Security

Crypto Security Reference: Documented Threats and What Actually Protects You

Crypto security threats are documented. Here's a reference for what actually protects against them.

On this page 21 sections
  1. 1 The major threat categories
  2. 2 Phishing attacks specifically
  3. 3 What protects against phishing
  4. 4 Malware attacks specifically
  5. 5 What protects against malware
  6. 6 Smart contract exploits specifically
  7. 7 What protects against smart contract exploits
  8. 8 Bridge attacks specifically
  9. 9 What protects against bridge attacks
  10. 10 Exchange compromises specifically
  11. 11 What protects against exchange compromises
  12. 12 Social engineering specifically
  13. 13 What protects against social engineering
  14. 14 Physical attacks specifically
  15. 15 What protects against physical attacks
  16. 16 The substantive security mindset
  17. 17 Common security failures
  18. 18 Security tool recommendations
  19. 19 What this cheat sheet doesn't cover
  20. 20 What I recommend
  21. 21 The honest takeaway

Crypto security threats are well-documented. Substantial losses occur regularly through specific attack patterns. Understanding the threats and what actually protects against them substantially improves security beyond promotional content. This reference covers documented threat patterns and substantive protective measures.

The major threat categories

Crypto security threats fall into specific categories:

Phishing attacks: deceptive sites and communications tricking users into providing keys or signing malicious transactions.

Malware attacks: software stealing keys, modifying transactions, or otherwise compromising users.

Smart contract exploits: bugs or design issues in smart contracts allowing fund extraction.

Bridge attacks: cross-chain bridges with security issues allowing fund extraction.

Exchange compromises: exchanges losing funds through hacks or insolvencies.

Social engineering: manipulation tricking users into voluntary fund transfer or key disclosure.

Physical attacks: theft, coercion, or other physical means.

Insider threats: people with legitimate access using it maliciously.

Different threats require different protections.

Phishing attacks specifically

Phishing is among most common attack patterns:

Fake exchange or wallet websites tricking users into entering credentials.

Fake support representatives asking for seed phrases or private keys.

Fake airdrop sites requiring wallet connection.

Fake DeFi interfaces tricking users into approving malicious transactions.

Fake browser extensions impersonating legitimate ones.

Email and social media impersonation campaigns.

Phishing produces substantial documented losses across substantial victim population.

What protects against phishing

Specific protections against phishing:

Always navigate to sites manually rather than clicking links.

Verify URLs carefully — phishing URLs often look similar to real ones.

Bookmark legitimate sites for direct access.

Use hardware wallet that displays transaction details for verification.

Be suspicious of unsolicited communications about your accounts.

Verify support contact methods through official sources only.

Don't share seed phrases or private keys with anyone, ever.

Recognize that legitimate support never asks for seed phrases.

Awareness substantially reduces phishing success.

Malware attacks specifically

Malware attacks include:

Clipboard malware replacing copied addresses with attacker addresses.

Keyloggers capturing entered passwords and seed phrases.

Cryptojacking using your computer for mining.

Specific crypto-stealing malware targeting wallet files.

Mobile malware targeting mobile wallet apps.

Browser extension malware accessing browser-based wallets.

Malware produces substantial documented losses.

What protects against malware

Specific protections:

Use hardware wallet — keys never on connected computer.

Always verify addresses on hardware wallet screen.

Maintain updated antivirus and operating system.

Use dedicated device for substantial crypto holdings.

Avoid pirated software and unknown downloads.

Specific browser security extensions help.

Mobile: install only from official app stores; verify legitimate apps.

Hardware wallet substantially mitigates many malware risks.

Smart contract exploits specifically

Smart contract exploits include:

Reentrancy attacks (specific class of vulnerabilities).

Logic errors in contract code.

Oracle manipulation affecting contract calculations.

Flash loan attacks combining multiple operations.

Governance attacks through token accumulation.

Exit scams by malicious developers.

Smart contract exploits produce substantial documented losses across DeFi.

What protects against smart contract exploits

Specific protections:

Use established protocols with substantial audit history.

Avoid new unaudited protocols regardless of attractive yields.

Diversify across protocols rather than concentrating in single protocol.

Pay attention to protocol security incidents and respond promptly.

Limit token approvals to specific amounts rather than unlimited.

Revoke unused token approvals periodically (specific tools help).

Recognize that "high yield" often correlates with elevated risk.

Smart contract risk is inherent in DeFi participation; protection is about managing rather than eliminating it.

Bridge attacks specifically

Bridge attacks have produced substantial documented losses:

Specific bridges have lost hundreds of millions of dollars in specific incidents.

Validator compromise affects bridge security models.

Specific bridge implementations have specific vulnerabilities.

Cross-chain transactions inherit security of bridge plus both chains.

Substantial caution warranted for cross-chain activities.

What protects against bridge attacks

Specific protections:

Use bridges with substantial security history.

