lista blanca de retiros

Enable address whitelisting so withdrawals can only go to addresses you approved in advance. Most exchanges apply a waiting period before a new address becomes active, which gives you time to react if your account is compromised.

Código anti-phishing

Configure un código anti-phishing donde el exchange lo ofrezca. Todos los correos electrónicos genuinos del exchange incluirán entonces su código. Un correo electrónico sin él es un intento de phishing.

Minimice las tenencias en el intercambio

Keep on the exchange only what you need for active trading. Move long-term holdings to a hardware wallet. Treat exchanges as on-ramps and off-ramps, not storage.

Qué hacer si eres hackeado

Si sospechas que tu cartera está comprometida, la rapidez es clave. El atacante podría estar vaciándola mientras lees esto. Sigue estos pasos en orden.

1

Revoca todas las aprobaciones de tokens inmediatamente

Go to revoke.cash, connect the wallet and revoke every active approval, starting with the tokens worth the most. This stops drains that rely on approvals. If the seed phrase itself leaked, skip straight to step 2: the attacker does not need approvals.

2

Transferir fondos restantes a una billetera segura

Crea una nueva cartera en un dispositivo limpio (idealmente una cartera de hardware). Mueve todo lo que quede en la cartera comprometida a la nueva. Si la frase semilla se filtró, cada dirección derivada de ella está comprometida, en todas las cadenas.

3

Asegura tus cuentas

Change the passwords on your email, exchange accounts and any service linked to the wallet. If you suspect malware, do not use that computer for any crypto account until it has been wiped and reinstalled.

4

Informar & Documentar

File a report with the police, or with the FBI Internet Crime Complaint Center (IC3) in the United States (see Sources); you will need it for any legal action. Keep the transaction hashes and the attacker's addresses. If the funds went to a centralized exchange, contact that exchange's support or compliance team at once: it may be able to freeze the account.

5

Forense de blockchain

For a large loss, consider a blockchain analytics or investigation firm. They can trace stolen funds across chains, and some victims have recovered assets through legal action once the funds reached an identifiable exchange account. Be wary of anyone who contacts you promising recovery for an upfront fee: recovery scams target people who have just been robbed.

Rendimiento con prioridad de seguridad en USDC

Earn 7.50% APY on USDC with Coinstancy Dollar Savings. Savings deposits first enter a multisignature wallet managed by Coinstancy’s team, then are allocated to the relevant on-chain strategy. Interest accrues every second and is automatically reinvested. No lock-up, withdraw anytime.

Comienza a ganar en Coinstancy

Preguntas frecuentes

¿Cuál es la forma más segura de almacenar criptomonedas?
For most people, the safest way to store cryptocurrency is a hardware wallet (cold storage) such as a Ledger or Trezor device. A hardware wallet keeps your private keys offline, so malware on your computer cannot read them, and every transaction must be confirmed on the device screen. It does not protect you from signing a bad transaction yourself, so still read what you sign. Keep the seed phrase backup on paper or metal in a secure place such as a safe, never in a digital file.
¿Se puede recuperar la criptomoneda robada?
En la mayoría de los casos, las criptomonedas robadas no se pueden recuperar. Las transacciones en la blockchain son irreversibles por diseño. Si los fondos robados llegan a un exchange centralizado, las autoridades pueden lograr que se congele la cuenta, por lo que debes denunciar el robo rápidamente (al FBI IC3 en Estados Unidos, o a la policía local en otros países) y también al exchange. Las empresas de análisis de blockchain pueden rastrear los fondos, y algunas víctimas han recuperado activos mediante procedimientos legales, pero esto es lento e incierto. La prevención es la única estrategia fiable.
¿Es seguro mantener cripto en un exchange?
Mantener criptomonedas en un exchange conlleva riesgo de contraparte. Los exchanges pueden ser hackeados (Mt. Gox, 2014), quebrar (FTX, noviembre de 2022) o congelar retiros. Para cantidades pequeñas que operas con frecuencia, un exchange de reputación sólida con una seguridad de cuenta robusta es aceptable. Para tenencias a largo plazo, transfiere los fondos a una cartera de hardware donde tú controlas las claves privadas.
¿Qué debo hacer si hice clic en un enlace de phishing?
If you clicked a phishing link but did not sign anything or enter your seed phrase, your funds are most likely safe. Disconnect your wallet from the site. If you signed a transaction, check your token approvals at revoke.cash and revoke anything you do not recognise. If you entered your seed phrase, create a new wallet on a clean device and move all assets out of the compromised wallet as fast as you can.
¿Qué es una aprobación de token y por qué es peligrosa?
A token approval is an on-chain permission you grant to a smart contract to spend your tokens on your behalf. If you approve a contract for unlimited spending, that contract can move your whole balance of that token at any time. Approval phishing tricks users into granting such an approval to a malicious contract. Limit approvals to the amount you need, and review and revoke unused approvals regularly at revoke.cash or the Etherscan token approval checker.
¿Es la autenticación de dos factores suficiente para proteger mi cripto?
La autenticación de dos factores (2FA) mejora mucho la seguridad de la cuenta del exchange, pero no es infalible. La 2FA basada en SMS es vulnerable a los ataques de intercambio de SIM, en los que un atacante convence a tu operador para que transfiera tu número a su teléfono. Las aplicaciones de autenticación son mejores, y las claves de seguridad de hardware (FIDO2, como una YubiKey) son la opción más sólida. Combina la 2FA con una contraseña única, una lista blanca de direcciones de retiro y un código antifishing.

