francesco Profile picture
Aug 7 77 tweets 20 min read Twitter logo Read on Twitter
What do crypto and an old Windows have in common?
Both are a Minefield 💣

You are always 1-2 clicks away from losing your life savings.

The Ultimate Crypto Survival Guide: How to Step up Your Wallet Security

🔐 ⬇️ Image
1/72

Navigating the crypto ecosystem is increasingly complex 🚨

Every day scammers find new ways to circumvent security measures and attempt to take control of your assets.

This is not even about naivety, a mere moment of distraction, and BOOM, your life savings are gone.
2/72

This can happen in so many ways:

• Clicking a wrong link

• Clicking a wrong Google ad

• Joining an unofficial Discord group

• Interacting with an imposter on Telegram

• Accessing a malicious website
3/72

Perhaps a hacked friend sends you a seemingly innocuous Google Doc on something you working on… 😔

Even the biggest NFTs projects are not immune: their Discord could get compromised and share malicious links, leading you into traps.
4/72

This is a major barrier to entry for new users ⛔

Imagine sharing with your friends interested in crypto that a simple misclick on a Google ad can cost someone 300k+ in NFTs.

Crypto is a tough sell.
6/72

There are a couple more factors that have to be taken into consideration:

1. The majority of users overlook essential security practices

2. Scammers evolve more rapidly than security tools
7/72

Regrettably, tools like Metamask have been very slow to step up the security of their wallet, despite leading the market for years 🦊

While scammers advance, our security often lags.
8/72

But the tools that can help us are out there, it’s just a matter of not being lazy and stepping up our security 💪

We always see scams as something we would never fall into.

Until we do.

😩
9/72

So.. What can we do to protect ourselves? 🛡️

Here are some steps we can take to step up our security:

1. Invest in a hardware cold wallet

2. Get rid of Metamask for Rabby

3. Install Wallet Security Extensions

4. Periodically revoke Contract Approvals
10/72

Before diving in, remember that your security level depends on your threat model and which adversary you are up against.
11/72

Get a Hardware Wallet 🔑

It’s astonishing how many degens store excessive amounts on software wallets like Metamask 🦊

This effectively means that you are always 1-2 clicks away from losing it all. Image
12/72

A hardware wallet can cost anywhere between 90/400€, including the most complex ones.

If you are invested even a couple of thousands in crypto, getting one is a prudent move.
13/72

Ledger isn’t your only option out there — lots of startups are crafting more privacy-focused hardware wallets, such as the @gridplus Lattice or the @BitLox Ultimate. Image
14/72

Hardware wallets add an extra level of protection as you need your physical wallet to confirm every transaction carried out.

But in itself, hardware wallets won’t save you from getting scammed 🙅
15/72

They can though save you from impulse-clicking links, but if you link your wallet and approve a transaction, your funds are vulnerable.

Always check what are you signing.
16/72

This brings us back to the screenshot of the hack at the beginning of this article, where the victim claims that ⬇️ Image
17/72

Well, this is simply not true. One way or another, he did connect the wallet and confirmed and signed the transaction.

18/72

However, hardware wallets are not the holy grail of security.

It is important to add that not a single hardware cold wallet at the moment is fully Open-Sourced - not even Trezor, Ledger, and the ones cited above.
19/72

Also, if you go to their websites you can see that they are one of these companies that does not consider the bug-bounty report "in scope" if you have physical access to the device ( @officer_cia )
20/72

This is a worrisome aspect since Trezor ”serves as the basis for many hardware wallet clones out there, but it also has no physical security which is why there are numerous key recovery services you can reach out to for extraction if you own one”.
21/72

In fact, companies like Trezor and Ledger have faced recent criticism:

Ledger acknowledged its ability to extract a user's private key via a firmware upgrade. Image
22/72

This emerged after a user commented about the launch of their new product: Ledger Recovery.
23/72

On the other hand, a security company @uncipheredLLC has shown that it is very well possible to physically hack into a Trezor wallet. Image
24/72

There’s also another video online with a user being able to recover funds by hacking a Trezor:

25/72

Some more articles on hacked hardware wallets:
( sourced from a list from @officer_cia )



