• bitcoinBitcoin (BTC) $ 73,392.00
  • ethereumEthereum (ETH) $ 2,016.88
  • tetherTether (USDT) $ 0.998536
  • bnbBNB (BNB) $ 639.59
  • xrpXRP (XRP) $ 1.32
  • usd-coinUSDC (USDC) $ 0.999627
  • solanaSolana (SOL) $ 82.28
  • tronTRON (TRX) $ 0.352216
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.099790
  • hyperliquidHyperliquid (HYPE) $ 60.52
  • usdsUSDS (USDS) $ 0.999621
  • leo-tokenLEO Token (LEO) $ 10.02
  • zcashZcash (ZEC) $ 554.25
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • rainRain (RAIN) $ 0.014308
  • cardanoCardano (ADA) $ 0.234510
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.201061
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 352.10
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.00
  • whitebitWhiteBIT Coin (WBT) $ 53.98
  • bitcoin-cashBitcoin Cash (BCH) $ 300.51
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • canton-networkCanton (CC) $ 0.154361
  • the-open-networkToncoin (TON) $ 1.77
  • usd1-wlfiUSD1 (USD1) $ 0.997991
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998895
  • daiDai (DAI) $ 0.999637
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • litecoinLitecoin (LTC) $ 51.80
  • memecoreMemeCore (M) $ 2.96
  • hedera-hashgraphHedera (HBAR) $ 0.088590
  • wethWETH (WETH) $ 2,268.37
  • avalanche-2Avalanche (AVAX) $ 8.92
  • suiSui (SUI) $ 0.930290
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999754
  • nearNEAR Protocol (NEAR) $ 2.41
  • crypto-com-chainCronos (CRO) $ 0.067248
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • tether-goldTether Gold (XAUT) $ 4,479.60
  • global-dollarGlobal Dollar (USDG) $ 0.999759
  • bittensorBittensor (TAO) $ 262.67
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • pax-goldPAX Gold (PAXG) $ 4,485.76
  • mantleMantle (MNT) $ 0.628261
  • polkadotPolkadot (DOT) $ 1.22
  • uniswapUniswap (UNI) $ 3.05
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.059361
  • okbOKB (OKB) $ 87.24
  • ondo-financeOndo (ONDO) $ 0.371064
  • aster-2Aster (ASTER) $ 0.674806
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • ripple-usdRipple USD (RLUSD) $ 0.999810
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • falcon-financeFalcon USD (USDF) $ 0.994507
  • pi-networkPi Network (PI) $ 0.145944
  • internet-computerInternet Computer (ICP) $ 2.78
  • skySky (SKY) $ 0.065578
  • pepePepe (PEPE) $ 0.000003
  • usddUSDD (USDD) $ 0.998589
  • bitget-tokenBitget Token (BGB) $ 1.99
  • bfusdBFUSD (BFUSD) $ 0.998177
  • morphoMorpho (MORPHO) $ 2.06
  • ethereum-classicEthereum Classic (ETC) $ 8.31
  • aaveAave (AAVE) $ 81.04
  • united-stablesUnited Stables (U) $ 0.999810
  • usdtbUSDtb (USDTB) $ 0.998873
  • kucoin-sharesKuCoin (KCS) $ 7.86
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 72.71
  • cosmosCosmos Hub (ATOM) $ 2.03
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • render-tokenRender (RENDER) $ 1.99
  • algorandAlgorand (ALGO) $ 0.109824
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.16
  • worldcoin-wldWorldcoin (WLD) $ 0.284812
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.087674
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.10
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • stable-2​​Stable (STABLE) $ 0.037648
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kaspaKaspa (KAS) $ 0.030915
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • nexoNEXO (NEXO) $ 0.823558
  • justJUST (JST) $ 0.093610
  • wbnbWrapped BNB (WBNB) $ 759.61
  • ethenaEthena (ENA) $ 0.088317
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • dexeDeXe (DEXE) $ 16.95
  • aptosAptos (APT) $ 0.940489
  • filecoinFilecoin (FIL) $ 0.964050
  • venice-tokenVenice Token (VVV) $ 16.40
  • gatechain-tokenGate (GT) $ 6.80
