Live · Sun, Aug 23, 2026 · 09:01 UTC Block 843,917 Fees 14 sat/vB Fear & Greed 72 · Greed
Newsletter Pro Terminal Sign in
McLeod Pacific Investments.
Subscribe →
Live · 09:01 UTC Block 843,917 F&G 72
Bitcoin Security Bitcoin Security desk

How to safely use public computers for Bitcoin

Public computers at libraries, hotels, and internet cafés are some of the most dangerous environments for Bitcoin activity. Here's what you need to know to stay safe when you have no other choice.

A row of computer workstations in a modern library in Wrocław, Poland, emphasizing technology and learning.

Photo by SHOX ART on Pexels

Public computers are everywhere. Hotel business centres, airport lounges, libraries, internet cafés. Most of the time, avoiding them for Bitcoin activity is the right call. But "most of the time" isn't always. If you're travelling and your phone dies, or you're locked out of your device and need to check a wallet address, you may find yourself sitting at a shared machine with no alternative. Knowing what to do in that moment is what keeps your funds safe.

Why public computers are so dangerous for Bitcoin

The core problem with shared computers is that you have no idea what software is running on them. Keyloggers are the most common threat: small programs that record every keystroke, capturing passwords, seed phrases, and private keys as you type. You won't see them. They leave no obvious trace. A keylogger installed on a public terminal can silently forward your credentials to an attacker within seconds of you typing them.

Beyond keyloggers, public computers may run outdated browsers with unpatched vulnerabilities, or have browser extensions installed that intercept clipboard content. That last point matters a lot for Bitcoin users. If you copy a wallet address on a compromised machine, a malicious extension can swap it for the attacker's address before you paste it. This is exactly how Bitcoin clipboard hijacking attacks work, and shared computers are prime territory for them.

Browsers also save form data, passwords, and session cookies by default. Log into an exchange on a public machine without clearing that data, and the next user may be able to resume your session.

What you should never do on a public computer

Some actions carry so much risk that no precaution makes them acceptable on shared hardware. Avoid these completely:

  • Typing or pasting your seed phrase for any reason
  • Logging into an exchange or web wallet that holds significant funds
  • Entering a private key directly into any browser field
  • Installing browser extensions or software, even temporarily

Your seed phrase is the one thing an attacker needs to drain your wallet permanently. No legitimate reason exists to type it on a machine you don't control. If you're in a situation where you think you need to, stop and find another way. McLeod Pacific Investments strongly advises treating seed phrase entry as a hardware-wallet-only action, done on a device you own, in a private setting.

What you can do, with care

Lower-risk tasks are sometimes acceptable on public machines, provided you take the right steps. Checking a Bitcoin address to confirm funds arrived, for example, requires no login and no sensitive input. You're only reading the blockchain, not signing anything.

If you must log into an account, use accounts with minimal funds and treat those credentials as compromised after the session. Change the password from a trusted device immediately. Enable two-factor authentication before you travel so that a captured password alone isn't enough to access your account. An authenticator app (not SMS) is the right tool here. Read more on why that distinction matters in our guide to what two-factor authentication is and why it matters.

Always open a private or incognito browsing window before you start. This doesn't protect you from keyloggers, but it does prevent the browser from saving your session, cookies, and form data after you close the window. Log out explicitly when you're done. Don't just close the tab.

How to reduce exposure when you have no choice

A few practical steps can limit the damage if you're forced to use shared hardware:

First, check whether the machine allows you to boot from a USB drive. A live operating system like Tails runs entirely in memory, leaves nothing on the host machine, and bypasses any software installed on the computer's hard drive. It's the closest thing to a clean environment on untrusted hardware. Carry a Tails USB if you travel frequently and expect to need Bitcoin access.

Second, use your phone as a hotspot and work on a device you control, even if that device is someone else's personal laptop rather than a library terminal. Personal devices are far less likely to carry keyloggers than machines with unrestricted public access.

Third, consider using a read-only watch wallet on public machines. A watch wallet lets you check balances and generate receiving addresses without ever exposing a private key. Apps like Electrum support this. You configure the wallet with your public key only, and the machine never sees anything that can move funds.

After using a public computer

Assume the machine was compromised. That's not paranoia. It's the correct default assumption. After your session, take these steps from a trusted device:

Change any password you typed. Revoke any active sessions in your exchange account's security settings. Check your transaction history for any unexpected activity. If you have any reason to believe you entered a sensitive phrase or key, move your funds to a new wallet immediately using a device you control.

Good Bitcoin security isn't only about hardware wallets and seed phrase storage. It's also about recognising dangerous environments before you interact with them. Public computers are one of those environments. Keeping your Bitcoin security checklist up to date includes knowing which actions are off-limits away from home, and building habits that hold up even when you're tired, rushed, or far from your usual setup.

The safest rule is a simple one: if you wouldn't hand a stranger your wallet password, don't type it on their computer.

→ The Confirmations · Daily newsletter

One email at 06:00 UTC. Six minutes. The only digest written for desks, not for retail.