• https://t.co/NtlZ7wKGiL

• https://t.co/bpXz472FQF

• https://t.co/sNU7B3jmZK

• https://t.co/uQ74s3091t

• https://t.co/sFoi3A4G3Fkaspersky.com/blog/hardware-…
adatainment.com/index.php
ieeexplore.ieee.org/document/92847…
cossacklabs.com/blog/crypto-wa…
cipherblade.com/blog/list-of-b…
graph.org/All-known-smar…
26/72

• https://t.co/jWKsCR7M07

• https://t.co/2mhjP595sR https://t.co/2mhjP595sR

• https://t.co/6i0ADZOuz4 https://t.co/b9w6UuiAxk

• https://t.co/5qFi918cO6

• https://t.co/SaTYmX0G1uarxiv.org/pdf/2108.14004…
arxiv.org/pdf/2108.14004…
bloom.co/blog/6-ways-a-…
bloom.co/blog/6-ways-a-…
phishfort.com/blog/web3-phis…
phishfort.com/blog/web3-phis…
arxiv.org/pdf/2204.01487…
arxiv.org/pdf/2111.08893…
27/72

Well - hardware wallets are not perfect.

If you decide to purchase a hardware wallet, always buy them directly from manufacturers.

Avoid Amazon or eBay since these devices might be tampered with 🙅

Nonetheless getting a hardware wallet is an improvement.
28/72

What’s even more important is to organize wallets by function, and maintain separate COLD 🧊 and HOT 🔥 wallets. Image
29/72

This distinction is pretty straightforward: never use your cold wallet for casual work 👍

➡️ Be a degen on your hot wallet
➡️ Safely send your funds over to your cold wallet.
30/72

Among the possible improvements to this OpSec, it would be nice, for instance, to include warnings and descriptions on the transaction you are signing, which brings us to the next point.
31/72

From Foxes to Rabbits 🐇

If you are still using Metamask, you either like being hacked or you haven’t checked Twitter for the last few years. Image
32/72

This is one of those “Game of Thrones” situations where everyone just keeps telling you to check it out!!!!

I eventually downloaded Rabby after a bit of peer pressure AND now I get it 😳
33/72

Why is everyone obsessed with @Rabby_io ? 🤯

Rabby is a wallet extension, developed by the Debank team.
34/72

While technically similar to Metamask, it is greatly improved with regard to:

• UX
• Security Warnings for Users
• In-app Swaps
• Multichain Portfolio Tracker
• In-app Revoke
35/72

Our King @monosarin here sums up some of the main differences: Image
36/72

By using its own RPCs Rabby does not share your information with third parties providers such as Infure - contrary to what Metamask does.
37/72

This also means that Rabby automatically switches across all supported networks, as well as having waaay fewer RPC issues - especially on new networks.
38/72

Rabby’s privacy policy is also better than Metamask:

https://t.co/XG1ER8TynGrabby.io/docs/privacy/
Image
39/72

But more importantly, Rabby brings about a couple of security-focused improvements:

1️⃣ You can revoke contracts directly in-wallet by simply clicking on approvals on the wallet homepage: Image
40/72

It then opens a page showing you all the contracts you have ever approved with your address, which you can also sort by token.

Similarly to Revoke Cash you can then select all of them and revoke permission. Image
41/72

2️⃣ Every time you connect to a new contract or have to sign a transaction Rabby gives you an explanation of what you are about to sign, as well as showing you a graphical warning to inform you of the related risks. Image
42/72

At the last moment, you may realize that the contract you are about to sign might be compromised, and might steal your funds.

Last minute save. Image
43/72

3️⃣ Every new wallet created on Rabby has a new seed phrase. On the other hand, every time you create a new account on Metamask it is derived from the same seed phrase as the others.
44/72

But surely Rabby itself is not enough to save you from everything.

Consider pairing it with a supportive browser extension.
45/72

Browser Extensions 🌐

Browser extensions won’t make you more secure. Their main purpose is to help you understand what you are signing and alert you of malicious transactions.