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007856
  • arbitrumArbitrum (ARB) $ 0.105027
  • xdce-crowd-saleXDC Network (XDC) $ 0.031788
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • midnight-3Midnight (NIGHT) $ 0.036437
  • pump-funPump.fun (PUMP) $ 0.001716
  • beldexBeldex (BDX) $ 0.077690
  • jupiter-exchange-solanaJupiter (JUP) $ 0.176318
  • ghoGHO (GHO) $ 0.998742
  • hash-2Provenance Blockchain (HASH) $ 0.010365
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.998503
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • injective-protocolInjective (INJ) $ 5.49
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • apxusdapxUSD (APXUSD) $ 0.999268
  • ousgOUSG (OUSG) $ 115.38
  • a7a5A7A5 (A7A5) $ 0.013288
  • clbtcclBTC (CLBTC) $ 76,920.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.229739
  • vechainVeChain (VET) $ 0.005955
  • dashDash (DASH) $ 40.23
  • yldsYLDS (YLDS) $ 0.999663
  • usxUSX (USX) $ 0.999255
  • true-usdTrueUSD (TUSD) $ 0.998103
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007791
  • unibaseUnibase (UB) $ 0.192293
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • edgexedgeX (EDGE) $ 1.37
  • tbtctBTC (TBTC) $ 70,942.00
  • bonkBonk (BONK) $ 0.000005
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • humanityHumanity (H) $ 0.260363
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.718369
  • sei-networkSei (SEI) $ 0.069753
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000082
  • kite-2Kite (KITE) $ 0.201323
  • official-trumpOfficial Trump (TRUMP) $ 1.89
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.35
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.435346
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • euro-coinEURC (EURC) $ 1.16
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • blockstackStacks (STX) $ 0.230561
  • adi-tokenADI (ADI) $ 3.79
  • aerodrome-financeAerodrome Finance (AERO) $ 0.412140
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • celestiaCelestia (TIA) $ 0.419538
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • hastra-primePRIME (PRIME) $ 1.04
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997714
  • chilizChiliz (CHZ) $ 0.035002
  • sun-tokenSun Token (SUN) $ 0.018596
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • labLAB (LAB) $ 4.69
  • ether-fiEther.fi (ETHFI) $ 0.391081
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kinesis-goldKinesis Gold (KAU) $ 142.78
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • tezosTezos (XTZ) $ 0.310413
  • siren-2Siren (SIREN) $ 0.458826
  • usdgoUSDGO (USDGO) $ 0.999993
  • curve-dao-tokenCurve DAO (CRV) $ 0.211405
  • doublezeroDoubleZero (2Z) $ 0.089587
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • bittorrentBitTorrent (BTT) $ 0.00000031
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • pyth-networkPyth Network (PYTH) $ 0.039015
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • the9bitThe9bit (9BIT) $ 0.037117
  • spx6900SPX6900 (SPX) $ 0.325780
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • gnosisGnosis (GNO) $ 113.89
  • grassGrass (GRASS) $ 0.485455
  • usdaiUSDai (USDAI) $ 0.999555
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • kaiaKaia (KAIA) $ 0.049028
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • lighterLighter (LIT) $ 1.15
  • the-graphThe Graph (GRT) $ 0.026364
  • decredDecred (DCR) $ 16.35
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • kinesis-silverKinesis Silver (KAG) $ 75.33
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Jameson Lopp: Self-custody is essential to avoid third-party risks, phishing attacks are the biggest threat, and a three-wallet system can enhance security | Bankless