Continuar aprendiendo

Explora más guías sobre carteras, contratos inteligentes y fundamentos de DeFi.

Protege tu cripto y hazla crecer

Now that your security fundamentals are in place, put your USDC to work. Earn 7.50% APY on USDC with Coinstancy Dollar Savings. Interest accrues every second and is automatically reinvested. No lock-up period, withdraw anytime.

Comienza a ganar en Coinstancy

Fuentes y lecturas adicionales

Las cifras y afirmaciones de esta página se basan en los documentos que aparecen a continuación. Las cifras sensibles al tiempo (tasas, rendimientos, comisiones, datos de mercado) cambian: verifica el valor en vivo en la fuente antes de actuar en consecuencia.

  1. Ethereum.org, Security and scam preventionethereum.org

    Seed phrase handling, hardware wallets, common scam patterns and how to check what you sign.

  2. Ethereum.org, Carterasethereum.org

    What a self-custodial wallet is and how private keys and recovery phrases work.

  3. Ledger Supportsupport.ledger.com

    Device setup, the secure element, PIN behaviour after wrong attempts, passphrase and buying only from official channels.

  4. Trezor Learntrezor.io

    Firmware de código abierto, configuración del dispositivo, protección mediante PIN y la función de passphrase (cartera oculta).

  5. Soporte de MetaMasksupport.metamask.io

    Editing token approval amounts, hardware wallet pairing and phishing warnings in MetaMask.

  6. Revoke.cashrevoke.cash

    Visualización y revocación de aprobaciones de tokens en distintas cadenas.

  7. Etherscan, Token Approval Checkeretherscan.io

    Revisión y revocación de aprobaciones en la red principal de Ethereum.

  8. Chainalysis, Crypto Crime Reportchainalysis.com

    Cifras anuales sobre fondos robados en hackeos, incluido el total de aproximadamente 3.800 millones de dólares en 2022 y el total de aproximadamente 1.700 millones de dólares en 2023.

  9. FBI Internet Crime Complaint Center (IC3)ic3.gov

    Yearly reports on cryptocurrency fraud losses reported by the public, and where US victims file a complaint.

  10. NIST SP 800-63B, Directrices de Identidad Digitalpages.nist.gov

    La longitud de la contraseña por encima de la complejidad, y la debilidad del SMS como segundo factor.

Última revisión: septiembre de 2026. Los enlaces externos se abren en una nueva pestaña; Coinstancy no es responsable de su contenido.

Mantente seguro, gana con confianza

With strong security practices in place, earn 7.50% APY on USDC with Coinstancy Dollar Savings. Interest accrues every second and is automatically reinvested, and you can withdraw anytime.