46/72

Here are a few of the most known ones:

1️⃣ @PocketUniverseZ Image
47/72

The differentiating element of Pocket Universe is that they simulate every transaction and signature and show you its outcome before sending it through your wallet. Image
48/72

What’s cool about Pocket Universe is that they also offer Insurance of up to $2000 on funds lost to scams that they don’t warn you about!

For more information on the insurance, you can refer to the Pocket Universe website. pocketuniverse.app/insurance
49/72

A user opinion: Image
50/72

2️⃣ @peckshield - @AegisWeb3

PeckShield is a blockchain security company providing auditing and threat protection services, which also incubated Aegis, a security browser extension.
51/72

Among its services, @AegisWeb3 can:

⛔ Block phishing sites
💰 Check token contracts
📝 Manage approvals
⚠️ Report risks
52/72

Like Pocket Universe, AegisWeb3 also simulates transactions and displays the results to you. Image
53/72

3️⃣ @RevokeCash

Revoke is the browser extension of the popular website allowing you to revoke smart contract permissions.

The main purpose of this extension is to pop up and inform you of the approval details every time you are about to sign an approval transaction. Image
54/72

This also works for NFTs - and is a useful addition that works as an additional warning.

Currently, the Revoke extension is available on Ethereum, Polygon, and Avalanche. Image
55/72

Which one should I use? Is there any difference? 🤔

I wouldn’t be picky here tbh - you can easily download all of them and use your favorite ones interchangeably.
56/72

Some might miss specific transactions, that others may instead be aware of.

Using more than one will provide maximum security coverage! 🛡️
57/72

On the negative side of the Web3 browser extension, we have to mention the fact that as third parties dApps, they all require you to trust the developing team 👎
58/72

Sure, some of them come from teams like PeckShield, which is a known auditing company, but nonetheless installing a browser extension comes with third-party risks ⚠️
59/72

Installing an extension introduces new software to your browser—software that could potentially have security weaknesses (or be downright malicious). Third-party extensions might secretly include malware, or have security flaws that hackers can exploit ( @brave )
60/72

Furthermore, the use of browser extensions also implies the fact that our data and personal information will be collected and disclosed.

For instance, these are the terms and conditions of Pocket Universe with regard to information disclosure:
https://t.co/VxEzOhpAL7pocketuniverse.app/privacy-policy
Image
61/72

Just like wallets, browser extensions also gather and share your data with third parties.

As such, using them is not recommended for everyone 🙅
62/72

However, if you have an active wallet that you use frequently to transact, then browser extensions may come in handy to increase warnings of malicious contracts.

Here’s a more extensive article with more examples of Web3 browser extensions:

medium.com/@wiimee/web3-b…
63/72

Finally, regularly revoke all contracts 🚫

This very easy practice is often overlooked and can go a long way to save your ass-ets.

You can do so within @Rabby_io or on @RevokeCash
64/72

Aside from the ones we have already mentioned, there are a couple of bonus measures you should be aware of.
65/72

Disposable Addresses 🗑️ ♻️

Ideally, you should never use any of your addresses more than once.

Every time you are transacting, you are supposed to create a new one, to preserve your privacy.

While admittedly cumbersome, disposable addresses are gaining traction.
66/72

@AirGap_it 🌬️

Did you know that you can easily turn your phone into a cold wallet?

Airgap is an interesting solution whereby you download an app and you are able to use 2 phones one of which is not connected to the internet to create a cold wallet. Image
67/72

@WalletScrutiny 🐕

As mentioned above, most wallets are not open-source - you can use some tools such as Wallet Scrutiny to verify whether a wallet is secure and open-source.walletscrutiny.com
68/72

Using an encrypted email provider and never linking your phone number to crypto platforms are also two other best practices. Image
69/72

More best practices from @officer_cia: Image
70/72

I am by no means a security expert.

But that’s the beauty of it. You don’t really need to be.

