The first hour
Create a separate spending wallet with its own recovery phrase and move anything not actively traded to a storage wallet. Review and revoke token approvals on every chain you have used. Verify your recovery phrase backup exists on durable media and is not a photograph.
Then create a bookmark for every crypto site you use, reached from an address you verified, and use only those bookmarks from now on.
The second hour
Move email and exchange accounts off SMS second factors onto an authenticator app or a hardware key. Add a carrier port-out PIN. Audit browser extensions and remove anything unused. Update your operating system, browser and wallet applications.
Test a wallet restore into a clean installation and confirm the first address matches, then remove that installation.
Ongoing habits
Read every wallet prompt: token, spender, amount, network. Send a small test transfer before any first transfer to a new destination. Never copy an address from transaction history. Never enter a recovery phrase anywhere except a wallet you are restoring.
Assume anyone who contacts you first is not who they claim to be, including anyone using the FBT Swap name.
What this does not cover
None of this protects against a protocol exploit, a bridge hack or a token whose team decides to leave. Those are risks of what you own, not of how you hold it, and they require diligence on each specific asset.
FBT Swap is non-custodial: it holds nothing, so it cannot freeze, reverse or recover anything. That is the trade this checklist exists to make survivable.