One of the most common concerns merchants raise about crypto is security: what happens if a customer pays from a stolen wallet? What if my wallet gets hacked? What if I lose everything and there's no one to call?
These are fair questions. Crypto does work differently from traditional banking, and the differences are real. This article explains the actual risks, puts them in context, and gives you concrete steps to protect yourself. No scaremongering — but no hand-waving either.
The risks that are real
Your wallet could be compromised
If someone gains access to your wallet — whether through a stolen seed phrase, a phishing attack, or malware on your device — they can drain it. Unlike a bank account, there is no fraud department to call, no 48-hour hold, no chargeback. Once crypto leaves a wallet, it's gone.
This is the most serious risk, and it deserves to be taken seriously. The good news is that it's also almost entirely preventable with basic security practices, which we'll cover below.
Payments from stolen wallets
If a customer pays you from a wallet that contains stolen crypto, you have generally received legitimate payment. The theft happened upstream — the scammer stole crypto from someone else and used it to pay you. In most cases, as the merchant, you are an innocent recipient and not liable.
That said, if law enforcement determines that funds in your wallet are directly traceable to a crime, they could potentially be frozen or seized as part of an investigation — even if you received them in good faith. This scenario is extremely rare in practice, particularly for small merchants accepting payment for legitimate goods and services.
No chargebacks — in both directions
Bitcoin payments are irreversible. This means you can't get a fraudulent chargeback from a customer claiming they didn't receive their order — a significant advantage over card payments, where chargebacks are a real and costly problem for merchants.
But it also means if you make an error — sending a refund to the wrong address, for example — it can't be undone. Precision matters.
Credit card chargebacks cost US merchants an estimated $100 billion per year. Crypto's irreversibility eliminates this entirely. For many merchants, the chargeback protection alone justifies accepting Bitcoin — especially for high-ticket items or digital goods where fraud is common.
What OrangeTill's architecture means for your risk
OrangeTill is non-custodial. That means your funds never pass through us — not for a second. When a customer pays you, the payment goes directly from their wallet to your wallet. OrangeTill generates the QR code and logs the transaction; that's it.
This has an important implication: OrangeTill cannot be hacked to steal your funds. Even if someone compromised OrangeTill's servers entirely, there is no pot of merchant funds to take. Your money is in your wallet, which is controlled by your seed phrase — and only you have that.
The flip side is that OrangeTill also can't help you recover funds if your wallet is compromised. That responsibility lives with you and your wallet provider.
How to actually keep your wallet safe
The overwhelming majority of crypto theft happens through one of three vectors: stolen seed phrases, phishing attacks, or malware. All three are largely preventable.
Hardware wallets — when they make sense
A hardware wallet (like a Ledger or Trezor) is a physical device that stores your private keys offline. Even if your computer is completely compromised, a hardware wallet cannot be drained without physical access to the device and your PIN.
For a merchant receiving occasional small payments, a hardware wallet is probably overkill. But if you're accumulating meaningful crypto — say, anything you'd be uncomfortable losing — a hardware wallet is worth the $80–$150 investment. You'd use it as a destination for periodic sweeps from your receiving wallet, not for day-to-day payments.
Our hardware wallets guide for merchants covers Ledger, Trezor, and Tangem in detail — when to use them, how they work, and how to set one up alongside OrangeTill.
No FDIC insurance — what that actually means
Bank deposits in the US are insured by the FDIC up to $250,000. Crypto held in a self-custody wallet has no equivalent protection — if you lose your seed phrase, or if you're successfully targeted by a sophisticated attacker, there is no government backstop.
This is a real difference from traditional banking, and it's worth being clear-eyed about. But it's worth putting in context: the FDIC insures against bank failure, not against you being robbed or losing your PIN. The practical risks for a merchant with a well-managed crypto setup are not dramatically different from the risks of keeping cash on premises — they just require different precautions.
The honest risk assessment
Crypto security risks are real but manageable. The merchants who lose crypto almost always do so through preventable mistakes — sharing seed phrases, falling for phishing scams, or keeping too much in an unprotected hot wallet. The merchants who follow basic security hygiene rarely have problems.
Use a dedicated receiving wallet. Write down your seed phrase and store it safely. Convert or sweep regularly. Don't keep more in your hot wallet than you'd keep in a cash drawer. Those four steps eliminate the vast majority of crypto security risk for a small merchant.
What is a Bitcoin wallet? — covers the basics of how wallets work, seed phrases, and which wallet to choose. Hardware wallets for merchants — when cold storage makes sense and how to set it up.
The content on this page is for informational and educational purposes only and does not constitute financial, investment, legal, or security advice. Cryptocurrency security practices evolve — always verify current best practices with your wallet provider and consult qualified professionals for advice specific to your situation. OrangeTill is a payment processing tool, not a security service.