There’s no barrier stopping you from stepping up your security literally right now.
71/72

But if you do want to learn more from an expert on the subject I highly recommend you take a look at @officer_cia Blog, which is the main source of some of the materials I used for this article:

officercia.mirror.xyz
72/72

..and his thread on the subject:

Special Mentions ⬇️ 🧠

@Rabby_io
@DeBankDeFi
@Plumferno
@DefiLlama
@LouisCooper_
@blockworksres
@adamscochran
@poopmandefi
@Slappjakke
@Hercules_Defi
@Deebs_DeFi
@Moomsxxx
@Cryptoalpharian
@Haylesdefi
@CryptoStreamHub
@CryptMoose_
@the_smart_ape
@C4dotgg
@OvrCldJonny
@Rektfencer
@0xFlips
@0xSalazar
@WinterSoldierxz
@0xcrypto_doctor
@Jake_pahor
@CryptoKoryo
@ThorHartvigsen
@rektdiomedes
@0xFlips
@0xFinish
@VirtualKenji
@JiraiyaReal
@TheNorwegianNFT
@officer_cia
Please leave a like and retweet
if you enjoyed this thread!

Comment if you have any feedback!

And Follow me @francescoweb3.

Subscribe to my Blog for more articles!
(it's free - LINK IN BIO)

Thanks
Full article on: tinyurl.com/6h9ch83j

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with francesco

francesco Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @francescoweb3

Jul 20
The Solana Renaissance: Solana 2.0

Are you ready for the most hated rally? 📈 ⬇️ Image
Following the debacle of FTX, Solana has been slowly growing up as a puppy tiger left alone in the forest. Image
Some projects left, notably the DeGods, while others have remained, declaring their loyalty to the chain.

Nowadays seems that Solana is having a bit of a renaissance and most are getting ready for what they call “the most hated rally ever”.
Read 31 tweets
Jul 3
Unlocking DeFi's Potential on Bitcoin 🟠
while Preserving Protocol Security and Decentralization ✨

An Introduction to @stacks ⬇️ 🔵
After a very uncertain period, the market is finally moving again.

Bitcoin has climbed back to $30k, an important and symbolic support 📈

As such, enthusiasm is slowly starting to spark.

Are we really going up? 🔮 ✨

I switch from max pain to max euphoria a few times a day 🤢
Well, there’s no certainty on where we are right now, but one thing we do know: whenever there’s a market reversal towards the upside after a bottom, Bitcoin is the first asset to rise 🟠 📈
Read 74 tweets
Jun 26
Did you know that @MakerDAO just hiked the Interest Rates of DeFi?

This is a Big Deal: the DeFi equivalent of the FED adjusting the interest rate for the US Dollar 🇺🇸

⬇️
Maker DAO is a key DeFi protocol where users provide liquidity and in turn can borrow DAI, a decentralized stablecoin.
For most people, this is nonsense jargon, but this simple change will have faraway consequences and a ripple effect all over DeFi.
Read 27 tweets
Jun 15
What’s better than some good news in days of FUD?

🌐 Eigen Layer Launches Restaking on Ethereum Mainnet ⬇️ Image
What is Eigen Layer? 🤔

In a few words, is a protocol that allows ETH stakers to opt-in and reuse their ETH on the consensus layer.

Stakers can opt-in to EigenLayer and have additional staking opportunities by extending security to other applications to earn extra yields 🤑
This has positive contributions since reusing ETH to provide security:

💸 Reduced capital costs for stakers
🛡️ Increased trust guarantees for services
Read 40 tweets
Jun 13
How to Become a Digital Resident of Palau and
Get your own Blockchain-based Web3 🆔

⬇️ Image
Palau is a beautiful island off the coast between the Philippines and Papua New Guinea, offering a Digital Residency Program that is designed for Web3! ⛓️ 🌐 Image
This comes as no surprise as Palau's president has recently been hosted on the Network State podcast by @balajis , mentioning his plan to leave a mark in Web3

⬇️
Read 19 tweets
Jun 12
Tired of getting wrecked by market volatility?

@goodentrylabs is here to help you trade without liquidations and drawdowns ⬇️ 🟢 Image
On Good Entry you can avoid liquidation by price using Protected Perps.

How can they do so? 🤯

They leverage 🦄 Uniswap v3 liquidity and lend it to traders 👀

🚨 This post in particular has been sponsored by the Good Entry team, nonetheless, I see potential in this protocol and its features and am contemplating a long-term partnership with them! 🤝

Let’s get to it.
Read 40 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(