0 3


Key takeaways

  • Self-custody in crypto is crucial to avoid reliance on third parties, which pose significant risks.
  • Privacy acts as the first line of defense in crypto security, preventing further attacks.
  • Physical attacks on crypto holders are increasing, highlighting the need for enhanced security measures.
  • Trusted third parties remain the primary threat to crypto holders, overshadowing smart contract risks.
  • Economic pressures on crypto companies may reduce the frequency of smart contract audits, increasing investor risk.
  • Phishing attacks are the most common threat to individuals managing their own crypto assets.
  • Digital security must be prioritized to counteract the high probability of phishing attacks.
  • Scammers impersonate reputable brands to trick users into granting permissions, leading to asset theft.
  • Physical threats, including home invasions, are a significant risk for crypto holders.
  • Malware targeting devices that secure private keys poses a major threat to wallet security.
  • Social engineering is a common tactic in phishing attacks, emphasizing the need for user awareness.
  • A three-wallet system is recommended for managing risk in crypto transactions.

Guest intro

Jameson Lopp is Co-Founder and CTO of Casa, a Bitcoin security company specializing in key management solutions. He previously worked at BitGo, where he enhanced multisignature security services that now secure 20% of all Bitcoin transactions. Lopp also created Statoshi, a platform monitoring the Bitcoin network for attacks.

The threat of third-party reliance in crypto

  • “The biggest threat to crypto natives is reliance on trusted third parties and not taking custody of their own assets.” – Jameson Lopp
  • Self-custody is emphasized as a critical security measure to mitigate risks.
  • “Privacy is the outermost layer of security in the crypto space.” – Jameson Lopp
  • Physical attacks on crypto holders are gaining attention, highlighting a new security concern.
  • “The primary threat to crypto holders comes from trusted third parties rather than novel smart contracts or branch attacks.” – Jameson Lopp
  • Economic pressures may lead to fewer smart contract audits, increasing risks for investors.
  • Phishing attacks are the most probable threat for individuals managing their own crypto assets.
  • Digital security should be prioritized to protect against common threats in crypto.

The rise of physical and digital threats

  • “Scammers often impersonate reputable brands to trick users into granting permissions that allow them to steal assets.” – Jameson Lopp
  • The most dangerous course of action involves potential physical threats to individuals and their families.
  • Attackers often use malware to compromise devices that secure private keys, leading to potential wallet theft.
  • “Almost all phishing attempts involve elements of social engineering.” – Jameson Lopp
  • Combating digital threats in crypto requires simplicity and minimizing attack surfaces.
  • Users should segregate their crypto wallets based on the amount of funds and risk involved.
  • Avoiding on-chain activities entirely may not be the best solution to mitigate risks.

Managing crypto security through wallet strategies

  • “A three-wallet system can help manage risk in crypto transactions.” – Jameson Lopp
  • Simply owning an ETF instead of participating in crypto activities defeats the purpose of owning digital assets.
  • Properly managing private keys and seed phrases can significantly reduce the risk of losing crypto assets.
  • Users should avoid keeping all their crypto assets in one wallet to mitigate risks.
  • A good wallet segmentation approach involves using a hot wallet for small amounts and a cold wallet for larger holdings.
  • Social engineering is the most common form of attack against crypto holders today.

The importance of self-custody and security measures

  • “Individuals must recognize the responsibility that comes with taking custody of their crypto assets.” – Jameson Lopp
  • Operating a crypto wallet requires peak cognitive condition to avoid costly mistakes.
  • Transactions involving on-chain assets should never be rushed, especially under emotional stress.
  • Most communication channels lack authentication, making them vulnerable to impersonation.
  • “I don’t trust any incoming message that seems fishy.” – Jameson Lopp
  • Using shared insider knowledge for authentication is more reliable than random words.

Enhancing security with physical and digital measures

  • “It’s safer to log in directly to websites rather than clicking on links in messages.” – Jameson Lopp
  • Password managers protect users from various types of phishing attacks by ensuring credentials are only autofilled on legitimate websites.
  • Investing in a hardware security key like a YubiKey is a wise decision for anyone involved in crypto.
  • SMS for two-factor authentication is highly insecure and should not be used.
  • Yubikeys provide superior security for two-factor authentication by storing secrets on the hardware device itself.
  • Email accounts are the most critical aspect of most people’s digital lives.

