Most Bitcoin security advice centres on wallets and private keys. But one threat that doesn't get enough attention is the public computer: the shared terminal at a hotel business centre, the library PC, the internet café machine. These devices are some of the most dangerous environments for any Bitcoin-related activity, and the danger isn't always obvious until it's too late.
Why public computers are so risky for Bitcoin
A public computer is, by definition, used by dozens or hundreds of different people. You have no idea what software is running on it, who configured it, or whether the previous user installed something malicious. Keyloggers are common on compromised public machines. A keylogger records every keystroke you type, including wallet passwords, seed phrases, and exchange login credentials. You'd never know it was running.
Beyond keyloggers, public computers often have browser extensions installed that intercept clipboard data. This matters because Bitcoin addresses are long and impossible to type from memory, so people copy and paste them. A Bitcoin clipboard hijacking attack swaps your recipient address for an attacker's address in the moment you paste, silently redirecting your funds. It's fast, invisible, and irreversible.
Session hijacking is a third risk. Even if you log out of an exchange or wallet interface, session cookies can persist on a public browser. A user who opens the same browser tab or navigates to recently visited sites may find your session still active.
What you should never do on a public computer
Some actions are simply off-limits on any shared device. These are not edge cases or unlikely scenarios. They're how real losses happen.
- Typing or pasting a seed phrase or private key into any browser field or application
- Logging into a Bitcoin exchange or custodial wallet with your real credentials
- Sending a Bitcoin transaction, even a small one, from a hot wallet
- Downloading wallet software or browser extensions onto the machine
- Saving any credentials, recovery codes, or wallet files to the local drive or desktop
The consequences of any of these actions on a compromised machine can be permanent. Bitcoin transactions can't be reversed. Once a private key is captured by a keylogger, your entire wallet is exposed indefinitely, even if you don't lose funds immediately.
What's sometimes acceptable in limited situations
Blanket avoidance isn't always practical. Sometimes you're travelling and need to check something urgently. There are a narrow range of lower-risk activities you can perform on a public machine, provided you follow strict precautions.
Checking a read-only block explorer to verify an incoming transaction is relatively low risk. You're not entering credentials or initiating any action. You're only viewing public blockchain data. Similarly, accessing a watch-only wallet interface to check a balance without signing anything doesn't expose private keys. A Bitcoin watch-only wallet is designed specifically for situations where you want visibility without control, which makes it a sensible option when you're away from your own devices.
If you must log into an email account that receives Bitcoin notifications, use a temporary session and log out immediately. Don't access any accounts linked to your exchange or wallet on that same browser session.
Practical precautions if you have no choice
If a public machine is your only option and you need to take action, a few steps can reduce (not eliminate) the risk.
Open the browser in a private or incognito window. This doesn't protect against keyloggers or malicious extensions, but it prevents session data and browsing history from persisting after you close the tab. It's a floor, not a ceiling.
Use two-factor authentication on any account you access. An authenticator app on your own phone adds a layer that a keylogger alone can't bypass, since it only captures what you type, not what appears on your phone screen. Hardware-based two-factor authentication (like a physical security key) is even stronger, but you'd need to carry it with you. Two-factor authentication is one of the most effective defences against credential theft, and it matters more on shared devices than anywhere else.
After using any public machine, change your passwords and revoke active sessions from a trusted device as soon as possible. Don't assume that logging out on the public machine was enough.
Better alternatives to public computers
Mobile data on your own phone is almost always a safer option than a public computer, even if you're using a public network. Your own device hasn't been touched by strangers, doesn't have unknown software installed, and only you know the unlock PIN. If you need to check a balance, send a small transaction, or verify an address, do it from your phone on mobile data rather than reaching for the hotel PC.
A hardware wallet also changes the equation significantly. Even if you connect to a compromised computer, a hardware wallet signs transactions internally on the device itself. Your private keys never leave the hardware. The compromised computer sees only the signed transaction, not the key that produced it. If you travel frequently with significant Bitcoin holdings, a hardware wallet is a practical security measure, not a luxury.
The real lesson from public computer risks
Public machines illustrate a wider point about Bitcoin security: the threat model isn't just about what you hold, but where you access it. A strong password, a reliable exchange, and a good wallet choice all help. None of them protect you if you enter your credentials on a machine running a keylogger.
The safest rule is simple. Treat any computer that isn't yours as compromised. Act accordingly, and save any real Bitcoin activity for a device you control.

