The drained wallet that finally convinced me to change my own setup belonged to a guy who had done everything right by the usual standards. Hardware wallet, seed phrase on steel, no screenshots, none of the obvious mistakes. He had also used that same address for two years of active DeFi. Long-term ETH, LP positions, NFT mints, airdrop claims, every experiment he ever tried, all signed from one key. When he eventually hit a fake mint page and signed one bad approval, the attacker did not need to break anything. The permissions had been piling up across hundreds of transactions, and everything the address held was reachable from the moment he clicked confirm.
The seed phrase in the drawer is usually fine. What gets active users is the slow accumulation of signatures granted while actually using DeFi. Every token approval is a standing permission that lives on-chain until you revoke it, and plenty of dApps still request unlimited approvals by default. On top of that, permit-style standards let tokens move based on an off-chain message, so a wallet can be drained by something that never looked like a transaction at all. If one address holds your net worth and also does your daily signing, every signature is a bet of the whole stack.
The fix is structural rather than behavioral, which is exactly why I like it. You will eventually sign something bad. I have, most active users have, and the phishing pages keep getting more convincing. Segmentation accepts that and shrinks the blast radius of a bad signature down to a wallet you already decided you could lose.
The three tiers and what each one is allowed to sign
The vault is a hardware wallet holding anything you plan to keep for months or years. Its rules are strict and short. It never connects to a dApp, it never signs a message of any kind, and it never grants a token approval, not once, not for anything. The only transactions it signs are plain transfers out, which should be rare. It receives constantly and sends almost never. If a website is asking your vault for a signature, the answer is no by policy, so you never have to evaluate whether this particular claim page seems legit.
The hot wallet is the daily driver. It touches established protocols with long audit histories and real value at stake, and it holds whatever capital you are actively deploying. A useful sizing rule is an amount that would hurt to lose but would not change your life. Approvals are allowed here because they have to be, but you cap them to what you are actually trading whenever the interface lets you, and you review and revoke old ones on a schedule. Ideally this one is hardware-backed too, since it still carries real money.
The burner exists for everything with an unknown blast radius. New mints, unaudited farms, links from Discord, claims on contracts nobody has reviewed, anything you found on social media less than a week ago. It holds gas plus whatever the specific action needs and nothing else. You treat it as already compromised, because functionally it might be, and you rotate to a fresh one after anything that felt off. A burner holding pocket money can sign the sketchiest mint on the internet, and the worst case is the pocket money.
A setup you can do in an afternoon
Here is the concrete version, in order.
- Buy a hardware wallet directly from the manufacturer, initialize it with a fresh seed, and back the seed up offline. This is the vault. Note the address somewhere handy, because receiving is the only thing you will do with it regularly.
- Set up the hot wallet on a completely separate seed phrase. A second hardware device is the nice version, a fresh software wallet is the acceptable one. What matters is that it shares no seed with the vault.
- Create the burner as a fresh software wallet, again on its own seed, and fund it with a little gas from an exchange rather than from your other wallets.
- Move your long-term holdings to the vault. Send a small test amount first, confirm it arrived, then send the rest.
- Bookmark an approval checker such as revoke.cash or your block explorer's token approval page, and set a monthly reminder to review the hot wallet's outstanding approvals.
- Write the signing rules down, even just in a phone note. Vault signs nothing, hot signs known protocols with capped approvals, burner signs the rest.
The separate seed phrases matter more than people expect. Multiple accounts inside one wallet extension usually derive from a single seed, which makes them one root secret wearing different addresses. Approvals are tracked per address, so account two cannot drain account one that way, but a leaked or malware-captured seed takes everything derived from it at once. Three tiers on one seed is really one tier with extra steps.
The cross-contamination mistakes that quietly undo it
Most segmentation failures I have seen were self-inflicted, and they usually show up months after the setup, once the discipline has gone soft.
The most common is connecting the vault to a dApp just once, because some claim or migration or governance vote only works from the address holding the assets. Occasionally that is genuinely unavoidable, and the move is to do the single action, verify exactly what you are signing on the hardware screen, and grant nothing reusable. What usually happens instead is the one-time exception becomes a habit, the vault picks up a couple of approvals, and the tier quietly stops existing.
Related to that, message signing feels safe in a way transactions do not, and it should not. Gasless listing signatures and permit approvals can move assets without anything that looks like a send. If your private rule says the vault can sign messages as long as it avoids transactions, you have rebuilt the original problem with better branding.
Funding paths leak too. Top up your burner straight from the vault and the two addresses are publicly linked, one hop apart. When the burner shows up in a phishing site's logs, anyone curious can walk back through its funding history, find the address with the real balance, and start targeting you personally instead of as part of a spray. Routing burner funding through an exchange account breaks the link. That one is privacy more than security, but targeted phishing is where the ugly losses come from.
The subtler version is key material creep. People spin up a proper burner, then import its seed into the same browser extension profile that holds the hot wallet, on the machine they use for everything. The on-chain separation is intact, but one infostealer now captures both. Separate browser profiles are the minimum, and a cheap dedicated device for the hot wallet is the comfortable version if the balances justify it.
And when you move money between your own tiers, paste addresses from your own records, never from transaction history. Address poisoning seeds your history with lookalike addresses that match your real ones at the first and last characters, built specifically to catch people transferring between their own wallets on autopilot. A small test send before any large internal transfer costs a little gas and removes the whole category.
The ongoing cost of all this is friction, and the friction is doing most of the work. When a mint closes in four minutes and the site wants a signature from the wallet that matters, the fact that you physically cannot do that from the couch is what saves you, because in the moment your judgment will be worse than your policy. My burner has signed some things I am not proud of. The vault has never signed anything at all, and I intend to keep it that way.