Addressing privacy vulnerabilities in the digital age

  • “Investing in security measures like passkeys and YubiKeys will become essential for everyone in the future.” – Jameson Lopp
  • The goal of security is to have better defenses than potential attackers.
  • Using a separate machine for signing crypto transactions is a foolproof method to enhance security.
  • The number of violent in-person attacks targeting individuals with digital assets is increasing.
  • Attackers are identifying potential targets by monitoring their digital presence and wealth indicators.
  • The digital age has created significant privacy vulnerabilities for individuals.

Organized crime and cross-border threats

  • “Attacks on crypto figures often involve kidnapping for ransom.” – Jameson Lopp
  • Dubai has the highest rate of rich attacks due to high-value face-to-face OTC trades.
  • Corruption within tax authorities can lead to the exposure of individuals with crypto assets to organized crime.
  • Organized crime often involves a remote mastermind who coordinates with local criminals.
  • Organized crime is leveraging cross-border jurisdictional arbitrage to conduct attacks on crypto holders.
  • Attackers can easily pinpoint a victim’s physical address through various data leaks.

Preventing physical and digital security breaches

  • “Preventing oneself from becoming a target is crucial in mitigating risks associated with physical home invasion attacks.” – Jameson Lopp
  • Rich attacks can occur even when assets are held with custodians, not just in self-custody.
  • Ransom attackers have a greater than 50% success rate and are able to steal tens of millions of dollars annually.
  • To prevent a wrench attack, one must eliminate themselves as a single point of failure in their security setup.
  • A distributed key system enhances security by using multiple hardware devices from different manufacturers.
  • Public permissionless networks can achieve security models that surpass traditional institutions like banks or Fort Knox.

The role of multisig and decentralized security

  • “Using air-gapped devices like ledgers and treasures is crucial for protecting crypto keys from online attacks.” – Jameson Lopp
  • The biggest risks in self-custody are not from hackers but from mistakes and environmental failures.
  • Multisig setups provide flexibility and redundancy in key management, reducing the risk of catastrophic failure.
  • Decisions about key distribution in crypto involve trade-offs between convenience and security.
  • Distributing keys across various locations enhances security but can be inconvenient.
  • Physical safeguards and multi-signature setups are crucial in preventing successful wrench attacks.

The future of self-custody and financial sovereignty

  • “Vitalik Buterin’s multisig setup incorporates a social recovery mechanism to enhance security.” – Jameson Lopp
  • If the success rate of attacks drops significantly, attackers will find it less profitable to conduct home invasions.
  • Becoming a hard target is crucial for personal security.
  • Reinforcing home security can significantly delay unauthorized entry.
  • Most American home construction uses inadequate materials for security.
  • Home defense requires a strategic approach to weapon accessibility and safety.

Enhancing privacy and security in crypto transactions

  • “To enhance on-chain privacy, it’s important to use new wallets funded from different exchanges than those used for previous wallets.” – Jameson Lopp
  • Using mixers for privacy can lead to compliance risks and unwanted associations.
  • For strong privacy, it’s better to use crypto designed with privacy features at the protocol level.
  • Privacy in the crypto industry is currently inadequate and poses significant risks.
  • Using exchange API keys in tax software can lead to security vulnerabilities.
  • The responsibility of managing private keys can feel overwhelming and may deter some from self-custody.

Balancing convenience and security in self-custody

  • “Self-custodial crypto may still be the end game despite current setbacks.” – Jameson Lopp
  • Self-custody in crypto empowers individuals by allowing them to take control of their finances without relying on external authorities.
  • Human nature tends to favor convenience, which complicates the adoption of self-custody in finance.
  • Self-custody in crypto must be made more convenient to prevent users from outsourcing their control to third parties.
  • Empowering individuals through public permissionless protocols is essential for achieving financial sovereignty.



Source link

Leave A Reply

Your email address will not be published.