Limit amounts crossing bridges to acceptable risk levels.

Avoid keeping substantial assets in bridge-wrapped tokens long-term.

Stay informed about bridge security incidents.

Consider whether cross-chain activity is necessary for your specific use case.

Bridge attacks are substantial risk specifically for cross-chain activities.

Exchange compromises specifically

Exchange compromises take various forms:

Hot wallet hacks where exchange security is compromised.

Insider theft by employees with access.

Operational failures producing fund losses.

Insolvencies (FTX, Celsius, others).

Regulatory actions freezing user funds.

Geographic restrictions affecting access.

Substantial documented losses across crypto exchange history.

What protects against exchange compromises

Specific protections:

"Not your keys, not your coins" — keep substantial holdings in self-custody.

Use exchanges only for specific necessary activities (trading, on-ramping).

Withdraw promptly after transactions.

Spread risk across multiple exchanges if substantial exchange holdings necessary.

Use established exchanges with substantial security history.

Pay attention to exchange financial health and regulatory status.

Substantial holdings warrant self-custody despite convenience cost.

Social engineering specifically

Social engineering attacks include:

Romance scams developing relationships before requesting crypto.

Fake investment opportunities presented through trusted-seeming sources.

Fake support representatives reaching out to "help."

Pressure tactics creating urgency.

Authority impersonation (claimed law enforcement, regulators, others).

Family member impersonation.

Social engineering produces substantial documented losses.

What protects against social engineering

Specific protections:

Skepticism toward unsolicited communications.

Verify identities through known channels separately.

Don't respond to urgency pressure — legitimate matters allow time for verification.

Recognize that legitimate authorities don't typically request crypto payments.

Discuss substantial transactions with trusted people before executing.

Maintain awareness of common scam patterns.

Substantial losses from social engineering are largely preventable through awareness.

Physical attacks specifically

Physical attack patterns include:

Robbery of devices and cash.

"$5 wrench attack" — coercion to transfer assets.

Burglary targeting hardware wallets and seed phrase backups.

Specific kidnapping cases targeting crypto holders.

Specific patterns emerging in physical security incidents.

What protects against physical attacks

Specific protections:

Operational security — don't advertise substantial crypto holdings.

Distributed seed phrase storage in multiple secure locations.

Specific decoy wallets containing small amounts for coercion scenarios.

Physical security for hardware wallets and backups.

Substantial holdings warrant substantial physical security.

Multi-signature setups reduce single-point-of-physical-failure.

Privacy is part of physical security for substantial holdings.

The substantive security mindset

Substantive crypto security requires:

Treating security as ongoing practice rather than one-time setup.

Understanding that perfect security is impossible — managing rather than eliminating risk.

Matching security level to actual stakes.

Maintaining awareness of evolving threats.

Substantive practice over substantial time builds capability.

The mindset matters as much as specific tools.

Common security failures

Patterns producing substantial losses:

Storing seed phrase digitally.

Using same password across services.

Keeping substantial holdings on exchanges.

Trusting unsolicited communications.

Approving unlimited token allowances.

Using unfamiliar protocols without due diligence.

Falling for pressure tactics.

Not maintaining backup systems.

Insufficient operational security around substantial holdings.

Awareness of common failures supports avoiding them.

Security tool recommendations

Specific tools that help:

Hardware wallets (Ledger, Trezor, Coldcard, others) for substantial holdings.

Password managers for unique strong passwords.

Two-factor authentication (preferring hardware tokens or authenticator apps over SMS).

Specific browser security extensions.

Address book features for verified addresses.

Specific revocation tools for token approval management.

Tools support security but don't replace substantive security practices.

What this cheat sheet doesn't cover

The cheat sheet doesn't cover:

Specific implementation details for advanced security setups.

Operational security for high-profile or high-risk individuals.

Specific incident response procedures.

Detailed forensics for compromise investigation.

Substantive guidance for specific advanced situations requires more detailed material.

What I recommend

For substantive crypto security:

Match security level to stakes.

Use hardware wallet for substantial holdings.

Maintain substantial seed phrase security.

Stay informed about evolving threats.

Maintain skepticism about unsolicited communications.

Practice substantive operational security.

Treat security as ongoing rather than one-time activity.

Substantial holdings warrant substantial security investment.

The honest takeaway

Crypto security threats are well-documented across multiple categories.

Substantial losses occur regularly through specific attack patterns.

Specific protections exist for each threat category.

Substantive security practices substantially reduce avoidable losses.

Perfect security is impossible; managing risk is achievable.

Substantive understanding produces better protection than promotional content provides.

The space evolves continuously — continued attention warrants continuing.

For substantive crypto participation: substantive security is part of the practice.

For everyone: documented threats and documented protections support informed decisions.

That's the security reference. Specific situations warrant specific deeper analysis.